About this role
Security Engineer
Working Pattern: Hybrid – 2 days onsite per week
Employment Type: Permanent
The Opportunity
We’re working with a leading global financial services organisation to recruit an experienced Security Engineer to join its Proactive Security team.
This is a key role within a mature cyber security function, offering the opportunity to work across security engineering, detection engineering, threat hunting, SIEM, SOAR, automation and security improvement initiatives.
You’ll play an important role in strengthening the organisation’s cyber resilience by designing and implementing security technologies, improving detection and monitoring capabilities, and developing automation that enables teams to respond to threats more effectively.
The role would suit someone who enjoys getting hands-on with technology while also having the opportunity to influence wider security strategy and continuous improvement.
What You’ll Be Doing
- Design and develop threat models for applications, services and information assets, identifying risks and recommending appropriate security controls.
- Build and enhance solutions for proactive threat detection, configuration monitoring and automated remediation.
- Develop and integrate security automation and SOAR capabilities across the security technology stack.
- Design, implement and optimise SIEM capabilities, including data connectors, analytics rules, workbooks, playbooks and automation workflows.
- Develop advanced queries to support threat hunting, investigations, reporting and security monitoring.
- Identify and onboard new security log sources, improving logging coverage across critical infrastructure and applications.
- Troubleshoot log ingestion and data pipeline issues and work with custom log formats to maximise detection visibility.
- Develop and continuously improve threat detection use cases, translating threat intelligence and vulnerability information into practical detection capabilities.
- Conduct proactive threat hunting based on emerging threats, adversary behaviours and attack techniques.
- Improve security visibility across infrastructure, applications, identities and cloud environments.
- Work closely with SOC and incident response teams to enhance detection capabilities and operational readiness.
- Develop security playbooks, operational procedures and automation workflows.
- Provide security engineering expertise across projects, applications and infrastructure initiatives.
- Evaluate new security technologies through proof-of-concepts and gap assessments.
- Contribute to security metrics, control assurance and wider cyber security improvement programmes.
What We’re Looking For
We’re looking for a security professional with strong hands-on engineering experience and a genuine interest in detection, automation and proactive security.
You’ll ideally have
- 5+ years’ experience in Security Engineering, Detection Engineering, Security Automation, Security Orchestration or a closely related cyber security role.
- Strong enterprise experience across technologies such as SIEM, EDR, DLP, Secure Email Gateways and Web Proxies.
- Proven experience designing and implementing security monitoring and threat detection use cases.
- Strong hands-on experience with SIEM implementation, configuration, custom rule development and optimisation.
- Experience developing SOAR playbooks and security automation workflows.
- Strong knowledge of threat detection methodologies and adversary behaviours.
- Advanced skills in security query languages and data analysis.
- Strong scripting and automation capability using PowerShell and/or Python.
- Experience with Microsoft Sentinel or an equivalent SIEM platform.
- Good understanding of Windows Event Collection, logging and enterprise log management.
- Strong knowledge of Active Directory security, authentication mechanisms, attack vectors and associated logging.
- Solid understanding of TCP/IP networking, firewalls, VPNs, proxies and security protocols.
- Experience securing and monitoring Azure, AWS and/or GCP environments.
- Working knowledge of Windows Server, Linux/Unix and enterprise networking environments.
- Exposure to technologies such as Palo Alto and Fortinet would be advantageous.
Security Knowledge
You should have a strong understanding of recognised cyber security frameworks and methodologies, including:
- MITRE ATT&CK
- NIST
- Cyber Kill Chain
- Incident response methodologies
- Threat intelligence and detection engineering
- Identity security and privileged access management
- Modern threat detection and prevention techniques
Desirable Certifications
Relevant security certifications would be advantageous, including:
- Microsoft AZ-500
- Microsoft SC-200
- Microsoft SC-900
- CompTIA Security+
- Relevant SIEM/SOAR certifications
- Other recognised cyber security certifications
Why Consider This Role?
This is an excellent opportunity to join a high-profile financial services environment where security is a strategic priority.
You’ll have the chance to work on meaningful security engineering challenges, influence the development of detection and automation capabilities, and collaborate with experienced teams across cyber security, infrastructure and engineering.
If you’re looking for a role where you can combine hands-on technical engineering with proactive threat detection and security transformation, we’d be keen to hear from you.
About cyber security & digital forensics roles for ex-police
Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.
See all cyber security & digital forensics jobs in London →Why this fits a police background
- Intelligence & OSINT
- Incident command & response
- Investigative casework
What cyber security & digital forensics roles pay ex-police
Advertised UK ranges, editorial estimates reviewed July 2026
| Digital forensics analyst | £32,000–£45,000 |
| DFIR consultant | £45,000–£65,000 |
| Senior forensics / IR specialist | £60,000–£80,000 |
| Threat-intelligence specialist | £55,000–£80,000 |