SlipstreamJobsFresh Startup & VC-Backed Jobs

Engineer, Threat Detection - 5

Tide - London, England, United Kingdom - In-office - posted 2026-08-05

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Tide is a fintech platform serving over 2 million SMEs globally with business banking and administrative solutions. The Security Engineering team comprises three core areas: Product Security, Identity, and Threat Detection & Response. This role sits within Threat Detection & Response, focusing on building a robust detection and automation platform to protect Tide's infrastructure and users. Key responsibilities include: - Supporting the development and implementation of strategic vision for threat detection, driving direction and priorities for a team of talented engineers - Working hands-on with SIEM systems (Splunk, Sentinel, or similar), including creating custom log parsers for in-house applications, configuring alert rules, performing log analysis, and tuning detections to reduce false positives - Creating security automations and services to automate routine tasks, from data enrichment to automatically removing phishing emails from employee mailboxes - Continuously hunting for sophisticated threats across infrastructure, leveraging threat intelligence and innovative detection techniques to stay ahead of attackers - Monitoring and responding to threats across AWS, GCP, internal applications, and employee endpoints (Windows, macOS) - Collaborating with cross-functional teams to develop and implement business-specific threat detection rules - Ensuring quality of detections and uptime of the detection ecosystem through test-driven development and proactive health monitoring - Identifying opportunities to build or enhance internal tools that streamline threat detection processes and improve response efficiency - Leading complex incident investigations, coordinating efforts across security, IT, and engineering teams for rapid containment and remediation - Participating in the wider security incident response on-call rotation Required qualifications: - Strong knowledge of SIEM platforms (Splunk, Sentinel, or similar) - Strong understanding of modern attack and defence techniques for Cloud (AWS, GCP), SaaS (Google Workspace, Okta), and desktop (Windows, macOS) environments - Passion for knowledge sharing with colleagues - Hands-on attitude and ability to drive solutions to completion - Strong experience in security automation, scripting, and SOAR platforms - Excellent spoken and written communication skills - Experience writing automation scripts and tools

Similar roles