About this role
Millennium SOC is going through a transformation, we are looking for an experienced Threat Detection Engineer to drive our best-in-class posture. This is a highly technical role, and successful candidates will have demonstrable knowledge and experience across a range of business and security technologies within a fast-paced, innovative organization.
Principal Responsibilities
- Threat Hunting – The ability to leverage multiple data sources to identify modern evolving threats and develop new detection and response approaches.
- Detection Engineering – Creation and operation of high-fidelity detections mechanisms that drive efficient, effective and repeatable response.
- Playbook Creation – Own, operate and automate detection and response workflows, that enable the team to focus on strategic objectives.
- Lead Information Security response activities for the firm.
- Team Player – Ability to work across business and technology teams to deliver positive outcomes across the firm.
- Technical Prowess – Comfortable explaining complex technology and information security related concepts to a wide range of stakeholders.
- Security Ambassador - Enforce security policies and procedures by administering and monitoring appropriate systems, events and answering stakeholder queries.
- Threat Intel - Actively monitor new and emerging security and privacy related technologies, trends, issues, and solutions and assess their applicability to Millennium key business initiatives and business strategies.
- Operational Excellence – Ensure Millennium Information Security capabilities remain fit for purpose and evolve to meet the changing threat landscape.
Qualifications/Skills Required
- Bachelor or master’s degree in computer science or cyber security with strong IT background or equivalent demonstrable experience.
- 3 years’ experience working in a security engineering role, financial industry experience preferred.
- Experience in creating detections in modern query languages (KQL, SQL, SPL).
- Possesses security certifications (Security+, OSCP, CISSP, CEH, GCIA, GCIH).
- Experience with modern security tooling across security domains; network, endpoint, data, identity and cloud.
- Experience in standard enterprise technology stack, Active Directory, Entra, Group Policy, Intune, DNS, TCP/IP, PKI, Microsoft 365, Windows, Linux, MacOS, etc.
- Ability to handle sensitive and/or confidential materials with appropriate discretion.
- Required scripting, development and automation skills using PowerShell or Python and proficient development tools.
- Experience in OSINT, Threat hunting and analysing malicious emails.
- Able to prioritize in a fast moving, high pressure, constantly changing environment
About cyber security & digital forensics roles for ex-police
Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.
See all cyber security & digital forensics jobs in London →Why this fits a police background
- Intelligence & OSINT
What cyber security & digital forensics roles pay ex-police
Advertised UK ranges, editorial estimates reviewed July 2026
| Digital forensics analyst | £32,000–£45,000 |
| DFIR consultant | £45,000–£65,000 |
| Senior forensics / IR specialist | £60,000–£80,000 |
| Threat-intelligence specialist | £55,000–£80,000 |