Security Monitoring & Detection Engineering Lead

SmartRecruiters, Inc.

Manchester, Greater London

Hybrid

GBP 120,000 - 150,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

27 days holiday
Pension matched contributions
Discretionary bonus
Share schemes
Private healthcare
Dental plan
Life insurance
Travel and bike loan
Employee Assistance Programme

Job summary

AJ Bell is seeking a Security Monitoring & Detection Engineering Lead to drive the technical direction of security monitoring and incident response. You will own SIEM architecture, detection engineering, and threat-informed defense, coordinating with the Cyber Defence Operations and MSSP to protect customer data and services.

You will lead complex investigations, oversee telemetry onboarding across cloud and on‑prem environments, and advance automation and playbooks while operating in a hybrid

Qualifications

  • Experience in security monitoring, SIEM engineering and incident response in a large enterprise.
  • Strong track record designing and operating Microsoft Sentinel production capabilities.
  • Ability to translate threat intel and adversary behaviour into detections and workflows.

Responsibilities

  • Own the technical direction and delivery of Security Monitoring & Detection Engineering.
  • Lead architecture and development of SIEM, detection rules, and incident response processes.
  • Oversee onboarding of telemetry across on-prem, Azure, AWS, and third parties.
  • Manage detection engineering lifecycle including design, testing, deployment and tuning.
  • Drive automated investigation and response workflows and cross-team collaboration.
  • Lead CIRT activities during security incidents and coordinate with MSSP.

Skills

Security monitoring
Incident response
Leadership
Threat hunting
Communication
Cloud security
SIEM engineering
Analytical thinking

Education

Relevant certifications or training

Tools

Microsoft Sentinel
Azure
AWS
KQL
Logic Apps
PowerShell
Python
Mimecast
Varonis

Job description

Security Monitoring & Detection Engineering Lead
  • Full-time
  • Business Areas: Technology Services
  • Location: Manchester or London
  • Department: Information Security
  • Purpose

    The Cyber Defence Operations function protects AJ Bell against external adversaries and internal risks through four specialist capabilities: Security Monitoring & Detection Engineering, Cyber Threat Intelligence, Cyber Threat Exposure Management and Insider Risk Management. Together, these capabilities combine detection, intelligence, exposure management and insider risk to safeguard AJ Bell’s customers, data, critical services and the trust placed in the firm.

    Security Monitoring & Detection Engineering provides an integrated monitoring, detection and response capability, combining internal technical expertise with 24x7 support from the Managed Security Service Provider.

    The Security Monitoring & Detection Engineering Lead is the principal technical authority for Security Monitoring & Detection Engineering capability, accountable for the effectiveness of security monitoring, detection engineering, technical investigation and incident response. This is a hands‑on technical role responsible for the architecture, engineering and operational performance of Microsoft Sentinel and the wider security monitoring estate.

    The role would particularly suit an experienced detection engineering, security operations, red‑team, purple‑team or offensive‑security leader who can translate real‑world adversary behaviour into effective monitoring, detection and response. The role leads complex investigations and technical incident response, ensures the internal team and MSSP operate as one capability, and drives measurable improvements that reduce the potential for customer, operational, financial and regulatory harm.

    On-Call Requirement

    This role participates in the Cyber Defence Operations on-call rota, providing senior technical leadership during significant out-of-hours security events and declared cyber incidents.

