Security Engineer, Detection & Response
Security Engineer, Detection & Response

Security Engineer, Detection & Response

Full-Time 36000 - 60000 £ / year (est.) No home office possible
doxy.me

At a Glance

  • Tasks: Shape Doxy.me's security operations by writing detection rules and responding to threats.
  • Company: Join a leading telehealth platform dedicated to protecting patient data globally.
  • Benefits: Enjoy competitive salary, unlimited PTO, and flexible work options.
  • Why this job: Make a real impact in healthcare security while working with innovative technology.
  • Qualifications: Strong programming skills in Python/TypeScript and experience with detection engineering.
  • Other info: Be part of a small, high-impact team with excellent career growth opportunities.

The predicted salary is between 36000 - 60000 £ per year.

Who You Are

You are a security engineer with a strong software engineering background who would rather write detection-as-code than click through a SIEM UI. You care about protecting healthcare providers and the patients who depend on them - and you want to build the systems that make that possible. You will own Doxy.me's detection and security operations function: writing detection rules, building telemetry pipelines, and responding to threats across our cloud-native platform. You will apply engineering principles to security - detection-as-code over point-and-click, automation over manual toil. Most of your time will be spent on detection engineering, but you will also contribute to threat modeling and product security alongside the wider team. You are comfortable with ambiguity, self-directed, and motivated by impact. There is no SOC manager - you will shape this function from scratch.

Your Skills

  • Experience writing and shipping detection rules using a detection-as-code approach
  • Strong programming skills in Python and/or TypeScript; comfortable with SQL for querying security data
  • Experience with AWS and cloud-native infrastructure
  • Familiarity with observability and monitoring platforms like Datadog
  • Understanding of attacker techniques and frameworks like MITRE ATT&CK
  • Experience with CI/CD pipelines and software engineering workflows
  • Comfort with threat modeling and application security concepts

Nice to have

  • Experience with incident response and forensic investigation
  • Familiarity with identity and access management systems

The Team

The Information Security team at Doxy.me is small and high-impact: a CISO, plus engineers covering corporate security, GRC & compliance, and product & application security. You will be our first dedicated detection engineer - meaning you will shape the function, the tooling, and the approach from the ground up. You will work most closely with our product security engineer on threat modeling and detection strategy, and across the company with product and engineering teams.

Detection Engineering

  • Own the detection lifecycle end-to-end: research threats, write rules as code, deploy via CI/CD, tune for precision, and maintain over time
  • Build and maintain telemetry pipelines that give visibility into application, infrastructure, and identity activity
  • Correlate signals across multiple data sources to improve detection accuracy and reduce false positives

Security Operations & Response

  • Investigate and respond to security events, including containment, remediation, and post-incident analysis
  • Build automated response workflows that integrate with our cloud infrastructure and identity systems

Broader Security

  • Partner with product and engineering teams on threat modelling to identify detection opportunities early in the design process
  • Contribute to security monitoring standards, response procedures, and operational playbooks

Technical Assessment

As part of the interview process, you will complete a practical assessment focused on detection engineering and threat analysis - or share a portfolio of relevant past work (detection rules, blog posts, open-source contributions, conference talks).

Who We Are

At Doxy.me, we are on a mission to connect the world to the future of healthcare. With the trust of over one million providers we are one of the largest Telehealth platforms in the world - but we are not done there. We are HIPAA-regulated and trusted with sensitive patient data across 180+ countries - protecting that trust is why our security team exists. Blending innovative technology and world-class design, we enhance the patient-provider experience and extend the reach of healthcare to every corner of the globe. Our team is motivated by making a difference in the world and pushing the boundaries of what is possible. If you want to change the world by impacting the lives of millions while having fun with a great team, come join us!

