Cyber Security Engineer (Threat Detection & Automation)

Cyber Security Engineer (Threat Detection & Automation)

Full-Time 60000 - 80000 £ / year (est.) Home office (partial)
Additional Resources

At a Glance

  • Tasks: Develop and enhance threat detection capabilities in a cloud-first environment.
  • Company: Join a leading biotech firm revolutionising healthcare with AI and genetic data.
  • Benefits: Enjoy a competitive salary, hybrid working options, and great benefits.
  • Other info: Collaborative culture with opportunities for professional growth.
  • Why this job: Make a real impact on cyber security and protect vital health data.
  • Qualifications: Experience in threat detection and strong KQL expertise required.

The predicted salary is between 60000 - 80000 £ per year.

An exciting opportunity has arisen for a Threat Detection Engineer to join a well-established biotech company using large-scale genetic data and AI to predict disease risk and advance precision healthcare.

As a Threat Detection Engineer, you will be responsible for developing and enhancing threat detection capabilities within a modern cloud-first setting. This role offers hybrid / remote working options, a salary range of 60,000 - 80,000 and benefits.

You will be responsible for:

  • Designing and implementing threat-led detection logic informed by threat intelligence and hunting activities.
  • Developing innovative analytical techniques to identify incidents effectively.
  • Collaborating with an outsourced SOC to maintain, tune, and optimise detection catalogues.
  • Creating and refining DLP, Insider Risk Management, and other security rules using cloud-native tools.
  • Monitoring and ensuring high-quality service delivery from external SOC providers.
  • Automating reporting on security performance and operational metrics.
  • Partnering with technology teams to ensure adequate monitoring across cloud platforms, SaaS, and internal systems.
  • Documenting security processes, tool configurations, and contributing to service delivery documentation.
  • Supporting colleagues with ISO 27001 compliance and KQL-related tasks.

What we are looking for:

  • Previously worked as a Threat Detection Engineer or in a similar role.
  • Must have strong expertise in KQL.
  • Hands-on experience with Microsoft Sentinel and Defender (Endpoint, Office 365).
  • Familiarity with Microsoft Entra ID, including Identity Governance.
  • Experience with Microsoft Purview, particularly DLP and data protection tools.
  • Exposure to cloud-native logging in Azure and Kubernetes environments.
  • Understanding of “detection as code” or “everything as code” approaches, including CI/CD pipelines.
  • Experience working with or alongside MSP SOC teams.
  • Awareness of Agile methodologies and ways of working.
  • Knowledge of attacker TTPs, threat modelling, and cyber security frameworks.
  • Understanding of statistics, data science, or AI/ML as applied to security.
  • Awareness of ISO 27001 standards.
  • Relevant cyber security certifications (e.g., MS-500, AZ-500, SC-200, SC-300, SC-400, Security+, GSOC, CCSK).

This is a rare chance to contribute to meaningful cyber security work in a role where your expertise will directly influence how threats are detected and mitigated at scale.

Cyber Security Engineer (Threat Detection & Automation) employer: Additional Resources

Join a forward-thinking company that values innovation and technical excellence, where as a Senior Platform Engineer, you will play a pivotal role in scaling a pioneering platform. With a strong emphasis on employee growth, collaborative work culture, and the opportunity to lead cutting-edge projects, this position offers a unique chance to make a meaningful impact in a dynamic environment. Located in a vibrant area, the company provides excellent benefits and fosters a culture of continuous learning and development.

Additional Resources

Contact Details:

Additional Resources Recruitment Team

We think you need these skills to ace Cyber Security Engineer (Threat Detection & Automation)

KQL
Microsoft Sentinel
Microsoft Defender
Microsoft Entra ID
Microsoft Purview
DLP
Cloud-native logging