> Markdown version of [/jobs/ext/2817900-senior-cyber-detection-and-response-engineer](https://www.wearedevelopers.com/jobs/ext/2817900-senior-cyber-detection-and-response-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cyber Detection and Response Engineer - **Company:** Pirum Systems Ltd. - **Location:** London, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Clean Code Principles, Artificial Intelligence, Amazon Web Services, Microsoft Azure, Software as a Service, Cloud Computing Security, Intrusion Detection and Prevention, Python (Programming Language), Log Analysis, Security Information and Event Management, Mitre Att&ck, Mttr, Information Technology, Cybercrime - **Published:** September 10, 2026 - **Apply:** https://www.collegerecruiter.com/job/2840614156-senior-cyber-detection-and-response-engineer ## About the Role The successful candidate will be a hands-on detection engineer who can think like an adversary, writes production-quality code and treats detection as an engineering discipline rather than an alerting afterthought. You will be comfortable operating independently in a lean team, making consequential decisions at pace and translating technical findings into clear reporting for technical and non-technical audiences alike., * Hands-on detection engineering experience, writing and maintaining SIEM detection rules, correlation logic and detection-as-code pipelines. * Demonstrated incident response experience, leading or contributing to high-priority (P1/P2) investigations, containment and post-incident reviews. * Proven experience running structured, hypothesis-driven threat hunting cycles and translating findings into new detections. * Working knowledge of cloud security and native cloud telemetry sources (AWS and/or Azure). * Practical use of the MITRE ATT&CK framework to structure detection coverage and gap analysis. * Hands-on experience building and operating SOAR playbooks and response automation, orchestrating across security tooling and ticketing. * Proficiency in Python or an equivalent language for detection development, log parsing and automation, producing readable, maintainable code. * Experience leading a SOC and/or managing a third-party SOC. * Ability to work independently and collaborate with technical stakeholders across the business. * Strong written communication, able to translate technical findings into clear reporting for non-technical stakeholders and to influence across the technology team. * A strong technical background and genuine interest in technology., * Relevant certifications such as GCIA, GCIH, GCDA, BTL2 or equivalent practical experience. * A history of competing in CTF competitions and/or running a home lab. * A Computer Science or Engineering degree (preferred but not essential). * Experience in financial services, fintech or a SaaS business serving regulated customers. * Awareness of AI and LLM security risks, relevant as Pirum's own AI capabilities continue to expand. ## Description We are looking for a Senior Detection and Response Engineer to lead Pirum's detection and response capability, enabling us to detect, investigate and contain threats at machine speed across our AWS, on-premises, workforce IT and endpoint estate. This is a high-autonomy role reporting directly to the CISO: you will set the direction for detection engineering at Pirum, work closely with our engineering teams, and be trusted to run with it., You will use your expertise and experience to own, develop and deliver across a range of areas, including: * Detection engineering - design, build and continuously improve detection content, managed as code and version-controlled, mapping coverage to adversary tactics and techniques using the MITRE ATT&CK framework and prioritising the techniques most relevant to a financial services SaaS provider. * Telemetry and visibility - maintain a clear view of the estate and the telemetry available across AWS, on-premises, workforce IT and endpoints, working with engineering teams to ensure the right data reaches the detection platform. * Threat hunting - run structured, hypothesis-driven threat hunting cycles, documenting findings and converting them into new detection content. * Incident response - lead detection, triage and response across the incident lifecycle, authoring and maintaining playbooks for the most significant incident types and owning clear, calm communication up to and including the CISO. * Response automation - build SOAR-style automation to accelerate and standardise response, targeting automated first-actions for high-priority incidents and reducing manual triage so the team scales without proportional headcount. * Monitoring operating model - help shape the right operating model for security monitoring, balancing in-house and managed capability and keeping pace with an evolving threat landscape, including AI and LLM-enabled attacks. * Measurement and reporting - define and track meaningful detection and response metrics, including MTTD and MTTR, and produce a regular programme metrics report for the CISO and CTO. * Collaboration and capability building - partner with engineering teams to embed detection and monitoring requirements into new and existing services, agree risk-based treatment where issues cannot be immediately remediated, and grow internal security capability through documentation, knowledge sharing and structured mentoring as the team grows. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [Progressive Delivery in Kubernetes](https://www.wearedevelopers.com/videos/949-progressive-delivery-in-kubernetes) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)