
Job Description
Ovii's Interpretation of the Role
ElevenLabs seeks a Security Detection & Response Engineer to design, tune, and operate detection rules, lead incident investigations, and automate response workflows across cloud and SaaS environments.
Role Snapshot
- Build and maintain detection rules in Google Chronicle SIEM
- Lead triage and response for security alerts
- Automate detection and response with Python/Bash
- Monitor GCP workloads and SaaS services
- Apply MITRE ATT&CK and NIST frameworks
Must-Have Requirements
- Incident response
- Detection engineering
- Google Chronicle SIEM
- Python scripting
- Bash scripting
- JAMF MDM monitoring
- Google Workspace monitoring
- Okta monitoring
- GCP security monitoring
- Security Command Center
- MITRE ATT&CK framework
- NIST Cybersecurity Framework
- incident response
- detection engineering
- SIEM management
- cloud security monitoring
Work Setup
- Location: London, United Kingdom
- Work mode: HYBRID
- Employment type: Full-Time
Not Specified in JD
- Salary range
- Visa sponsorship
- Remote eligibility
- Education requirement
- Certifications
- Travel
- Coding test
- Portfolio
- GitHub
- Cover letter
What You'll Likely Work On
- Develop, tune, and maintain security detection rules and alerts in Google Chronicle
- Automate alert triage and response using Python or Bash scripts
- Integrate telemetry from macOS MDM, Google Workspace, Okta, and other SaaS tools into the SIEM
- Monitor Google Cloud workloads via Security Command Center and generate actionable alerts
- Investigate security incidents, perform root‑cause analysis, and lead remediation actions
- Translate threat‑intel and ATT&CK techniques into detection logic
- Create dashboards and parsers to visualize security data
- Collaborate with engineering teams to embed security controls and improve overall posture
Good Fit If You Have
- Passionate about security frameworks and continuous improvement
- Enjoys rapid experimentation and automation
- Thrives in a high‑velocity, impact‑focused environment
- Strong analytical and problem‑solving abilities
Skills
- Google Chronicle SIEM
- Python & Bash scripting
- JAMF MDM, Google Workspace, Okta monitoring
- GCP security & Security Command Center
- Detection engineering
- Incident response
- Threat intelligence frameworks (MITRE ATT&CK, NIST)