Latest Threat Detection Jobs

Spotlight
Lab 1 logo

Senior Data Engineer

The role involves designing, building, and operating scalable batch and streaming data pipelines that transform vast, unstructured exposed data into reliable, queryable intelligence. You'll work end-to-end across the data lifecycle, ensuring high data quality and close integration with machine learning workflows for feature engineering and model training. The position emphasizes ownership of data platforms using modern cloud and data stack technologies in a collaborative, remote-first startup environment.

Lab 1 London, Greater London, United Kingdom £85,000 – £125,000 pa
Hybrid Permanent

Threat Detection Engineer

This role involves designing and developing threat-led detections using threat intelligence and hunting outputs, collaborating with an MSP SOC, and building automated reporting dashboards. The focus is on protecting sensitive genomic and AI-driven data, with high autonomy and a mission to advance precision healthcare.

Additional Resources London, United Kingdom £60,000 – £80,000 pa
Hybrid Permanent Flexible

Threat Detection Engineer

Design and develop threat-led detection capabilities using Microsoft Sentinel, KQL, and threat intelligence to protect sensitive genomic and AI-driven healthcare data. Build automated reporting dashboards, collaborate with an outsourced SOC, and ensure monitoring coverage across cloud, SaaS, and Kubernetes environments. Contribute to security initiatives including ISO 27001 compliance and detection logic documentation.

Additional Resources Wc1A2Sl, United Kingdom £60,000 – £80,000 pa
Hybrid
Darktrace logo

Threat Research Analyst

The role involves in-depth analysis of cyber threats, malware, and adversary TTPs using data science and analytical techniques. You'll proactively hunt for emerging threats, develop threat intelligence reports, and refine detection methodologies based on research. Collaboration with security researchers and product teams helps strengthen Darktrace’s AI-driven threat response capabilities.

Darktrace London, UB8 1LQ, United Kingdom
Darktrace logo

Threat Research Analyst

The role involves in-depth analysis of cyber threats, malware, and adversary TTPs using data science and analytical techniques. You'll proactively hunt for emerging threats, develop threat detection methodologies, produce intelligence reports, and present findings internally and externally. Collaboration with research, security, and product teams is key to enhancing Darktrace's AI-driven threat intelligence capabilities.

Darktrace Cambridge, CB2 3BJ, United Kingdom

Senior Threat Behavior Researcher (UK)

This role involves conducting in-depth behavioral analysis of Windows-based threats and developing real-time protection rules to detect and block malicious activities, including hands-on keyboard attacks, malware payloads, and APTs. The researcher will create behavioral and cleanup rules, improve sandbox detection by identifying evasion techniques, and produce technical reports. Collaboration with cross-functional teams and mentoring junior researchers are also key responsibilities, all within a remote-first, globally distributed security team.

Sophos United Kingdom
Remote Permanent

Senior Threat Researcher (UK)

Develops high-fidelity threat detections by analyzing malware and web attacks using multi-source telemetry and threat intelligence. Translates research into actionable alerts across Sophos' security platform with a focus on reducing noise. Works closely with threat intelligence and product teams to enhance detection accuracy for endpoint, cloud, and network environments.

Sophos United Kingdom
Remote Permanent
CrowdStrike logo

Sr. SDET - Cloud, Detection Engineer , London)

Design and build scalable cloud detection systems that process billions of events to identify sophisticated threats across multi-cloud environments. Work at the intersection of distributed systems, data engineering, and security analytics, implementing custom query languages, event orchestration, and advanced correlation engines. Collaborate with security researchers to turn expertise into production-grade detection capabilities with low latency and high reliability.

CrowdStrike London, United Kingdom
Hybrid Permanent
Experis logo

SOC Analyst

This SOC Analyst role involves real-time monitoring, triage, and incident response within a modern enterprise security environment. The candidate will investigate security events, fine-tune detection rules, and collaborate with internal teams to strengthen security operations. Focus is on proactive threat detection, incident documentation, and continuous improvement of SOC processes using tools like Microsoft Sentinel and Microsoft Defender.

Experis London, City And County Of the City Of London, United Kingdom £400 – £500 pd
Hybrid Contract Clearance Required
Experis logo

Splunk SIEM Engineer

Role Title: Splunk SIEM EngineerDuration: contract to run until 30/11/2026Location: Knutsford. Hybrid, 3 days per week onsiteRate: up to £587.33 p/d Umbrella inside IR35Role purpose / summaryJoin us as Splunk SIEM Engineer where you must design, develop and improve software,...

Experis Knutsford, Cheshire, United Kingdom
Bridewell logo

Senior Security Engineer

This role involves leading Microsoft Sentinel adoption, managing client onboarding, and developing custom connectors to ingest log data into SIEM platforms. The engineer will work on multi-vendor SIEM proof of concepts, create dashboards, develop queries, and configure alerts. Proficiency in infrastructure as code, DevOps pipelines, and scripting is central to the position.

Bridewell Cardiff, United Kingdom
Hybrid Permanent

Security Operations Analyst

This role involves monitoring and analysing cyber threats, conducting threat modelling, and producing intelligence reports to strengthen security controls. The analyst will work within a security team to detect, investigate, and respond to threats using frameworks like MITRE ATT&CK, while supporting both strategic and operational resilience initiatives. Collaboration with SOC, threat intelligence, and engineering teams is central to the role.

Matchtech London, United Kingdom £594 pd

Senior Architect - Email & Collaboration Security

This role involves shaping the technical direction of Mimecast's core Email & Collaboration Security (ECS) product line by translating complex customer and business challenges into durable, scalable architectures. The Senior Architect will lead problem-framing workshops, own critical integration contracts, and ensure engineering teams have a stable foundation to innovate quickly—while navigating two decades of legacy systems and AI-augmented threats. The position demands deep collaboration across product, engineering, and architecture leadership, with a strong emphasis on AI-first design practices and cost-aware, customer-centric decision-making.

Mimecast London, United Kingdom £124,000 – £186,000 pa
On-site Permanent Clearance Required

IT / Network Security Engineer

This role involves defending enterprise infrastructure and data by managing threat detection, security appliances, and compliance frameworks. The engineer will analyze network telemetry, respond to incidents, ensure alignment with ISO 27001, and collaborate across teams to integrate security into system design. Work follows a hybrid model with two days per week on-site in Oxfordshire.

Tank Recruitment Oxfordshire, United Kingdom £45,000 – £55,000 pa

SOC Manager

Lead and shape the strategic direction of a mature Security Operations Centre within a high-profile public sector organisation. Oversee security monitoring, incident response, and threat intelligence capabilities while managing a high-performing team and collaborating with MSSPs and vendors. Drive continuous improvement in cyber resilience and operational excellence in a fully remote role.

Fox Morris Group Ltd Hackney Central, London, United Kingdom £700 – £850 pd

Director, Program Delivery Management

Leads the program and delivery management function across Mimecast’s Product and R&D organization, setting standards for planning, execution, and governance. Champions operational excellence, drives systemic improvements, and integrates AI to enhance delivery velocity. Focuses on team development, cross-functional alignment, and executive-level reporting to ensure reliable, scalable delivery at scale.

Mimecast London, United Kingdom £104,000 – £156,000 pa