Security Detection Engineer
  • England,London,City of London
  • Full Time, Permanent
  • Competitive salary
Job Description:
Full job description Security Detection Engineer
London (Hybrid)
£600-£750 per day (Inside IR35)
Initial 6-Month Contract
We are looking for an experienced SecurityDetection Engineer to take ownership of detection engineering, and threat hunting across Azure and GCP environments.
This is a hands-on opportunity for a security professional with strong SIEM, cloud security, and automation expertise who can operate independently in a fast-paced environment.
Key Responsibilities
Detection Engineering & SIEM Uplift
*Design and implement detection rules in Datadog (or Sentinel/SIEM equivalent)
*Support UEBA (User & Entity Behaviour Analytics) to catch compromise early
*Use Claude Code to develop detection logic and correlation rules
*Build AI-powered anomaly detection (user behaviour, access patterns)
*Automate alert triage and prioritization
Platform Integration & Automation
*Integrate Datadog with Azure monitoring and GCP Cloud Logging
*Use Terraform to automate detection deployment and configuration
*Build CI/CD for detection rules (version control, testing, rollback)
*Develop custom metrics and alerting for deal-sensitive operations
Required Experience & Skills
Core Detection & Threat Analysis
*Experienced building detection rules (SIEM, EDR, or cloud-native tooling)
*Deep understanding of attack patterns (MITRE ATT&CK framework)
*SOC operations, threat analysis, or incident response
Datadog & Cloud Monitoring
*Hands-on Datadog OR equivalent Sentinel/SIEM experience
*Azure Monitor and Log Analytics familiarity
*GCP Cloud Logging and Cloud Security Command Center desirable
Technical Engineering
*SQL proficiency (query security events, build custom reports)
*Python or PowerShell (detection automation, data enrichment)
*Terraform (automate detection deployment) essential
*YAML (configuration management for detections)
Cloud & Data Platforms
*Azure security architecture (Entra ID, networking, identity)
*GCP security basics desirable
*Snowflake security fundamentals
*EDR platform experience (CrowdStrike, Microsoft Defender, or similar)
Security & Compliance
*Knowledge of financial services threats (insider threats, data theft, credential abuse)
*Understanding of regulatory requirements (DORA, FCA, SOC2)
*Familiarity with incident response frameworks
*Comfortable in 24/7 on-call environment during integration crisis period
Ideal candidate:
*Seasoned Security engineer who can operate independently
*Experience of hands-on detection/threat analysis
*Strong technical foundations (SQL, Python, cloud platforms)
*Integration or M&A security experience
*Forward-thinking mindset (AI-assisted security, emerging threats)
*Independent operator (self-directed in ambiguous environment)
*Datadog OR Sentinel experience (or very strong hands-on SIEM background)
*Open-source and modern tech stack comfortable
*Snowflake and/or data platform security exposure valuable
Job number 4215000
The jobs on site are for both men and women