Detection Engineer - Security Exposure & Third-Party Cyber Assurance
Role Overview
We are looking for a Detection Engineer to support the build-out and operations of the Security Exposure and Third-Party Cyber Assurance Centre of Excellence, under Cybersecurity Assurance and Defense (CASD) - External Threat Operations.
The role will provide hands-on technical and operational support across two key areas:
- Security Exposure Management (SEM): Continuous, outside-in monitoring of the organisation and its portfolio companies internet-facing attack surface.
- Third-Party Cyber Assurance (TPCA): Cybersecurity due diligence and continuous assurance across third parties and the broader supply chain.
The successful candidate will operate continuous monitoring platforms, conduct third-party cyber assessments, validate active and emerging threats, and coordinate remediation to reduce the time between exposure identification and potential exploitation.
Key Responsibilities
- Operate and maintain always-on security exposure and external threat monitoring platforms.
- Monitor the organisation, portfolio companies, and third parties for internet-facing vulnerabilities, exposures, and emerging cyber threats.
- Perform Attack Surface Management (ASM/EASM) activities to identify, assess, validate, and prioritise external security exposures.
- Conduct third-party/vendor cybersecurity assessments, including security questionnaires and due diligence activities such as VDD, ODD, and SIG.
- Assess third-party security controls against established frameworks including NIST, ISO 27001, and CIS Controls.
- Leverage Cyber Threat Intelligence (CTI), digital risk, and dark-web monitoring to identify and validate relevant threats.
- Investigate and validate high-risk or imminent security threats and coordinate appropriate remediation with relevant stakeholders.
- Analyse third- and fourth-party cyber risks and their potential impact across the organisation and supply chain.
- Develop scripts and automation using Python, PowerShell, or Bash to streamline monitoring, analysis, reporting, and operational activities.
- Build and maintain operational dashboards, reporting capabilities, and cyber posture metrics using data lake platforms.
- Document findings, processes, assessments, and remediation actions clearly for both technical and business stakeholders.
- Support continuous improvement of detection logic, control baselines, monitoring processes, and exposure management capabilities.
Requirements
- Degree in Computer Science, Information Technology, or a related discipline.
- 3-5 years of hands-on cybersecurity experience, preferably within cybersecurity operations, attack surface/exposure management, third-party cyber risk assessment, or data lake environments.
- Practical experience conducting third-party/vendor security assessments and questionnaires, including VDD, ODD, and SIG.
- Good knowledge of cybersecurity frameworks such as NIST, ISO 27001, and CIS Controls.
- Hands-on experience with ASM/EASM, cyber exposure management, digital risk monitoring, dark-web monitoring, and/or Cyber Threat Intelligence (CTI) platforms.
- Strong scripting capabilities using Python, PowerShell, or Bash, particularly for automation and reporting.
- Strong understanding of TCP/IP, DNS, HTTP/S, and common security exposures across AWS, Azure, and GCP.
- Understanding of third- and fourth-party cyber risk and how security exposure can propagate through the supply chain.
- Strong analytical and documentation skills, with the ability to handle sensitive security findings appropriately.
- Good communication and stakeholder management skills across technical and business teams.
- Collaborative, adaptable, and comfortable working in a fast-evolving cybersecurity environment.
Good to Have
- Certifications such as Security+, CEH, GIAC (GSEC/GCIH), CompTIA CySA+, or equivalent.
- CISSP Associate or CISM candidature.
- Experience developing cyber posture scorecards and operational security dashboards.
- Familiarity with detection engineering, including tuning detection logic and refining security control baselines as capabilities mature.
SEM | TPCA | ASM/EASM | CTI | Third-Party Cyber Risk | VDD/ODD | SIG | NIST | ISO 27001 | CIS Controls | Digital Risk & Dark-Web Monitoring | Python | PowerShell | Bash | TCP/IP | DNS | HTTP/S | AWS | Azure | GCP | Data Lakes | Detection Engineering