> Markdown version of [/jobs/ext/2208135-information-security-analyst-secops-detection](https://www.wearedevelopers.com/jobs/ext/2208135-information-security-analyst-secops-detection). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Analyst - SecOps Detection - **Company:** Starling - **Location:** London, UK - **Experience:** Experienced - **Salary:** £60,104.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Microsoft Windows, Amazon Web Services, Apple Mac Systems, ARM Architecture, Microsoft Azure, Bash Shell, Software as a Service, Cloud Computing, Cloud Computing Security, Cyber Security, Computer Programming, Linux, Digital Forensics, Intrusion Detection and Prevention, Python (Programming Language), Network Security, Security Information and Event Management, Scripting, Google Cloud, Mitre Att&ck, Malware, Cyber Threat Analysis, Falcon Platform, Kubernetes, Cybercrime, Purple Team (Cyber Security), Splunk, SentinelOne Expertise, Docker, Security Orchestration, Automation & Response, Golang - **Published:** August 24, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5854394079 ## About the Role We have a Hybrid approach to working here at Starling - our preference is that you're located within a commutable distance of one of our offices so that we're able to interact and collaborate in person. In Technology, we're asking that you attend the office a minimum of 1 day per week., * 3+ years in a technical security role, such as detection engineering, threat hunting, incident response, or threat intelligence. * Attacker Knowledge: Practical experience analysing attacker behavior, with a strong understanding and application of threat analysis models like MITRE ATT&CK to prioritize and enhance detective controls. * SIEM Expertise: Hands-on experience with SIEM platforms (e.g., Splunk, Google SecOps, Elastic, Sentinel) for rule/query creation and analytics. * Threat Hunting: Experience conducting proactive threat hunts, defining hypotheses, and developing hunting methodologies. * Cloud Security: Solid knowledge of security risks and detection strategies for AWS, GCP, Azure. * EDR Proficiency: Experience with EDR tools (e.g., Crowdstrike, SentinelOne, Cortex XDR). * Core Technical Skills: Good understanding of OS internals (macOS, Linux, Windows) and network security principles. * Key Attributes: Excellent analytical, problem-solving, and communication skills. Self-starter, able to lead projects, and highly collaborative. * Growth Mindset: Eagerness to learn and apply knowledge to new security challenges. Preferred * Experience with at least one programming or scripting language (e.g., Python, Go, Bash) for security automation or analysis. * Experience with container security monitoring (Docker, Kubernetes). * Experience with Detection-as-Code. * Experience with SOAR platforms. * Knowledge of digital forensics and incident response procedures. * Understanding of malware analysis techniques. * It would be great if you have one or more of the following qualifications, but it's not essential; * GIAC Certified Forensic Analyst (GCFA) * GIAC Cloud Threat Detection (GCTD) * GIAC iOS and macOS Examiner (GIME) ## Description We're seeking a passionate and skilled Detection Engineer and Threat Hunter to join our growing Security Operations team, and proactively defend Starling's customers, assets, and systems against emerging threats. Reporting to the Information Security Lead - Detection, the analyst's primary responsibility will be to proactively identify and defend against potential threats to the bank. You will achieve this by developing, tuning, and maintaining detection rules, conducting intelligence-driven threat hunts, and participating in collaborative defence improvement activities like Purple Teaming to identify and mitigate risks before they impact the bank. What you'll get to do / Responsibilities * Detection Engineering - Design, build, test, and maintain high-fidelity detection rules and analytics in our SIEM and other security platforms. * Proactive Threat Hunting - Formulate hypotheses and hunt for undetected attacker TTPs across our cloud (AWS, GCP, Azure), SaaS, and endpoint environments. * Purple Team - Collaborate with our Adversarial Simulation team in Purple Team exercises to test, validate, and improve detection logic and response. * Incident Response SME support - Act as a Subject Matter Expert during security incidents, providing deep technical analysis and aiding remediation. * Threat Intelligence integration - Integrate and operationalise threat intelligence to inform detection strategies and hunting projects. * Collaboration - Work closely with the wider Security Operations team, and other stakeholders to uplift Starling's security posture and improve detective controls. * Documentation - Maintain clear documentation for detection rules, hunting playbooks, and processes. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)