Security Engineer Detection Engineering & Automation in London
Security Engineer Detection Engineering & Automation

Security Engineer Detection Engineering & Automation in London

London Full-Time 36000 - 60000 £ / year (est.) No home office possible
Go Premium
ION

At a Glance

  • Tasks: Design and build scalable detection and response capabilities in cloud and enterprise environments.
  • Company: Join a leading tech firm transforming financial technology with innovative solutions.
  • Benefits: Competitive salary, inclusive culture, and opportunities for professional growth.
  • Why this job: Make a real impact by engineering high-fidelity detections and automating security workflows.
  • Qualifications: Experience in detection engineering and automation, with strong scripting skills.
  • Other info: Dynamic work environment with a commitment to diversity and inclusion.

The predicted salary is between 36000 - 60000 £ per year.

We are seeking a Security Engineer specialising in Detection Engineering and Security Automation to design, build, and operate scalable detection and response capabilities across cloud and enterprise environments. This role focuses on engineering high-fidelity detections and automating response workflows across platforms such as Rapid7, SentinelOne, and CrowdStrike, using Azure Logic Apps and API-driven integrations to reduce manual effort and improve response speed. This is a hands-on engineering role for someone who thinks in attacker behaviours, builds resilient automation, and prefers engineering solutions over manual SOC processes.

Key Responsibilities

  • Detection Engineering
    • Design, implement, and continuously improve threat detections across endpoint, identity, vulnerability, and cloud telemetry.
    • Engineer detections using data from Rapid7, SentinelOne, and CrowdStrike, including behavioural, anomaly-based, and contextual detections.
    • Translate MITRE ATT&CK techniques and real-world threat intelligence into actionable detection logic.
    • Develop and tune detection logic to reduce false positives while preserving signal quality.
    • Validate detections through testing, attack simulation, and post-incident review.
    • Maintain detection coverage mapping across the attack lifecycle.
  • Security Automation & SOAR
    • Design and implement security automation workflows using Azure Logic Apps to support alert triage, enrichment, containment, and response.
    • Automate workflows such as alert enrichment from asset inventories and vulnerability data, risk-based prioritisation using exploitability and exposure context, endpoint containment or isolation actions, and case creation, updates, and closure across security platforms.
    • Integrate tools via REST APIs, webhooks, and managed connectors.
    • Build modular, reusable automation components with robust error handling and observability.
  • Platform Integration & Engineering
    • Integrate and correlate telemetry across Rapid7, SentinelOne, CrowdStrike, and supporting security systems.
    • Work closely with security and cloud teams to onboard new data sources and ensure data quality.
    • Apply detection-as-code and automation-as-code principles using version control and structured deployment processes.
    • Build dashboards and metrics to measure detection efficacy, alert quality, and automation impact.
  • Incident Response & Continuous Improvement
    • Support incident response by enhancing detections and automations based on real incidents.
    • Feed learnings from investigations back into detection logic and response workflows.
    • Maintain documentation, playbooks, and runbooks for detections and automations.
    • Contribute to purple-team activities and detection gap analysis.

Required Skills, Experience and Qualifications

  • Proven experience in detection engineering, security operations engineering, or security automation roles.
  • Hands-on experience with Rapid7, SentinelOne, and/or CrowdStrike in detection or response contexts.
  • Strong experience building automation using Azure Logic Apps.
  • Proficiency integrating systems using REST APIs, JSON payloads, authentication, and pagination.
  • Solid understanding of endpoint security, vulnerability management, and attacker tradecraft.
  • Deep familiarity with MITRE ATT&CK and behaviour-based detection methodologies.

Engineering & Operational Skills

  • Strong scripting or engineering background (e.g. Python, PowerShell).
  • Experience working with structured data, event pipelines, and telemetry correlation.
  • Understanding of alert lifecycle management and incident response workflows.
  • Ability to design automation that is safe, resilient, and auditable.

Preferred Experience

  • Correlating endpoint, vulnerability, and asset data for risk-based detection.
  • Familiarity with SOAR design patterns and automation governance.
  • Exposure to cloud security telemetry and identity-based attack detection.
  • Experience operating in large-scale or regulated environments.
  • Knowledge of CI/CD or infrastructure-as-code approaches for security tooling.

