Threat Detection Engineer - Hybrid / Remote
Reference: SBM/AR/070319Job Type: PermanentSalary: 60,000 - 80,000Location: Westminster, Central LondonSector: ITPosted: 2026-05-08Join a well-established biotech company using large-scale genetic data and AI to predict disease risk and advance precision healthcare.We’re looking for a Threat Detection Engineer who thrives on innovation and technical ownership. This role is not a traditional SOC position, you’ll focus on building high-impact detection capabilities, shaping how security protects sensitive genomic and AI-driven data at scale.This role offers hybrid / remote working options, a salary range of 60,000 - 80,000 and benefits.Why This Role is ExcitingHigh autonomy: Lead projects from idea to deploymentInnovation-driven: Develop cutting-edge detections beyond standard SIEM rulesCollaborative: Work closely with internal teams and an outsourced SOC partnerMission-focused: Protect critical healthcare data that supports precision medicineKey ResponsibilitiesDesign and develop threat-led detections using threat intelligence and threat-hunting outputsCreate novel analytic techniques for incident detectionCollaborate with an MSP SOC to maintain and tune the detection catalogueBuild automated reporting dashboards using Microsoft Sentinel workbooksSupport security initiatives including ISO 27001 activities and KQL-based tasksEnsure monitoring coverage across cloud platforms, SaaS apps, and internal systemsContribute to documentation of processes, tools, and detection logicWhat You’ll BringMust-Have Skills & Experience:Previously worked as a Threat Detection Engineer or in a similar role.Strong proficiency in KQL and hands-on experience with Microsoft SentinelFamiliarity with Microsoft Defender tools (Endpoint & O365)Exposure to Azure cloud logging and Kubernetes environmentsKnowledge of attacker TTPs and MITRE ATT&CK frameworksProactive, collaborative, and innovative mindsetDesirable / Nice-to-Have:Experience with Python, Terraform, or CI/CD pipelinesFamiliarity with Microsoft Purview, Entra ID, DLP, or Insider Risk toolsUnderstanding of ISO 27001, Agile ways of workingKnowledge of statistics, data science, or AI/ML applied to cybersecurityRelevant certifications (MS-500, AZ-500, SC-series, Security+, GSOC, CCSK)Perks & BenefitsHybrid / remote working optionsFlexible benefits packageOpportunity to innovate and make a real impact in threat detectionWork in a small, fast-paced, highly collaborative teamContribute to advancing precision healthcare using genomic data and AIReady to build next-generation threat detection and protect life-changing data? Apply today!Important Information: We endeavour to process your personal data in a fair and transparent manner. In applying for this role, Additional Resources will be acting in your best interest and may contact you in relation to the role, either by email, phone, or text message. For more information see our Privacy Policy on our website. It is important you are aware of your individual rights and the provisions the company has put in place to protect your data. If you would like further information on the policy or GDPR please contact us.Additional Resources Ltd is an Employment Business and an Employment Agency as defined within The Conduct of Employment Agencies & Employment Businesses Regulations 2003.Keywords: Cyber Threat Engineer, Detection & Response Engineer, SIEM Engineer, Security Detection Engineer,T hreat Hunting Engineer, Security Automation Engineer, SOC Engineer, Incident Response Engineer, Cloud Security Engineer, Network Security Engineer, Cybersecurity Analyst (Threat Focus), Threat Intelligence Analyst, Security Monitoring Engineer, Endpoint Security Engineer, Cyber Defense Engineer