SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Tide is a fintech platform serving over 2 million SMEs globally with business banking and administrative solutions (invoicing, accounting, etc.). The company operates across the UK, India, Germany, and France with 2,800+ employees and has raised over $300 million.
The Threat Detection & Response team is part of Tide's Security Engineering organization, which also includes Product Security and Identity teams. This role focuses on building and maintaining a robust detection and automation platform to protect Tide's infrastructure and customer data against evolving threats.
Key responsibilities include:
- Developing and executing the strategic vision for threat detection, guiding a team of talented engineers
- Hands-on work with SIEM systems (Splunk, Sentinel, or similar), including custom log parsing, alert rule configuration, log analysis, and detection tuning
- Building security automations and services to reduce manual work—from data enrichment to automated phishing email removal
- Proactive threat hunting across AWS, GCP, internal applications, and employee endpoints (Windows, macOS)
- Collaborating with cross-functional teams to develop business-specific threat detection rules
- Ensuring detection quality and ecosystem uptime through test-driven development and health monitoring
- Identifying opportunities to build or enhance internal tools for threat detection and response efficiency
- Leading complex incident investigations and coordinating response across security, IT, and engineering teams
- Participating in security incident response on-call rotation
Required qualifications:
- Strong expertise with SIEM platforms (Splunk, Sentinel, Sumo Logic, or similar)
- Deep understanding of modern attack and defense techniques in cloud (AWS, GCP), SaaS (Google Workspace, Okta), and desktop (Windows, macOS) environments
- Hands-on security automation experience: scripting, SOAR platforms, and end-to-end workflow automation
- Passion for knowledge sharing and mentoring colleagues
- Excellent communication skills (written and verbal)
- Ability to drive solutions to completion independently
The role is based in Sofia, Bulgaria, where Tide operates a technology center. The team emphasizes collaboration, with daily standups and shared communication channels across all security functions.