> Markdown version of [/jobs/ext/3008186-lead-detection-and-response-engineer](https://www.wearedevelopers.com/jobs/ext/3008186-lead-detection-and-response-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Detection and Response Engineer - **Company:** Joinour - **Location:** London, UK - **Experience:** Expert - **Salary:** £280,800.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Computing Security, Issue Tracking Systems, Intrusion Detection and Prevention, Python (Programming Language), Log Analysis, Security Information and Event Management, Large Language Models, Mitre Att&ck, Mttr, Git, Security Orchestration, Automation & Response - **Published:** September 20, 2026 - **Apply:** https://www.apply4u.co.uk/jobs/lead-detection-and-response-engineer/47706381 ## About the Role structured mentoring as the team grows Who you are Hands on detection engineering experience, writing and maintaining SIEM detection rules, correlation logic and detection as code pipelines Proficient in Python or equivalent for detection development, log parsing and automation Demonstrated incident response experience, leading or contributing to P1 and P2 investigations, post incident reviews and containment Experience with cloud security on AWS and/or Azure, including native cloud telemetry sources Familiar with MITRE ATT&CK as a framework for detection design and gap analysis Hands on experience building and operating SOAR playbooks and response automation across SIEM, EDR, cloud and ticketing Experience leading a SOC and/or managing a third party SOC Demonstrated experience running structured threat hunting cycles Able to influence stakeholders across the technology team. Strong written communication, able to translate technical findings for non-technical stakeholders Able to work independently and collaborate with technical stakeholders across the business Tech stackCloud: AWS (primary), SIEM, SOAR, EDR, Python for detection development, log parsing and automation, MITRE ATT&CK as the detection design and gap analysis framework, Detection as code, version controlled (Git or equivalent), Ticketing and workflow tooling across SIEM, EDR, cloud and ticketing systems Why you'll join Genuine build from scratch mandate. You are not inheriting someone else's detection stack, you are designing it High stakes, high trust environment. The platform underpins $6.5 trillion in daily transactions for 25 of the 30 global systemically important banks Direct line into the CISO and CTO, with real visibility on your work at leadership level A clear path to building and leading a team as the function grows Hybrid working in London ## Description premises, Workforce IT and user endpoints Assess current security monitoring and third party SOC coverage against LLM enabled attacks. Deliver a risk based plan using a hybrid SOC model, working with engineering teams to implement it Build documented MITRE ATT&CK detection coverage across all Tier 1 tactics within 12 months, managed as code and version controlled Author and maintain playbooks for the top incident types by likelihood and impact. Automate containment and response actions through SOAR, targeting 80% automated first action on P1 and P2 responses Establish MTTD and MTTR baselines within 90 days and set improvement targets Run structured threat hunting cycles each quarter and convert findings into new detection rules Review unpatchable vulnerabilities with engineering teams and recommend treatment Produce a monthly detection and response programme metrics report for the CISO and CTO Build internal security capability through knowledge sharing, runbook documentation and