At a Glance
- Tasks: Develop and enhance threat detection capabilities in a cloud-first environment.
- Company: Join a leading biotech firm revolutionising healthcare with AI and genetic data.
- Benefits: Enjoy a competitive salary, hybrid working options, and great benefits.
- Other info: Collaborative culture with opportunities for professional growth.
- Why this job: Make a real impact on cyber security and protect vital health data.
- Qualifications: Experience in threat detection and strong KQL expertise required.
The predicted salary is between 60000 - 80000 £ per year.
An exciting opportunity has arisen for a Threat Detection Engineer to join a well-established biotech company using large-scale genetic data and AI to predict disease risk and advance precision healthcare.
As a Threat Detection Engineer, you will be responsible for developing and enhancing threat detection capabilities within a modern cloud-first setting. This role offers hybrid / remote working options, a salary range of 60,000 - 80,000 and benefits.
You will be responsible for:
- Designing and implementing threat-led detection logic informed by threat intelligence and hunting activities.
- Developing innovative analytical techniques to identify incidents effectively.
- Collaborating with an outsourced SOC to maintain, tune, and optimise detection catalogues.
- Creating and refining DLP, Insider Risk Management, and other security rules using cloud-native tools.
- Monitoring and ensuring high-quality service delivery from external SOC providers.
- Automating reporting on security performance and operational metrics.
- Partnering with technology teams to ensure adequate monitoring across cloud platforms, SaaS, and internal systems.
- Documenting security processes, tool configurations, and contributing to service delivery documentation.
- Supporting colleagues with ISO 27001 compliance and KQL-related tasks.
What we are looking for:
- Previously worked as a Threat Detection Engineer or in a similar role.
- Must have strong expertise in KQL.
- Hands-on experience with Microsoft Sentinel and Defender (Endpoint, Office 365).
- Familiarity with Microsoft Entra ID, including Identity Governance.
- Experience with Microsoft Purview, particularly DLP and data protection tools.
- Exposure to cloud-native logging in Azure and Kubernetes environments.
- Understanding of “detection as code” or “everything as code” approaches, including CI/CD pipelines.
- Experience working with or alongside MSP SOC teams.
- Awareness of Agile methodologies and ways of working.
- Knowledge of attacker TTPs, threat modelling, and cyber security frameworks.
- Understanding of statistics, data science, or AI/ML as applied to security.
- Awareness of ISO 27001 standards.
- Relevant cyber security certifications (e.g., MS-500, AZ-500, SC-200, SC-300, SC-400, Security+, GSOC, CCSK).
This is a rare chance to contribute to meaningful cyber security work in a role where your expertise will directly influence how threats are detected and mitigated at scale.
Cyber Security Engineer (Threat Detection & Automation) employer: Additional Resources
Join a forward-thinking company that values innovation and technical excellence, where as a Senior Platform Engineer, you will play a pivotal role in scaling a pioneering platform. With a strong emphasis on employee growth, collaborative work culture, and the opportunity to lead cutting-edge projects, this position offers a unique chance to make a meaningful impact in a dynamic environment. Located in a vibrant area, the company provides excellent benefits and fosters a culture of continuous learning and development.