{bc}
workable

Information Security Analyst - SecOps Detection

Starling
GBR
Full-time
Onsite
Discovered 1 weeks ago
Detection engineeringThreat huntingSecurity information and event management (SIEM)MITRE ATT&CKCloud securityAWS
Free

Job Fit Check

Base Career helps you apply smarter for this job.

?%
Ready to Scan

Key skills for this role

Detection engineeringThreat huntingSecurity information and event management (SIEM)
Smart Apply

Full Job Posting

About the role

Starling is seeking a Detection Engineer and Threat Hunter to proactively defend its customers, assets, and systems against emerging threats.

The role reports to the Information Security Lead - Detection and focuses on detection rules, threat hunting, and collaborative defense improvement.

Hybrid working

  • The role uses a hybrid working approach, with a preference for candidates within commuting distance of a Starling office.
  • Technology employees are expected to attend the office at least one day per week.

Responsibilities

  • Design, build, test, and maintain high-fidelity detection rules and analytics in SIEM and other security platforms.
  • Conduct intelligence-driven threat hunts across AWS, GCP, Azure, SaaS, and endpoint environments.
  • Collaborate in purple team exercises to test, validate, and improve detection logic and response.
  • Provide subject matter expert support during security incidents through technical analysis and remediation assistance.
  • Integrate and operationalize threat intelligence for detection strategies and hunting projects.
  • Improve Starling's security posture and detective controls with Security Operations and other stakeholders.
  • Maintain documentation for detection rules, hunting playbooks, and processes.

Essential requirements

  • At least 3 years of experience in a technical security role such as detection engineering, threat hunting, incident response, or threat intelligence.
  • Practical experience analyzing attacker behavior and applying MITRE ATT&CK or similar threat analysis models.
  • Hands-on SIEM experience for rule and query creation and analytics.
  • Experience conducting proactive threat hunts and developing hunting methodologies.
  • Knowledge of cloud security risks and detection strategies across AWS, GCP, and Azure.
  • Experience with EDR tools and understanding of operating system internals and network security principles.
  • Strong analytical, problem-solving, communication, collaboration, and project leadership skills.
  • Eagerness to learn and apply knowledge to new security challenges.

Preferred skills and qualifications

  • Programming or scripting experience with Python, Go, or Bash for security automation or analysis.
  • Experience with container security monitoring, Detection-as-Code, or SOAR platforms.
  • Knowledge of digital forensics, incident response procedures, or malware analysis techniques.
  • GIAC Certified Forensic Analyst, GIAC Cloud Threat Detection, or GIAC iOS and macOS Examiner certification is advantageous but not essential.

Benefits

  • The benefits package includes holiday allowance, paid volunteering time, enhanced pension, life insurance, income protection, private medical insurance, family-friendly policies, and employee discounts.
  • Additional initiatives include Cycle to Work, gym partnerships, and electric vehicle leasing.

Interview process

  • The interview process generally includes a talent team call, first interview, technical interview, and final interview.

Apply for this job in 1 click

Skip the repetitive application forms

Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.

Sarah M.James T.Maya R.

Trusted by over 500,000 job seekers on Base Career

Start Free Today

More from this employer

More jobs at Starling