Now hiring

Security Detection Engineer @ McCabe & Barton

Ashbourne Grove 2, South East LondonOnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

Salary: £68,000 - 108,000 per year

Requirements: We are looking for an experienced Security Detection Engineer with strong SIEM, cloud security, and automation expertise.We need someone who can take ownership of detection engineering and threat hunting across Azure and GCP environments.You should have experience building detection rules in SIEM, EDR, or cloud-native tooling.You should have a deep understanding of attack patterns and the MITRE ATT&CK framework.We need experience in SOC operations, threat analysis, or incident response.Hands-on Datadog experience or equivalent Sentinel/SIEM experience is required.Familiarity with Azure Monitor and Log Analytics is required.Experience with GCP Cloud Logging and Cloud Security Command Center is desirable.You should have SQL proficiency for querying security events and building custom reports.Experience with Python or PowerShell for detection automation and data enrichment is required.Terraform experience for automating detection deployment is essential.YAML experience for configuration management of detections is required.We need experience with Azure security architecture, including Entra ID, networking, and identity.GCP security basics are desirable.Snowflake security fundamentals are required.Experience with EDR platforms such as CrowdStrike, Microsoft Defender, or similar is required.Knowledge of financial services threats such as insider threats, data theft, and credential abuse is required.Understanding of regulatory requirements including DORA, FCA, and SOC2 is required.Familiarity with incident response frameworks is required.You should be comfortable working in a 24/7 on-call environment during the integration crisis period.We are looking for a seasoned security engineer who can operate independently in an ambiguous environment.Integration or M&A security experience is desirable.You should be comfortable with open-source and modern tech stacks.Snowflake and/or data platform security exposure is valuable. Responsibilities: Design and implement detection rules in Datadog or an equivalent SIEM platform.Support UEBA to identify compromise early.Use Claude Code to develop detection logic and correlation rules.Build AI-powered anomaly detection for user behaviour and access patterns.Automate alert triage and prioritization.Integrate Datadog with Azure monitoring and GCP Cloud Logging.Use Terraform to automate detection deployment and configuration.Build CI/CD pipelines for detection rules, including version control, testing, and rollback.Develop custom metrics and alerting for deal-sensitive operations.Take ownership of detection engineering and threat hunting across Azure and GCP environments. Technologies: AIAzureCI/CDClaude CodeCloudDatadogGCPSupportPowerShellPythonSQLSecuritySnowflakeTerraform More:

We are offering a London-based hybrid 6-month initial contract at £600-£750 per day inside IR35 for a hands-on Security Detection Engineer. This is an opportunity to work in a fast-paced environment where you will help uplift detection engineering and threat hunting across Azure and GCP, using modern security tooling, automation, and AI-assisted approaches. We are seeking someone who can operate independently and contribute to a forward-thinking security function focused on cloud monitoring, detection automation, and emerging threats.

last updated 39 week of 2026

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores