LOG IN
SIGN UP
Canary Wharfian - Online Investment Banking & Finance Community.
Sign In
or continue with e-mail and password
Forgot password?
Don't have an account?
Create an account
or continue with e-mail and password
By signing up, you agree to our Terms & Conditions and Privacy Policy.

Technical Specialist - Detection, Engineering and Automation

ExperiencedNo visa sponsorship
Fidelity Investments logo

at Fidelity Investments

Asset Management

Posted 2 days ago

No clicks

**Technical Specialist - Detection, Engineering and Automation**: Strengthen global cybersecurity with Fidelity International. Engineer and automate detections (Sentinel-as-Code, KQL), manage CI/CD pipelines, and optimize SIEM/SOAR/EDR tools. Requires 4+ years of detection engineering experience, strong scripting skills, and Microsoft Sentinel expertise. Level 4, reports to Senior Manager. Permanente role; deadline: 31 July 2026. Based in Kingswood, Surrey.

Compensation
Not specified

Currency: Not specified

City
Not specified
Country
United Kingdom

Full Job Description

About the Opportunity

Job Type: Permanent

Application Deadline: 31 July 2026

Job Description

Title Technical Specialist - Detection, Engineering and Automation

Department FIL Global Cybersecurity Operations

Location Kingswood, Surrey

Reports To Senior Manager - Detection, Engineering and Automation

Level 4

We share a commitment to making things better for clients and each other. We continually explore new technology and different ways of working to put our clients first. So bring your boldest ideas to our Cyber Defense Operations team and feel like youre making progress.

About your team

Technology function across FIL is responsible for all global aspects of Technology, Digital, Cybersecurity, and Innovation. Fidelity is a value-driven, customer-obsessed organization and in Technology we are fortunate to play a direct role in helping our clients with one of the most important aspects of their lives their financial well-being.

Within the Technology function is our Global Cyber & Information Security (GCIS) that operates enterprise security services and controls. These are designed to mitigate Cyber and Information Security risks ensuring that Fidelity's business operates securely. The Technical Cybersecurity teams monitor both the internal and external threat environment, responding to security alerts and events in close to real time, as well as providing security assurance and access management services across the enterprise technology and business environment. Our global innovative Cyber Defence Operations team sits within GCIS and provides proactive, cutting-edge solutions to protect clients digital assets and infrastructure against evolving cyber threats.

The Detection Engineering & Automation team within our Global Cybersecurity Operations focuses on the development of automated detection capabilities to reduce manual effort of the Global Cybersecurity Operations team freeing up time to focus on real cyber threats. They ensure that security controls are performing effectively and efficiently and that they are feeding into automation technologies allowing the organisation to make intelligent correlated decisions.

About your role
The Detection Engineering & Automation Specialist plays a critical handson role in strengthening the Global Cybersecurity Operations capability by building, maintaining and enhancing the security tooling that underpins our detection and response functions. The ideal candidate will work deeply across technologies including SIEM, SOAR, EDR, email security and cloud security platforms, contributing engineering expertise to ensure these controls operate effectively and deliver highquality telemetry.

You will be responsible for developing and improving detections, building CI/CD pipelines, onboarding new log sources, implementing automation and supporting technical investigations during security incidents. The ideal candidate has experience using a wide range of security technologies to enhance detection coverage, streamline analyst workflows and support the ongoing maintenance and optimisation of critical security controls. This role is essential in supporting engineering maturity and ensuring our cyber defence capabilities remain modern, integrated and responsive to evolving threats.

About you

Key Responsibilities

The Detection, Automation and Engineering Specialist will be responsible to:

  • Build, maintain and enhance security detections using SentinelasCode, ensuring accurate and highquality analytics.

  • Develop and maintain CI/CD pipelines to automate deployment of detections, automation playbooks and configuration updates.

  • Engineer and optimise SOAR automation and integrations to reduce manual analyst workload and streamline response processes.

  • Onboard highvalue security logs into the SIEM from the backlog, ensuring quality, normalisation and integration into detection logic.

  • Support SOC and CIRT during incidents by providing engineering expertise, rapid telemetry onboarding, and timely detection and automation enhancements.

  • Maintain and improve security controls across SIEM, SOAR, EDR, email security and network detection tooling.

  • Assess and implement tool updates, new features and product enhancements, ensuring their secure and effective adoption across the environment.

  • Manage toolingrelated incidents with vendors and internal teams, ensuring business impact is known, communicated and minimised.

  • Work with global engineering teams to deliver highpriority backlog items and operational improvements.

  • Collaborate with frontline analysts to identify quickwin improvements for detections, automation and tooling integrations.

  • Produce clear documentation, reporting and quality checks to support engineering delivery and continuous improvement.

Experience and Skills Required

  • At least 4 years of experience working in a Detection Engineering function, or a combination of Detection Engineering and hands on engineering responsibilities within a SOC environment.

  • Experience focusing on automation, engineering maturity and continuous improvement within security operations.

  • Experience managing and maintaining security tools within a global environment, preferably within Financial Services.

  • Hands on experience developing detections in Microsoft Sentinel, including strong KQL and detection as code practices.

  • Proven ability to build and maintain CI/CD pipelines (Azure DevOps, GitHub Actions) for detection, automation and configuration deployments.

  • Experience onboarding and operationalising new log sources into a SIEM, ensuring data quality, enrichment and alignment with detection logic.

  • Practical experience engineering SIEM, SOAR or EDR platforms and improving their operational effectiveness.

  • Experience supporting security incidents from an engineering perspective by enabling telemetry, building detections and enhancing automation under time pressure.

  • Strong experience with cloud platforms, particularly AWS and Azure, including their native security telemetry and integrations.

  • Experience with email security solutions (such as Proofpoint, Microsoft Defender for Office 365, or equivalent), with a solid understanding of how email telemetry can be used in detection engineering.

  • Strong scripting skills (PowerShell, Python, Bash or JavaScript) for automation, integration and tooling improvements.

  • Familiarity with YAML/JSON, IaC principles and modern automation frameworks.

  • Knowledge of Azure and/or AWS cloud environments and their native security telemetry.

  • Strong communication skills with the ability to take technical feedback from SOC/CIRT and translate it into meaningful engineering improvements.

  • Analytical mindset with a passion for cybersecurity, process improvement and challenging inefficient workflows.

Preferred Certifications:

Microsoft SC 200, AZ 500, AWS Security Specialty, CySA+, SSCP, OSCP.

Feel rewarded

For starters, well offer you a comprehensive benefits package. Well value your wellbeing and support your development. And well be as flexible as we can about where and when you work finding a balance that works for all of us. Its all part of our commitment to making you feel motivated by the work you do and happy to be part of our team. For more about our work, our approach to dynamic working and how you could build your future here, visit careers.fidelityinternational.com.

For more about our work, our approach to dynamic working and how you could build your future here, visit careers.fidelityinternational.com.

As an international financial services organisation, we are in-scope of international regulations in the way that we carry out our work. This position is involved in work that is regulated by the FCA and/or the PRA and their Individual Conduct Rules (COCON) apply to it, along with any other regulation. We provide training on COCON and how it affects our employees. More information about COCON can be found in the Employment Handbook.

Location: Kingswood Fields Office

Time Type: Full time

Technical Specialist - Detection, Engineering and Automation

Compensation

Not specified

City: Not specified

Country: United Kingdom

Fidelity Investments logo
Asset Management

2 days ago

No clicks

at Fidelity Investments

ExperiencedNo visa sponsorship

**Technical Specialist - Detection, Engineering and Automation**: Strengthen global cybersecurity with Fidelity International. Engineer and automate detections (Sentinel-as-Code, KQL), manage CI/CD pipelines, and optimize SIEM/SOAR/EDR tools. Requires 4+ years of detection engineering experience, strong scripting skills, and Microsoft Sentinel expertise. Level 4, reports to Senior Manager. Permanente role; deadline: 31 July 2026. Based in Kingswood, Surrey.

Full Job Description

About the Opportunity

Job Type: Permanent

Application Deadline: 31 July 2026

Job Description

Title Technical Specialist - Detection, Engineering and Automation

Department FIL Global Cybersecurity Operations

Location Kingswood, Surrey

Reports To Senior Manager - Detection, Engineering and Automation

Level 4

We share a commitment to making things better for clients and each other. We continually explore new technology and different ways of working to put our clients first. So bring your boldest ideas to our Cyber Defense Operations team and feel like youre making progress.

About your team

Technology function across FIL is responsible for all global aspects of Technology, Digital, Cybersecurity, and Innovation. Fidelity is a value-driven, customer-obsessed organization and in Technology we are fortunate to play a direct role in helping our clients with one of the most important aspects of their lives their financial well-being.

Within the Technology function is our Global Cyber & Information Security (GCIS) that operates enterprise security services and controls. These are designed to mitigate Cyber and Information Security risks ensuring that Fidelity's business operates securely. The Technical Cybersecurity teams monitor both the internal and external threat environment, responding to security alerts and events in close to real time, as well as providing security assurance and access management services across the enterprise technology and business environment. Our global innovative Cyber Defence Operations team sits within GCIS and provides proactive, cutting-edge solutions to protect clients digital assets and infrastructure against evolving cyber threats.

The Detection Engineering & Automation team within our Global Cybersecurity Operations focuses on the development of automated detection capabilities to reduce manual effort of the Global Cybersecurity Operations team freeing up time to focus on real cyber threats. They ensure that security controls are performing effectively and efficiently and that they are feeding into automation technologies allowing the organisation to make intelligent correlated decisions.

