CloudBees

CloudBees

London

Security Operations Engineer

Full-Time£65,000 - 105,000 per yearपरसोंUnited Kingdom
IT

Job Description

Salary: £65,000 - 105,000 per year

Requirements:
  • 3+ years of experience in Security Operations, Detection Engineering, or Security Engineering.
  • Hands-on experience with enterprise SIEM platforms such as Splunk, Microsoft Sentinel, Elastic, Chronicle, or QRadar.
  • Experience building and tuning detection rules.
  • Experience developing SOAR playbooks or security automation.
  • Strong scripting skills using Python, PowerShell, or similar languages.
  • Experience working within cloud environments; AWS is preferred, and Azure or GCP experience is also valued.
  • Solid understanding of the MITRE ATT&CK framework.
  • Experience supporting security incident response.
  • Comfortable working with Git, APIs, and engineering workflows.
  • Excellent communication skills with both Security and Engineering teams.
  • Preferred experience with Detection Engineering methodologies.
  • Preferred experience with AI-assisted detection or security automation.
  • Familiarity with Sigma, Atomic Red Team, or detection testing frameworks.
  • Experience with Infrastructure as Code such as Terraform, CloudFormation, or ARM.
  • Kubernetes or container security experience.
  • Experience working within SaaS, DevOps, or software delivery organizations.
  • Relevant certifications including GCIH, GCIA, GCDA, GCED, or AWS Security Specialty.
Responsibilities:
  • Design, build, and continuously improve detection rules across cloud, endpoint, SaaS, and application environments.
  • Own the full detection lifecycle from hypothesis through deployment and continuous tuning.
  • Create high-fidelity detections using operational threat intelligence, incident learnings, and purple team findings.
  • Measure and improve detection coverage using the MITRE ATT&CK framework.
  • Continuously reduce false positives while improving visibility into emerging attacker techniques.
  • Design and maintain SOAR playbooks that automate alert triage, enrichment, containment, and response.
  • Identify repetitive analyst workflows and automate them using APIs, scripting, and orchestration platforms.
  • Build integrations across SIEM, EDR, CNAPP, vulnerability management, and ticketing systems.
  • Help introduce AI-assisted workflows that improve investigation quality and analyst productivity.
  • Monitor and investigate security events across corporate and production environments.
  • Participate in weekend on-call support for Security Operations.
  • Lead or support incident response activities including investigation, containment, recovery, and lessons learned.
  • Perform proactive threat hunting using telemetry across multiple security platforms.
  • Improve operational playbooks and incident response processes.
  • Partner with Product and Platform Engineering teams to improve security telemetry and logging.
  • Help define security observability requirements for new services.
  • Collaborate with developers to improve security visibility across our platform.
  • Translate operational findings into practical engineering improvements.
  • Contribute to vulnerability assessment and management processes, prioritizing findings based on threat context and exploitability.
  • Consume and operationalize threat intelligence feeds, translating indicators and TTPs into detection logic and hunting hypotheses.
  • Participate in red team and purple team exercises, using findings to validate and improve the detection stack.
Technologies:
  • AI
  • ARM
  • AWS
  • Azure
  • Cloud
  • DevOps
  • GCP
  • Git
  • Support
  • Kubernetes
  • Matrix
  • PowerShell
  • Python
  • Security
  • Splunk
  • Terraform
  • Jenkins

More:

We are CloudBees, a leading software delivery platform for enterprises that helps organizations continuously innovate, compete, and deliver scalable, compliant, governed, and secure software. We were founded in 2010 and are backed by Goldman Sachs, Morgan Stanley, Bridgepoint Credit, HSBC, Golub Capital, Delta-v Capital, Matrix Partners, and Lightspeed Venture Partners. We are growing our Global Security team for a Security Operations Engineer role based in London, GBR, with a UK hybrid work setup. This is a mid/senior-level opportunity for engineers who want to build security capabilities through detection engineering, automation, threat hunting, incident response, and close collaboration with Product and Platform Engineering. We offer a highly competitive benefits and vacation package, team outings, a fun, hardworking, and casual environment, and endless growth opportunities. We are committed to diversity and believe it strengthens our products, our customers, and our global community.

last updated 34 week of 2026

Interested in this role?

Submit your application now

How to Apply

Ready to apply for this position? Here's what you need:

  • An updated resume highlighting relevant experience
  • A compelling cover letter (if required)
  • Portfolio or work samples (for relevant positions)

About CloudBees

CloudBees

CloudBees

London

IT

Skills & Technologies

PythonGoScalaAWSAzureGCPKubernetesTerraformGitJenkinsAIDevOps

Inferred from job description

Salary Insight

£85,000

This role

£60,000

UK median

This salary is 42% above the UK median for Software Engineers60,000/yr).

Based on 2024–2025 UK technology sector benchmarks

Explore More UK Opportunities

Thousands of tech jobs across the United Kingdom