A leading international financial services organisation is seeking a Cyber Security Engineer to join its Proactive Security function. This role will focus on strengthening security capabilities through threat detection, security engineering, automation, and proactive defence initiatives across a complex enterprise environment.
- Permanent (£70k - £80k)
- London / Hybrid
- Must have UK citizenship / ILR Visa / EU settled status
Key Responsibilities
Threat Modelling & Security Engineering
- Develop and maintain threat models for business-critical systems and services.
- Assess security risks and recommend controls during project design and implementation.
- Build and maintain capabilities for proactive detection, configuration monitoring, and automated remediation.
- Lead security tooling integrations and orchestration initiatives.
- Develop and enhance SOAR capabilities.
- Support identity-based threat detection, privileged access management, and session monitoring.
SIEM Engineering & Security Monitoring
- Design, implement, and maintain SIEM workspaces, data connectors, analytics rules, dashboards, and playbooks.
- Develop advanced threat hunting queries and investigation workflows.
- Onboard and optimise critical security log sources across on-premise and cloud environments.
- Improve detection accuracy through continuous tuning and use case development.
- Troubleshoot and resolve log ingestion and data quality issues.
Threat Detection & Incident Response
- Design and deploy advanced detection use cases covering modern attack techniques.
- Translate threat intelligence into actionable monitoring and detection capabilities.
- Perform proactive threat hunting activities.
- Contribute to security playbooks, response procedures, and operational improvements.
Security Advisory
- Provide expert guidance on application and infrastructure security.
- Support the evaluation and proof of concept of emerging security technologies.
- Act as a subject matter expert across cyber security initiatives.
Required Experience
- 5+ years' experience in Security Engineering, Security Operations, Security Automation, or a related cyber security discipline.
- Strong hands-on experience with SIEM platforms, EDR solutions, and detection engineering.
- Experience developing and supporting SOAR capabilities.
- Solid understanding of Active Directory security and Windows event logging.
- Proficiency with PowerShell and/or Python scripting.
- Good understanding of networking concepts including firewalls, VPNs, proxies, and security protocols.
- Experience securing Azure, AWS, or GCP environments.
- Knowledge of cyber security frameworks such as NIST, MITRE ATT&CK, and Cyber Kill Chain.
- Excellent communication and stakeholder management skills.
What You'll Gain
- Opportunity to work in a mature and forward-thinking cyber security environment.
- Exposure to enterprise-scale security technologies and cloud platforms.
- Ownership of detection engineering, threat hunting, and security automation initiatives.
- Collaboration with experienced cyber security professionals across infrastructure, cloud, and security operations teams.
Sounds interesting? Apply to find out more!