SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Tide is a fintech platform serving over 2 million SMEs globally with business banking and administrative solutions. The Security Engineering team comprises three core areas: Product Security, Identity, and Threat Detection & Response. This role focuses on the Threat Detection & Response function, building a robust detection and automation platform to protect Tide's infrastructure and users.
Key responsibilities include:
- Supporting the development and implementation of strategic vision for threat detection, driving direction and priorities for a team of talented engineers
- Working hands-on with SIEM systems (Splunk, Sentinel, or similar), creating custom log-parsers for in-house applications, configuring alert rules, performing log analysis, and tuning detections to reduce false positives
- Creating security automations and services to automate routine tasks, from data enrichment to automatically removing phishing emails
- Continuously hunting for sophisticated threats across infrastructure, leveraging threat intelligence and innovative detection techniques to stay ahead of attackers
- Monitoring and responding to threats across AWS, GCP, internal applications, and employee endpoints (Windows, macOS)
- Collaborating with cross-functional teams to develop and implement business-specific threat detection rules
- Ensuring quality of detections and uptime of the detection ecosystem through test-driven development and proactive health monitoring
- Identifying opportunities to build or enhance internal tools that streamline threat detection processes and improve response efficiency
- Leading complex incident investigations, coordinating efforts across security, IT, and engineering teams
- Participating in the wider security incident response on-call rotation
Required qualifications:
- Strong knowledge of SIEM platforms (Splunk, Sentinel, or similar) or SecOps tools
- Strong understanding of modern attack and defense techniques applicable to Cloud (AWS, GCP), SaaS (Google Workspace, Okta), and desktop (Windows, macOS) environments
- Passion for knowledge sharing with colleagues
- Hands-on attitude with ability to drive solutions to completion
- Strong experience in security automation, scripting, and ideally SOAR platforms
- Excellent spoken and written communication skills
- Experience writing automation scripts and tools