About your role
The Detection Engineering & Automation Specialist plays a critical handson role in strengthening the Global Cybersecurity Operations capability by building, maintaining and enhancing the security tooling that underpins our detection and response functions. The ideal candidate will work deeply across technologies including SIEM, SOAR, EDR, email security and cloud security platforms, contributing engineering expertise to ensure these controls operate effectively and deliver highquality telemetry.

You will be responsible for developing and improving detections, building CI/CD pipelines, onboarding new log sources, implementing automation and supporting technical investigations during security incidents. The ideal candidate has experience using a wide range of security technologies to enhance detection coverage, streamline analyst workflows and support the ongoing maintenance and optimisation of critical security controls. This role is essential in supporting engineering maturity and ensuring our cyber defence capabilities remain modern, integrated and responsive to evolving threats.

About you

Key Responsibilities

The Detection, Automation and Engineering Specialist will be responsible to:

  • Build, maintain and enhance security detections using SentinelasCode, ensuring accurate and highquality analytics.

  • Develop and maintain CI/CD pipelines to automate deployment of detections, automation playbooks and configuration updates.

  • Engineer and optimise SOAR automation and integrations to reduce manual analyst workload and streamline response processes.

  • Onboard highvalue security logs into the SIEM from the backlog, ensuring quality, normalisation and integration into detection logic.

  • Support SOC and CIRT during incidents by providing engineering expertise, rapid telemetry onboarding, and timely detection and automation enhancements.

  • Maintain and improve security controls across SIEM, SOAR, EDR, email security and network detection tooling.

  • Assess and implement tool updates, new features and product enhancements, ensuring their secure and effective adoption across the environment.

  • Manage toolingrelated incidents with vendors and internal teams, ensuring business impact is known, communicated and minimised.

  • Work with global engineering teams to deliver highpriority backlog items and operational improvements.

  • Collaborate with frontline analysts to identify quickwin improvements for detections, automation and tooling integrations.

  • Produce clear documentation, reporting and quality checks to support engineering delivery and continuous improvement.

Experience and Skills Required

  • At least 4 years of experience working in a Detection Engineering function, or a combination of Detection Engineering and hands on engineering responsibilities within a SOC environment.

  • Experience focusing on automation, engineering maturity and continuous improvement within security operations.

  • Experience managing and maintaining security tools within a global environment, preferably within Financial Services.

  • Hands on experience developing detections in Microsoft Sentinel, including strong KQL and detection as code practices.

  • Proven ability to build and maintain CI/CD pipelines (Azure DevOps, GitHub Actions) for detection, automation and configuration deployments.

  • Experience onboarding and operationalising new log sources into a SIEM, ensuring data quality, enrichment and alignment with detection logic.

  • Practical experience engineering SIEM, SOAR or EDR platforms and improving their operational effectiveness.

  • Experience supporting security incidents from an engineering perspective by enabling telemetry, building detections and enhancing automation under time pressure.

  • Strong experience with cloud platforms, particularly AWS and Azure, including their native security telemetry and integrations.

  • Experience with email security solutions (such as Proofpoint, Microsoft Defender for Office 365, or equivalent), with a solid understanding of how email telemetry can be used in detection engineering.

  • Strong scripting skills (PowerShell, Python, Bash or JavaScript) for automation, integration and tooling improvements.

  • Familiarity with YAML/JSON, IaC principles and modern automation frameworks.

  • Knowledge of Azure and/or AWS cloud environments and their native security telemetry.

  • Strong communication skills with the ability to take technical feedback from SOC/CIRT and translate it into meaningful engineering improvements.

  • Analytical mindset with a passion for cybersecurity, process improvement and challenging inefficient workflows.

Preferred Certifications:

Microsoft SC 200, AZ 500, AWS Security Specialty, CySA+, SSCP, OSCP.

Feel rewarded

For starters, well offer you a comprehensive benefits package. Well value your wellbeing and support your development. And well be as flexible as we can about where and when you work finding a balance that works for all of us. Its all part of our commitment to making you feel motivated by the work you do and happy to be part of our team. For more about our work, our approach to dynamic working and how you could build your future here, visit careers.fidelityinternational.com.

For more about our work, our approach to dynamic working and how you could build your future here, visit careers.fidelityinternational.com.

As an international financial services organisation, we are in-scope of international regulations in the way that we carry out our work. This position is involved in work that is regulated by the FCA and/or the PRA and their Individual Conduct Rules (COCON) apply to it, along with any other regulation. We provide training on COCON and how it affects our employees. More information about COCON can be found in the Employment Handbook.

Location: Kingswood Fields Office

Time Type: Full time