Summary
✨ AI‑Generated
A global financial technology organization is seeking a Senior Threat Detection and Security Engineer to strengthen its security engineering capabilities. You will build SIEM detections, automate security operations, develop data protection controls, and help secure cloud, SaaS, and endpoint environments while exploring emerging AI-related security challenges.
Highlights
Earn a base salary of up to £120,000 while working in a senior security engineering role with broad technical influence. Build detection capabilities, automate security operations, and work on evolving challenges involving cloud, sensitive data, and AI.
Description
Senior Threat Detection & Security Engineer
London | Hybrid – 3 days per week | Up to £120,000 base
I'm working with a global payments business looking for a Senior Security Engineer to join its security team in London.
This isn't a traditional SOC role.
They're looking for someone who enjoys building and improving security capability – engineering detections, automating security processes and helping solve newer challenges around data protection, cloud and AI.
You'll be working across a modern, high-volume technology environment, with plenty of scope to influence how security tooling and controls develop.
What you'll be working on
You'll be hands-on across areas including:
Building and improving SIEM detections, alerting and detection-as-codeDeveloping automation to reduce manual security operations workDLP and data security – developing policies, controls and detections rather than simply responding to alertsProtecting sensitive data across cloud, SaaS, endpoints and increasingly GenAI toolsEmail security and associated threat/detection controlsThreat detection and intelligence, turning threat information into useful detections and controlsWorking across AWS, GCP and Azure environmentsUsing Python/KQL and APIs to integrate and automate security toolingInfrastructure-as-code and engineering workflows using Terraform and GitLabHelping the organisation think through emerging risks around AI agents, GenAI, data exfiltration, prompt injection and access controls
Their current security stack includes Microsoft Sentinel, SentinelOne, Netskope and Flashpoint, alongside cloud-native tooling.
What they're looking for
The strongest candidates are likely to be hands-on security engineers who can demonstrate things they've personally built, configured and improved.
You'll ideally bring strong experience across:
Detection engineering / SIEM – building and tuning detections rather than primarily monitoring alerts.DLP / data security – hands-on experience configuring policies, rules or controls.
Experience around governing data access to AI tools would be particularly relevant.Automation – Python, APIs, KQL or similar, with examples of removing manual processes or improving security operations at scale.Email security – practical experience securing and monitoring modern email environments.Cloud security – exposure to AWS, GCP and/or Azure in a modern engineering environment.You don't need to have worked with every tool in their stack.
They're much more interested in the depth of what you've personally delivered and your ability to explain the technical decisions behind it.
Why it's interesting
The role sits at the intersection of security engineering, detection, automation and data protection, at a point where AI is creating a completely new set of security problems to solve.
They're already thinking about questions like: how do you safely give AI agents access to internal tools? How do you prevent sensitive information leaving through GenAI platforms? How should DLP evolve when employees are using Copilot, ChatGPT and similar tooling? And how much of security operations can be automated without losing appropriate controls?
It's a good opportunity for someone who wants to stay technically hands-on while working on problems that are changing quickly.