Skip to main content
AfterDuty

Security Engineer

RevTech · London, Greater London

Type
Full-time
Posted
7 days ago

Overview

Your investigative judgement and evidence discipline transfer well into detection engineering and threat hunting.

About this role

Security Engineer

Working Pattern: Hybrid – 2 days onsite per week

Employment Type: Permanent

The Opportunity

We’re working with a leading global financial services organisation to recruit an experienced Security Engineer to join its Proactive Security team.

This is a key role within a mature cyber security function, offering the opportunity to work across security engineering, detection engineering, threat hunting, SIEM, SOAR, automation and security improvement initiatives.

You’ll play an important role in strengthening the organisation’s cyber resilience by designing and implementing security technologies, improving detection and monitoring capabilities, and developing automation that enables teams to respond to threats more effectively.

The role would suit someone who enjoys getting hands-on with technology while also having the opportunity to influence wider security strategy and continuous improvement.

What You’ll Be Doing

  • Design and develop threat models for applications, services and information assets, identifying risks and recommending appropriate security controls.
  • Build and enhance solutions for proactive threat detection, configuration monitoring and automated remediation.
  • Develop and integrate security automation and SOAR capabilities across the security technology stack.
  • Design, implement and optimise SIEM capabilities, including data connectors, analytics rules, workbooks, playbooks and automation workflows.
  • Develop advanced queries to support threat hunting, investigations, reporting and security monitoring.
  • Identify and onboard new security log sources, improving logging coverage across critical infrastructure and applications.
  • Troubleshoot log ingestion and data pipeline issues and work with custom log formats to maximise detection visibility.
  • Develop and continuously improve threat detection use cases, translating threat intelligence and vulnerability information into practical detection capabilities.
  • Conduct proactive threat hunting based on emerging threats, adversary behaviours and attack techniques.
  • Improve security visibility across infrastructure, applications, identities and cloud environments.
  • Work closely with SOC and incident response teams to enhance detection capabilities and operational readiness.
  • Develop security playbooks, operational procedures and automation workflows.
  • Provide security engineering expertise across projects, applications and infrastructure initiatives.
  • Evaluate new security technologies through proof-of-concepts and gap assessments.
  • Contribute to security metrics, control assurance and wider cyber security improvement programmes.

What We’re Looking For

We’re looking for a security professional with strong hands-on engineering experience and a genuine interest in detection, automation and proactive security.

You’ll ideally have

  • 5+ years’ experience in Security Engineering, Detection Engineering, Security Automation, Security Orchestration or a closely related cyber security role.
  • Strong enterprise experience across technologies such as SIEM, EDR, DLP, Secure Email Gateways and Web Proxies.
  • Proven experience designing and implementing security monitoring and threat detection use cases.
  • Strong hands-on experience with SIEM implementation, configuration, custom rule development and optimisation.
  • Experience developing SOAR playbooks and security automation workflows.
  • Strong knowledge of threat detection methodologies and adversary behaviours.
  • Advanced skills in security query languages and data analysis.
  • Strong scripting and automation capability using PowerShell and/or Python.
  • Experience with Microsoft Sentinel or an equivalent SIEM platform.
  • Good understanding of Windows Event Collection, logging and enterprise log management.
  • Strong knowledge of Active Directory security, authentication mechanisms, attack vectors and associated logging.
  • Solid understanding of TCP/IP networking, firewalls, VPNs, proxies and security protocols.
  • Experience securing and monitoring Azure, AWS and/or GCP environments.
  • Working knowledge of Windows Server, Linux/Unix and enterprise networking environments.
  • Exposure to technologies such as Palo Alto and Fortinet would be advantageous.

Security Knowledge

You should have a strong understanding of recognised cyber security frameworks and methodologies, including:

  • MITRE ATT&CK
  • NIST
  • Cyber Kill Chain
  • Incident response methodologies
  • Threat intelligence and detection engineering
  • Identity security and privileged access management
  • Modern threat detection and prevention techniques

Desirable Certifications

Relevant security certifications would be advantageous, including:

  • Microsoft AZ-500
  • Microsoft SC-200
  • Microsoft SC-900
  • CompTIA Security+
  • Relevant SIEM/SOAR certifications
  • Other recognised cyber security certifications

Why Consider This Role?

This is an excellent opportunity to join a high-profile financial services environment where security is a strategic priority.

You’ll have the chance to work on meaningful security engineering challenges, influence the development of detection and automation capabilities, and collaborate with experienced teams across cyber security, infrastructure and engineering.

If you’re looking for a role where you can combine hands-on technical engineering with proactive threat detection and security transformation, we’d be keen to hear from you.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in London

Why this fits a police background

  • Intelligence & OSINT
  • Incident command & response
  • Investigative casework

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • £35,000 – £40,000Estimated

    Your risk assessment and incident management skills from policing are directly applicable to this GRC role.

    Posted 3 days ago

  • Full-time

    Your incident command and multi-agency coordination experience translates directly to operational resilience and third-party oversight.

    Posted 3 days ago

  • Full-time

    Your investigative mindset and evidence-handling discipline from policing transfer directly to digital forensics and incident response.

    Posted 4 days ago

  • GRC Manager - 6 month FTC

    Trayport · London

    Full-time

    Your experience managing risk, policy, and regulatory compliance under frameworks like PACE transfers directly to GRC.

    Posted 6 days ago