SlipstreamJobsFresh Startup & VC-Backed Jobs

Engineer, Threat Detection - 5

Tide - Sofia, Bulgaria - In-office - posted 2026-07-23

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Tide is a fintech platform serving over 2 million SMEs globally with business banking and administrative solutions (invoicing, accounting, etc.). The company operates across the UK, India, Germany, and France with 2,800+ employees and has raised over $300 million. The Threat Detection & Response team is part of Tide's Security Engineering organization, which also includes Product Security and Identity teams. This role focuses on building and maintaining a robust detection and automation platform to protect Tide's infrastructure and customer data against evolving threats. Key responsibilities include: - Developing and executing the strategic vision for threat detection, guiding a team of talented engineers - Hands-on work with SIEM systems (Splunk, Sentinel, or similar), including custom log parsing, alert rule configuration, log analysis, and detection tuning - Building security automations and services to reduce manual work—from data enrichment to automated phishing email removal - Proactive threat hunting across AWS, GCP, internal applications, and employee endpoints (Windows, macOS) - Collaborating with cross-functional teams to develop business-specific threat detection rules - Ensuring detection quality and ecosystem uptime through test-driven development and health monitoring - Identifying opportunities to build or enhance internal tools for threat detection and response efficiency - Leading complex incident investigations and coordinating response across security, IT, and engineering teams - Participating in security incident response on-call rotation Required qualifications: - Strong expertise with SIEM platforms (Splunk, Sentinel, Sumo Logic, or similar) - Deep understanding of modern attack and defense techniques in cloud (AWS, GCP), SaaS (Google Workspace, Okta), and desktop (Windows, macOS) environments - Hands-on security automation experience: scripting, SOAR platforms, and end-to-end workflow automation - Passion for knowledge sharing and mentoring colleagues - Excellent communication skills (written and verbal) - Ability to drive solutions to completion independently The role is based in Sofia, Bulgaria, where Tide operates a technology center. The team emphasizes collaboration, with daily standups and shared communication channels across all security functions.

Similar roles