Lead Threat Detection Engineer

Orbis Group

Greater London

On-site

GBP 72,000 - 120,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Orbis Group is seeking a Lead Threat Detection Engineer in London to own and evolve our threat detection lifecycle across a multi-cloud environment. You will build and refine SIEM detections, automate response, and work with engineering to turn findings into scalable security improvements.

The role emphasizes hands-on threat hunting, threat intelligence, and clear ownership of security outcomes in a fintech-oriented landscape, with a base salary up to £120k plus bonus.

Qualifications

  • Experience building detections, not only responding to alerts.
  • Strong SIEM experience with Microsoft Sentinel, Splunk or similar.
  • Cloud security across AWS, GCP and Azure.
  • Experience with KQL, SPL or similar querying.
  • Python scripting and security automation.
  • Terraform / Infrastructure as Code exposure.
  • Threat intelligence or threat hunting experience.
  • Strong ownership and stakeholder communication.

Responsibilities

  • Own and improve threat detection lifecycle across cloud estate.
  • Build and enhance SIEM detections and monitoring.
  • Automate manual detection/remediation.
  • Develop threat intelligence and hunting capabilities.
  • Improve security monitoring across AWS, GCP, Azure.
  • Collaborate with engineering to translate findings into improvements.
  • Review tooling and influence future tech decisions.
  • Provide technical leadership and upskill others.

Skills

SIEM experience
Cloud security
Querying skills
Python scripting
Terraform IaC
Threat intelligence
Threat hunting
Ownership
Communication

Job description

Lead Threat Detection Engineer| London | Up to £120k + Bonus

I'm working with a leading global fintech on a senior hire into a newly established security function.

This is a hands-on role for someone who wants to go beyond responding to alerts and take real ownership of how threat detection and intelligence is built, automated and improved across a large-scale, multi-cloud environment.

You’ll be joining at a point where the core security tooling is already in place, but there’s significant scope to define what best-in-class looks like.

What you’ll be doing:
  • Own and improve the threat detection lifecycle across a complex cloud estate
  • Build and enhance SIEM detection rules, use cases and monitoring
  • Automate manual detection and remediation processes
  • Develop threat intelligence and threat-hunting capabilities
  • Improve security monitoring across AWS, GCP and Azure
  • Work closely with engineering teams to turn security findings into scalable technical improvements
  • Review existing tooling and influence future technology decisions
  • Provide technical leadership and help upskill others across the security function
What we’re looking for:
  • Experience building detections rather than purely responding to SOC alerts
  • Strong SIEM experience – Microsoft Sentinel, Splunk or similar
  • Cloud security experience across AWS, GCP and/or Azure
  • KQL, SPL or similar querying experience
  • Python scripting / security automation
  • Terraform / Infrastructure as Code exposure
  • Experience with threat intelligence or threat hunting
  • Strong ownership and stakeholder communication skills

This would particularly suit someone from a fintech, payments or financial‑services environment who wants the opportunity to shape a growing security capability rather than inherit a finished one.

Up to £120k base + discretionary bonus

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer - Detection & Response | Leading Global Investment Group
Security Engineer - Detection & Response | Leading Global Investment Group

Techfellow Limited • Greater London

Hybrid
GBP 250,000 - 350,000
Cloud-Native Threat Detection Lead
Cloud-Native Threat Detection Lead

Orbis Group • Greater London

On-site
GBP 72,000 - 120,000
Cyber Security Engineer
Cyber Security Engineer

Additional Resources • Greater London

Hybrid
GBP 60,000 - 80,000
Lead Software Security Engineer
Lead Software Security Engineer

United States Digital Space LLC • Greater London

Hybrid
GBP 120,000 - 150,000
Pension scheme
Generous holiday allowance
Ongoing learning and professional development
Lead Security Engineer
Lead Security Engineer

Radley James • England

On-site
GBP 60,000 - 80,000
Competitive compensation
Growth opportunities
Collaborative culture
Senior Security Engineering Consultant
Senior Security Engineering Consultant

Infosec • Basingstoke

Hybrid
GBP 56,000 - 80,000
Salary up to £80,000
Bonuses
Hybrid work
Threat Detection Engineer — Cloud Security & AI Automation
Threat Detection Engineer — Cloud Security & AI Automation

Additional Resources • Greater London

Hybrid
GBP 60,000 - 80,000
Security Architect
Security Architect

Understanding Recruitment • Greater London

Hybrid
GBP 110,000 - 150,000
Hybrid working
London office access
Autonomy and ownership
+2
Cyber Security Lead
Cyber Security Lead

REX Cyber Security • Greater London

Hybrid
GBP 110,000 - 140,000
Lead Security Engineer
Lead Security Engineer

Ocho People • Belfast City District

Hybrid
GBP 90,000 - 120,000
Share options
Hybrid/Remote Belfast
35 days annual leave inc stats
+2