Role
You will own and evolve the company's threat detection and threat-hunting capability. This role defines what "good" looks like for detection and increasingly engineers it directly as capability shifts into Cyber Security.
This is not an alert-triage role. You are here to understand attacker behaviour, convert it into high-fidelity detection logic, and raise the security baseline for the entire organisation.
You will partner closely with Security Operations, GRC and Engineering-setting standards, direction, and expectations-while progressively taking ownership of the most complex and high-value detection and threat engineering work.
What you'll be responsible for
- Engineering high-fidelity threat detections across endpoint, identity, cloud, and SaaS
- Defining detection standards, principles, and quality thresholds for Security Operations
- Conducting proactive threat hunting based on attacker behaviour, not vendor alerts
- Translating threat intelligence and incident learnings into durable, reusable detections
- Mapping detections to MITRE ATT & C K and real-world attack paths
- Reducing alert fatigue through logic refinement, correlation, and contextual enrichment
- Advising and supporting during high-severity security incidents; contribute to runbooks and escalation playbooks
- Driving the transition of advanced detection capability into Cyber Security ownership
What we're looking for
- Proven experience in detection engineering, threat hunting, or advanced SOC roles
- Deep understanding of modern attacker tradecraft and intrusion techniques across the attack lifecycle
- Hands-on experience buidling detection logic in modern SIEM platforms (e.g Sentinel)
- Proficienty with scripting and programmaining (e.g. Python, KQL) to build detection pipelines and automation
- Willingness to challenge bad detections, weak assumptions, and vanity metrics
- Pragmatic mindset: precision and impact beat coverage theatre
- Experience operating beyond traditional SOC or MSSP models
- Hands on cloud detection experience (identity, control plane, SaaS)
- Familiarity with threat intelligence platforms and frameworks such as PCI DSS, NIST CSF, SOC 2, ISO27001, CIS Benchmarks, and MITRE ATT & C K for Cloud.