Detection Engineer & Threat Hunter – SIEM & Cloud Security

Starling

Cardiff

Hybrid

GBP 70,000 - 110,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Private Medical Insurance
Life Insurance
Pension scheme
Cycle to Work
Salary Sacrificed Gym Partnerships
EV leasing

Job summary

Starling Bank is seeking a passionate Detection Engineer and Threat Hunter to join our Security Operations team. You will design, tune, and maintain detection rules across SIEMs, while proactively hunting for threats in cloud, SaaS, and endpoint environments.

You will collaborate with the Purple Team, provide incident response support, and help operationalise threat intelligence to strengthen our security posture. Hybrid working with office presence required.

Qualifications

  • 3+ years in a technical security role (detection engineering, threat hunting, incident response, or threat intelligence).
  • Strong understanding of MITRE ATT&CK and how to apply it to detection.
  • Extensive SIEM experience with rule/query development and analytics.
  • Solid knowledge of cloud security (AWS, GCP, Azure) and related risks.
  • Experience with EDR tools and endpoint detection strategies.

Responsibilities

  • Design, build, test, and maintain high-fidelity detection rules and analytics in SIEMs.
  • Proactively hunt for attacker TTPs across cloud, SaaS, and endpoints.
  • Collaborate with Adversarial Simulation teams in Purple Team exercises.
  • Act as Incident Response SME during security incidents with deep technical analysis.
  • Integrate and operationalise threat intelligence to inform detection strategies.
  • Collaborate with Security Operations and stakeholders to uplift Starling’s security posture.
  • Maintain documentation for detection rules, hunting playbooks, and processes.

Skills

Detection engineering
Threat hunting
SIEM expertise
Cloud security
EDR proficiency
OS internals
Scripting (Python)
Docker & Kubernetes security
SOAR platforms
Incident response
Threat intelligence

Tools

Splunk
Elastic
Google SecOps
AWS
Azure
GCP
CrowdStrike
SentinelOne
Cortex XDR
SOAR

Job description

Starling Bank is seeking a passionate Detection Engineer and Threat Hunter to join our Security Operations team. You will design, tune, and maintain detection rules across SIEMs, while proactively hunting for threats in cloud, SaaS, and endpoint environments.

You will collaborate with the Purple Team, provide incident response support, and help operationalise threat intelligence to strengthen our security posture. Hybrid working with office presence required.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Threat Hunter & Detection Engineer | Hybrid Role | Cloud & SIEM
Threat Hunter & Detection Engineer | Hybrid Role | Cloud & SIEM

Starling • Greater London

Hybrid
GBP 80,000 - 120,000
25 days holiday
Birthday day off
Pension scheme
+8
Detection Engineer & Threat Hunter — SecOps
Detection Engineer & Threat Hunter — SecOps

Starling • Manchester

Hybrid
GBP 70,000 - 110,000
Annual leave 25 days
Private Medical Insurance
Pension scheme
+2
Detection Engineer & Threat Hunter - Hybrid Security Ops
Detection Engineer & Threat Hunter - Hybrid Security Ops

Starling • Southampton

Hybrid
GBP 65,000 - 90,000
Private Medical Insurance with Vitalty
Cycle to Work
Life Insurance 4x salary
+2
Information Security Analyst - SecOps Detection
Information Security Analyst - SecOps Detection

Starling • Greater London

On-site
GBP 80,000 - 120,000
25 days holiday
Birthday day off
Pension scheme
+8
Information Security Analyst - SecOps Detection
Information Security Analyst - SecOps Detection

Starling • Manchester

Hybrid
GBP 70,000 - 110,000
Annual leave 25 days
Private Medical Insurance
Pension scheme
+2
Information Security Analyst - SecOps Detection
Information Security Analyst - SecOps Detection

Starling • Cardiff

On-site
GBP 70,000 - 110,000
Private Medical Insurance
Life Insurance
Pension scheme
+3
Information Security Analyst - Secops Detection
Information Security Analyst - Secops Detection

Starling • Southampton

On-site
GBP 65,000 - 90,000
Private Medical Insurance with Vitalty
Cycle to Work
Life Insurance 4x salary
+2
Incident Response Lead - Cloud & Forensics (Hybrid)
Incident Response Lead - Cloud & Forensics (Hybrid)

Starling • Cardiff

Hybrid
GBP 55,000 - 90,000
Private Medical Insurance
Life insurance 4x salary
Perkbox membership
+1
Threat Detection Engineer – Cybersecurity & Threat Hunting
Threat Detection Engineer – Cybersecurity & Threat Hunting

PowerToFly • Glasgow

On-site
GBP 70,000 - 100,000
Flexible working opportunities
Employee benefits
Equal opportunity employer
Hybrid InfoSec Incident Response Analyst | Cloud Forensics
Hybrid InfoSec Incident Response Analyst | Cloud Forensics

JOBS247 INC LTD • Southampton

Hybrid
GBP 60,000 - 90,000
25 days holiday
Company enhanced pension
Buy/sell up to five extra days off