Refractal
Security Engineer (Detection & Response)
Requirements
Candidates need hands-on experience writing and tuning detection rules, using SIEM platforms such as Splunk or Datadog, and investigating security activity. They must understand analyst workflows, false positives, and telemetry gaps, and be able to communicate security needs to engineers through clear requirements and test cases.
Job Description
Location: London
Working arrangement: In office, five days a week
Employment type: Full-time
Salary: £60,000–£115,000 + equity
Refractal is an AI security company building the infrastructure organisations need to defend against autonomous AI threats. 2026 has shown that generally capable intelligence is here. The challenge now is modernising security to stop AI-enabled threats, whether they come from internal agents going rogue or from attackers using AI to become more dangerous.
Refractal was founded on cybersecurity and AI expertise from MIT, Microsoft, NASA and the U.S. Navy. Our product lets organisations detect AI-enabled threats at low cost without sacrificing detection quality. We take a practical approach to AI risk, combining proven cybersecurity methods with frontier AI security research.
Today, we work with governments and organisations that can't afford to get security wrong. We're backed by leading deep-tech and cybersecurity investors and are growing the team to deliver on this mission.
You'll bring hands-on detection and response experience into Refractal's product. Working with our software and research engineers, you'll draw on your experience writing detection rules, using SIEMs and investigating threats to shape what we build.
- Translate detection and investigation workflows into product requirements, helping engineers understand what security teams need and why.
- Use your experience with detection rules and SIEMs such as Splunk and Datadog to guide product design and integration priorities.
- Build realistic examples and test cases that capture attacker behaviour, benign activity and common sources of false positives.
- Evaluate product outputs for detection quality, useful context and the effort required for an analyst to reach a decision.
- Work with customers and colleagues to identify gaps, prioritise improvements and check that changes address practical security needs.
- You've translated important detection and response needs into clear product requirements and helped deliver improvements.
- You've built representative test cases that help the team assess detection quality and investigation usefulness.
- You've established a feedback loop that brings practitioner experience into engineering and research decisions.
Essential
- Hands-on experience writing and tuning detection rules, with examples of how you assessed whether they worked.
- Practical experience using SIEM platforms, including Splunk or Datadog, to query security data and investigate activity.
- Experience in detection and response, with a clear understanding of analyst workflows, false positives and gaps in security telemetry.
- The ability to explain security problems to software engineers and translate your experience into requirements and test cases.
- An interest in building products and a willingness to challenge assumptions using evidence from practical security work.
- Experience contributing to a security product or working closely with software and research engineers.
- Scripting skills for preparing data, prototyping ideas or creating repeatable security tests.
- An interest in how AI changes attacker behaviour and the security of autonomous agents.
Radical transparency. We believe the best work happens when everyone feels able to give and receive honest, constructive feedback.
Public service. We see AI security as a form of public service. Getting the AI transition right means putting the right infrastructure in place to manage the threats that come with it, and our work helps protect the institutions and services society depends on.
Fail fast. We test ideas early, seek feedback and learn quickly. We experiment rapidly and change course when something isn't working, without compromising on security.
Pragmatism, not dogmatism. We choose approaches based on how well they solve the problem. That means combining established cybersecurity methods with frontier AI research, questioning our assumptions, and changing our minds when the evidence changes.
- Salary: £60,000–£115,000
- Competitive equity to share in Refractal's growth
- Pension contribution
- Private medical and dental cover
- Visa and relocation support
Skills
About Refractal
AI agents can access sensitive data, use tools and act across enterprise systems, but security teams lack visibility and control. Refractal discovers AI activity, detects cross-layer attacks and enforces policy across models, tools, data and modalities.