AJ Bell logo

Security Monitoring & Detection Engineering Lead

Hiring from
United Kingdom
Work type
Hybrid
Posted
Sep 30, 2026
Is this job info correct?

Purpose

The Cyber Defence Operations function protects AJ Bell against external adversaries and internal risks through four specialist capabilities: Security Monitoring & Detection Engineering, Cyber Threat Intelligence, Cyber Threat Exposure Management and Insider Risk Management. Together, these capabilities combine detection, intelligence, exposure management and insider risk to safeguard AJ Bell’s customers, data, critical services and the trust placed in the firm.

Security Monitoring & Detection Engineering provides an integrated monitoring, detection and response capability, combining internal technical expertise with 24x7 support from the Managed Security Service Provider.

The Security Monitoring & Detection Engineering Lead is the principal technical authority for Security Monitoring & Detection Engineering capability, accountable for the effectiveness of security monitoring, detection engineering, technical investigation and incident response. This is a hands-on technical role responsible for the architecture, engineering and operational performance of Microsoft Sentinel and the wider security monitoring estate.

The role would particularly suit an experienced detection engineering, security operations, red-team, purple-team or offensive-security leader who can translate real-world adversary behaviour into effective monitoring, detection and response. The role leads complex investigations and technical incident response, ensures the internal team and MSSP operate as one capability, and drives measurable improvements that reduce the potential for customer, operational, financial and regulatory harm.

On-Call Requirement

This role participates in the Cyber Defence Operations on-call rota, providing senior technical leadership during significant out-of-hours security events and declared cyber incidents.

Key Responsibilities

  • Own the technical direction, quality and delivery performance of Security Monitoring & Detection Engineering, translating CDO priorities into a clear roadmap for monitoring, detection, investigation and response.
  • Lead the architecture, engineering and continued development of our SIEM solution, ensuring the SIEM remains resilient, scalable, cost-effective and aligned with AJ Bell’s technology estate and threat profile.
  • Define and govern the onboarding of security telemetry across on-premises, Microsoft Azure, AWS and third-party services, ensuring log sources address genuine visibility gaps and provide reliable value for detection and investigation.
  • Own the detection engineering lifecycle across requirements, design, testing, deployment, tuning, performance assessment and retirement, supported by version control, peer review and controlled release practices.
  • Lead the development of analytics rules, hunting queries, workbooks and automated investigation and response workflows.
  • Own the operational effectiveness of security solutions managed by CDO ensuring configurations, integrations, detections and workflows deliver measurable security outcomes.
  • Drive threat-informed defence with Cyber Threat Intelligence and Cyber Threat Exposure Management, translating relevant threat actors, campaigns, TTPs, IOCs, critical vulnerabilities and attack paths into detections, targeted threat hunts and automated defensive actions.
  • Maintain an evidence-based view of service performance through agreed KPIs, KRIs and operational MI, identifying material variations, recurring failure points and capacity constraints, and driving corrective actions through to a measurable outcome.
  • Act as the senior technical escalation point for complex, ambiguous and high-severity security events, leading investigations through scoping, attack reconstruction, business-impact assessment, containment and resolution.
  • Experience investigating malicious code, identity compromise, business email compromise, fraud-related intrusion, data exfiltration, cloud compromise or third-party intrusion.
  • Lead technical response within CIRT during declared cyber incidents, coordinating the internal team, MSSP and relevant technology functions in accordance with the firm’s incident-management processes to contain threats and reduce business impact.
  • Build and improve investigation and response playbooks for priority threat scenarios, and lead tabletop, purple-team and practical exercises that test detection coverage, technical readiness and coordination with relevant business functions.
  • Operate the internal team and MSSP as one integrated monitoring and response capability, setting clear expectations for investigation quality, escalation consistency and response effectiveness, and addressing service issues before they affect security outcomes.
  • Maintain an evidence-based view of alert demand, detection quality, MTTA, MTTR, investigation outcomes, service capacity and recurring failure points, using these measures to prioritise and demonstrate improvement.
  • Lead service reviews with key security vendors and providers, assessing delivery against expected outcomes and driving actions that maximise the contribution of existing investment to CDO’s Detect, Defend and Respond objectives.
  • Identify and deliver appropriate uses of automation and AI across detection engineering, enrichment, investigation and response, measuring the resulting improvement in quality, speed, consistency or coverage.
  • Develop Senior Analysts and junior team members through technical leadership, investigation review, practical training and structured knowledge transfer, creating credible succession within the function.
  • Report functional performance, incident readiness, monitoring coverage, material risks and capability constraints to the Head of Cyber Defence Operations, providing clear recommendations and action plans.

