Haystack
← Back to Jobs
Temporary/Casual
Administrative
M&

Security Detection Engineer

McCabe & BartonSouth East London, London🇬🇧United KingdomPosted 18 Sept 2026

Quick Overview

Salary
£600 - £750/mo
Seniority
Mid Senior
Employment type
Temporary/Casual
Work mode
Hybrid
Location
South East London, London, United Kingdom
Posted
11 hours ago

Job Description

Security Detection Engineer

London (Hybrid)

£600-£750 per day (Inside IR35)

Initial 6-Month Contract

We are looking for an experienced Security Detection Engineer to take ownership of detection engineering, and threat hunting across Azure and GCP environments.

This is a hands-on opportunity for a security professional with strong SIEM, cloud security, and automation expertise who can operate independently in a fast-paced environment.

Key Responsibilities

Detection Engineering & SIEM Uplift

  • Design and implement detection rules in Datadog (or Sentinel/SIEM equivalent)
  • Support UEBA (User & Entity Behaviour Analytics) to catch compromise early
  • Use Claude Code to develop detection logic and correlation rules
  • Build AI-powered anomaly detection (user behaviour, access patterns)
  • Automate alert triage and prioritization

Platform Integration & Automation

  • Integrate Datadog with Azure monitoring and GCP Cloud Logging
  • Use Terraform to automate detection deployment and configuration
  • Build CI/CD for detection rules (version control, testing, rollback)
  • Develop custom metrics and alerting for deal-sensitive operations

Required Experience & Skills

Core Detection & Threat Analysis

  • Experienced building detection rules (SIEM, EDR, or cloud-native tooling)
  • Deep understanding of attack patterns (MITRE ATT&CK framework)
  • SOC operations, threat analysis, or incident response

Datadog & Cloud Monitoring

  • Hands-on Datadog OR equivalent Sentinel/SIEM experience
  • Azure Monitor and Log Analytics familiarity
  • GCP Cloud Logging and Cloud Security Command Center desirable

Technical Engineering

  • SQL proficiency (query security events, build custom reports)
  • Python or PowerShell (detection automation, data enrichment)
  • Terraform (automate detection deployment) essential
  • YAML (configuration management for detections)

Cloud & Data Platforms

  • Azure security architecture (Entra ID, networking, identity)
  • GCP security basics desirable
  • Snowflake security fundamentals
  • EDR platform experience (CrowdStrike, Microsoft Defender, or similar)

Security & Compliance

  • Knowledge of financial services threats (insider threats, data theft, credential abuse)
  • Understanding of regulatory requirements (DORA, FCA, SOC2)
  • Familiarity with incident response frameworks
  • Comfortable in 24/7 on-call environment during integration crisis period

Ideal candidate:

  • Seasoned Security engineer who can operate independently
  • Experience of hands-on detection/threat analysis
  • Strong technical foundations (SQL, Python, cloud platforms)
  • Integration or M&A security experience
  • Forward-thinking mindset (AI-assisted security, emerging threats)
  • Independent operator (self-directed in ambiguous environment)
  • Datadog OR Sentinel experience (or very strong hands-on SIEM background)
  • Open-source and modern tech stack comfortable
  • Snowflake and/or data platform security exposure valuable



Similar jobs