Security Monitoring & Detection Engineering Lead

Aj Bell

Manchester

On-site

GBP 90,000 - 120,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

AJ Bell is seeking a hands-on Cyber Defence Operations Lead to own the architecture, engineering and operational performance of Microsoft Sentinel and the wider security monitoring estate, based in Manchester.

You will translate real-world adversary behaviour into effective monitoring and response, drive complex investigations, develop playbooks and ensure coordinated action with the MSSP and internal teams to reduce risk.

Responsibilities

  • Own the technical direction, quality and delivery performance of Security Monitoring & Detection Engineering, translating priorities into a clear roadmap for monitoring, detection, investigation and response.
  • Lead the architecture, engineering and continued development of the SIEM solution, ensuring resilience, scalability and alignment with technology estate and threat profile.
  • Define onboarding of security telemetry across on-premises, Azure, AWS and third-party services, ensuring value for detection and investigation.
  • Own the detection engineering lifecycle from requirements to retirement, with version control and controlled release practices.
  • Lead analytics rules, hunting queries, workbooks and automated investigation and response workflows.
  • Ensure operational effectiveness of security solutions managed by CDO with measurable outcomes.
  • Drive threat-informed defence with Threat Intelligence and Exposure Management, translating adversaries into detections and defensive actions.
  • Maintain evidence-based service performance through KPIs and MI, driving corrective actions to measurable outcomes.
  • Lead technical escalation for complex security events, guiding investigations and containment.
  • Lead tabletop, purple-team and practical exercises to test detection coverage and readiness.
  • Operate the internal team and MSSP as one integrated monitoring and response capability, ensuring escalation consistency and performance.
  • Maintain alert demand, detection quality and MTTA/MTTR metrics to prioritise improvements.
  • Lead service reviews with vendors to maximise value of investments to CDO's objectives.
  • Identify and deliver automation opportunities across detection, enrichment, investigation and response.

Job description

The Cyber Defence Operations function protects AJ Bell against external adversaries and internal risks through four specialist capabilities: Security Monitoring & Detection Engineering, Cyber Threat Intelligence, Cyber Threat Exposure Management and Insider Risk Management. Together, these capabilities combine detection, intelligence, exposure management and insider risk to safeguard AJ Bell's customers, data, critical services and the trust placed in the firm. Security Monitoring & Detection Engineering provides an integrated monitoring, detection and response capability, combining internal technical expertise with 24x7 support from the Managed Security Service Provider. The Security Monitoring & Detection Engineering Lead is the principal technical authority for Security Monitoring & Detection Engineering capability, accountable for the effectiveness of security monitoring, detection engineering, technical investigation and incident response. This is a hands-on technical role responsible for the architecture, engineering and operational performance of Microsoft Sentinel and the wider security monitoring estate. The role would particularly suit an experienced detection engineering, security operations, red-team, purple-team or offensive-security leader who can translate real-world adversary behaviour into effective monitoring, detection and response. The role leads complex investigations and technical incident response, ensures the internal team and MSSP operate as one capability, and drives measurable improvements that reduce the potential for customer, operational, financial and regulatory harm.,

