Security Operations Detection, Tooling & Assurance Engineer
Indexed description
Security Operations Detection, Tooling & Assurance Engineer
Are you an experienced security professional with deep, hands-on expertise across security platforms, detection engineering, and security operations?
Do you want to play a key role in improving how threats are detected, investigated, and responded to across a complex healthcare environment? Are you passionate about enhancing security tooling, strengthening detection capabilities, improving operational processes, and ensuring security operations deliver measurable outcomes?
About the Team / Business Area
The Security Operations team sits at the core of our organisation, protecting nationally critical healthcare systems that support frontline patient care across the UK.
Operating within a highly regulated environment, the team is responsible for SOC oversight, vulnerability management, attack surface monitoring, and real-time threat detection across enterprise, cloud, identity, and network platforms.
This function plays a critical role in ensuring system resilience, maintaining regulatory compliance, and enabling the secure delivery of healthcare services at scale.
About the Role
As a Security Operations Detection, Tooling & Assurance Engineer, you will be responsible for the performance, optimisation, and continuous improvement of security tooling, detection capabilities, and security operations processes.
This is a hands-on engineering role focused on improving how threats are identified, investigated, and managed across the organisation. You will work to enhance detection quality, reduce false positives, improve investigative outcomes, and ensure security tooling is operating effectively and efficiently across all environments.
A key aspect of the role is providing operational assurance across Security Operations activities delivered by both internal teams and managed security service providers (MSSPs). You will review alerts, incidents, investigations, and SOC case activity to identify trends, control gaps, process improvements, and opportunities to strengthen detection and response capabilities.
Working closely with Cyber Defence analysts, Security Engineering teams, and external SOC providers, you will support the development of improved detections, response playbooks, automation capabilities, and investigation methodologies that enhance the organisation's overall security posture.
This role requires proven, hands-on, administrator-level experience across core security platforms including Darktrace, CrowdStrike, and Google SecOps. Candidates without this level of direct platform ownership and administration experience will not be suitable.
Key Responsibilities
- Own and optimise core security platforms including SIEM, EDR, NDR, SASE and related security technologies, ensuring effective performance, utilisation and governance.
- Design, build, maintain and tune detections to improve alert fidelity, visibility and threat identification capabilities.
- Review security alerts, incidents, investigations and SOC case activity to identify opportunities to improve detection logic, triage processes and operational effectiveness.
- Work closely with Cyber Defence analysts to improve security monitoring, investigation processes, response playbooks and detection content.
- Provide assurance and oversight of Security Operations activities delivered by managed SOC providers, supporting continuous improvement in investigation quality, service performance and operational outcomes.
- Engage with SOC partners and service providers to improve monitoring, detection, triage and incident response processes.
- Drive improvements in detection coverage through threat intelligence, incident learnings and recognised frameworks such as MITRE ATT&CK.
- Identify opportunities to rationalise tooling, improve efficiency and reduce operational overhead.
- Develop and implement automation to improve workflows and reduce manual effort across Security Operations.
- Produce reporting on detection effectiveness, coverage gaps, platform performance and SOC service outcomes.
- Define and maintain standards for detection engineering, security tooling and operational security monitoring activities.
What You Bring
You are a technically capable and operationally focused security professional with experience across security tooling, detection engineering and security operations.
You are comfortable analysing alerts, incidents and investigations to understand how security controls perform in practice, and you can translate those findings into meaningful improvements across tooling, detections, processes and operational outcomes.
You work effectively with technical teams, analysts and service providers, bringing a structured and analytical approach to problem solving, continuous improvement and operational excellence.
Key Skills, Experience & Qualifications
Essential
- Strong experience in Security Operations, Detection Engineering, Security Tooling or Cyber Defence roles.
- Hands-on administration and engineering experience across security platforms including SIEM, EDR, NDR or equivalent technologies.
- Hands-on, administrator-level experience with Darktrace, CrowdStrike and Google SecOps (minimum, non-negotiable requirement).
- Proven experience designing, building and tuning detections to improve alert quality and reduce false positives.
- Experience reviewing security alerts, investigations, incidents or SOC operations to identify and deliver operational improvements.
- Experience working closely with analysts, engineering teams or SOC providers to improve detection and response outcomes.
- Strong understanding of security monitoring, incident response and threat detection methodologies.
- Solid understanding of detection frameworks and methodologies such as MITRE ATT&CK.
Desirable
- Experience working with managed security service providers (MSSPs) or outsourced SOC functions.
- Experience in tooling optimisation, platform rationalisation or data and log reduction initiatives.
- Experience implementing automation within Security Operations environments.
- Experience developing operational metrics, assurance processes or service performance reporting.
- Relevant certifications such as CySA+, SC-200, GIAC or vendor-specific certifications.
Ready to Join Us?
At EMIS / Optum UK, we are a leader in healthcare technology, supporting professionals across primary care, community services, pharmacy and beyond.
This is an opportunity to take ownership of security tooling, detection capability and operational assurance within a complex, high-impact environment. You will play a key role in improving how threats are detected, investigated and responded to, helping protect systems that underpin patient care across the UK.
If you are looking for a role where you can influence security operations, improve detection capability and make a measurable impact, we would welcome your application
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search