    Key Responsibilities

    • Own the technical direction, quality and delivery performance of Security Monitoring & Detection Engineering, translating CDO priorities into a clear roadmap for monitoring, detection, investigation and response.
    • Lead the architecture, engineering and continued development of our SIEM solution, ensuring the SIEM remains resilient, scalable, cost-effective and aligned with AJ Bell’s technology estate and threat profile.
    • Define and govern the onboarding of security telemetry across on-premises, Microsoft Azure, AWS and third-party services, ensuring log sources address genuine visibility gaps and provide reliable value for detection and investigation.
    • Own the detection engineering lifecycle across requirements, design, testing, deployment, tuning, performance assessment and retirement, supported by version control, peer review and controlled release practices.
    • Lead the development of analytics rules, hunting queries, workbooks and automated investigation and response workflows.
    • Own the operational effectiveness of security solutions managed by CDO ensuring configurations, integrations, detections and workflows deliver measurable security outcomes.
    • Drive threat‑informed defence with Cyber Threat Intelligence and Cyber Threat Exposure Management, translating relevant threat actors, campaigns, TTPs, IOCs, critical vulnerabilities and attack paths into detections, targeted threat hunts and automated defensive actions.
    • Maintain an evidence‑based view of service performance through agreed KPIs, KRIs and operational MI, identifying material variations, recurring failure points and capacity constraints, and driving corrective actions through to a measurable outcome.
    • Act as the senior technical escalation point for complex, ambiguous and high‑severity security events, leading investigations through scoping, attack reconstruction, business‑impact assessment, containment and resolution.
    • Experience investigating malicious code, identity compromise, business email compromise, fraud‑related intrusion, data exfiltration, cloud compromise or third‑party intrusion.
    • Lead technical response within CIRT during declared cyber incidents, coordinating the internal team, MSSP and relevant technology functions in accordance with the firm’s incident‑management processes to contain threats and reduce business impact.
    • Build and improve investigation and response playbooks for priority threat scenarios, and lead tabletop, purple‑team and practical exercises that test detection coverage, technical readiness and coordination with relevant business functions.
    • Operate the internal team and MSSP as one integrated monitoring and response capability, setting clear expectations for investigation quality, escalation consistency and response effectiveness, and addressing service issues before they affect security outcomes.
    • Maintain an evidence‑based view of alert demand, detection quality, MTTA, MTTR, investigation outcomes, service capacity and recurring failure points, using these measures to prioritise and demonstrate improvement.
    • Lead service reviews with key security vendors and providers, assessing delivery against expected outcomes and driving actions that maximise the contribution of existing investment to CDO’s Detect, Defend and Respond objectives.
    • Identify and deliver appropriate uses of automation and AI across detection engineering, enrichment, investigation and response, measuring the resulting improvement in quality, speed, consistency or coverage.
    • Develop Senior Analysts and junior team members through technical leadership, investigation review, practical training and structured knowledge transfer, creating credible succession within the function.
    • Report functional performance, incident readiness, monitoring coverage, material risks and capability constraints to the Head of Cyber Defence Operations, providing clear recommendations and action plans.

    Skills & Experience

    • Extensive experience across security monitoring, SIEM engineering, detection engineering and incident response within a complex enterprise environment.
    • A strong record of designing, building, operating and evolving Microsoft Sentinel as a production security monitoring and response capability.
    • Deep expertise in KQL and the engineering of analytics rules, hunting queries, workbooks and threat‑informed detection content.
    • Extensive experience designing telemetry architectures and onboarding security data, including connectors, parsing, normalisation, retention, ingestion health, data quality and cost management.
    • Experience integrating cloud‑hosted services and security telemetry into central monitoring and leading investigations and incident‑response activity across AWS, Azure environments.
    • Strong knowledge of Microsoft Defender XDR across endpoint, identity, email and cloud security, including the correlation of evidence across the Microsoft security ecosystem.
    • Experience designing and implementing automated investigation and response workflows using Azure Logic Apps, APIs, PowerShell, Python or comparable orchestration technologies.
    • Experience establishing and governing a production detection engineering lifecycle, including testing, peer review, version control, controlled deployment, performance monitoring and retirement.
    • Experience operating and materially improving enterprise security platforms such as Mimecast, Varonis, or comparable email and data‑security technologies.
    • Experience translating adversary behaviour, threat intelligence, incident findings, exposure data and offensive‑security results into improved detection and response capability.
    • Strong written and verbal communication, with the ability to translate complex threats, incidents and capability gaps into clear business implications, recommendations and decisions.

    Preferred

    • Experience leading red‑team, purple‑team or offensive‑security activity and converting identified attack paths and adversary techniques into improved detection and response.
    • Experience in financial services, or a regulated environment.

