This is a newly created Staff-level position with end-to-end ownership of that area. You will own our SIEM and the detection content that runs on it, lead security investigations from first alert to resolution, and set the hardening standard across endpoints, identity, servers and cloud. You will also own the engineering relationship with the external partners who support us.
We are looking for someone who has built a detection capability. Our environment is predominantly Microsoft and Azure, and you will have genuine influence over the tooling, the architecture and the standards we adopt instead of maintaining decisions that were made before you arrived.
This is a senior individual contributor role. You set the detection and hardening standard for the security team, you work without a technical lead above you, and you report directly to the Director Cybersecurity & IT.
Build and own the SIEM
- Take ownership of the platform from the implementation partner, to a depth that allows you to defend or revise its design decisions
- Own data source onboarding, parsing, normalisation and coverage
- Make and justify explicit decisions on log coverage, retention and ingest cost
- Develop the platform as the estate grows, rather than leaving it as delivered
Detection engineering
- Write, tune and maintain the detection content, beyond the vendor's default rule set
- Map coverage against the techniques relevant to our estate and close the gaps that matter
- Treat detections as code: version control, review, testing, and a defined process for false positives
- Convert offensive security findings into detections
Incident response
- Investigate and lead the technical side of security incidents end to end
- Threat hunting against our own telemetry, proactively rather than in response to a report
- Own the technical half of the incident response process and refine it after each event
Hardening
- Design and roll out security baselines across endpoints, servers, identity and cloud
- Work with IT and engineering to get them applied, including where that requires making the case
- Measure configuration drift and close it
Partners and tooling
- Own the engineering relationship with our external security partners: scope, escalation and expectations
- Make build-versus-buy decisions on detection and response tooling, including the cost implications
