Latest Threat Detection Jobs

Darktrace logo

Threat Research Analyst

The role involves in-depth analysis of cyber threats, malware, and adversary TTPs using data science and analytical techniques. You'll proactively hunt for emerging threats, develop threat intelligence reports, and refine detection methodologies based on research. Collaboration with security researchers and product teams helps strengthen Darktrace’s AI-driven threat response capabilities.

Darktrace London, UB8 1LQ, United Kingdom
Darktrace logo

Threat Research Analyst

The role involves in-depth analysis of cyber threats, malware, and adversary TTPs using data science and analytical techniques. You'll proactively hunt for emerging threats, develop threat detection methodologies, produce intelligence reports, and present findings internally and externally. Collaboration with research, security, and product teams is key to enhancing Darktrace's AI-driven threat intelligence capabilities.

Darktrace Cambridge, CB2 3BJ, United Kingdom

Senior Security Researcher - (AI & Detection Engineering)

This role involves researching emerging cyber threats and leveraging AI technologies to improve threat detection and security automation. The candidate will develop prototypes and tools in Python, explore Agentic AI applications in security, and collaborate with engineering teams to integrate research into product capabilities. It's a research-driven position focused on advancing AI-powered cyber defence through innovation and technical exploration.

Salt Search London, United Kingdom £70,000 – £90,000 pa

Director, R&D, Email & Collaboration Threat Protection

Lead a multi-squad engineering organisation responsible for Mimecast’s mission-critical Mail Transfer Agent, processing over 1.7 billion emails daily. Drive technical strategy, engineering excellence, and AI-augmented development across a globally distributed platform. Foster leadership, organisational health, and high-performance culture within Email & Collaboration Security.

Mimecast London, United Kingdom £124,000 – £186,000 pa

IT Cyber Security Analyst

This role involves managing patching, vulnerability remediation, and incident response within a large enterprise environment, supporting both IT and OT systems. The analyst will work closely with internal teams and external SOC/MDR providers to enhance threat detection and security maturity. Key responsibilities include coordinating security controls, supporting audits, and improving detection capabilities across networks, endpoints, identity, and cloud platforms.

Rise Technical Recruitment Scunthorpe, DN15 6SS, United Kingdom £45,000 – £50,000 pa
On-site Permanent Clearance Required

Anaplan Developer

Design and develop Anaplan models for sales and finance planning, including territory, quota, and incentive compensation. Collaborate with stakeholders and IT teams to build scalable, integrated planning systems using Anaplan best practices. Improve performance and governance across multi-model architectures.

Sophos United Kingdom £50,000 – £84,000 pa
Remote Permanent Clearance Required
Bridewell logo

Senior Security Engineer

This role involves leading Microsoft Sentinel adoption, managing client onboarding, and developing custom connectors to ingest log data into SIEM platforms. The engineer will work on multi-vendor SIEM proof of concepts, create dashboards, develop queries, and configure alerts. Proficiency in infrastructure as code, DevOps pipelines, and scripting is central to the position.

Bridewell Cardiff, United Kingdom
Hybrid Permanent

Security Operations Analyst

This role involves monitoring and analysing cyber threats, conducting threat modelling, and producing intelligence reports to strengthen security controls. The analyst will work within a security team to detect, investigate, and respond to threats using frameworks like MITRE ATT&CK, while supporting both strategic and operational resilience initiatives. Collaboration with SOC, threat intelligence, and engineering teams is central to the role.

Matchtech London, United Kingdom £594 pd

Cyber Security Engineer / SOC Analyst

This role involves maintaining and optimising cybersecurity toolsets within a Defence organisation's Security Operations Centre. The engineer will lead on SIEM, threat detection, and network visibility, performing playbook scripting, tool integration, and backend refresh activities. The position requires deep technical expertise in security infrastructure, automation, and incident investigation across hybrid environments.

Tatton Recruitment Stevenage, Hertfordshire, United Kingdom £92 ph
On-site Contract Clearance Required

IT / Network Security Engineer

This role involves defending enterprise infrastructure and data by managing threat detection, security appliances, and compliance frameworks. The engineer will analyze network telemetry, respond to incidents, ensure alignment with ISO 27001, and collaborate across teams to integrate security into system design. Work follows a hybrid model with two days per week on-site in Oxfordshire.

Tank Recruitment Oxfordshire, United Kingdom £45,000 – £55,000 pa

SOC Manager

Lead and shape the strategic direction of a mature Security Operations Centre within a high-profile public sector organisation. Oversee security monitoring, incident response, and threat intelligence capabilities while managing a high-performing team and collaborating with MSSPs and vendors. Drive continuous improvement in cyber resilience and operational excellence in a fully remote role.

Fox Morris Group Ltd Hackney Central, London, United Kingdom £700 – £850 pd

Cyber Security & Infrastructure Engineer

This role involves protecting systems, networks, and data by monitoring security alerts, leading incident response, and improving security posture across on-premises and cloud environments. The engineer will implement and maintain Azure, Microsoft 365, and Intune security, conduct vulnerability management, and ensure compliance with standards like ISO 27001 and NCSC. A key focus is threat detection, forensic investigation, and enhancing infrastructure resilience within a small, technical IT team.

Adria Solutions East Howdon, Tyne & Wear, United Kingdom £40,000 – £50,000 pa

SC Cleared Splunk SIEM Engineer

Design, develop, and enhance SIEM solutions using Splunk and Microsoft Sentinel within a secure enterprise environment. Manage data pipelines, develop correlation rules, and support security operations with strong focus on automation, incident response, and cross-platform integration. Work in a hybrid model with regular on-site presence in Cheshire.

Hays Technology Knutsford, Cheshire, United Kingdom £500 – £638 pd

SOC Analyst - Active SC required

Monitor and respond to security incidents using IBM QRadar SIEM, conducting threat detection, log analysis, and incident investigation across enterprise systems. Support a defence/aerospace client with robust security controls and detailed post-incident reporting. Engage in proactive threat hunting and handle diverse cyber threats including phishing and malware.

Matchtech Harlow, Essex, United Kingdom
Hybrid Contract Clearance Required

Compliance Enablement Technical Program Manager

This role involves leading the technical compliance automation function for Sophos' Trust and Assurance team, focusing on ensuring controls in the GRC platform are accurate, continuously monitored, and aligned with cybersecurity frameworks. The candidate will work cross-functionally with engineering teams to integrate compliance into development workflows and reduce audit burden through automation. A strong blend of technical depth, program management, and AI-assisted compliance operations is central to the position.

Sophos Canada CA$109,000 – CA$181,000 pa
Remote