Security Detection Engineer

McCabe & Barton

Greater London

On-site

GBP 70,000 - 110,000

Full time

8 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

McCabe & Barton in the United Kingdom seeks an experienced Security Detection Engineer to own detection engineering and threat hunting across Azure and GCP environments. This hands-on role requires strong SIEM, cloud security, and automation expertise to operate independently in a fast-paced setting.

You will design and implement detection rules in Datadog or Sentinel, integrate monitoring with Azure and GCP, and automate alert triage using Terraform and scripting.

Qualifications

  • Extensive experience building detection rules (SIEM/EDR/cloud-native tools).
  • Deep knowledge of attack patterns (MITRE ATT&CK).
  • Experience in SOC operations, threat analysis, or incident response.
  • Familiarity with Azure Monitor and Log Analytics.
  • Understanding of GCP Cloud Logging and Cloud Security Command Center.
  • Proficiency in SQL; scripting in Python or PowerShell.
  • Experience with Azure security architecture (Entra ID, networking, identity).
  • Knowledge of financial services threats and regulatory requirements (DORA, FCA, SOC2).

Responsibilities

  • Design and implement detection rules in Datadog or Sentinel/SIEM equivalent.
  • Support UEBA to catch compromise early.
  • Use Claude Code to develop detection logic and correlation rules.
  • Build AI-powered anomaly detection (user behaviour, access patterns).
  • Automate alert triage and prioritization.
  • Integrate Datadog with Azure monitoring and GCP Cloud Logging.
  • Use Terraform to automate detection deployment and configuration.
  • Develop custom metrics and alerting for deal-sensitive operations.

Skills

Detection engineering
SIEM
Cloud security
Automation
Datadog
Azure Monitor
GCP Cloud Logging
Terraform
Python
PowerShell
SQL
EDR
MITRE ATT&CK
UEBA
On-call readiness

Tools

Datadog
Terraform
CrowdStrike
Microsoft Defender
Azure Sentinel
GCP Cloud Logging

Job description

We are looking for an experienced Security Detection Engineer to take ownership of detection engineering, and threat hunting across Azure and GCP environments.

This is a hands-on opportunity for a security professional with strong SIEM, cloud security, and automation expertise who can operate independently in a fast-paced environment.

Key Responsibilities
Detection Engineering & SIEM Uplift
  • Design and implement detection rules in Datadog (or Sentinel/SIEM equivalent)
  • Support UEBA (User & Entity Behaviour Analytics) to catch compromise early
  • Use Claude Code to develop detection logic and correlation rules
  • Build AI-powered anomaly detection (user behaviour, access patterns)
  • Automate alert triage and prioritization
Platform Integration & Automation
  • Integrate Datadog with Azure monitoring and GCP Cloud Logging
  • Use Terraform to automate detection deployment and configuration
  • Develop custom metrics and alerting for deal-sensitive operations
Required Experience & Skills
Core Detection & Threat Analysis
  • Experienced building detection rules (SIEM, EDR, or cloud-native tooling)
  • Deep understanding of attack patterns (MITRE ATT&CK framework)
  • SOC operations, threat analysis, or incident response
  • Azure Monitor and Log Analytics familiarity
  • GCP Cloud Logging and Cloud Security Command Center desirable
Technical Engineering
  • SQL proficiency (query security events, build custom reports)
  • Python or PowerShell (detection automation, data enrichment)
  • Azure security architecture (Entra ID, networking, identity)
  • Snowflake security fundamentals
  • EDR platform experience (CrowdStrike, Microsoft Defender, or similar)
Security & Compliance
  • Knowledge of financial services threats (insider threats, data theft, credential abuse)
  • Understanding of regulatory requirements (DORA, FCA, SOC2)
  • Familiarity with incident response frameworks
  • Comfortable in 24/7 on-call environment during integration crisis period
  • Seasoned Security engineer who can operate independently
  • Experience of hands-on detection/threat analysis
  • Strong technical foundations (SQL, Python, cloud platforms)
  • Integration or M&A security experience
  • Forward-thinking mindset (AI-assisted security, emerging threats)
  • Independent operator (self-directed in ambiguous environment)
  • Datadog OR Sentinel experience (or very strong hands-on SIEM background)
  • Open-source and modern tech stack comfortable
  • Snowflake and/or data platform security exposure valuable
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Engineer - Threat Detection
Cyber Security Engineer - Threat Detection

Intercontinental Exchange Holdings, Inc. • City Of London

On-site
GBP 70,000 - 110,000
Security Engineer - Detection & Response | Leading Global Investment Group
Security Engineer - Detection & Response | Leading Global Investment Group

Techfellow Limited • Greater London

Hybrid
GBP 250,000 - 350,000
Senior Detection and Response Engineer
Senior Detection and Response Engineer

Jobtailor • Cambridge

On-site
GBP 65,000 - 95,000
Cyber Security Engineer
Cyber Security Engineer

La Fosse • Greater London

On-site
GBP 60,000 - 80,000
Senior Security Engineer - Contract
Senior Security Engineer - Contract

United States Digital Space LLC • Greater London

On-site
GBP 70,000 - 110,000
Cyber Security Engineer - Threat Detection
Cyber Security Engineer - Threat Detection

ICE Clear Europe Limited • Greater London

Hybrid
GBP 70,000 - 120,000
Junior Security Engineer
Junior Security Engineer

Cybanetix • Greater London

On-site
GBP 50,000 - 70,000
Hands-on experience with modern SIEM, EDR, and Azure security tooling
Structured progression into security engineering
Mentorship from senior engineers and architects
Cyber Security Engineer - Threat Detection
Cyber Security Engineer - Threat Detection

ICE • Greater London

On-site
GBP 85,000 - 110,000
Senior Security Engineering Consultant
Senior Security Engineering Consultant

Infosec • Basingstoke

Hybrid
GBP 56,000 - 80,000
Salary up to £80,000
Bonuses
Hybrid work
Lead Security Operations Engineer
Lead Security Operations Engineer

Jobtailor • Greater London

On-site
GBP 120,000 - 170,000