Cyber Security Engineer (Threat Detection & Automation)

Company: Additional Resources
Apply for the Cyber Security Engineer (Threat Detection & Automation)
Location: London
Job Description:

Overview

As Threat Detection Engineer, you will build and refine threat detection in a cloud-first environment, supporting a biotech company leveraging genetic data and AI. You’ll work with an outsourced SOC to tune detection catalogs and implement data-protection rules, while automating security metrics. The role blends hands-on detection engineering with cross-functional collaboration across cloud platforms and security teams. This is an opportunity to impact threat visibility at scale and help maintain compliance posture. You will be at the forefront of translating threat intel into practical protections.

Pay / Benefits

  • hybrid/remote working options
  • benefits package

Responsibilities

  • Design and implement threat-led detection logic guided by threat intel and hunting activity
  • Develop analytical techniques to improve incident identification
  • Collaborate with an outsourced SOC to maintain and optimize detection catalogs
  • Create and refine DLP, Insider Risk Management, and other security rules using cloud-native tools
  • Monitor and ensure service quality from external SOC providers
  • Automate reporting of security performance and operational metrics
  • Partner with technology teams to ensure monitoring across cloud platforms, SaaS, and internal systems
  • Document security processes, tool configurations, and contribute to service delivery documentation
  • Support ISO 27001 compliance and KQL-related tasks

Key requirements

  • Experience as Threat Detection Engineer or similar role
  • Strong expertise in KQL
  • Hands-on with Microsoft Sentinel and Defender (Endpoint, Office 365)
  • Familiarity with Microsoft Entra ID and Identity Governance
  • Experience with Microsoft Purview, especially DLP and data protection tools
  • Exposure to cloud-native logging in Azure and Kubernetes environments
  • Understanding of detection as code/everything as code, including CI/CD
  • Experience with MSP SOC teams
  • Knowledge of attacker TTPs, threat modelling, and cybersecurity frameworks
  • Awareness of ISO 27001 standards
  • Relevant cybersecurity certifications (e.g., MS-500, AZ-500, SC-200/300/400, Security+)
  • collaboration
  • agile mindset
  • communication
  • KQL
  • Microsoft Sentinel
  • Defender (Endpoint, Office 365)

Posted: September 14th, 2026