Haystack
← Back to Jobs
Full time
Administrative
M&

Security Detection Engineer

McCabe & BartonLondon🇬🇧United KingdomPosted 26 Aug 2026

Quick Overview

Salary
£600 - £750/mo
Seniority
Mid Senior
Employment type
Full Time
Work mode
Hybrid
Location
London, United Kingdom
Posted
22 hours ago

Job Description

Security Detection Engineer

London (Hybrid)

£600-£750 per day (Inside IR35)

Initial 6-Month Contract

We are looking for an experienced SecurityDetection Engineer to take ownership of detection engineering, and threat hunting across Azure and GCP environments.

This is a hands-on opportunity for a security professional with strong SIEM, cloud security, and automation expertise who can operate independently in a fast-paced environment.

Key Responsibilities

Detection Engineering & SIEM Uplift

  1. Design and implement detection rules in Datadog (or Sentinel/SIEM equivalent)
  2. Support UEBA (User & Entity Behaviour Analytics) to catch compromise early
  3. Use Claude Code to develop detection logic and correlation rules
  4. Build AI-powered anomaly detection (user behaviour, access patterns)
  5. Automate alert triage and prioritization

Platform Integration & Automation

  1. Integrate Datadog with Azure monitoring and GCP Cloud Logging
  2. Use Terraform to automate detection deployment and configuration
  3. Build CI/CD for detection rules (version control, testing, rollback)
  4. Develop custom metrics and alerting for deal-sensitive operations

Required Experience & Skills

Core Detection & Threat Analysis

  1. Experienced building detection rules (SIEM, EDR, or cloud-native tooling)
  2. Deep understanding of attack patterns (MITRE ATT&CK framework)
  3. SOC operations, threat analysis, or incident response

Datadog & Cloud Monitoring

  1. Hands-on Datadog OR equivalent Sentinel/SIEM experience
  2. Azure Monitor and Log Analytics familiarity
  3. GCP Cloud Logging and Cloud Security Command Center desirable

Technical Engineering

  1. SQL proficiency (query security events, build custom reports)
  2. Python or PowerShell (detection automation, data enrichment)
  3. Terraform (automate detection deployment) essential
  4. YAML (configuration management for detections)

Cloud & Data Platforms

  1. Azure security architecture (Entra ID, networking, identity)
  2. GCP security basics desirable
  3. Snowflake security fundamentals
  4. EDR platform experience (CrowdStrike, Microsoft Defender, or similar)

Security & Compliance

  1. Knowledge of financial services threats (insider threats, data theft, credential abuse)
  2. Understanding of regulatory requirements (DORA, FCA, SOC2)
  3. Familiarity with incident response frameworks
  4. Comfortable in 24/7 on-call environment during integration crisis period

Ideal candidate:

  1. Seasoned Security engineer who can operate independently
  2. Experience of hands-on detection/threat analysis
  3. Strong technical foundations (SQL, Python, cloud platforms)
  4. Integration or M&A security experience
  5. Forward-thinking mindset (AI-assisted security, emerging threats)
  6. Independent operator (self-directed in ambiguous environment)
  7. Datadog OR Sentinel experience (or very strong hands-on SIEM background)
  8. Open-source and modern tech stack comfortable
  9. Snowflake and/or data platform security exposure valuable

Similar jobs