Rodeo
Get started

AJ Bell

Security Monitoring & Detection Engineering Lead

London
Posted about 19 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Job Description

Purpose

The Cyber Defence Operations function protects AJ Bell against external adversaries and internal risks through four specialist capabilities:

  • Security Monitoring & Detection Engineering
  • Cyber Threat Intelligence
  • Cyber Threat Exposure Management
  • Insider Risk Management

Together, these capabilities combine detection, intelligence, exposure management and insider risk to safeguard AJ Bell’s customers, data, critical services and the trust placed in the firm.

Security Monitoring & Detection Engineering provides an integrated monitoring, detection and response capability, combining internal technical expertise with 24x7 support from the Managed Security Service Provider.

About the Role

The Security Monitoring & Detection Engineering Lead is the principal technical authority for Security Monitoring & Detection Engineering capability, accountable for the effectiveness of security monitoring, detection engineering, technical investigation and incident response. This is a hands-on technical role responsible for the architecture, engineering and operational performance of Microsoft Sentinel and the wider security monitoring estate.

The role would particularly suit an experienced detection engineering, security operations, red-team, purple-team or offensive-security leader who can translate real-world adversary behaviour into effective monitoring, detection and response. The role leads complex investigations and technical incident response, ensures the internal team and MSSP operate as one capability, and drives measurable improvements that reduce the potential for customer, operational, financial and regulatory harm.

Key Responsibilities

  • Own the technical direction, quality and delivery performance of Security Monitoring & Detection Engineering, translating CDO priorities into a clear roadmap for monitoring, detection, investigation and response.
  • Lead the architecture, engineering and continued development of our SIEM solution, ensuring the SIEM remains resilient, scalable, cost-effective and aligned with AJ Bell’s technology estate and threat profile.
  • Define and govern the onboarding of security telemetry across on-premises, Microsoft Azure, AWS and third-party services, ensuring log sources address genuine visibility gaps and provide reliable value for detection and investigation.
  • Own the detection engineering lifecycle across requirements, design, testing, deployment, tuning, performance assessment and retirement, supported by version control, peer review and controlled release practices.
  • Lead the development of analytics rules, hunting queries, workbooks and automated investigation and response workflows.
  • Own the operational effectiveness of security solutions managed by CDO ensuring configurations, integrations, detections and workflows deliver measurable security outcomes.
  • Drive threat-informed defence with Cyber Threat Intelligence and Cyber Threat Exposure Management, translating relevant threat actors, campaigns, TTPs, IOCs, critical vulnerabilities and attack paths into detections, targeted threat hunts and automated defensive actions.
  • Maintain an evidence-based view of service performance through agreed KPIs, KRIs and operational MI, identifying material variations, recurring failure points and capacity constraints, and driving corrective actions through to a measurable outcome.
  • Act as the senior technical escalation point for complex, ambiguous and high-severity security events, leading investigations through scoping, attack reconstruction, business-impact assessment, containment and resolution.
  • Experience investigating malicious code, identity compromise, business email compromise, fraud-related intrusion, data exfiltration, cloud compromise or third-party intrusion.
  • Lead technical response within CIRT during declared cyber incidents, coordinating the internal team, MSSP and relevant technology functions in accordance with the firm’s incident-management processes to contain threats and reduce business impact.
  • Build and improve investigation and response playbooks for priority threat scenarios, and lead tabletop, purple-team and practical exercises that test detection coverage, technical readiness and coordination with relevant business functions.
  • Operate the internal team and MSSP as one integrated monitoring and response capability, setting clear expectations for investigation quality, escalation consistency and response effectiveness, and addressing service issues before they affect security outcomes.
  • Maintain an evidence-based view of alert demand, detection quality, MTTA, MTTR, investigation outcomes, service capacity and recurring failure points, using these measures to prioritise and demonstrate improvement.
  • Lead service reviews with key security vendors and providers, assessing delivery against expected outcomes and driving actions that maximise the contribution of existing investment to CDO’s Detect, Defend and Respond objectives.
  • Identify and deliver appropriate uses of automation and AI across detection engineering, enrichment, investigation and response, measuring the resulting improvement in quality, speed, consistency or coverage.
  • Develop Senior Analysts and junior team members through technical leadership, investigation review, practical training and structured knowledge transfer, creating credible succession within the function.
  • Report functional performance, incident readiness, monitoring coverage, material risks and capability constraints to the Head of Cyber Defence Operations, providing clear recommendations and action plans.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Essential Skills & Experience

