Latest Threat Detection Jobs

Threat Detection Engineer

This role involves designing and developing threat-led detections using threat intelligence and hunting outputs, collaborating with an MSP SOC, and building automated reporting dashboards. The focus is on protecting sensitive genomic and AI-driven data, with high autonomy and a mission to advance precision healthcare.

Additional Resources London, United Kingdom £60,000 – £80,000 pa
Hybrid Permanent Flexible
Darktrace logo

Threat Research Analyst

The role involves in-depth analysis of cyber threats, malware, and adversary TTPs using data science and analytical techniques. You'll proactively hunt for emerging threats, develop threat intelligence reports, and refine detection methodologies based on research. Collaboration with security researchers and product teams helps strengthen Darktrace’s AI-driven threat response capabilities.

Darktrace London, UB8 1LQ, United Kingdom
Darktrace logo

Threat Research Analyst

The role involves in-depth analysis of cyber threats, malware, and adversary TTPs using data science and analytical techniques. You'll proactively hunt for emerging threats, develop threat detection methodologies, produce intelligence reports, and present findings internally and externally. Collaboration with research, security, and product teams is key to enhancing Darktrace's AI-driven threat intelligence capabilities.

Darktrace Cambridge, CB2 3BJ, United Kingdom

Senior Threat Behavior Researcher (UK)

This role involves conducting in-depth behavioral analysis of Windows-based threats and developing real-time protection rules to detect and block malicious activities, including hands-on keyboard attacks, malware payloads, and APTs. The researcher will create behavioral and cleanup rules, improve sandbox detection by identifying evasion techniques, and produce technical reports. Collaboration with cross-functional teams and mentoring junior researchers are also key responsibilities, all within a remote-first, globally distributed security team.

Sophos United Kingdom
Remote Permanent

Senior Threat Researcher (UK)

Develops high-fidelity threat detections by analyzing malware and web attacks using multi-source telemetry and threat intelligence. Translates research into actionable alerts across Sophos' security platform with a focus on reducing noise. Works closely with threat intelligence and product teams to enhance detection accuracy for endpoint, cloud, and network environments.

Sophos United Kingdom
Remote Permanent

Director, R&D, Email & Collaboration Threat Protection

Lead a multi-squad engineering organisation responsible for Mimecast’s mission-critical Mail Transfer Agent, processing over 1.7 billion emails daily. Drive technical strategy, engineering excellence, and AI-augmented development across a globally distributed platform. Foster leadership, organisational health, and high-performance culture within Email & Collaboration Security.

Mimecast London, United Kingdom £124,000 – £186,000 pa
CrowdStrike logo

Sr. SDET - Cloud, Detection Engineer , London)

Design and build scalable cloud detection systems that process billions of events to identify sophisticated threats across multi-cloud environments. Work at the intersection of distributed systems, data engineering, and security analytics, implementing custom query languages, event orchestration, and advanced correlation engines. Collaborate with security researchers to turn expertise into production-grade detection capabilities with low latency and high reliability.

CrowdStrike London, United Kingdom
Hybrid Permanent
Amazon logo

Software Development Engineer - Security Automation, AWS Security Epoxy

This role involves building and operating large-scale automation platforms that enable threat detection, risk remediation, and incident response across AWS accounts. The engineer will design, implement, and maintain highly resilient systems with a strong focus on operational excellence, automation, and security at scale. Key responsibilities include developing features, improving system resiliency, leading incident response, and mentoring team members while working closely with partner security teams.

Amazon London, United Kingdom
Permanent
Experis logo

Splunk SIEM Engineer

Role Title: Splunk SIEM EngineerDuration: contract to run until 30/11/2026Location: Knutsford. Hybrid, 3 days per week onsiteRate: up to £587.33 p/d Umbrella inside IR35Role purpose / summaryJoin us as Splunk SIEM Engineer where you must design, develop and improve software,...

Experis Knutsford, Cheshire, United Kingdom
Bridewell logo

Senior Security Engineer

This role involves leading Microsoft Sentinel adoption, managing client onboarding, and developing custom connectors to ingest log data into SIEM platforms. The engineer will work on multi-vendor SIEM proof of concepts, create dashboards, develop queries, and configure alerts. Proficiency in infrastructure as code, DevOps pipelines, and scripting is central to the position.

Bridewell Cardiff, United Kingdom
Hybrid Permanent

Security Operations Analyst

This role involves monitoring and analysing cyber threats, conducting threat modelling, and producing intelligence reports to strengthen security controls. The analyst will work within a security team to detect, investigate, and respond to threats using frameworks like MITRE ATT&CK, while supporting both strategic and operational resilience initiatives. Collaboration with SOC, threat intelligence, and engineering teams is central to the role.

Matchtech London, United Kingdom £594 pd

Senior Solution Architect - Email & Collaboration Security

This role involves shaping the technical direction of Mimecast's core Email & Collaboration Security (ECS) product line by translating complex customer and business challenges into durable, scalable architectures. The Senior Architect will lead problem-framing workshops, own critical integration contracts, and ensure engineering teams have a stable foundation to innovate quickly—while navigating two decades of legacy systems and AI-augmented threats. The position demands deep collaboration across product, engineering, and architecture leadership, with a strong emphasis on AI-first design practices and cost-aware, customer-centric decision-making.

Mimecast London, United Kingdom £124,000 – £186,000 pa
On-site Permanent Clearance Required

IT / Network Security Engineer

This role involves defending enterprise infrastructure and data by managing threat detection, security appliances, and compliance frameworks. The engineer will analyze network telemetry, respond to incidents, ensure alignment with ISO 27001, and collaborate across teams to integrate security into system design. Work follows a hybrid model with two days per week on-site in Oxfordshire.

Tank Recruitment Oxfordshire, United Kingdom £45,000 – £55,000 pa

SOC Manager

Lead and shape the strategic direction of a mature Security Operations Centre within a high-profile public sector organisation. Oversee security monitoring, incident response, and threat intelligence capabilities while managing a high-performing team and collaborating with MSSPs and vendors. Drive continuous improvement in cyber resilience and operational excellence in a fully remote role.

Fox Morris Group Ltd Hackney Central, London, United Kingdom £700 – £850 pd

SC Cleared Splunk SIEM Engineer

Design, develop, and enhance SIEM solutions using Splunk and Microsoft Sentinel within a secure enterprise environment. Manage data pipelines, develop correlation rules, and support security operations with strong focus on automation, incident response, and cross-platform integration. Work in a hybrid model with regular on-site presence in Cheshire.

Hays Technology Knutsford, Cheshire, United Kingdom £500 – £638 pd