Threat Detection Engineer & IR Specialist

DRW

Greater London

On-site

GBP 55,000 - 90,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

DRW seeks a Threat Specialist for our London office to triage security alerts, respond to incidents, and develop detections. You will work with SIEM, EDR, and SOAR tools, contribute to playbooks, and mentor through a fast-paced security operations environment.

Ideal candidates have 1–3 years of industry experience, a passion for security, and strong scripting skills (PowerShell, Bash, Python, Ruby or Perl). We value meticulous analysts who communicate clearly and collaborate across teams.

Qualifications

  • A bachelor’s degree, or equivalent experience for 1-3 years in industry.
  • Interest in digital forensics and physical security.
  • A passion for security and problem solving.
  • Heightened attention to detail and forward thinking.
  • Strong knowledge of Windows, MacOS, or Linux with an interest in learning the details of platforms that you might not have experience with.
  • Knowledge of the Incident Response Cycle.
  • Knowledge of static & dynamic malware analysis, including network packet captures.
  • Knowledge of core networking & cloud security concepts.
  • Experience with Security Information and Event Management (SIEM) products.
  • Experience with Endpoint Detection & Response (EDR) products.
  • Experience with SOAR (Security Orchestration, Automation, and Response) products.
  • Experience with data analysis of events in security related sources such as IPS, Web Security, Endpoint Protection, Event Logs
  • Experience working with GitHub
  • Experience with PowerShell, Bash, Python, Ruby, or Perl
  • Exceptional time management skills
  • Excellent verbal and written communication skills

Responsibilities

  • Perform triage of global security alerts generated from various sources (including IPS, Web Security, Event Logs, Endpoint Protection, Brand Protection, Phishing)
  • Respond to any incidents identified from analysis of security alerts
  • Triage & route internal support tickets sent to the Security team
  • Creation & revision of threat detections
  • Perform SIEM product administration for event correlation and threat detection
  • Perform SOAR playbook/dashboard management and product administration
  • Provide insider threat investigation assistance to teams of internal stakeholders
  • Drive automated detection, response, and configuration through various scripting and programming languages
  • Evaluate commercial and open-source tools as needed
  • Collaborate with internal Infosec peers to continuously improve security posture
  • Contribute to internal documentation of standard processes & procedures
  • Educate users on security best practices
  • Assess security risks as they relate to new projects and initiatives
  • Attend security conferences, seminars, and regular training to stay ahead of the ever-changing security landscape

Skills

Problem solving
Attention to detail
Time management
Communication skills

Education

Bachelor's degree or equivalent

Tools

SIEM
EDR
SOAR
GitHub
PowerShell
Bash
Python
Ruby
Perl

Job description

DRW seeks a Threat Specialist for our London office to triage security alerts, respond to incidents, and develop detections. You will work with SIEM, EDR, and SOAR tools, contribute to playbooks, and mentor through a fast-paced security operations environment.

Ideal candidates have 1–3 years of industry experience, a passion for security, and strong scripting skills (PowerShell, Bash, Python, Ruby or Perl). We value meticulous analysts who communicate clearly and collaborate across teams.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Threat Detection & Incident Response Specialist
Threat Detection & Incident Response Specialist

DRW • City Of London

On-site
GBP 60,000 - 90,000
Threat Hunter & Incident Response Pro
Threat Hunter & Incident Response Pro

Drweng • Greater London

On-site
GBP 60,000 - 85,000
Threat Specialist
Threat Specialist

DRW • City Of London

On-site
GBP 60,000 - 90,000
Threat Specialist
Threat Specialist

DRW • Greater London

On-site
GBP 55,000 - 90,000
Threat Specialist
Threat Specialist

Drweng • Greater London

On-site
GBP 60,000 - 85,000
Threat Detection Engineer — SIEM/EDR/NDR Specialist
Threat Detection Engineer — SIEM/EDR/NDR Specialist

ICE Clear Europe Limited • Greater London

Hybrid
GBP 70,000 - 120,000
Senior SecOps Analyst UK — Threat Hunting & IR Lead
Senior SecOps Analyst UK — Threat Hunting & IR Lead

Anduril Industries • Greater London

On-site
GBP 90,000 - 130,000
Equity grants
Competitive benefits
Threat Detection & Security Engineering Specialist
Threat Detection & Security Engineering Specialist

Entasis Partners • Greater London

Hybrid
GBP 70,000 - 110,000
Senior Threat Detection & Response Engineer
Senior Threat Detection & Response Engineer

Pirum Systems Ltd. • Greater London

Hybrid
GBP 90,000 - 150,000
Hybrid work options
Private medical insurance
Eyecare
+5
Threat Detection Engineer
Threat Detection Engineer

Intercontinental Exchange Holdings, Inc. • City Of London

On-site
GBP 70,000 - 110,000