Security Operations Engineer

CloudBees

Greater London

Hybrid

GBP 65,000 - 105,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

CloudBees in London is seeking a mid/senior Security Operations Engineer to drive detection engineering, automation, threat hunting, incident response, and close collaboration with Product and Platform Engineering.

You will build and tune detections across cloud, endpoint, SaaS, and applications, own the detection lifecycle, and work with engineering to enhance telemetry and logging.

Qualifications

  • 3+ years in Security Operations, Detection Engineering, or Security Engineering.
  • Hands-on experience with enterprise SIEM platforms such as Splunk, Microsoft Sentinel, Elastic, Chronicle, or QRadar.
  • Experience building and tuning detection rules.
  • Experience developing SOAR playbooks or security automation.
  • Strong scripting skills using Python, PowerShell, or similar languages.
  • Cloud experience (AWS preferred; Azure/GCP valued).
  • Solid understanding of the MITRE ATT&CK framework.
  • Experience supporting security incident response.
  • Comfortable with Git, APIs, and engineering workflows.
  • Excellent communication with Security and Engineering teams.

Responsibilities

  • Design, build, and improve detection rules across cloud, endpoint, SaaS, and applications.
  • Own the full detection lifecycle from hypothesis through deployment and tuning.
  • Create high-fidelity detections using threat intelligence and incident learnings.
  • Measure coverage using the MITRE ATT&CK framework.
  • Reduce false positives while improving visibility into attacker techniques.
  • Design and maintain SOAR playbooks that automate alert triage and response.
  • Automate repetitive analyst workflows with APIs and scripting.
  • Build integrations across SIEM, EDR, CNAPP, and ticketing systems.
  • Support AI-assisted workflows to improve investigation quality.
  • Participate in on-call and incident response activities.

Skills

Detection engineering
Threat hunting
Python
PowerShell
AWS
Azure
GCP
Splunk
Git
APIs
MITRE ATT&CK
IR experience
Automation

Tools

Splunk
Terraform
CloudFormation
Kubernetes
ARM

Job description

Salary: £65,000 - 105,000 per year

Requirements:
  • 3+ years of experience in Security Operations, Detection Engineering, or Security Engineering.
  • Hands-on experience with enterprise SIEM platforms such as Splunk, Microsoft Sentinel, Elastic, Chronicle, or QRadar.
  • Experience building and tuning detection rules.
  • Experience developing SOAR playbooks or security automation.
  • Strong scripting skills using Python, PowerShell, or similar languages.
  • Experience working within cloud environments; AWS is preferred, and Azure or GCP experience is also valued.
  • Solid understanding of the MITRE ATT&CK framework.
  • Experience supporting security incident response.
  • Comfortable working with Git, APIs, and engineering workflows.
  • Excellent communication skills with both Security and Engineering teams.
  • Preferred experience with Detection Engineering methodologies.
  • Preferred experience with AI-assisted detection or security automation.
  • Familiarity with Sigma, Atomic Red Team, or detection testing frameworks.
  • Experience with Infrastructure as Code such as Terraform, CloudFormation, or ARM.
  • Kubernetes or container security experience.
  • Experience working within SaaS, DevOps, or software delivery organizations.
  • Relevant certifications including GCIH, GCIA, GCDA, GCED, or AWS Security Specialty.
Responsibilities:
  • Design, build, and continuously improve detection rules across cloud, endpoint, SaaS, and application environments.
  • Own the full detection lifecycle from hypothesis through deployment and continuous tuning.
  • Create high-fidelity detections using operational threat intelligence, incident learnings, and purple team findings.
  • Measure and improve detection coverage using the MITRE ATT&CK framework.
  • Continuously reduce false positives while improving visibility into emerging attacker techniques.
  • Design and maintain SOAR playbooks that automate alert triage, enrichment, containment, and response.
  • Identify repetitive analyst workflows and automate them using APIs, scripting, and orchestration platforms.
  • Build integrations across SIEM, EDR, CNAPP, vulnerability management, and ticketing systems.
  • Help introduce AI-assisted workflows that improve investigation quality and analyst productivity.
  • Monitor and investigate security events across corporate and production environments.
  • Participate in weekend on-call support for Security Operations.
  • Lead or support incident response activities including investigation, containment, recovery, and lessons learned.
  • Perform proactive threat hunting using telemetry across multiple security platforms.
  • Improve operational playbooks and incident response processes.
  • Partner with Product and Platform Engineering teams to improve security telemetry and logging.
  • Help define security observability requirements for new services.
  • Collaborate with developers to improve security visibility across our platform.
  • Translate operational findings into practical engineering improvements.
  • Contribute to vulnerability assessment and management processes, prioritizing findings based on threat context and exploitability.
  • Consume and operationalize threat intelligence feeds, translating indicators and TTPs into detection logic and hunting hypotheses.
  • Participate in red team and purple team exercises, using findings to validate and improve the detection stack.
Technologies:
  • AI
  • ARM
  • AWS
  • Azure
  • Cloud
  • DevOps
  • GCP
  • Git
  • Support
  • Kubernetes
  • Matrix
  • PowerShell
  • Python
  • Security
  • Splunk
  • Terraform
  • Jenkins
More:

