Security Engineering Lead - Detection and Response in London

Security Engineering Lead - Detection and Response in London

London Full-Time 95000 - 145000 £ / year (est.) Home office (partial)
Open Select

At a Glance

  • Tasks: Build and shape detection and response capabilities from scratch in a high-stakes fintech environment.
  • Company: Join a leading London-based fintech automating the securities finance lifecycle.
  • Benefits: Competitive salary, bonus, hybrid working, and opportunities for team leadership.
  • Other info: Direct access to CISO and CTO with excellent career growth potential.
  • Why this job: Make a real impact on security for $6.5 trillion in daily transactions.
  • Qualifications: Hands-on experience in detection engineering and incident response, proficient in Python.

The predicted salary is between 95000 - 145000 £ per year.

Location: London / hybrid

Salary: £95,000 - £145,000 plus bonus

Industry: Fintech / Securities Finance Technology

Work Authorization: This role requires the right to work in the UK, no sponsorship available

Who you'll join

Our client is a London based fintech that automates the securities finance lifecycle. The platform processes over $6.5 trillion in transactions every day, connecting more than 150 financial institutions worldwide, including 25 of the 30 global systemically important banks.

You will report directly into the CISO and CTO, with real scope to shape how the company detects and responds to threats.

What you'll do

  • Build the company's detection and response capability from the ground up, establishing the processes, telemetry and tooling needed to detect, investigate and contain threats across AWS, on premises, Workforce IT and the endpoint estate.
  • Produce a documented asset and telemetry map across AWS, on premises, Workforce IT and user endpoints.
  • Assess current security monitoring and third party SOC coverage against LLM enabled attacks. Deliver a risk based plan using a hybrid SOC model, working with engineering teams to implement it.
  • Build documented MITRE ATT&CK detection coverage across all Tier 1 tactics within 12 months, managed as code and version controlled.
  • Author and maintain playbooks for the top incident types by likelihood and impact. Automate containment and response actions through SOAR, targeting 80% automated first action on P1 and P2 responses.
  • Establish MTTD and MTTR baselines within 90 days and set improvement targets.
  • Run structured threat hunting cycles each quarter and convert findings into new detection rules.
  • Review unpatchable vulnerabilities with engineering teams and recommend treatment.
  • Produce a monthly detection and response programme metrics report for the CISO and CTO.
  • Build internal security capability through knowledge sharing, runbook documentation and structured mentoring as the team grows.

Who you are

  • Hands on detection engineering experience, writing and maintaining SIEM detection rules, correlation logic and detection as code pipelines.
  • Proficient in Python or equivalent for detection development, log parsing and automation.
  • Demonstrated incident response experience, leading or contributing to P1 and P2 investigations, post incident reviews and containment.
  • Experience with cloud security on AWS and/or Azure, including native cloud telemetry sources.
  • Familiar with MITRE ATT&CK as a framework for detection design and gap analysis.
  • Hands on experience building and operating SOAR playbooks and response automation across SIEM, EDR, cloud and ticketing.
  • Experience leading a SOC and/or managing a third party SOC.
  • Demonstrated experience running structured threat hunting cycles.
  • Able to influence stakeholders across the technology team. Strong written communication, able to translate technical findings for non-technical stakeholders.
  • Able to work independently and collaborate with technical stakeholders across the business.

Tech stack

  • Cloud: AWS (primary), SIEM, SOAR, EDR, Python for detection development, log parsing and automation, MITRE ATT&CK as the detection design and gap analysis framework, Detection as code, version controlled (Git or equivalent), Ticketing and workflow tooling across SIEM, EDR, cloud and ticketing systems.

Why you'll join

  • Genuine build from scratch mandate. You are not inheriting someone else's detection stack, you are designing it.
  • High stakes, high trust environment. The platform underpins $6.5 trillion in daily transactions for 25 of the 30 global systemically important banks.
  • Direct line into the CISO and CTO, with real visibility on your work at leadership level.
  • A clear path to building and leading a team as the function grows.
  • Hybrid working in London.

Security Engineering Lead - Detection and Response in London employer: Open Select

Join a pioneering fintech in London that is at the forefront of automating the securities finance lifecycle, processing over $6.5 trillion in transactions daily. As a Security Engineering Lead, you'll have the unique opportunity to build detection and response capabilities from the ground up, working directly with the CISO and CTO in a high-stakes environment that values innovation and collaboration. With a strong focus on employee growth, hybrid working options, and a clear path to leadership, this role offers a rewarding career in a dynamic and impactful industry.

Open Select

Contact Details:

Open Select Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Security Engineering Lead - Detection and Response in London

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Open Select, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Open Select

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Open Select. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Security Engineering Lead - Detection and Response in London

Detection Engineering
SIEM Detection Rules
Correlation Logic
Detection as Code
Python
Log Parsing
Automation

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Open Select insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Open Select that you’re committed to staying ahead in the game.

How to prepare for a job interview at Open Select

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Open Select to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Open Select.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.