Detection & Incident Response Engineer
We are looking for an experienced Detection & Incident Response Engineer to transform our security operations capability and ways of working. In this role, you will be at the core of detecting, investigating and responding to security threats, while driving automation and improving detection coverage across the organisation.
- Build and continuously improve security monitoring and alerting capabilities
- Investigate security events and operate the incident response process end-to-end
- Design, implement and tune detection rules and alerts to maximise effectiveness and reduce noise
- Own and maintain incident response procedures and alert playbooks
- Perform threat intelligence activities to enhance detection and response capabilities
- Monitor logs and respond to alerts in a timely and effective manner
- Integrate security tools and data sources into detection and alerting pipelines
- Configure and optimise Security Orchestration, Automation and Response (SOAR) workflows
- Enhance our DLP monitoring
- Contribute to broader security initiatives and tasks as required
- Strong SOC and security operations experience
- Hands-on experience with SIEM platforms (e.g. Elastic, Microsoft Sentinel)
- Proficiency in KQL
- Solid incident response experience
- Experience with automation and orchestration (SOAR)
- Understanding of SOAP and security integrations
