Back to jobs
Refractal

Refractal

Security Engineer (Detection & Response)

London On-site 2-5 yrs exp Software Development 9 employees£60k – £115k / year
Detection Rule Writing and TuningSIEM PlatformsSplunkDatadogSecurity Data Querying

Requirements

Candidates need hands-on experience writing and tuning detection rules, using SIEM platforms such as Splunk or Datadog, and investigating security activity. They must understand analyst workflows, false positives, and telemetry gaps, and be able to communicate security needs to engineers through clear requirements and test cases.

Job Description

Security Engineer (Detection & Response)

Location: London

Working arrangement: In office, five days a week

Employment type: Full-time

Salary: £60,000–£115,000 + equity


About Refractal


Refractal is an AI security company building the infrastructure organisations need to defend against autonomous AI threats. 2026 has shown that generally capable intelligence is here. The challenge now is modernising security to stop AI-enabled threats, whether they come from internal agents going rogue or from attackers using AI to become more dangerous.


Refractal was founded on cybersecurity and AI expertise from MIT, Microsoft, NASA and the U.S. Navy. Our product lets organisations detect AI-enabled threats at low cost without sacrificing detection quality. We take a practical approach to AI risk, combining proven cybersecurity methods with frontier AI security research.


Today, we work with governments and organisations that can't afford to get security wrong. We're backed by leading deep-tech and cybersecurity investors and are growing the team to deliver on this mission.


The role

You'll bring hands-on detection and response experience into Refractal's product. Working with our software and research engineers, you'll draw on your experience writing detection rules, using SIEMs and investigating threats to shape what we build.


What you'll do
  • Translate detection and investigation workflows into product requirements, helping engineers understand what security teams need and why.
  • Use your experience with detection rules and SIEMs such as Splunk and Datadog to guide product design and integration priorities.
  • Build realistic examples and test cases that capture attacker behaviour, benign activity and common sources of false positives.
  • Evaluate product outputs for detection quality, useful context and the effort required for an analyst to reach a decision.
  • Work with customers and colleagues to identify gaps, prioritise improvements and check that changes address practical security needs.


Success in your first six months
  • You've translated important detection and response needs into clear product requirements and helped deliver improvements.
  • You've built representative test cases that help the team assess detection quality and investigation usefulness.
  • You've established a feedback loop that brings practitioner experience into engineering and research decisions.


About you
Essential


  • Hands-on experience writing and tuning detection rules, with examples of how you assessed whether they worked.
  • Practical experience using SIEM platforms, including Splunk or Datadog, to query security data and investigate activity.
  • Experience in detection and response, with a clear understanding of analyst workflows, false positives and gaps in security telemetry.
  • The ability to explain security problems to software engineers and translate your experience into requirements and test cases.
  • An interest in building products and a willingness to challenge assumptions using evidence from practical security work.


Nice to have
  • Experience contributing to a security product or working closely with software and research engineers.
  • Scripting skills for preparing data, prototyping ideas or creating repeatable security tests.
  • An interest in how AI changes attacker behaviour and the security of autonomous agents.


Our values

Radical transparency. We believe the best work happens when everyone feels able to give and receive honest, constructive feedback.

Public service. We see AI security as a form of public service. Getting the AI transition right means putting the right infrastructure in place to manage the threats that come with it, and our work helps protect the institutions and services society depends on.

Fail fast. We test ideas early, seek feedback and learn quickly. We experiment rapidly and change course when something isn't working, without compromising on security.

Pragmatism, not dogmatism. We choose approaches based on how well they solve the problem. That means combining established cybersecurity methods with frontier AI research, questioning our assumptions, and changing our minds when the evidence changes.


Compensation and benefits


  • Salary: £60,000–£115,000
  • Competitive equity to share in Refractal's growth
  • Pension contribution
  • Private medical and dental cover
  • Visa and relocation support


Skills

Detection Rule Writing and TuningSIEM PlatformsSplunkDatadogSecurity Data QueryingThreat InvestigationDetection and ResponseAnalyst WorkflowsFalse Positive AnalysisSecurity TelemetryProduct RequirementsTest Case DevelopmentDetection Quality EvaluationCustomer CollaborationScriptingAI Security

About Refractal

AI agents can access sensitive data, use tools and act across enterprise systems, but security teams lack visibility and control. Refractal discovers AI activity, detects cross-layer attacks and enforces policy across models, tools, data and modalities.