Sourcing as a channel, not a feature.

Security Detection & Tooling Lead

Remote
Any
Actively hiring

Security Detection & Tooling Lead

Optum
Remote
Any
Optum
Actively hiring

hackajob is partnering with Optum to fill this position. Create a profile to be automatically considered for this role—and others that match your experience.

 

Security Detection & Tooling Lead

Are you an experienced security professional with deep, hands-on expertise across security platforms and detection engineering?

Do you want to take ownership of how security tooling performs at scale — improving detection quality, reducing noise, and ensuring threats are effectively identified across complex environments?

 

About the Team / Business Area

The Security Operations team sits at the core of our organisation, protecting nationally critical healthcare systems that support frontline patient care across the UK.

Operating within a highly regulated environment, the team is responsible for SOC oversight, vulnerability management, attack surface monitoring, and real-time threat detection across enterprise, cloud, and network platforms.

This function plays a critical role in ensuring system resilience, maintaining regulatory compliance, and enabling the secure delivery of healthcare services at scale.

 

About the Role

As the Security Detection & Tooling Lead, you will take ownership of the performance, optimisation, and governance of key security platforms and detection capabilities.

This is a senior, hands-on engineering role focused on improving how threats are detected across the organisation. You will drive improvements in detection quality, reduce false positives, and ensure security tooling is used effectively and efficiently across all environments.

This role requires proven, hands-on, administrator-level experience across core security platforms (including Darktrace, CrowdStrike, and Google SecOps). Candidates without this level of direct platform ownership and administration experience will not be suitable.

Working closely with SOC, Security Engineering, and wider technology teams, you will define detection standards, influence tooling strategy, and ensure security controls remain aligned to risk.

 

 

 

Key Responsibilities

  • Own and optimise core security platforms (SIEM, EDR, NDR, SASE), ensuring performance, utilisation, and governance
  • Design, build, and tune detection logic to improve alert fidelity and reduce noise
  • Drive improvements in detection coverage using frameworks such as MITRE ATT&CK
  • Partner with SOC teams to enhance incident detection, triage, and response outcomes
  • Identify opportunities to rationalise tooling, improve efficiency, and reduce operational overhead
  • Develop and implement automation to improve workflows and reduce manual effort
  • Produce reporting on detection performance, coverage gaps, and platform effectiveness
  • Define and maintain detection and tooling standards across Security Operations

 

What You Bring

You are a hands-on, technically strong security professional with experience operating and optimising security tooling at scale. You take ownership of platforms and outcomes, focusing on delivering measurable improvements in detection capability and operational efficiency.

You are comfortable working across teams, influencing change, and applying a structured, analytical approach to improving security operations.

 

Key Skills, Experience & Qualifications

Essential

  • Strong experience in Security Operations, Detection Engineering, or Security Tooling roles
  • Hands-on administration and engineering experience across security platforms (SIEM, EDR, NDR or equivalent)
  • Hands-on, administrator-level experience with Darktrace, CrowdStrike, and Google SecOps (minimum, non-negotiable requirement)
  • Proven experience designing, building, and tuning detections to improve alert quality and reduce false positives
  • Experience working closely with SOC teams to improve detection and response outcomes
  • Solid understanding of detection frameworks and methodologies (e.g. MITRE ATT&CK)

 

Ready to Join Us?

At EMIS / Optum UK, we are a leader in healthcare technology, supporting professionals across primary care, community services, pharmacy, and beyond.

This is an opportunity to take ownership of detection and tooling capability within a complex, high-impact environment — directly contributing to the protection of systems that underpin patient care across the UK.

If you are looking for a role where you can lead, optimise, and make a measurable impact, we would welcome your application.

 

hackajob is partnering with Optum to fill this position. Create a profile to be automatically considered for this role—and others that match your experience.

 

Upskill

Level up the hackajob way. Verify your skills, learn brand new ones and test your ability with Pathways, our learning and development platform.

Ready to reach your potential?