Skip to main content
Posted 02 August, 2026

Threat Detection Engineer (KQL, SPL, Python/PowerShell, Microsoft Security) - Permanent

Scope AT Limited
London, ENG, GB Full Time

Job Description

\n

Threat Detection Engineer (KQL, SPL, Python/PowerShell, Microsoft Security) - Permanent

\n

Location: London
Job Type: Permanent

\n

A leading global financial services organisation is looking for a Threat Detection Engineer to help transform its Security Operations capability.

\n

You'll be responsible for threat hunting, detection engineering, security automation and incident response, developing high-quality detections to protect a large enterprise environment.

\n

Key Responsibilities

\n
    \n
  • Proactive threat hunting across multiple data sources.
  • \n
  • Build and optimise detections using KQL, SPL and SQL.
  • \n
  • Develop automated detection and response playbooks.
  • \n
  • Lead technical security investigations and incident response.
  • \n
  • Improve monitoring capabilities and security operations.
  • \n
  • Work closely with infrastructure and technology teams to strengthen cyber resilience.
  • \n
\n

Required Skills

\n
    \n
  • 3+ years in Threat Detection, Security Engineering or SOC.
  • \n
  • Strong threat hunting and detection engineering experience.
  • \n
  • Experience with KQL, SPL or SQL.
  • \n
  • Scripting with PowerShell and/or Python.
  • \n
  • Experience with OSINT and malicious email analysis.
  • \n
  • Knowledge of enterprise security technologies across endpoint, identity, network and cloud.
  • \n
  • Strong Microsoft infrastructure knowledge including Active Directory, Entra ID, Intune, Microsoft 365, Windows and Linux.
  • \n
  • Security certifications such as CISSP, OSCP, Security+, CEH, GCIA or GCIH are advantageous.
  • \n
\n

This is a fantastic opportunity to join a high-performing security team working with modern technologies in a fast-paced, enterprise environment.