Lead Detection & Response Engineer

Lloyds Banking Group
Edinburgh, UK
4 days ago
Apply on lbg.wd3.myworkdayjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
£72,702.0 - £80,780.0
Working hours
Shift work

Tech stack

Artificial Intelligence Data Analysis Cyber Security Digital Forensics Intrusion Detection and Prevention Cybercrime

Job description

Help defend one of the UK’s largest organisations against evolving cyber threats. As a Lead Detection and Response Engineer within our Cyber Defence Centre, you’ll play a key role in protecting the organisation through the investigation of security incidents, identification of malicious activity, and continuous improvement of detection and response capabilities.

You’ll combine deep technical expertise with analytical thinking to investigate complex cyber security challenges, strengthen cyber resilience, and help shape how we detect and respond to threats across the Group. Alongside remaining hands-on in cyber defence activities, you’ll provide leadership and support to Security Engineers across the team, helping to raise technical standards and foster continuous learning., * Leading investigations into security alerts, incidents and emerging threats, ensuring effective containment, eradication and recovery activities.

  • Analysing security events, attacker behaviours and threat intelligence to identify risks and determine appropriate response actions.
  • Conducting threat hunting, forensic investigations and proactive cyber defence activities to identify previously unknown threats.
  • Contributing to the ongoing enhancement of detection and response capabilities through continuous improvement initiatives.
  • Using automation, AI and modern security tooling to improve operational effectiveness and efficiency.
  • Supporting, developing and managing Security Engineers while promoting engineering excellence and knowledge sharing.

Requirements

  • Strong experience within a Security Operations Centre, Cyber Defence, Incident Response, Threat Hunting or a related cyber security environment.
  • Experience investigating and responding to cyber security incidents using enterprise security technologies and processes.
  • Strong understanding of threat detection lifecycles, attacker behaviours and tactics, techniques and procedures.
  • Proven ability to lead, mentor and develop colleagues while fostering an inclusive, high-performing team culture.
  • Strong analytical and problem-solving skills with the ability to assess complex situations and determine appropriate actions.
  • Ability to influence technical outcomes through expertise, collaboration and credibility, communicating effectively with both technical and non-technical audiences.

And any experience of this would be really useful

  • Experience in digital forensics, detection engineering or threat analysis.
  • Experience applying automation or AI-enabled approaches to improve cyber defence outcomes.
  • Experience contributing to continuous improvement initiatives within cyber security operations., If you’re passionate about cyber defence, incident response and continuous improvement, we’d love to hear from you. Join us and help build the resilience, protection and security capabilities that support our customers, colleagues and communities every day.

Benefits & conditions

  • 30 days’ holiday, with bank holidays on top.
  • A generous pension contribution.
  • Discretionary annual performance-related award.
  • Flexible benefits designed to support your health, wellbeing and lifestyle.
  • Access to a range of colleague and family support initiatives.

About the company

Like the modern Britain we serve, we’re evolving. Investing in the technologies, people and capabilities needed to make a real difference for our customers, we’re building a more sustainable and inclusive future.

Our focus is on creating better outcomes for customers, colleagues and communities. By joining us, you’ll have the opportunity to work on meaningful challenges, develop your skills and contribute to the security and resilience of one of the UK’s largest organisations., Our ambition is to be the leading UK business for diversity, equity and inclusion, supporting our customers, colleagues and communities. We are committed to creating an environment in which everyone can thrive, learn and develop.

We were one of the first major organisations to set goals on diversity in senior roles, create a menopause health package, and launch a dedicated Working with Cancer initiative., At Lloyds Banking Group, we’re driven by a clear purpose; to help Britain prosper. Across the Group, our colleagues are focused on making a difference to customers, businesses and communities. With us you’ll have a key role to play in shaping the financial services of the future, whilst the scale and reach of our Group means you’ll have many opportunities to learn, grow and develop.

We keep your data safe. So, we’ll only ever ask you to provide confidential or sensitive information once you have formally been invited along to an interview or accepted a verbal offer to join us which is when we run our background checks. We’ll always explain what we need and why, with any request coming from a trusted Lloyds Banking Group person.

We’re focused on creating a values-led culture and are committed to building a workforce which reflects the diversity of the customers and communities we serve. Together we’re building a truly inclusive workplace where all of our colleagues have the opportunity to make a real difference.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on lbg.wd3.myworkdayjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Addressing active AI incident remediation and broad ecosystem support

Matthew Brady Matthew Brady · World Congress 2026 Europe

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

1:48 min

Automating exploratory data analysis within training pipelines

Dora Petrella · World Congress 2023

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:31 min

Dual usage of machine learning in cybersecurity

Wolfgang Ettlinger +1 · World Congress 2023

2:11 min

Securing heterogeneous legacy payment infrastructure against AI

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

Videos

See all

Related articles

See all