We are CloudBees, a leading software delivery platform for enterprises that helps organizations continuously innovate, compete, and deliver scalable, compliant, governed, and secure software. We were founded in 2010 and are backed by Goldman Sachs, Morgan Stanley, Bridgepoint Credit, HSBC, Golub Capital, Delta-v Capital, Matrix Partners, and Lightspeed Venture Partners. We are growing our Global Security team for a Security Operations Engineer role based in London, GBR, with a UK hybrid work setup. This is a mid/senior-level opportunity for engineers who want to build security capabilities through detection engineering, automation, threat hunting, incident response, and close collaboration with Product and Platform Engineering. We offer a highly competitive benefits and vacation package, team outings, a fun, hardworking, and casual environment, and endless growth opportunities. We are committed to diversity and believe it strengthens our products, our customers, and our global community.

last updated 36 week of 2026

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

CloudBees • Greater London

Hybrid
GBP 65,000 - 105,000
Security Engineer - Security Operations
Security Engineer - Security Operations

Perk • Greater London

On-site
GBP 72,000 - 85,000
Equity options
Private medical insurance
Life insurance
+2
Senior SecOps Specialist
Senior SecOps Specialist

Teya Solutions • Greater London

Hybrid
GBP 63,000 - 103,000
Health insurance
25 days annual leave
Friday lunch in the office
+2
Cloud Security Engineer
Cloud Security Engineer

Ocho People • Belfast City District

Hybrid
GBP 70,000 - 95,000
35 days annual leave
8% matched pension
Equity/share options
+1
Sr. Software Engineer, Cloud Detection
Sr. Software Engineer, Cloud Detection

CrowdStrike • Greater London

On-site
GBP 65,000 - 105,000
Senior Security Engineer Consultant
Senior Security Engineer Consultant

InfoSec People Ltd • Basingstoke

Hybrid
GBP 70,000 - 100,000
Hybrid working model
Comprehensive employee benefits
Senior Security Engineering Consultant
Senior Security Engineering Consultant

Infosec • Basingstoke

Hybrid
GBP 56,000 - 80,000
Salary up to £80,000
Bonuses
Hybrid work
Cyber Security Engineer
Cyber Security Engineer

La Fosse • Greater London

On-site
GBP 60,000 - 80,000
Lead Security Operations Engineer
Lead Security Operations Engineer

Jobtailor • Greater London

On-site
GBP 120,000 - 170,000
Detection Engineer
Detection Engineer

AI Startups UK • Greater London

Hybrid
GBP 90,000 - 130,000