Overview
Cyber Defense Engineer responsible for monitoring, investigating, and responding to security events across corporate and product environments. The role also contributes to detection engineering, incident response, automation, and AI-augmented security operations.
What you'll do
- Monitor and triage alerts across SIEM, EDR, and CSPM platforms.
- Investigate incidents, collect evidence, determine root causes, and support remediation.
- Write, tune, and validate detection rules mapped to MITRE ATT&CK.
- Translate threat intelligence into actionable detection content.
- Use and improve AI-driven tools, prompts, agent workflows, and automation pipelines.
- Maintain runbooks, handoff notes, metrics, and incident reports.
- Participate in on-call rotations, tabletop exercises, purple team activities, and post-incident reviews.
What you'll need
- 2+ years of experience in SOC, security operations, or incident response.
- Knowledge of MITRE ATT&CK, network protocols, and endpoint behavior.
- Experience with at least one SIEM platform and security search or detection queries.
- Familiarity with EDR platforms and cloud environments.
- Comfort using AI systems in security workflows.
- Strong written communication for technical and non-technical audiences.
Nice to have
- Complex incident response leadership experience.
- IAM, CSPM, SOAR, scripting, or security automation experience.
- Experience with AI agent architectures, LLM automation, or prompt engineering.
- Threat intelligence, detection-as-code, or privileged access management experience.
Details
- Fully remote in the UK.
- Up to four weeks per year working abroad, subject to approval.
- Participation in an after-hours incident escalation rotation.
Read the full description and apply on the company’s own careers page.