Cyber Security Engineer – Threat Detection

Company: Intercontinental Exchange
Apply for the Cyber Security Engineer – Threat Detection
Location: London
Job Description:

Overview

In this role you will design and maintain detection content across SIEM, EDR, and NDR to rapidly identify malicious activity. You will work closely with threat intelligence, incident response, and red teams to ensure detections reflect real adversary behavior. You will tune alerts, reduce false positives, and map coverage to MITRE ATT&CK to close gaps. You will also lead proactive hunts and productionize findings to strengthen ICE’s security posture. This is a hands-on opportunity to shape detection capability in a complex, security-focused environment.

Responsibilities

  • Design, build, test, and maintain detection content across SIEM, EDR, and NDR
  • Own false positive rates and alert health for assigned detection areas
  • Map detection coverage to MITRE ATT&CK and close telemetry gaps
  • Convert threat intelligence into prioritized detection and hunting work
  • Develop and execute focused hunts and productionize successful findings
  • Remediate detection gaps from red/purple team exercises and validate on retest
  • Validate health and completeness of log sources and onboard/update SIEM sources
  • Apply scripting to build internal tooling and automate repetitive tasks

Key requirements

  • Threat detection, security operations, or threat hunting experience
  • Hands-on experience with SIEM, EDR, and NDR platforms with detection logic
  • Scripting ability for automation to build internal tooling
  • Ability to investigate suspicious activity end-to-end and communicate conclusions
  • Familiarity with MITRE ATT&CK framework and adversary tradecraft
  • Solid understanding of OS internals, networking, and security telemetry
  • University degree in Engineering, MIS, CIS, or related discipline; or equivalent experience
  • Problem-solving mindset
  • Clear written and verbal communication
  • Collaborative cross-functional work
  • SIEM, EDR, NDR platforms (Splunk, Elasticsearch, Tanium, CrowdStrike, SentinelOne)
  • Scripting in Python or PowerShell
  • Threat intelligence integration and threat hunting methodologies

…

Posted: September 21st, 2026