At a Glance
- Tasks: Design and maintain detection content to identify malicious activity and enhance security.
- Company: Join a leading cybersecurity team focused on proactive threat detection.
- Benefits: Competitive salary, flexible work options, and opportunities for professional growth.
- Other info: Collaborative culture with a focus on innovation and continuous learning.
- Why this job: Make a real impact in cybersecurity by shaping detection capabilities in a dynamic environment.
- Qualifications: Experience in threat detection and hands-on knowledge of SIEM, EDR, and NDR platforms.
The predicted salary is between 58500 - 71500 £ per year.
Overview
In this role you will design and maintain detection content across SIEM, EDR, and NDR to rapidly identify malicious activity.
You will work closely with threat intelligence, incident response, and red teams to ensure detections reflect real adversary behavior.
You will tune alerts, reduce false positives, and map coverage to MITRE ATT&CK to close gaps.
You will also lead proactive hunts and productionize findings to strengthen ICE’s security posture.
This is a hands-on opportunity to shape detection capability in a complex, security-focused environment.
Responsibilities
- Design, build, test, and maintain detection content across SIEM, EDR, and NDR
- Own false positive rates and alert health for assigned detection areas
- Map detection coverage to MITRE ATT&CK and close telemetry gaps
- Convert threat intelligence into prioritized detection and hunting work
- Develop and execute focused hunts and productionize successful findings
- Remediate detection gaps from red/purple team exercises and validate on retest
- Validate health and completeness of log sources and onboard/update SIEM sources
- Apply scripting to build internal tooling and automate repetitive tasks
- Key requirements
- Threat detection, security operations, or threat hunting experience
- Hands-on experience with SIEM, EDR, and NDR platforms with detection logic
- Scripting ability for automation to build internal tooling
- Ability to investigate suspicious activity end-to-end and communicate conclusions
- Familiarity with MITRE ATT&CK framework and adversary tradecraft
- Solid understanding of OS internals, networking, and security telemetry
- University degree in Engineering, MIS, CIS, or related discipline; or equivalent experience
- Problem-solving mindset
- Clear written and verbal communication
- Collaborative cross-functional work
- SIEM, EDR, NDR platforms (Splunk, Elasticsearch, Tanium, Crowd Strike, Sentinel One)
- Scripting in Python or Power Shell
- Threat intelligence integration and threat hunting methodologies
Cyber Security Engineer - Threat Detection in London employer: Intercontinental Exchange
Intercontinental Exchange, Inc. (ICE) is an exceptional employer that offers engineers the chance to work on innovative technology within a dynamic and collaborative environment. With a strong focus on employee growth, ICE provides extensive training opportunities and encourages professional development, ensuring that team members can thrive in their careers while contributing to one of the largest global financial networks. Located in a vibrant area, employees enjoy a supportive work culture that values problem-solving and teamwork, making it a rewarding place to build a meaningful career.