Lead Detection and Response Engineer

Open Select

Greater London

Hybrid

GBP 122,000 - 149,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Open Select in London is seeking a hands-on Detection Engineer to build a from-scratch security detection and response capability for a fintech platform handling large daily transactions.

You will implement telemetry, tooling, and processes across AWS, on‑premise, Workforce IT and endpoints, reporting to the CISO and CTO.

Responsibilities include MITRE ATT&CK coverage, SOAR-driven containment, threat hunting, and leadership in a growing security function.

Qualifications

  • Hands-on detection engineering experience with SIEM and detection-as-code pipelines.
  • Strong Python development for detection, parsing and automation.
  • Incident response leadership with P1/P2 investigations.
  • Experience with cloud security on AWS and/or Azure and native telemetry.
  • Familiarity with MITRE ATT&CK for detection design and gaps.
  • Experience building SOAR playbooks across SIEM/EDR/cloud/ticketing.
  • Ability to influence stakeholders and translate technical findings.

Responsibilities

  • Build detection and response capability from ground up, with telemetry and tooling.
  • Create asset/telemetry maps across AWS, on-prem, Workforce IT and endpoints.
  • Develop risk-based plan for hybrid SOC using engineering collaboration.
  • Define MITRE ATT&CK coverage for Tier 1 tactics and maintain as code.
  • Author and maintain incident playbooks; automate containment via SOAR.
  • Set and monitor MTTD/MTTR baselines; lead threat hunting cycles quarterly.
  • Review unpatchable vulns with engineering and propose remediation.
  • Produce monthly detection and response metrics for leadership.

Skills

Detection engineering
Python
Incident response
MITRE ATT&CK
SOAR
SIEM
EDR
Threat hunting
Cloud security
Stakeholder communication
Leadership

Tools

AWS
Azure
SIEM
SOAR
EDR
Git
Ticketing systems

Job description

Location: London / hybrid (2 days onsite)

Salary: Total compensation up to £135,000

Industry: Fintech / Securities Finance Technology

Work Authorization: This role requires the right to work in the UK, no sponsorship available

Who you'll join

Our client is a London based fintech that automates the securities finance lifecycle. The platform processes over $6.5 trillion in transactions every day, connecting more than 150 financial institutions worldwide, including 25 of the 30 global systemically important banks.

You will report directly into the CISO and CTO, with real scope to shape how the company detects and responds to threats.

What you'll do
  • Build the company's detection and response capability from the ground up, establishing the processes, telemetry and tooling needed to detect, investigate and contain threats across AWS, on premises, Workforce IT and the endpoint estate
  • Produce a documented asset and telemetry map across AWS, on premises, Workforce IT and user endpoints
  • Assess current security monitoring and third party SOC coverage against LLM enabled attacks. Deliver a risk based plan using a hybrid SOC model, working with engineering teams to implement it
  • Build documented MITRE ATT&CK detection coverage across all Tier 1 tactics within 12 months, managed as code and version controlled
  • Author and maintain playbooks for the top incident types by likelihood and impact. Automate containment and response actions through SOAR, targeting 80% automated first action on P1 and P2 responses
  • Establish MTTD and MTTR baselines within 90 days and set improvement targets
  • Run structured threat hunting cycles each quarter and convert findings into new detection rules
  • Review unpatchable vulnerabilities with engineering teams and recommend treatment
  • Produce a monthly detection and response programme metrics report for the CISO and CTO
  • Build internal security capability through knowledge sharing, runbook documentation and structured mentoring as the team grows
Who you are
  • Hands on detection engineering experience, writing and maintaining SIEM detection rules, correlation logic and detection as code pipelines
  • Proficient in Python or equivalent for detection development, log parsing and automation
  • Demonstrated incident response experience, leading or contributing to P1 and P2 investigations, post incident reviews and containment
  • Experience with cloud security on AWS and/or Azure, including native cloud telemetry sources
  • Familiar with MITRE ATT&CK as a framework for detection design and gap analysis
  • Hands on experience building and operating SOAR playbooks and response automation across SIEM, EDR, cloud and ticketing
  • Experience leading a SOC and/or managing a third party SOC
  • Demonstrated experience running structured threat hunting cycles
  • Able to influence stakeholders across the technology team. Strong written communication, able to translate technical findings for non-technical stakeholders
  • Able to work independently and collaborate with technical stakeholders across the business

Cloud: AWS (primary), SIEM, SOAR, EDR, Python for detection development, log parsing and automation, MITRE ATT&CK as the detection design and gap analysis framework, Detection as code, version controlled (Git or equivalent), Ticketing and workflow tooling across SIEM, EDR, cloud and ticketing systems

Why you'll join
  • Genuine build from scratch mandate. You are not inheriting someone else's detection stack, you are designing it
  • High stakes, high trust environment. The platform underpins $6.5 trillion in daily transactions for 25 of the 30 global systemically important banks
  • Direct line into the CISO and CTO, with real visibility on your work at leadership level
  • A clear path to building and leading a team as the function grows
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer - Detection & Response | Leading Global Investment Group
Security Engineer - Detection & Response | Leading Global Investment Group

Techfellow Limited • Greater London

Hybrid
GBP 250,000 - 350,000
Lead Threat Detection Engineer
Lead Threat Detection Engineer

Orbis Group • Greater London

On-site
GBP 72,000 - 120,000
Senior Security Engineering Consultant
Senior Security Engineering Consultant

Infosec • Southampton

Hybrid
GBP 72,000 - 88,000
Performance-based bonuses
Collaborative engineering environment
Industry-leading benefits
Principal Analyst Detection Engineering - Technology Vendor
Principal Analyst Detection Engineering - Technology Vendor

Hamilton Barnes Associates Limited • United Kingdom

Remote
GBP 60,000 - 70,000
Remote-first with travel
Senior Security Engineering Consultant
Senior Security Engineering Consultant

Infosec • Basingstoke

Hybrid
GBP 56,000 - 80,000
Salary up to £80,000
Bonuses
Hybrid work
Senior Detection & Response Engineer - From-Scratch Build
Senior Detection & Response Engineer - From-Scratch Build

Open Select • Greater London

Hybrid
GBP 122,000 - 149,000
Lead Detection & Response Engineer
Lead Detection & Response Engineer

Lloyds Banking Group • Leeds

Hybrid
GBP 90,000 - 120,000
30 days holiday
Discretionary award
Flexible benefits
+1
Lead Detection & Response Engineer
Lead Detection & Response Engineer

Lloyds Banking Group • West of England

Hybrid
GBP 73,000 - 81,000
Senior Detection and Response Engineer
Senior Detection and Response Engineer

Jobtailor • Cambridge

On-site
GBP 65,000 - 95,000
Detection & Response Engineer
Detection & Response Engineer

Lloyds Banking Group • Manchester

Hybrid
GBP 65,000 - 100,000
30 days holiday
Generous pension contribution
Private health cover
+2