Security Detection Engineer - Cloud SIEM & Threat Hunting

McCabe & Barton

Greater London

On-site

GBP 70,000 - 110,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

McCabe & Barton in the United Kingdom seeks an experienced Security Detection Engineer to own detection engineering and threat hunting across Azure and GCP environments. This hands-on role requires strong SIEM, cloud security, and automation expertise to operate independently in a fast-paced setting.

You will design and implement detection rules in Datadog or Sentinel, integrate monitoring with Azure and GCP, and automate alert triage using Terraform and scripting.

Qualifications

  • Extensive experience building detection rules (SIEM/EDR/cloud-native tools).
  • Deep knowledge of attack patterns (MITRE ATT&CK).
  • Experience in SOC operations, threat analysis, or incident response.
  • Familiarity with Azure Monitor and Log Analytics.
  • Understanding of GCP Cloud Logging and Cloud Security Command Center.
  • Proficiency in SQL; scripting in Python or PowerShell.
  • Experience with Azure security architecture (Entra ID, networking, identity).
  • Knowledge of financial services threats and regulatory requirements (DORA, FCA, SOC2).

Responsibilities

  • Design and implement detection rules in Datadog or Sentinel/SIEM equivalent.
  • Support UEBA to catch compromise early.
  • Use Claude Code to develop detection logic and correlation rules.
  • Build AI-powered anomaly detection (user behaviour, access patterns).
  • Automate alert triage and prioritization.
  • Integrate Datadog with Azure monitoring and GCP Cloud Logging.
  • Use Terraform to automate detection deployment and configuration.
  • Develop custom metrics and alerting for deal-sensitive operations.

Skills

Detection engineering
SIEM
Cloud security
Automation
Datadog
Azure Monitor
GCP Cloud Logging
Terraform
Python
PowerShell
SQL
EDR
MITRE ATT&CK
UEBA
On-call readiness

Tools

Datadog
Terraform
CrowdStrike
Microsoft Defender
Azure Sentinel
GCP Cloud Logging

Job description

McCabe & Barton in the United Kingdom seeks an experienced Security Detection Engineer to own detection engineering and threat hunting across Azure and GCP environments. This hands-on role requires strong SIEM, cloud security, and automation expertise to operate independently in a fast-paced setting.

You will design and implement detection rules in Datadog or Sentinel, integrate monitoring with Azure and GCP, and automate alert triage using Terraform and scripting.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Detection Engineer
Security Detection Engineer

McCabe & Barton • Greater London

On-site
GBP 70,000 - 110,000
Azure Vulnerability Engineer: Cloud Security & Automation
Azure Vulnerability Engineer: Cloud Security & Automation

McCabe & Barton • Greater London

On-site
GBP 70,000 - 110,000
Security Operations Engineer - Threat Detection
Security Operations Engineer - Threat Detection

Perk • Greater London

On-site
GBP 72,000 - 85,000
Equity options
Private medical insurance
Life insurance
+2
Contract Senior Security Engineer: Azure & SIEM
Contract Senior Security Engineer: Azure & SIEM

Flagstone Group • Greater London

Hybrid
GBP 90,000 - 120,000
Security Monitoring Engineer - SIEM & Cloud Threat Detection
Security Monitoring Engineer - SIEM & Cloud Threat Detection

Forsyth Barnes • Manchester

Hybrid
GBP 50,000 - 70,000
Cloud Security Engineer - Azure | SIEM & Threat Defense
Cloud Security Engineer - Azure | SIEM & Threat Defense

Computershare • West of England

Hybrid
GBP 28,000 - 45,000
Flexible working
Hybrid role (Bristol/Edinburgh)
Health and wellbeing rewards
+3
Cyber Security Engineer
Cyber Security Engineer

La Fosse • Greater London

On-site
GBP 60,000 - 80,000
Cyber Security Engineer - Threat Detection
Cyber Security Engineer - Threat Detection

Intercontinental Exchange Holdings, Inc. • City Of London

On-site
GBP 70,000 - 110,000
Remote UK: Threat Detection Content Engineer
Remote UK: Threat Detection Content Engineer

BlueVoyant • United Kingdom

Remote
GBP 75,000 - 120,000
Security Engineer, AWS SOC — Detections & Automation
Security Engineer, AWS SOC — Detections & Automation

Amazon Web Services (AWS) • Greater London

On-site
GBP 70,000 - 100,000