  • Extensive experience across security monitoring, SIEM engineering, detection engineering and incident response within a complex enterprise environment.
  • A strong record of designing, building, operating and evolving Microsoft Sentinel as a production security monitoring and response capability.
  • Deep expertise in KQL and the engineering of analytics rules, hunting queries, workbooks and threat-informed detection content.
  • Extensive experience designing telemetry architectures and onboarding security data, including connectors, parsing, normalisation, retention, ingestion health, data quality and cost management.
  • Experience integrating cloud-hosted services and security telemetry into central monitoring and leading investigations and incident-response activity across AWS, Azure environments.
  • Strong knowledge of Microsoft Defender XDR across endpoint, identity, email and cloud security, including the correlation of evidence across the Microsoft security ecosystem.
  • Experience designing and implementing automated investigation and response workflows using Azure Logic Apps, APIs, PowerShell, Python or comparable orchestration technologies.
  • Experience establishing and governing a production detection engineering lifecycle, including testing, peer review, version control, controlled deployment, performance monitoring and retirement.
  • Experience operating and materially improving enterprise security platforms such as Mimecast, Varonis, or comparable email and data-security technologies.
  • Experience translating adversary behaviour, threat intelligence, incident findings, exposure data and offensive-security results into improved detection and response capability.
  • Strong written and verbal communication, with the ability to translate complex threats, incidents and capability gaps into clear business implications, recommendations and decisions.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Preferred Skills & Experience

  • Experience leading red-team, purple-team or offensive-security activity and converting identified attack paths and adversary techniques into improved detection and response.
  • Experience in financial services, or a regulated environment.

Qualifications

Relevant certifications or completed professional training may include:

  • Security Blue Team, Blue Team Level 2, BTL2
  • GIAC Certified Incident Handler, GCIH
  • GIAC Certified Intrusion Analyst, GCIA
  • CREST Registered Intrusion Analyst, CRIA
  • Certified Red Team Operator, CRTO
  • OffSec Certified Professional, OSCP
  • OffSec Wireless Professional, OSWP
  • EC-Council Certified Ethical Hacker, CEH

About AJ Bell

At AJ Bell, we believe investing should feel good. Whether you're looking for an ISA, pension or dealing account, whether you want to invest with the help of a financial adviser or do it yourself, we have easy-to-use solutions to suit people from all walks of life.

We're one of the UK's fastest-growing investment platform businesses, trusted by everyone from professional financial advisers to first-time investors.

Today, over 723,000 customers trust us to manage more than £108.7 billion of assets. By continually striving to make investing simpler and more accessible, we're helping more people take control of their financial futures.

We're proud to be recognised as one of the UK's Best 100 Companies to Work For for six consecutive years, and a Great Place to Work® in 2025 and 2026, a reflection of our supportive and collaborative culture.

What We Offer

  • 27 days holiday, increasing with service + buy/sell scheme + bank holidays
  • 8% Pension with matched contributions
  • Discretionary bonus scheme
  • Share schemes (including free shares and BAYE)
  • Private healthcare and Dental plan
  • Healthcare Cash Plan
  • Enhanced family leave (subject to qualifying criteria)
  • Travel and bike loan schemes
  • Employee Assistance Programme

Life at AJ Bell

  • Regular social events including summer and Christmas parties
  • Learning and development opportunities tailored to you
  • Casual dress code
  • Friendly, supportive team environment

Our Ways of Working

At AJ Bell, our people are the heart of our culture. We believe in building strong connections by working together. That's why we offer a hybrid working model, where you'll spend a minimum of 50% of your working time from the office in either our Head office in Manchester or London Office. For new team members, the first 3 months will be spent full-time in the office to help you immerse yourself in our business and build valuable relationships with your colleagues.

Inclusion & Diversity

We’re committed to creating an inclusive environment where everyone feels respected, supported and able to be themselves at work.

We welcome applications from all backgrounds and make hiring decisions based on skills, experience and potential.

Agency Information

This vacancy is being managed exclusively by our in-house Recruitment team. We are not partnering with recruitment agencies on this opportunity and will only accept applications submitted directly by candidates.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Location

London, England, United Kingdom

Sign up to applySee more jobs like this