Posted 02 August, 2026
Threat Detection Engineer (KQL, SPL, Python/PowerShell, Microsoft Security) - Permanent
Scope AT Limited
London, ENG, GB
Full Time
Job Description
\n
Threat Detection Engineer (KQL, SPL, Python/PowerShell, Microsoft Security) - Permanent
\nLocation: London
Job Type: Permanent
A leading global financial services organisation is looking for a Threat Detection Engineer to help transform its Security Operations capability.
\nYou'll be responsible for threat hunting, detection engineering, security automation and incident response, developing high-quality detections to protect a large enterprise environment.
\nKey Responsibilities
\n- \n
- Proactive threat hunting across multiple data sources. \n
- Build and optimise detections using KQL, SPL and SQL. \n
- Develop automated detection and response playbooks. \n
- Lead technical security investigations and incident response. \n
- Improve monitoring capabilities and security operations. \n
- Work closely with infrastructure and technology teams to strengthen cyber resilience. \n
Required Skills
\n- \n
- 3+ years in Threat Detection, Security Engineering or SOC. \n
- Strong threat hunting and detection engineering experience. \n
- Experience with KQL, SPL or SQL. \n
- Scripting with PowerShell and/or Python. \n
- Experience with OSINT and malicious email analysis. \n
- Knowledge of enterprise security technologies across endpoint, identity, network and cloud. \n
- Strong Microsoft infrastructure knowledge including Active Directory, Entra ID, Intune, Microsoft 365, Windows and Linux. \n
- Security certifications such as CISSP, OSCP, Security+, CEH, GCIA or GCIH are advantageous. \n
This is a fantastic opportunity to join a high-performing security team working with modern technologies in a fast-paced, enterprise environment.
