Cyber Threat Engineer

Dojo

Greater London

On-site

GBP 85,000 - 120,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Dojo is reinventing payments with a rapidly growing security function. We seek a Cyber Threat Engineer to lead detection, response, and tooling improvements in our Cyber Defence Centre.

You will own threat hunting across cloud, network, and endpoint, optimize SIEM/SOAR tooling, and evolve IaC security pipelines while mentoring teammates and driving security metrics.

Qualifications

  • Security Engineering or Incident Response background in fast-paced environments.
  • Hands-on experience with SIEM and SOAR platforms; Google SecOps preferred.
  • Proficiency in Python or Go and maintaining Infrastructure as Code pipelines.
  • Strong experience in cloud environments (GCP and AWS).
  • Deep understanding of threat actors, TTPs, and root cause analysis.

Responsibilities

  • Triage alerts, coordinate end-to-end security incident management, and conduct root cause analysis.
  • Conduct proactive threat hunting across network, endpoint, and cloud environments to uncover hidden threats.
  • Maintain and optimize critical security tooling (SIEM, EDR, SOAR).
  • Maintain and update Infrastructure as Code (IaC) pipelines to ensure security configurations and tools are consistently applied.
  • Build high-fidelity detection rules and design SOAR playbooks to automate workflows and enrich alerts.
  • Identify visibility gaps and engineer solutions to advance security operations capabilities.
  • Mentor team members in automation practices and produce metrics and dashboards.

Skills

Security Engineering
Incident Response
Threat hunting
Scripting (Python/Go)
Cloud (GCP/AWS)
SOAR
Collaborative work

Tools

SIEM
SOAR
Python
Go
IaC Pipelines

Job description

We're reinventing payments. In less than four years, Dojo disrupted the market to become the largest and most loved acquirer in the UK. Our payments infrastructure, purpose-built for in-person commerce, is game changing.

Now, over 150,000 customers across four countries choose to transact billions with us every year. But we're just getting started.

Our people are the driving force behind our success. They are our greatest investment and our ultimate competitive advantage. We hire exceptional people and give them the autonomy, trust, and ownership to thrive. The results take care of themselves.

The Role

As a Cyber Threat Engineer within our Cyber Defence Centre, you will bridge the gap between security engineering and incident response operations. You will champion the health, optimization, and evolution of our security tooling while leading active detection and response efforts. In this pivotal role, you will take ownership of safeguarding our systems and collaborate across teams to protect our mission as we transform the payments sector.

What You Will Do...
  • Triage alerts, coordinate end-to-end security incident management, and conduct root cause analysis.
  • Conduct proactive threat hunting across network, endpoint, and cloud environments to uncover hidden threats.
  • Maintain and optimize critical security tooling (SIEM, EDR, SOAR).
  • Maintain and update our Infrastructure as Code (IaC) pipelines to ensure security configurations and tools are consistently applied and managed.
  • Build high-fidelity detection rules and design SOAR playbooks to automate workflows and enrich alerts.
  • Identify visibility gaps and engineer solutions to continually advance our security operations capabilities.
  • Mentor team members in automation practices and produce insightful metrics and reporting dashboards.
What You Will Bring...
  • Proven background in Security Engineering or Incident Response within fast-paced environments.
  • Hands-on expertise with SIEM and SOAR platforms, with Google SecOps experience strongly preferred.
  • Proficiency in scripting (e.g., Python, Go) and maintaining Infrastructure as Code (IaC) pipelines.
  • Strong experience working within cloud environments, particularly Google Cloud Platform (GCP) and AWS.
  • Deep understanding of threat actors, TTPs, and a structured approach to root cause analysis.
  • Strong collaborative skills to partner across teams, understand attack surfaces, and drive security improvements.
Dojo home and away

We believe our best work happens when we collaborate in-person. These "together days" foster communication, drive innovation and spark our brightest ideas. That's why we have an office-first culture. This means working from the office 4+ days per week. With offices across Europe, we know a thing or two about staying dynamic. Need deep focus? Head to a quiet zone. Big ideas? Collaboration spaces have you covered. Just here for a catch-up? Our social hubs make it easy. Do work that counts, in spaces made for you.

Question: what's curious, relentless, and customer obsessed?

If you're keen to know the answer, you're a third of the way to meeting our Dojo values.

If The Following Speak To You, Let's Talk

You're curious. You have a real desire to learn and create.

You're relentless. You keep going even when it's easier not to.

You're customer-obsessed. You know how important customers are to what you do.

Diversity, equity, and inclusion at Dojo

From local bakeries to well-known eateries, Dojo payments serve over 150,000 places across the UK.

And something that's fundamental to creating relevant, innovative products at Dojo is to build teams to reflect the diversity of the businesses we serve.

Our drive to improve diversity, equity, and inclusion is closely linked to helping employees thrive and innovating for better customer experiences.

If you care about your work, you're curious, and you think customer-first, you have a place at Dojo.

To make sure you're the best you can be throughout the recruitment process, let us know if you need any extra adjustments to help you thrive.

Visit dojo.careers to find out more about our benefits and what it's like to work at Dojo, or check out our LinkedIn and Instagram pages.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Product Security Engineer
Senior Product Security Engineer

Dojo • Greater London

On-site
GBP 80,000 - 110,000
Head of Financial Crime & DMLRO
Head of Financial Crime & DMLRO

Paymentsense • Greater London

On-site
GBP 120,000 - 180,000
Office‑first culture
Collaborative environment
Software Engineer .NET
Software Engineer .NET

Dojo • London

On-site
GBP 40,000 - 70,000
Collaborative office environment
Career development opportunities
Diversity and inclusion initiatives
Workplace Technology Specialist
Workplace Technology Specialist

Paymentsense • West of England

On-site
GBP 30,000 - 42,000
Workplace Technology Specialist
Workplace Technology Specialist

Dojo • West of England

On-site
GBP 28,000 - 42,000
Engineering Manager
Engineering Manager

Dojo • Greater London

On-site
GBP 120,000 - 180,000
Senior Product Manager - Finance
Senior Product Manager - Finance

Paymentsense • Greater London

On-site
GBP 85,000 - 105,000
Office-first culture
In-office collaboration spaces
Quiet zones
+1
Field Support Administrator (4-month Secondment)
Field Support Administrator (4-month Secondment)

Dojo • Hull and East Yorkshire

On-site
GBP 20,000 - 28,000
Senior Product Manager - Finance
Senior Product Manager - Finance

Dojo • Greater London

On-site
GBP 90,000 - 120,000
Marketing Operations Lead
Marketing Operations Lead

Dojo • Greater London

On-site
GBP 70,000 - 110,000