Skills & Experience

Essential

  • Extensive experience across security monitoring, SIEM engineering, detection engineering and incident response within a complex enterprise environment.
  • A strong record of designing, building, operating and evolving Microsoft Sentinel as a production security monitoring and response capability.
  • Deep expertise in KQL and the engineering of analytics rules, hunting queries, workbooks and threat-informed detection content.
  • Extensive experience designing telemetry architectures and onboarding security data, including connectors, parsing, normalisation, retention, ingestion health, data quality and cost management.
  • Experience integrating cloud-hosted services and security telemetry into central monitoring and leading investigations and incident-response activity across AWS, Azure environments.
  • Strong knowledge of Microsoft Defender XDR across endpoint, identity, email and cloud security, including the correlation of evidence across the Microsoft security ecosystem.
  • Experience designing and implementing automated investigation and response workflows using Azure Logic Apps, APIs, PowerShell, Python or comparable orchestration technologies.
  • Experience establishing and governing a production detection engineering lifecycle, including testing, peer review, version control, controlled deployment, performance monitoring and retirement.
  • Experience operating and materially improving enterprise security platforms such as Mimecast, Varonis, or comparable email and data-security technologies.
  • Experience translating adversary behaviour, threat intelligence, incident findings, exposure data and offensive-security results into improved detection and response capability.
  • Strong written and verbal communication, with the ability to translate complex threats, incidents and capability gaps into clear business implications, recommendations and decisions.

Preferred

  • Experience leading red-team, purple-team or offensive-security activity and converting identified attack paths and adversary techniques into improved detection and response.
  • Experience in financial services, or a regulated environment.

Qualifications

Relevant certifications or completed professional training may include:

  • Security Blue Team, Blue Team Level 2, BTL2
  • GIAC Certified Incident Handler, GCIH
  • GIAC Certified Intrusion Analyst, GCIA
  • CREST Registered Intrusion Analyst, CRIA
  • Certified Red Team Operator, CRTO
  • OffSec Certified Professional, OSCP
  • OffSec Wireless Professional, OSWP
  • EC-Council Certified Ethical Hacker, CEH

About AJ Bell

At AJ Bell, we believe investing should feel good. Whether you're looking for an ISA, pension or dealing account, whether you want to invest with the help of a financial adviser or do it yourself, we have easy-to-use solutions to suit people from all walks of life.

We're one of the UK's fastest-growing investment platform businesses, trusted by everyone from professional financial advisers to first-time investors.

Today, over 723,000 customers trust us to manage more than £108.7 billion of assets. By continually striving to make investing simpler and more accessible, we're helping more people take control of their financial futures.

We're proud to be recognised as one of the UK's Best 100 Companies to Work For for six consecutive years, and a Great Place to Work® in 2025 and 2026, a reflection of our supportive and collaborative culture.

What we offer

  • 27 days holiday, increasing with service + buy/sell scheme + bank holidays
  • 8% Pension with matched contributions
  • Discretionary bonus scheme
  • Share schemes (including free shares and BAYE)
  • Private healthcare and Dental plan
  • Healthcare Cash Plan
  • Enhanced family leave (subject to qualifying criteria)
  • Travel and bike loan schemes
  • Employee Assistance Programme

Life at AJ Bell

  • Regular social events including summer and Christmas parties
  • Learning and development opportunities tailored to you
  • Casual dress code
  • Friendly, supportive team environment

Our ways of working

At AJ Bell, our people are the heart of our culture. We believe in building strong connections by working together. That's why we offer a hybrid working model, where you'll spend a minimum of 50% of your working time from the office in either our Head office in Manchester or London Office. For new team members, the first 3 months will be spent full-time in the office to help you immerse yourself in our business and build valuable relationships with your colleagues.

Inclusion & diversity

We’re committed to creating an inclusive environment where everyone feels respected, supported and able to be themselves at work.

We welcome applications from all backgrounds and make hiring decisions based on skills, experience and potential.

Agency information

This vacancy is being managed exclusively by our in-house Recruitment team. We are not partnering with recruitment agencies on this opportunity and will only accept applications submitted directly by candidates.

Similar jobs

Apply for this job