At a Glance
- Tasks: Design and maintain detection content to combat cyber threats across global infrastructure.
- Company: Join a leading cybersecurity team dedicated to protecting digital assets.
- Benefits: Competitive salary, flexible work options, and opportunities for professional growth.
- Other info: Dynamic team environment with a focus on innovation and collaboration.
- Why this job: Make a real difference in cybersecurity by detecting and preventing threats.
- Qualifications: Experience in threat detection and familiarity with SIEM and scripting languages.
The predicted salary is between 72000 - 88000 £ per year.
The ICE Cybersecurity Threat Detection team is responsible for detecting malicious behaviour across ICE's global infrastructure quickly and reliably enough to contain it. We build, tune, and maintain the detection content that security operation teams depend on, and hunt proactively for threats that existing controls do not catch, working alongside threat intelligence, incident response, and red team functions to keep coverage grounded in real adversary behaviour.
Responsibilities
- Detection Engineering - Design, build, test, and maintain detection content across SIEM, EDR, and NDR platforms, and document the intent, data source, and expected behaviour of each detection.
- Detection Tuning and Health - Own false positive rates, alert volume, and rule health for assigned detection areas, including retiring logic that no longer earns its place.
- Detection Coverage - Map detection coverage to the MITRE ATT&CK framework, identify gaps, and propose the telemetry or logic needed to close them.
- Threat Intelligence Integration - Convert threat intelligence reporting into prioritised detection and hunting work, so coverage follows the adversaries and techniques most relevant to the sector rather than whatever arrived most recently.
- Proactive Threat Hunting - Develop and execute focused hunts to discover threats that evade existing controls, and promote successful hunt outcomes into durable production detections.
- Red Team Gap Remediation - Take ownership of detection gaps reported through red team and purple team exercises; track each gap to closure, build or amend the detection, and validate that the exercise activity is caught on retest.
- Log Source Health - Validate the health and completeness of security log sources, detect collection failures and silent feeds, and onboard or update SIEM log sources in a timely manner.
- Automation and Tooling - Apply a developer and problem-solving mindset to the work, using scripting to build internal tooling, process and normalise data, and remove repetitive manual effort wherever it appears.
Knowledge and Experience
- Relevant experience in threat detection, security operations, or threat hunting.
- Hands-on, day-to-day experience with SIEM, EDR, and NDR platforms, including writing and tuning detection logic.
- Working knowledge of a scripting language for automation, at the level needed to build useful internal tooling.
- Demonstrated ability to investigate suspicious activity end to end: read the logs, form a conclusion, and communicate it clearly.
- Familiarity with the MITRE ATT&CK framework and the ability to reason about adversary tradecraft rather than only indicators.
- Solid understanding of operating system internals, networking, and authentication as they appear in security telemetry.
- University degree in Engineering, MIS, CIS, or related discipline; or equivalent years of experience.
Preferred Experience
- Authoring Sigma rules and working with portable, vendor-neutral detection formats.
- Detection as code practices, including Git workflows, peer-reviewed rule changes, automated rule testing, and pipeline-based deployment.
- Structured hunting methodologies such as PEAK or TaHiTI, and experience hunting against a documented backlog rather than ad hoc.
- Applied AI engineering in a security context, including use or development of LLM assisted tooling for triage, enrichment, rule drafting, or log summarisation, together with a realistic understanding of where these systems fail and how to evaluate their output.
- Malware analysis, digital forensics, or reverse engineering fundamentals.
Specific Technologies
- SIEM platforms including Splunk and Elasticsearch.
- Endpoint detection and response platforms including Tanium, CrowdStrike, and SentinelOne.
- Network detection and response tooling and network traffic analysis.
- MITRE ATT&CK.
- Scripting and automation in Python or PowerShell.
- Windows, Linux, and cloud security telemetry, including authentication, process execution, and network log formats.
- Version control and ticketing workflows.
Cyber Security Engineer - Threat Detection in London employer: Intercontinental Exchange Holdings
Intercontinental Exchange Inc. (ICE) is an exceptional employer, offering a dynamic work environment in the heart of the financial services sector. With a strong focus on employee growth and development, ICE provides opportunities for professional advancement while fostering a collaborative culture that values innovation and strategic thinking. Located in a vibrant area, employees benefit from a diverse range of networking opportunities and industry events, making it an ideal place for those looking to make a meaningful impact in the world of financial information services.
Contact Details:
Intercontinental Exchange Holdings Recruitment Team
StudySmarter Expert Advice🤫
We think this is how you could land Cyber Security Engineer - Threat Detection in London
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Intercontinental Exchange Holdings, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Intercontinental Exchange Holdings
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Intercontinental Exchange Holdings. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Cyber Security Engineer - Threat Detection in London
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Intercontinental Exchange Holdings insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Intercontinental Exchange Holdings that you’re committed to staying ahead in the game.
How to prepare for a job interview at Intercontinental Exchange Holdings
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Intercontinental Exchange Holdings to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Intercontinental Exchange Holdings.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.