  • Own the technical direction, quality and delivery performance of Security Monitoring & Detection Engineering, translating CDO priorities into a clear roadmap for monitoring, detection, investigation and response.
  • Lead the architecture, engineering and continued development of our SIEM solution, ensuring the SIEM remains resilient, scalable, cost-effective and aligned with AJ Bell's technology estate and threat profile.
  • Define and govern the onboarding of security telemetry across on-premises, Microsoft Azure, AWS and third‑party services, ensuring log sources address genuine visibility gaps and provide reliable value for detection and investigation.
  • Own the detection engineering lifecycle across requirements, design, testing, deployment, tuning, performance assessment and retirement, supported by version control, peer review and controlled release practices.
  • Lead the development of analytics rules, hunting queries, workbooks and automated investigation and response workflows.
  • Own the operational effectiveness of security solutions managed by CDO ensuring configurations, integrations, detections and workflows deliver measurable security outcomes.
  • Drive threat‑informed defence with Cyber Threat Intelligence and Cyber Threat Exposure Management, translating relevant threat actors, campaigns, TTPs, IOCs, critical vulnerabilities and attack paths into detections, targeted threat hunts and automated defensive actions.
  • Maintain an evidence‑based view of service performance through agreed KPIs, KRIs and operational MI, identifying material variations, recurring failure points and capacity constraints, and driving corrective actions through to a measurable outcome.
  • Act as the senior technical escalation point for complex, ambiguous and high‑severity security events, leading investigations through scoping, attack reconstruction, business‑impact assessment, containment and resolution.
  • Experience investigating malicious code, identity compromise, business email compromise, fraud‑related intrusion, data exfiltration, cloud compromise or third‑party intrusion.
  • Lead technical response within CIRT during declared cyber incidents, coordinating the internal team, MSSP and relevant technology functions in accordance with the firm's incident‑management processes to contain threats and reduce business impact.
  • Build and improve investigation and response playbooks for priority threat scenarios, and lead tabletop, purple‑team and practical exercises that test detection coverage, technical readiness and coordination with relevant business functions.
  • Operate the internal team and MSSP as one integrated monitoring and response capability, setting clear expectations for investigation quality, escalation consistency and response effectiveness, and addressing service issues before they affect security outcomes.
  • Maintain an evidence‑based view of alert demand, detection quality, MTTA, MTTR, investigation outcomes, service capacity and recurring failure points, using these measures to prioritise and demonstrate improvement.
  • Lead service reviews with key security vendors and providers, assessing delivery against expected outcomes and driving actions that maximise the contribution of existing investment to CDO's Detect, Defend and Respond objectives.
  • Identify and deliver appropriate uses of automation and AI across detection engineering, enrichment, investigation and response, measuring the resulting improvement in quality, speed, consistency or coverage.
  • Develop
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Monitoring & Detection Lead — SIEM & Incident Response
Security Monitoring & Detection Lead — SIEM & Incident Response

SmartRecruiters, Inc. • Manchester, Greater London

Hybrid
GBP 120,000 - 150,000
27 days holiday
Pension matched contributions
Discretionary bonus
+6
Head of Security Monitoring & Detection Engineering
Head of Security Monitoring & Detection Engineering

Aj Bell • Manchester

On-site
GBP 90,000 - 120,000
24 x 7 Security Analyst
24 x 7 Security Analyst

LRQA Group Limited 2021 • Birmingham

On-site
GBP 45,000 - 65,000
24 x 7 Security Analyst
24 x 7 Security Analyst

Nettitude Group • Birmingham

On-site
GBP 50,000 - 80,000
Head of Security Operations Technology · London, Dubai · Hybrid
Head of Security Operations Technology · London, Dubai · Hybrid

Sokin • Greater London

On-site
GBP 120,000 - 180,000
Lead Detection & Response Engineer
Lead Detection & Response Engineer

Lloyds • City of Edinburgh

Hybrid
GBP 90,000 - 140,000
Holiday allowance
Flexible working
Private medical insurance
+2
Head of Security Operations
Head of Security Operations

Sokin • Harrow

On-site
GBP 120,000 - 170,000
Security Consultant
Security Consultant

Franklin Fitch • England

Hybrid
GBP 55,000 - 70,000
Security Monitoring & Detection Engineering Lead
Security Monitoring & Detection Engineering Lead

SmartRecruiters, Inc. • Manchester, Greater London

Hybrid
GBP 120,000 - 150,000
27 days holiday
Pension matched contributions
Discretionary bonus
+6
Senior Security Engineering Consultant
Senior Security Engineering Consultant

Infosec • Basingstoke

On-site
GBP 56,000 - 80,000
Salary up to £80,000
Bonuses
Hybrid work