    Qualifications

    Relevant certifications or completed professional training may include:

    • Security Blue Team, Blue Team Level 2, BTL2
    • GIAC Certified Intrusion Analyst, GCIA
    • CREST Registered Intrusion Analyst, CRIA
    • Certified Red Team Operator, CRTO
    • OffSec Wireless Professional, OSWP
    • EC-Council Certified Ethical Hacker, CEH

    About AJ Bell

    At AJ Bell, we believe investing should feel good. Whether you're looking for an ISA, pension or dealing account, whether you want to invest with the help of a financial adviser or do it yourself, we have easy‑to‑use solutions to suit people from all walks of life.

    We're one of the UK's fastest‑growing investment platform businesses, trusted by everyone from professional financial advisers to first‑time investors.

    Today, over 723,000 customers trust us to manage more than £108.7 billion of assets. By continually striving to make investing simpler and more accessible, we're helping more people take control of their financial futures.

    We're proud to be recognised as one of the UK's Best 100 Companies to Work For for six consecutive years, and a Great Place to Work in 2025 and 2026, a reflection of our supportive and collaborative culture.

    What we offer

    • 27days holiday, increasing with service + buy/sell scheme + bank holidays
    • 8% Pension with matched contributions
    • Discretionary bonus scheme
    • Share schemes (including free shares and BAYE)
    • Privatehealthcare and Dental plan
    • Enhanced family leave (subject to qualifying criteria)
    • Travel and bike loan schemes
    • Employee Assistance Programme

    Life at AJ Bell

    • Regular social events including summer and Christmas parties
    • Learning and development opportunities tailored to you
    • Casual dress code
    • Friendly, supportive team environment

    Our ways of working

    At AJ Bell, our people are the heart of our culture. We believe in building strong connections by working together. That's why we offer a hybrid working model, where you'll spend a minimum of 50% of your working time from the office in either our Head office in Manchester or London Office. For new team members, the first 3 months will be spent full‑time in the office to help you immerse yourself in our business and build valuable relationships with your colleagues.

    Inclusion & diversity

    We’re committed to creating an inclusive environment where everyone feels respected, supported and able to be themselves at work.

    We welcome applications from all backgrounds and make hiring decisions based on skills, experience and potential.

    Agency information

    This vacancy is being managed exclusively by our in-house Recruitment team. We are not partnering with recruitment agencies on this opportunity and will only accept applications submitted directly by candidates.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Engineer
Information Security Engineer

AJ Bell • Manchester

On-site
GBP 60,000 - 82,000
Competitive salary
26 days holiday + bank holidays
Pension with matched contributions
+7
Information Security Engineer
Information Security Engineer

Aj Bell • Lancashire

On-site
GBP 60,000 - 90,000
Competitive salary
26 days holiday
Pension with matched contributions
+7
Information Security Engineer
Information Security Engineer

Aj Bell • Broughton

Hybrid
GBP 60,000 - 90,000
Salary
Pension 7%
Discretionary bonus
+10
Senior Business Analyst
Senior Business Analyst

Manchester Digital • Manchester

Hybrid
GBP 65,000 - 90,000
Competitive starting salary
26 days holiday
7% Pension with matched contributions
+7
Senior Infrastructure Engineer in Salford
Senior Infrastructure Engineer in Salford

Energy Jobline ZR • Salford

Hybrid
GBP 65,000 - 90,000
Competitive salary
Pension 7%
Discretionary bonus
+2
Senior Business Analyst
Senior Business Analyst

AJ Bell Management Limited • Manchester

On-site
GBP 50,000 - 70,000
26 days holiday
Pension 7%
Discretionary bonus
+7
Senior Infrastructure Engineer
Senior Infrastructure Engineer

AJ Bell Management Limited • Manchester

On-site
GBP 70,000 - 100,000
26 days holiday
Pension 7%
Discretionary bonus
+6
Senior Information Security Engineer
Senior Information Security Engineer

AJ Bell Management Limited • United Kingdom

On-site
GBP 90,000 - 120,000
26 days holiday
Pension 7% matched
Discretionary bonus
+6
Senior Business Analyst
Senior Business Analyst

AJ Bell • Salford

On-site
GBP 60,000 - 80,000
Holiday allowance
Pension plan
Discretionary bonus scheme
+6
Information Security Engineer
Information Security Engineer

Manchester Digital • Manchester

Hybrid
GBP 70,000 - 100,000
26 days holiday
Pension 7% with matched contributions
Discretionary bonus scheme
+6