Job Search and Career Advice Platform

Enable job alerts via email!

Security Engineer & Detection Engineering Automation

ION Group

Greater London

On-site

GBP 60,000 - GBP 85,000

Full time

Today
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A financial technology firm is seeking a Security Engineer specializing in Detection Engineering and Security Automation to design scalable detection and response capabilities. This role focuses on building high-fidelity detections and automating workflows across platforms such as Rapid7, SentinelOne, and CrowdStrike. Candidates should have extensive experience in detection engineering and automation, with skills in Python scripting and REST API integrations. The ideal candidate will contribute to incident response, improving security automation processes across diverse environments.

Benefits

Supportive and inclusive work environment
Career growth opportunities
Diverse team culture

Qualifications

  • Proven experience in detection engineering or security automation roles.
  • Hands-on with Rapid7, SentinelOne, and/or CrowdStrike.
  • Solid understanding of endpoint security, vulnerability management, and attacker tradecraft.

Responsibilities

  • Design, implement, and continuously improve threat detections.
  • Automate security workflows using Azure Logic Apps.
  • Work closely with security and cloud teams to ensure data quality.

Skills

Detection Engineering
Security Automation
Scripting (Python, PowerShell)
Integration using REST APIs

Tools

Rapid7
SentinelOne
CrowdStrike
Job description

Home » Jobs » Security Engineer – Detection Engineering & Automation

Security Engineer – Detection Engineering & Automation

We are seeking a Security Engineer specialising in Detection Engineering and Security Automationto design, build, and operate scalable detection and response capabilities across cloud and enterprise environments.

This role focuses on engineering high-fidelity detections and automating response workflowsacross platforms such as Rapid7, SentinelOne, and CrowdStrike, using Azure Logic Appsand API-driven integrations to reduce manual effort and improve response speed.

This is a hands-on engineering role for someone who thinks in attacker behaviours, builds resilient automation, and prefers engineering solutions over manual SOC processes.

Key Responsibilities

  • Detection Engineering
  • Design, implement, and continuously improve threat detections across endpoint, identity, vulnerability, and cloud telemetry.
  • Engineer detections using data from Rapid7, SentinelOne, and CrowdStrike, including behavioural, anomaly-based, and contextual detections.
  • Translate MITRE ATT&CK techniques and real-world threat intelligence into actionable detection logic.
  • Develop and tune detection logic to reduce false positives while preserving signal quality.
  • Validate detections through testing, attack simulation, and post-incident review.
  • Maintain detection coverage mapping across the attack lifecycle.
  • Security Automation & SOAR
  • Design and implement security automation workflows using Azure Logic Apps to support alert triage, enrichment, containment, and response.
  • Automate workflows such as:
  • Alert enrichment from asset inventories and vulnerability data
  • Risk-based prioritisation using exploitability and exposure context
  • Endpoint containment or isolation actions
  • Case creation, updates, and closure across security platforms
  • Integrate tools via REST APIs, webhooks, and managed connectors.
  • Build modular, reusable automation components with robust error handling and observability.
  • Integrate and correlate telemetry across Rapid7, SentinelOne, CrowdStrike, and supporting security systems.
  • Work closely with security and cloud teams to onboard new data sources and ensure data quality.
  • Apply detection-as-code and automation-as-code principles using version control and structured deployment processes.
  • Build dashboards and metrics to measure detection efficacy, alert quality, and automation impact.
  • Support incident response by enhancing detections and automations based on real incidents.
  • Feed learnings from investigations back into detection logic and response workflows.
  • Maintain documentation, playbooks, and runbooks for detections and automations.
  • Contribute to purple-team activities and detection gap analysis.

Required Skills, Experience and Qualifications

  • Core Technical Skills
  • Proven experience in detection engineering, security operations engineering, or security automation roles.
  • Hands-on experience with Rapid7, SentinelOne, and/or CrowdStrike in detection or response contexts.
  • Proficiency integrating systems using REST APIs, JSON payloads, authentication, and pagination.
  • Solid understanding of endpoint security, vulnerability management, and attacker tradecraft.
  • Deep familiarity with MITRE ATT&CK and behaviour-based detection methodologies.
  • Engineering & Operational Skills
  • Strong scripting or engineering background (e.g. Python, PowerShell).
  • Experience working with structured data, event pipelines, and telemetry correlation.
  • Understanding of alert lifecycle management and incident response workflows.
  • Ability to design automation that is safe, resilient, and auditable.
  • Preferred
  • Experience correlating endpoint, vulnerability, and asset data for risk-based detection.
  • Familiarity with SOAR design patterns and automation governance.
  • Exposure to cloud security telemetry and identity-based attack detection.
  • Experience operating in large-scale or regulated environments.
  • Knowledge of CI/CD or infrastructure-as-code approaches for security tooling.
About us

We’re a diverse group of visionary innovators who provide trading and workflow automation software, high-value analytics, and strategic consulting to corporations, central banks, financial institutions, and governments. Founded in 1999, we’ve achieved tremendous growth by bringing together some of the best and most successful financial technology companies in the world.

• Over 2,000 of the world’s leading corporations, including 50% of the Fortune 500 and 30% of the world’s central banks, trust ION solutions to manage their cash, in-house banking, commodity supply chain, trading and risk.

• Over 800 of the world’s leading banks and broker-dealers use our electronic trading platforms to operate the world’s financial market infrastructure.

ION is a rapidly expanding and dynamic group with 13,000 employees and offices in more than 40 cities around the globe. Our ever-expanding global footprint, cutting edge products, and over 40,000 customers worldwide provide an unparalleled career experience for those who share our vision.

ION is committed to maintaining a supportive and inclusive environment for people with diverse backgrounds and experiences. We respect the varied identities, abilities, cultures, and traditions of the individuals who comprise our organization and recognize the value that different backgrounds and points of view bring to our business.

ION adheres to an equal employment opportunity policy that prohibits discriminatory practices or harassment against applicants or employees based on any legally impermissible factor.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Principal Business Consultant – Openlink

ION Group

United Kingdom
Remote
GBP 60,000 - 100,000
Full time
30+ days ago
Infrastructure Project Manager

ION Group

Greater London
Hybrid
GBP 60,000 - 80,000
Full time
30+ days ago
Commercial Analyst

ION Group

Woking
On-site
GBP 30,000 - 50,000
Full time
30+ days ago
Senior Business Consultant – Openlink

ION Group

United Kingdom
Remote
GBP 60,000 - 100,000
Full time
30+ days ago
Product Manager – Clarus Data

ION Group

London
On-site
GBP 70,000 - 90,000
Full time
30+ days ago
Senior Technical Project Manager

Ionate Limited

City of London
Hybrid
GBP 65,000 - 80,000
Full time
30+ days ago
Security Operations Analyst (SecOps)

Attio Ltd

United Kingdom
Hybrid
GBP 80,000 - 95,000
Full time
30+ days ago
Security Operations Engineer

Axis Europe Plc

Greater London
Hybrid
GBP 55,000 - 65,000
Full time
30+ days ago
Security Operations Manager

Methodfi

Greater London
On-site
GBP 70,000 - 90,000
Full time
30+ days ago
iSOC Engineer

iProov

Greater London
Hybrid
GBP 60,000 - 80,000
Full time
30+ days ago