About us

We’re a diverse group of visionary innovators who provide trading and workflow automation software, high-value analytics, and strategic consulting to corporations, central banks, financial institutions, and governments. Founded in 1999, we’ve achieved tremendous growth by bringing together some of the best and most successful financial technology companies in the world. Over 2,000 of the world’s leading corporations, including 50% of the Fortune 500 and 30% of the world’s central banks, trust ION solutions to manage their cash, in-house banking, commodity supply chain, trading and risk. Over 800 of the world’s leading banks and broker-dealers use our electronic trading platforms to operate the world’s financial market infrastructure. ION is a rapidly expanding and dynamic group with 13,000 employees and offices in more than 40 cities around the globe. Our ever-expanding global footprint, cutting-edge products, and over 40,000 customers worldwide provide an unparalleled career experience for those who share our vision. ION is committed to maintaining a supportive and inclusive environment for people with diverse backgrounds and experiences. We respect the varied identities, abilities, cultures, and traditions of the individuals who comprise our organization and recognize the value that different backgrounds and points of view bring to our business. ION adheres to an equal employment opportunity policy that prohibits discriminatory practices or harassment against applicants or employees based on any legally impermissible factor.

Security Engineer Detection Engineering & Automation in London employer: ION

ION is an exceptional employer for a Security Engineer, offering a dynamic work environment that fosters innovation and collaboration across diverse teams. With a commitment to employee growth, ION provides extensive training opportunities and the chance to work with cutting-edge technologies in a global setting, ensuring that your contributions have a meaningful impact on the financial technology landscape. The inclusive culture and focus on diversity make it a rewarding place to build a career while tackling real-world challenges in security automation and detection engineering.
ION

Contact Detail:

ION Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Security Engineer Detection Engineering & Automation in London

✨Tip Number 1

Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can refer you directly.

✨Tip Number 2

Show off your skills! Create a portfolio or GitHub repository showcasing your detection engineering projects or automation scripts. This gives potential employers a taste of what you can do and sets you apart from the crowd.

✨Tip Number 3

Prepare for interviews by practising common technical questions related to detection engineering and security automation. Use mock interviews to get comfortable discussing your experience with tools like Rapid7 and Azure Logic Apps.

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining our team at ION.

We think you need these skills to ace Security Engineer Detection Engineering & Automation in London

Detection Engineering
Security Automation
Azure Logic Apps
REST APIs
JSON Payloads
Endpoint Security
Vulnerability Management
MITRE ATT&CK
Behaviour-based Detection
Scripting (Python, PowerShell)
Telemetry Correlation
Incident Response Workflows
Automation Design
SOAR Design Patterns
CI/CD or Infrastructure-as-Code

Some tips for your application 🫡

Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience with detection engineering and security automation. We want to see how your skills align with the role, so don’t hold back on showcasing your hands-on experience with tools like Rapid7, SentinelOne, and CrowdStrike.

Show Off Your Technical Skills: Don’t forget to mention your scripting or engineering background! If you’ve got experience with Python or PowerShell, let us know. We’re keen to see how you can apply your technical skills to build resilient automation and improve our detection capabilities.

Demonstrate Your Problem-Solving Mindset: We love candidates who think like attackers! Share examples of how you’ve translated real-world threats into actionable detection logic or automated workflows. This will show us that you understand the importance of proactive security measures.

Apply Through Our Website: We encourage you to submit your application through our website. It’s the best way for us to keep track of your application and ensure it gets the attention it deserves. Plus, it’s super easy to do!

How to prepare for a job interview at ION

✨Know Your Tools Inside Out

Make sure you’re well-versed in the tools mentioned in the job description, like Rapid7, SentinelOne, and CrowdStrike. Familiarise yourself with their functionalities and how they integrate with Azure Logic Apps. Being able to discuss your hands-on experience with these platforms will show that you’re ready to hit the ground running.

✨Understand MITRE ATT&CK Framework

Brush up on the MITRE ATT&CK techniques and how they relate to detection engineering. Be prepared to discuss how you’ve translated real-world threat intelligence into actionable detection logic in past roles. This will demonstrate your ability to think like an attacker and design effective detections.

✨Showcase Your Automation Skills

Prepare examples of how you’ve built automation workflows using Azure Logic Apps or similar tools. Highlight any modular components you’ve created and how they improved efficiency. This will illustrate your capability to engineer solutions rather than relying on manual processes.

✨Be Ready for Scenario-Based Questions

Expect scenario-based questions that test your incident response skills and your approach to enhancing detections based on real incidents. Think of specific examples where you’ve contributed to detection gap analysis or improved automation workflows, as this will showcase your practical experience and problem-solving abilities.

Security Engineer Detection Engineering & Automation in London
ION
Location: London
Go Premium

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>