About the role
Security Engineering Lead - Detection and Response
Location: London / hybrid
Salary: £95,000 - £145,000 plus bonus
Industry: Fintech / Securities Finance Technology
Work Authorization: This role requires the right to work in the UK, no sponsorship available
Who you'll join
Our client is a London based fintech that automates the securities finance lifecycle. The platform processes over $6.5 trillion in transactions every day, connecting more than 150 financial institutions worldwide, including 25 of the 30 global systemically important banks.
You will report directly into the CISO and CTO, with real scope to shape how the company detects and responds to threats.
What you'll do
- Build the company's detection and response capability from the ground up, establishing the processes, telemetry and tooling needed to detect, investigate and contain threats across AWS, on premises, Workforce IT and the endpoint estate
- Produce a documented asset and telemetry map across AWS, on premises, Workforce IT and user endpoints
- Assess current security monitoring and third party SOC coverage against LLM enabled attacks. Deliver a risk based plan using a hybrid SOC model, working with engineering teams to implement it
- Build documented MITRE ATT&CK detection coverage across all Tier 1 tactics within 12 months, managed as code and version controlled
- Author and maintain playbooks for the top incident types by likelihood and impact. Automate containment and response actions through SOAR, targeting 80% automated first action on P1 and P2 responses
- Establish MTTD and MTTR baselines within 90 days and set improvement targets
- Run structured threat hunting cycles each quarter and convert findings into new detection rules
- Review unpatchable vulnerabilities with engineering teams and recommend treatment
- Produce a monthly detection and response programme metrics report for the CISO and CTO
- Build internal security capability through knowledge sharing, runbook documentation and structured mentoring as the team grows
Who you are
- Hands on detection engineering experience, writing and maintaining SIEM detection rules, correlation logic and detection as code pipelines
- Proficient in Python or equivalent for detection development, log parsing and automation
- Demonstrated incident response experience, leading or contributing to P1 and P2 investigations, post incident reviews and containment
- Experience with cloud security on AWS and/or Azure, including native cloud telemetry sources
- Familiar with MITRE ATT&CK as a framework for detection design and gap analysis
- Hands on experience building and operating SOAR playbooks and response automation across SIEM, EDR, cloud and ticketing
- Experience leading a SOC and/or managing a third party SOC
- Demonstrated experience running structured threat hunting cycles
- Able to influence stakeholders across the technology team. Strong written communication, able to translate technical findings for non-technical stakeholders
- Able to work independently and collaborate with technical stakeholders across the business
Tech stack
Cloud: AWS (primary), SIEM, SOAR, EDR, Python for detection development, log parsing and automation, MITRE ATT&CK as the detection design and gap analysis framework, Detection as code, version controlled (Git or equivalent), Ticketing and workflow tooling across SIEM, EDR, cloud and ticketing systems
Why you'll join
- Genuine build from scratch mandate. You are not inheriting someone else's detection stack, you are designing it
- High stakes, high trust environment. The platform underpins $6.5 trillion in daily transactions for 25 of the 30 global systemically important banks
- Direct line into the CISO and CTO, with real visibility on your work at leadership level
- A clear path to building and leading a team as the function grows
- Hybrid working in London