McCabe & Barton
Security Detection Engineer

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Security Detection Engineer
London (Hybrid)
£600-£750 per day (Inside IR35)
Initial 6-Month Contract
We are looking for an experienced Security Detection Engineer to take ownership of detection engineering, and threat hunting across Azure and GCP environments.
This is a hands-on opportunity for a security professional with strong SIEM, cloud security, and automation expertise who can operate independently in a fast-paced environment.
Key Responsibilities
Detection Engineering & SIEM Uplift
- Design and implement detection rules in Datadog (or Sentinel/SIEM equivalent)
- Support UEBA (User & Entity Behaviour Analytics) to catch compromise early
- Use Claude Code to develop detection logic and correlation rules
- Build AI-powered anomaly detection (user behaviour, access patterns)
- Automate alert triage and prioritization
Platform Integration & Automation
- Integrate Datadog with Azure monitoring and GCP Cloud Logging
- Use Terraform to automate detection deployment and configuration
- Build CI/CD for detection rules (version control, testing, rollback)
- Develop custom metrics and alerting for deal-sensitive operations
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Required Experience & Skills
Core Detection & Threat Analysis
- Experienced building detection rules (SIEM, EDR, or cloud-native tooling)
- Deep understanding of attack patterns (MITRE ATT&CK framework)
- SOC operations, threat analysis, or incident response
Datadog & Cloud Monitoring
- Hands-on Datadog OR equivalent Sentinel/SIEM experience
- Azure Monitor and Log Analytics familiarity
- GCP Cloud Logging and Cloud Security Command Center desirable
Technical Engineering
- SQL proficiency (query security events, build custom reports)
- Python or PowerShell (detection automation, data enrichment)
- Terraform (automate detection deployment) essential
- YAML (configuration management for detections)
Cloud & Data Platforms
- Azure security architecture (Entra ID, networking, identity)
- GCP security basics desirable
- Snowflake security fundamentals
- EDR platform experience (CrowdStrike, Microsoft Defender, or similar)


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Security & Compliance
- Knowledge of financial services threats (insider threats, data theft, credential abuse)
- Understanding of regulatory requirements (DORA, FCA, SOC2)
- Familiarity with incident response frameworks
- Comfortable in 24/7 on-call environment during integration crisis period
Ideal Candidate
- Seasoned Security engineer who can operate independently
- Experience of hands-on detection/threat analysis
- Strong technical foundations (SQL, Python, cloud platforms)
- Integration or M&A security experience
- Forward-thinking mindset (AI-assisted security, emerging threats)
- Independent operator (self-directed in ambiguous environment)
- Datadog OR Sentinel experience (or very strong hands-on SIEM background)
- Open-source and modern tech stack comfortable
- Snowflake and/or data platform security exposure valuable
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location