Senior Security Engineer

United States Digital Space LLC

Greater London

Hybrid

GBP 100,000 - 150,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

United States Digital Space LLC is seeking a security engineering leader to drive detection, response, and automation for a high-scale SaaS environment. You will own the Detection & Response domain, translate requirements into milestones, and design scalable alerting within SIEM/SOAR.

The role emphasizes threat intelligence, cross-functional collaboration, and advanced cloud security with Google Cloud Platform.

Qualifications

  • Experience operating across the core pillars of a modern security program—including Product, Cloud, and Corporate Security.
  • Experience turning raw telemetry into precise, actionable alerting and building the infrastructure required to defend a high-scale SaaS environment.
  • Proficiency with Google Cloud Platform ecosystem (Cloud Logging, BigQuery, Pub/Sub) to build automated security data pipelines.

Responsibilities

  • Domain Ownership: Serve as the domain expert for Detection & Response, integrating telemetry from across the ecosystem to build a unified, high-fidelity detection and response engine.
  • Technical Project Execution: Translate high-level project requirements into actionable milestones, managing task delivery and cross-functional results.
  • Architect Modern Detection: Design and implement precise alerting within Google Security Operations, treating detections as code and ensuring scalability.
  • Combat Modern Threats: Develop detection logic and playbooks to identify and mitigate application-layer abuses, ATO, and social engineering.
  • Operational Lead (EMEA): Lead security incidents during EMEA hours, driving investigations and cross-functional communication.
  • Build Threat Intelligence: Evolve threat intel into proactive SIEM/SOAR logic.
  • Infrastructure Management: Ensure operational health and telemetry flow of core security stack (SentinelOne, GCP Security Command Center, Mimecast Incydr).
  • Security Engineering Foundations: Work across Product, Cloud, and Corporate Security; IAM, threat modeling, and secure code reviews.

Skills

Python
IAM
Threat Modeling
Secure Code Reviews
Security Operations
GCP
SIEM/SOAR
APIs
AI in security

Tools

SentinelOne
GCP Security Command Center
Mimecast Incydr

Job description

About the company

the company is the leading product intelligence and analytics platform, trusted by more than 29,000 companies to help understand how people use the products they build. By combining powerful analytics with AI that knows your business, the company helps teams see what’s working, diagnose what’s not, and decide what to build next. Learn more at the company.com.

About the Information Security Team

We believe security isn't just a function—it's a platform for bold ideas. The Information Security Team at the company is a small, high-impact group committed to building a frictionless security program that serves as a model for our company and the broader industry. This is a team for those who are never satisfied, who dream big, and who have the resilience to see those ideas through.

We operate at the intersection of business strategy and technical execution, where we are critical partners to every team at the company. Our work requires a broad, generalist skill set across vulnerability management, threat detection, and access management. We strategically balance necessary compliance work with proactive initiatives, with a constant focus on automation as the path to a more efficient security program.

We use our expertise in a variety of well-known security platforms and tools to create seamless, automated processes that empower our peers. We are a lean team by design, and we succeed or fail together, committed to transparent communication and a strong sense of ownership.

Responsibilities
  • Domain Ownership: Serve as the domain expert for Detection & Response, integrating telemetry from across our entire ecosystem—including Product, Cloud, Corporate Infrastructure, and Identity to build a unified, high-fidelity detection and response engine.
  • Technical Project Execution: Translate high-level project requirements and technical scoping documents into actionable milestones, managing task delivery and driving cross-functional results.
  • Architect Modern Detection: Design and implement precise, actionable alerting within Google Security Operations (SIEM/SOAR), treating detections as code and ensuring they scale with our high-volume data ingestion.
  • Combat Modern Threats: Develop specialized detection logic and playbooks to identify and mitigate application-layer abuses, customer account-targeted events (ATO), and sophisticated social engineering.
  • Operational Lead (EMEA): Serve as the primary technical lead for security incidents during EMEA hours, driving investigations, containment efforts, and cross-functional communication.
  • Build Threat Intelligence: Evolve the company’s threat intelligence program by identifying relevant adversaries and translating tactical intel into proactive SIEM/SOAR logic.
  • Infrastructure Management: Ensure the operational health and telemetry flow of our core security stack—including SentinelOne, GCP Security Command Center, and Mimecast Incydr to maintain continuous visibility and alerting integrity.
We're Looking For Someone Who Has
  • Security Engineering Foundations: Experience operating across the core pillars of a modern security program—including Product, Cloud, and Corporate Security. You are comfortable navigating Identity (IAM), threat modeling, and secure code reviews as part of a unified team.
  • Detection & Response Specialization: A deep understanding of the detection-as-code lifecycle. You have experience turning raw telemetry into precise, actionable alerting and building the infrastructure required to defend a high-scale SaaS environment.
  • Operational Execution: The ability to manage a high volume of daily security tasks. You are prepared to handle a diverse range of responsibilities—from triaging vulnerabilities and policy violations to investigating suspicious activity across the entire stack.
  • Cloud Data Proficiency: Proficiency with the Google Cloud Platform ecosystem (specifically Cloud Logging, BigQuery, and Pub/Sub) to build automated security data pipelines and maintain visibility across high-volume environments.
  • Modern Automation & AI: Proficiency in Python to develop automated workflows and integrate security tools via APIs. You are comfortable leveraging AI and LLMs to build autonomous security workflows—such as automated alert enrichment, intelligent incident summarization, and AI-assisted code analysis to drastically reduce time-to-context.
Bonus Points For
  • Threat Intelligence Maturity: Experience evaluating and embedding external intelligence—including dark web monitoring, brand protection, and adversary tactics—into a security program. You know how to identify where a specific intelligence source provides the most defensive value and how to integrate that data into automated workflows.
  • Security Outreach & Mentorship: Experience leading "Security Champions" initiatives or a demonstrated ability to elevate the security IQ of non-security teams. You help others think critically about threat identification and telemetry—explaining the "why" behind visibility requirements when building new features or onboarding third-party vendors.
  • Deception & Canary Strategies: Familiarity with deploying deception techniques (e.g., honeytokens, canary credentials, or "fake" internal endpoints) to provide high-fidelity signals of unauthorized lateral movement or credential misuse.
  • Platform & Infrastructure Experience: Prior experience with enterprise-grade security tools such as Endpoint Detection & Response (EDR), Email Security gateways, and Cloud-native Security Command Centers.
  • SaaS & Analytics Scale: Experience defending an environment with massive, high-volume data ingestion and complex user-access patterns similar to the company’s architecture.
  • Offensive Security Exposure: Experience with vulnerability coordination platforms, automated external scanning, or managing findings from bug bounty programs.
Compensation
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cloud Security Engineer (SecOps)
Senior Cloud Security Engineer (SecOps)

Qodea • Greater London

Hybrid
GBP 70,000 - 90,000
Competitive base salary
Private medical insurance
28 days annual leave
+1
Senior Cloud Security Engineer (SecOps)
Senior Cloud Security Engineer (SecOps)

Qodea • Portsmouth

Hybrid
GBP 60,000 - 85,000
Private medical insurance
28 days annual leave
Flexible working hours
+1
Senior Cloud Security Engineer (SecOps)
Senior Cloud Security Engineer (SecOps)

bynd • Manchester

On-site
GBP 90,000 - 120,000
Competitive base salary
Pension scheme
Discretionary bonus
+1
Security Engineer
Security Engineer

Cubiq Recruitment • Greater London

Hybrid
GBP 90,000 - 130,000
Equity
Bonus
Benefits
Senior Security Engineer (GCP)
Senior Security Engineer (GCP)

Bynd Limited • Manchester

Hybrid
GBP 70,000 - 90,000
Competitive base salary
Private medical insurance
Flexible working hours
+1
Lead Security Operations Engineer
Lead Security Operations Engineer

Jobtailor • Greater London

On-site
GBP 120,000 - 170,000
Detection Engineer
Detection Engineer

AI Startups UK • Greater London

Hybrid
GBP 90,000 - 130,000
Senior Corporate Security Engineer
Senior Corporate Security Engineer

United States Digital Space LLC • Greater London

Hybrid
GBP 120,000 - 190,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Space Executive • Greater London

On-site
GBP 70,000 - 120,000
Senior Security Engineer
Senior Security Engineer

InfoSec People Ltd • Basingstoke

On-site
GBP 65,000 - 85,000