Rodeo
ResourcesPartnersSign in

Open Select

Security Engineering Lead - Detection and Response

London
£95k – £145k/yr
Posted 1 day ago
Sign up to applySee more jobs like this

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Security Engineering Lead - Detection and Response

Location

London / hybrid

Salary

£95,000 - £145,000 plus bonus

Industry

Fintech / Securities Finance Technology

Work Authorization

This role requires the right to work in the UK, no sponsorship available

Who you'll join

Our client is a London based fintech that automates the securities finance lifecycle. The platform processes over $6.5 trillion in transactions every day, connecting more than 150 financial institutions worldwide, including 25 of the 30 global systemically important banks.

You will report directly into the CISO and CTO, with real scope to shape how the company detects and responds to threats.

What you'll do

  • Build the company's detection and response capability from the ground up, establishing the processes, telemetry and tooling needed to detect, investigate and contain threats across AWS, on premises, Workforce IT and the endpoint estate
  • Produce a documented asset and telemetry map across AWS, on premises, Workforce IT and user endpoints
  • Assess current security monitoring and third party SOC coverage against LLM enabled attacks. Deliver a risk based plan using a hybrid SOC model, working with engineering teams to implement it
  • Build documented MITRE ATT&CK detection coverage across all Tier 1 tactics within 12 months, managed as code and version controlled
  • Author and maintain playbooks for the top incident types by likelihood and impact. Automate containment and response actions through SOAR, targeting 80% automated first action on P1 and P2 responses
  • Establish MTTD and MTTR baselines within 90 days and set improvement targets
  • Run structured threat hunting cycles each quarter and convert findings into new detection rules
  • Review unpatchable vulnerabilities with engineering teams and recommend treatment
  • Produce a monthly detection and response programme metrics report for the CISO and CTO
  • Build internal security capability through knowledge sharing, runbook documentation and structured mentoring as the team grows

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Who you are

  • Hands on detection engineering experience, writing and maintaining SIEM detection rules, correlation logic and detection as code pipelines
  • Proficient in Python or equivalent for detection development, log parsing and automation
  • Demonstrated incident response experience, leading or contributing to P1 and P2 investigations, post incident reviews and containment
  • Experience with cloud security on AWS and/or Azure, including native cloud telemetry sources
  • Familiar with MITRE ATT&CK as a framework for detection design and gap analysis
  • Hands on experience building and operating SOAR playbooks and response automation across SIEM, EDR, cloud and ticketing
  • Experience leading a SOC and/or managing a third party SOC
  • Demonstrated experience running structured threat hunting cycles
  • Able to influence stakeholders across the technology team. Strong written communication, able to translate technical findings for non-technical stakeholders
  • Able to work independently and collaborate with technical stakeholders across the business

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Tech stack

  • Cloud: AWS (primary), SIEM, SOAR, EDR, Python for detection development, log parsing and automation, MITRE ATT&CK as the detection design and gap analysis framework, Detection as code, version controlled (Git or equivalent), Ticketing and workflow tooling across SIEM, EDR, cloud and ticketing systems

Why you'll join

  • Genuine build from scratch mandate. You are not inheriting someone else's detection stack, you are designing it
  • High stakes, high trust environment. The platform underpins $6.5 trillion in daily transactions for 25 of the 30 global systemically important banks
  • Direct line into the CISO and CTO, with real visibility on your work at leadership level
  • A clear path to building and leading a team as the function grows
  • Hybrid working in London
Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Detection Engineering
Incident Response
Python
AWS
Azure
SIEM
SOAR
EDR
MITRE ATT&CK
Threat Hunting
Detection as Code
Log Parsing
Automation
Security Monitoring
Stakeholder Management
Git

Location

London, England, United Kingdom

Sign up to applySee more jobs like this