Lead Security Engineer in Preston

Lead Security Engineer in Preston

Preston Full-Time 60000 - 80000 £ / year (est.) No working from home possible
OptumUK

At a Glance

  • Tasks: Lead and optimise security platforms to enhance threat detection and reduce false positives.
  • Company: Join EMIS / Optum UK, a leader in healthcare technology.
  • Benefits: Competitive salary, impactful work, and opportunities for professional growth.
  • Other info: Dynamic role with a focus on collaboration and measurable improvements.
  • Why this job: Make a real difference in protecting critical healthcare systems across the UK.
  • Qualifications: Hands-on experience with security platforms like Darktrace and CrowdStrike is essential.

The predicted salary is between 60000 - 80000 £ per year.

Are you an experienced security professional with deep, hands-on expertise across security platforms and detection engineering? Do you want to take ownership of how security tooling performs at scale — improving detection quality, reducing noise, and ensuring threats are effectively identified across complex environments?

About the Team / Business Area

The Security Operations team sits at the core of our organisation, protecting nationally critical healthcare systems that support frontline patient care across the UK. Operating within a highly regulated environment, the team is responsible for SOC oversight, vulnerability management, attack surface monitoring, and real-time threat detection across enterprise, cloud, and network platforms. This function plays a critical role in ensuring system resilience, maintaining regulatory compliance, and enabling the secure delivery of healthcare services at scale.

About the Role

As the Security Detection & Tooling Lead, you will take ownership of the performance, optimisation, and governance of key security platforms and detection capabilities. This is a senior, hands-on engineering role focused on improving how threats are detected across the organisation. You will drive improvements in detection quality, reduce false positives, and ensure security tooling is used effectively and efficiently across all environments. This role requires proven, hands-on, administrator-level experience across core security platforms (including Darktrace, CrowdStrike, and Google SecOps). Candidates without this level of direct platform ownership and administration experience will not be suitable.

Working closely with SOC, Security Engineering, and wider technology teams, you will define detection standards, influence tooling strategy, and ensure security controls remain aligned to risk.

Key Responsibilities:

  • Own and optimise core security platforms (SIEM, EDR, NDR, SASE), ensuring performance, utilisation, and governance
  • Design, build, and tune detection logic to improve alert fidelity and reduce noise
  • Drive improvements in detection coverage using frameworks such as MITRE ATT&CK
  • Partner with SOC teams to enhance incident detection, triage, and response outcomes
  • Identify opportunities to rationalise tooling, improve efficiency, and reduce operational overhead
  • Develop and implement automation to improve workflows and reduce manual effort
  • Produce reporting on detection performance, coverage gaps, and platform effectiveness
  • Define and maintain detection and tooling standards across Security Operations

What You'll Bring:

You are a hands-on, technically strong security professional with experience operating and optimising security tooling at scale. You take ownership of platforms and outcomes, focusing on delivering measurable improvements in detection capability and operational efficiency. You are comfortable working across teams, influencing change, and applying a structured, analytical approach to improving security operations.

Key Skills, Experience & Qualifications

Essential

  • Strong experience in Security Operations, Detection Engineering, or Security Tooling roles
  • Hands-on administration and engineering experience across security platforms (SIEM, EDR, NDR or equivalent)
  • Hands-on, administrator-level experience with Darktrace, CrowdStrike, and Google SecOps (minimum, non-negotiable requirement)
  • Proven experience designing, building, and tuning detections to improve alert quality and reduce false positives
  • Experience working closely with SOC teams to improve detection and response outcomes
  • Solid understanding of detection frameworks and methodologies (e.g. MITRE ATT&CK)

Ready to Join Us? At EMIS / Optum UK, we are a leader in healthcare technology, supporting professionals across primary care, community services, pharmacy, and beyond. This is an opportunity to take ownership of detection and tooling capability within a complex, high-impact environment — directly contributing to the protection of systems that underpin patient care across the UK. If you are looking for a role where you can lead, optimise, and make a measurable impact, we would welcome your application.

Lead Security Engineer in Preston employer: OptumUK

At EMIS / Optum UK, we pride ourselves on being an exceptional employer, offering a dynamic work culture that fosters collaboration and innovation within our Security Operations team. Our commitment to employee growth is evident through continuous training opportunities and the chance to lead critical security initiatives that protect healthcare systems across the UK. Join us to make a meaningful impact in a supportive environment where your expertise will be valued and your contributions will directly enhance patient care.

OptumUK

Contact Details:

OptumUK Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Lead Security Engineer in Preston

Tip Number 1

Network like a pro! Reach out to folks in the industry, attend meetups, and connect with potential colleagues on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

Tip Number 2

Show off your skills! Create a portfolio or a GitHub repository showcasing your projects and achievements in security tooling. This gives you a chance to demonstrate your hands-on experience and technical prowess beyond just a CV.

Tip Number 3

Prepare for interviews by brushing up on key concepts and tools mentioned in the job description. Be ready to discuss your experience with platforms like Darktrace and CrowdStrike, and how you've improved detection capabilities in past roles.

Tip Number 4

Don't forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you're genuinely interested in joining our team and making an impact in healthcare technology.

We think you need these skills to ace Lead Security Engineer in Preston

Security Operations
Detection Engineering
Security Tooling
Hands-on Administration
SIEM
EDR
NDR

Some tips for your application 🫡

Tailor Your CV:Make sure your CV reflects the specific skills and experiences mentioned in the job description. Highlight your hands-on experience with security platforms like Darktrace and CrowdStrike, as we want to see how you can contribute to our team.

Craft a Compelling Cover Letter:Use your cover letter to tell us why you're passionate about security operations and how your background aligns with our mission. Share specific examples of how you've improved detection capabilities in previous roles — we love a good story!

Showcase Your Technical Skills:Don’t shy away from detailing your technical expertise in your application. We’re looking for candidates who can demonstrate their hands-on experience with security tooling and detection engineering, so be specific about your achievements.

Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you don’t miss out on any important updates regarding your application status.

How to prepare for a job interview at OptumUK

Know Your Tools Inside Out

Make sure you have a solid understanding of the security platforms mentioned in the job description, like Darktrace, CrowdStrike, and Google SecOps. Be ready to discuss your hands-on experience with these tools, including specific examples of how you've optimised their performance or improved detection capabilities.

Demonstrate Your Analytical Skills

Prepare to showcase your analytical approach to security operations. Think of scenarios where you've used frameworks like MITRE ATT&CK to enhance detection quality or reduce false positives. Being able to articulate your thought process will impress the interviewers.

Collaborate and Communicate

Since this role involves working closely with SOC teams, be prepared to discuss how you've effectively collaborated with others in past roles. Share examples of how you’ve influenced change or improved incident detection and response outcomes through teamwork.

Showcase Your Problem-Solving Skills

Think of specific challenges you've faced in security operations and how you tackled them. Whether it was rationalising tooling or automating workflows, being able to present your problem-solving skills will demonstrate your capability to take ownership and drive improvements.