Our Culture

  • Authentic: We are sincere and care personally. We do not let egos get in the way - getting to the right answer is more important than being right. We focus on doing the right thing and act with integrity.
  • Bright: We use our intelligence, talent, and curiosity to create simple, innovative, world-class solutions to problems. We are constantly seeking to increase our own brightness through learning and collaboration.
  • Effective: We are hungry self-starters who will get the job done regardless of circumstances. We do not need to be managed or told what to do. We pride ourselves in producing high-quality, world-class results.

Benefits

We are committed to giving you the tools you need to do your best work. We take care of the little things so you can focus on what matters most. Here is a taste of what you can expect:

  • A fun, flexible work environment (work from home or on location at one of our regional hubs)
  • Competitive salary
  • Paid trainings and certifications
  • Advancement opportunities in a growing company
  • Medical, Vision, and Dental insurance
  • 401k match
  • Unlimited PTO

Our employees give us a 4.9 rating on Glassdoor.

Security Engineer, Detection & Response employer: doxy.me

At Doxy.me, we pride ourselves on being an exceptional employer, offering a dynamic and flexible work environment that empowers our employees to make a meaningful impact in the healthcare sector. As a Security Engineer, Detection & Response, you'll have the unique opportunity to shape our security operations from the ground up while enjoying competitive salaries, unlimited PTO, and a strong commitment to professional growth through paid training and certifications. Join us in our mission to revolutionise healthcare and experience a culture that values authenticity, innovation, and effectiveness.
doxy.me

Contact Detail:

doxy.me Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Security Engineer, Detection & Response

✨Tip Number 1

Network like a pro! Reach out to folks in the industry, especially those already at Doxy.me. A friendly chat can open doors and give you insider info on what they're really looking for.

✨Tip Number 2

Show off your skills! If you've got a portfolio of detection rules or any cool projects, make sure to highlight them during interviews. It’s all about proving you can walk the walk, not just talk the talk.

✨Tip Number 3

Prepare for that technical assessment! Brush up on your detection engineering and threat analysis skills. Practise coding detection rules and be ready to discuss your thought process.

✨Tip Number 4

Apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you're genuinely interested in joining our mission at Doxy.me.

We think you need these skills to ace Security Engineer, Detection & Response

Detection-as-Code
Python
TypeScript
SQL
AWS
Cloud-Native Infrastructure
Datadog
MITRE ATT&CK
CI/CD Pipelines
Threat Modelling
Application Security
Incident Response
Forensic Investigation
Identity and Access Management

Some tips for your application 🫡

Show Your Passion for Security: Let us see your enthusiasm for security engineering! Share your experiences and projects that highlight your dedication to protecting healthcare providers and patients. We want to know why this role excites you!

Tailor Your Application: Make sure to customise your CV and cover letter to reflect the skills and experiences mentioned in the job description. Highlight your programming skills, detection-as-code experience, and any relevant projects you've worked on. We love seeing how you fit into our mission!

Be Clear and Concise: When writing your application, keep it straightforward and to the point. Use bullet points where possible to make your skills and experiences stand out. We appreciate clarity and want to quickly understand what you bring to the table!

Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it shows you’re serious about joining our team!

How to prepare for a job interview at doxy.me

✨Know Your Detection Rules

Make sure you’re well-versed in writing detection rules as code. Brush up on your Python and TypeScript skills, and be ready to discuss how you've applied these in real-world scenarios. Having examples of your work can really set you apart!

✨Understand the Threat Landscape

Familiarise yourself with attacker techniques and frameworks like MITRE ATT&CK. Be prepared to talk about how you’ve used this knowledge in past roles to improve security measures or respond to incidents.

✨Showcase Your Automation Skills

Since automation is key in this role, think of specific instances where you’ve automated processes or built CI/CD pipelines. Highlight how these efforts improved efficiency or reduced manual toil in your previous positions.

✨Prepare for the Technical Assessment

This role includes a practical assessment focused on detection engineering. Review your past work, whether it’s detection rules or relevant projects, and be ready to discuss your thought process and the impact of your contributions.

Security Engineer, Detection & Response
doxy.me

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>