Rodeo
Get started

OptumUK

Security Operations Detection, Tooling & Assurance Engineer

United Kingdom
Posted about 15 hours ago
Sign up to applySee more jobs like this

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Security Operations Detection, Tooling & Assurance Engineer

Are you an experienced security professional with deep, hands-on expertise across security platforms, detection engineering, and security operations?

Do you want to play a key role in improving how threats are detected, investigated, and responded to across a complex healthcare environment? Are you passionate about enhancing security tooling, strengthening detection capabilities, improving operational processes, and ensuring security operations deliver measurable outcomes?

About the Team / Business Area

The Security Operations team sits at the core of our organisation, protecting nationally critical healthcare systems that support frontline patient care across the UK.

Operating within a highly regulated environment, the team is responsible for SOC oversight, vulnerability management, attack surface monitoring, and real-time threat detection across enterprise, cloud, identity, and network platforms.

This function plays a critical role in ensuring system resilience, maintaining regulatory compliance, and enabling the secure delivery of healthcare services at scale.

About the Role

As a Security Operations Detection, Tooling & Assurance Engineer, you will be responsible for the performance, optimisation, and continuous improvement of security tooling, detection capabilities, and security operations processes.

This is a hands-on engineering role focused on improving how threats are identified, investigated, and managed across the organisation. You will work to enhance detection quality, reduce false positives, improve investigative outcomes, and ensure security tooling is operating effectively and efficiently across all environments.

A key aspect of the role is providing operational assurance across Security Operations activities delivered by both internal teams and managed security service providers (MSSPs). You will review alerts, incidents, investigations, and SOC case activity to identify trends, control gaps, process improvements, and opportunities to strengthen detection and response capabilities.

Working closely with Cyber Defence analysts, Security Engineering teams, and external SOC providers, you will support the development of improved detections, response playbooks, automation capabilities, and investigation methodologies that enhance the organisation's overall security posture.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

This role requires proven, hands-on, administrator-level experience across core security platforms including Darktrace, CrowdStrike, and Google SecOps. Candidates without this level of direct platform ownership and administration experience will not be suitable.

Key Responsibilities

  • Own and optimise core security platforms including SIEM, EDR, NDR, SASE and related security technologies, ensuring effective performance, utilisation and governance.
  • Design, build, maintain and tune detections to improve alert fidelity, visibility and threat identification capabilities.
  • Review security alerts, incidents, investigations and SOC case activity to identify opportunities to improve detection logic, triage processes and operational effectiveness.
  • Work closely with Cyber Defence analysts to improve security monitoring, investigation processes, response playbooks and detection content.
  • Provide assurance and oversight of Security Operations activities delivered by managed SOC providers, supporting continuous improvement in investigation quality, service performance and operational outcomes.
  • Engage with SOC partners and service providers to improve monitoring, detection, triage and incident response processes.
  • Drive improvements in detection coverage through threat intelligence, incident learnings and recognised frameworks such as MITRE ATT&CK.
  • Identify opportunities to rationalise tooling, improve efficiency and reduce operational overhead.
  • Develop and implement automation to improve workflows and reduce manual effort across Security Operations.
  • Produce reporting on detection effectiveness, coverage gaps, platform performance and SOC service outcomes.
  • Define and maintain standards for detection engineering, security tooling and operational security monitoring activities.

What You Bring

You are a technically capable and operationally focused security professional with experience across security tooling, detection engineering and security operations.

You are comfortable analysing alerts, incidents and investigations to understand how security controls perform in practice, and you can translate those findings into meaningful improvements across tooling, detections, processes and operational outcomes.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

You work effectively with technical teams, analysts and service providers, bringing a structured and analytical approach to problem solving, continuous improvement and operational excellence.

Key Skills, Experience & Qualifications

Essential

  • Strong experience in Security Operations, Detection Engineering, Security Tooling or Cyber Defence roles.
  • Hands-on administration and engineering experience across security platforms including SIEM, EDR, NDR or equivalent technologies.
  • Hands-on, administrator-level experience with Darktrace, CrowdStrike and Google SecOps (minimum, non-negotiable requirement).
  • Proven experience designing, building and tuning detections to improve alert quality and reduce false positives.
  • Experience reviewing security alerts, investigations, incidents or SOC operations to identify and deliver operational improvements.
  • Experience working closely with analysts, engineering teams or SOC providers to improve detection and response outcomes.
  • Strong understanding of security monitoring, incident response and threat detection methodologies.
  • Solid understanding of detection frameworks and methodologies such as MITRE ATT&CK.

Desirable

  • Experience working with managed security service providers (MSSPs) or outsourced SOC functions.
  • Experience in tooling optimisation, platform rationalisation or data and log reduction initiatives.
  • Experience implementing automation within Security Operations environments.
  • Experience developing operational metrics, assurance processes or service performance reporting.
  • Relevant certifications such as CySA+, SC-200, GIAC or vendor-specific certifications.

Ready to Join Us?

At EMIS / Optum UK, we are a leader in healthcare technology, supporting professionals across primary care, community services, pharmacy and beyond.

This is an opportunity to take ownership of security tooling, detection capability and operational assurance within a complex, high-impact environment. You will play a key role in improving how threats are detected, investigated and responded to, helping protect systems that underpin patient care across the UK.

If you are looking for a role where you can influence security operations, improve detection capability and make a measurable impact, we would welcome your application

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Detection Engineering
SIEM
EDR
NDR
Darktrace
CrowdStrike
Google SecOps
MITRE ATT&CK
Incident Response
Security Tooling
SOC Oversight
Vulnerability Management
Automation
Threat Intelligence
SASE
Operational Assurance

Location

United Kingdom

Sign up to applySee more jobs like this