← Back to Open Select
← All roles

About the role

Security Engineering Lead - Detection and Response

Location: London / hybrid

Salary: £95,000 - £145,000 plus bonus

Industry: Fintech / Securities Finance Technology

Work Authorization: This role requires the right to work in the UK, no sponsorship available


Who you'll join

Our client is a London based fintech that automates the securities finance lifecycle. The platform processes over $6.5 trillion in transactions every day, connecting more than 150 financial institutions worldwide, including 25 of the 30 global systemically important banks.

You will report directly into the CISO and CTO, with real scope to shape how the company detects and responds to threats.


What you'll do

  1. Build the company's detection and response capability from the ground up, establishing the processes, telemetry and tooling needed to detect, investigate and contain threats across AWS, on premises, Workforce IT and the endpoint estate
  2. Produce a documented asset and telemetry map across AWS, on premises, Workforce IT and user endpoints
  3. Assess current security monitoring and third party SOC coverage against LLM enabled attacks. Deliver a risk based plan using a hybrid SOC model, working with engineering teams to implement it
  4. Build documented MITRE ATT&CK detection coverage across all Tier 1 tactics within 12 months, managed as code and version controlled
  5. Author and maintain playbooks for the top incident types by likelihood and impact. Automate containment and response actions through SOAR, targeting 80% automated first action on P1 and P2 responses
  6. Establish MTTD and MTTR baselines within 90 days and set improvement targets
  7. Run structured threat hunting cycles each quarter and convert findings into new detection rules
  8. Review unpatchable vulnerabilities with engineering teams and recommend treatment
  9. Produce a monthly detection and response programme metrics report for the CISO and CTO
  10. Build internal security capability through knowledge sharing, runbook documentation and structured mentoring as the team grows


Who you are

  1. Hands on detection engineering experience, writing and maintaining SIEM detection rules, correlation logic and detection as code pipelines
  2. Proficient in Python or equivalent for detection development, log parsing and automation
  3. Demonstrated incident response experience, leading or contributing to P1 and P2 investigations, post incident reviews and containment
  4. Experience with cloud security on AWS and/or Azure, including native cloud telemetry sources
  5. Familiar with MITRE ATT&CK as a framework for detection design and gap analysis
  6. Hands on experience building and operating SOAR playbooks and response automation across SIEM, EDR, cloud and ticketing
  7. Experience leading a SOC and/or managing a third party SOC
  8. Demonstrated experience running structured threat hunting cycles
  9. Able to influence stakeholders across the technology team. Strong written communication, able to translate technical findings for non-technical stakeholders
  10. Able to work independently and collaborate with technical stakeholders across the business


Tech stack

Cloud: AWS (primary), SIEM, SOAR, EDR, Python for detection development, log parsing and automation, MITRE ATT&CK as the detection design and gap analysis framework, Detection as code, version controlled (Git or equivalent), Ticketing and workflow tooling across SIEM, EDR, cloud and ticketing systems


Why you'll join

  1. Genuine build from scratch mandate. You are not inheriting someone else's detection stack, you are designing it
  2. High stakes, high trust environment. The platform underpins $6.5 trillion in daily transactions for 25 of the 30 global systemically important banks
  3. Direct line into the CISO and CTO, with real visibility on your work at leadership level
  4. A clear path to building and leading a team as the function grows
  5. Hybrid working in London

Apply for this role

PDF or Word only. Max 5 MB.
USD or approximate USD equivalent.