Cyber Security Operations Specialist We are looking for an experienced Cyber Security Operations Specialist to join a growing security team responsible for protecting a complex IT, cloud and operational technology environment. You will play a key role in detecting, investigating and responding to cyber threats, while helping to improve the organisation's overall security monitoring and incident response capabilities. The role combines hands-on security operations, tooling optimisation and continuous improvement across a varied technology estate. Key responsibilities: Monitor, triage and investigate security alerts and incidents across IT, cloud and OT environments. Lead or support incident response, including containment, eradication, recovery and escalation. Develop and optimise SIEM detection rules, EDR policies and security monitoring capabilities. Reduce false positives and improve detection coverage using threat intelligence and incident learnings. Investigate threats using frameworks such as MITRE ATT&CK. Work closely with internal IT, engineering and security teams, alongside external security providers. Maintain and improve security playbooks, procedures, documentation and response processes. Support security reporting, compliance and audit activity. Provide technical guidance and support to junior members of the security team. Key skills and experience: Strong background in Security Operations, SOC or Incident Response. Hands-on experience with SIEM and EDR platforms , ideally including Microsoft security technologies. Experience investigating security incidents across cloud and on-premise environments . Knowledge of Windows environments, with working knowledge of Linux/Unix. Understanding of threat intelligence, IOCs, TTPs and the MITRE ATT&CK framework . Experience improving detection logic, alert quality and security controls. Strong stakeholder communication and incident management skills. Knowledge of frameworks such as ISO 27001, NIS and GDPR would be beneficial. Desirable certifications include: SC-200, SC-300, SC-400, MS-500, Security+ or similar cyber security qualifications. The role will involve participation in an out-of-hours incident response rota , with occasional travel where required.
Aug 22, 2026
Contractor
Cyber Security Operations Specialist We are looking for an experienced Cyber Security Operations Specialist to join a growing security team responsible for protecting a complex IT, cloud and operational technology environment. You will play a key role in detecting, investigating and responding to cyber threats, while helping to improve the organisation's overall security monitoring and incident response capabilities. The role combines hands-on security operations, tooling optimisation and continuous improvement across a varied technology estate. Key responsibilities: Monitor, triage and investigate security alerts and incidents across IT, cloud and OT environments. Lead or support incident response, including containment, eradication, recovery and escalation. Develop and optimise SIEM detection rules, EDR policies and security monitoring capabilities. Reduce false positives and improve detection coverage using threat intelligence and incident learnings. Investigate threats using frameworks such as MITRE ATT&CK. Work closely with internal IT, engineering and security teams, alongside external security providers. Maintain and improve security playbooks, procedures, documentation and response processes. Support security reporting, compliance and audit activity. Provide technical guidance and support to junior members of the security team. Key skills and experience: Strong background in Security Operations, SOC or Incident Response. Hands-on experience with SIEM and EDR platforms , ideally including Microsoft security technologies. Experience investigating security incidents across cloud and on-premise environments . Knowledge of Windows environments, with working knowledge of Linux/Unix. Understanding of threat intelligence, IOCs, TTPs and the MITRE ATT&CK framework . Experience improving detection logic, alert quality and security controls. Strong stakeholder communication and incident management skills. Knowledge of frameworks such as ISO 27001, NIS and GDPR would be beneficial. Desirable certifications include: SC-200, SC-300, SC-400, MS-500, Security+ or similar cyber security qualifications. The role will involve participation in an out-of-hours incident response rota , with occasional travel where required.
3rd Line Support Engineer Location: Worcester, Worcestershire Salary: £45,000-£50,000 DOE Benefits: 25 days' holiday + bank holidays, funded certifications, pension, volunteering days, free parking and career progression Our client, a growing UK technology and managed services organisation, is looking for an experienced 3rd Line Engineer to join its technical team in Worcester. This is a great opportunity for someone who enjoys getting stuck into complex technical challenges, working across modern Microsoft technologies and taking real ownership of issues through to resolution. You'll act as a senior technical escalation point, supporting a varied customer base across Microsoft 365, Azure, networking, infrastructure and cyber security, while also getting involved in migrations, projects and service improvements. What you'll do Take ownership of complex 3rd line incidents and technical escalations through to resolution Troubleshoot Microsoft 365, Azure, Windows Server, networking and infrastructure issues Support and administer Microsoft 365 environments across multiple customers Contribute to cloud migrations, infrastructure upgrades and wider technical projects Support major incidents and help restore services quickly and effectively Mentor 1st and 2nd Line Engineers and share technical knowledge across the team Identify opportunities to improve reliability, automation, documentation and service delivery Work with customers, internal technical teams and third-party suppliers to resolve issues Carry out occasional customer-site visits for installations, projects and technical support You'll work closely with Helpdesk, Field and Project Engineers alongside technical management, giving you the opportunity to influence both day-to-day support and the wider technical service. What we're looking for You'll ideally have proven experience working at 3rd Line level within an MSP environment, with strong technical knowledge across: Microsoft 365: Exchange Online, Intune, Entra ID, Teams, SharePoint, OneDrive and Defender Azure: Azure administration, Virtual Machines, Azure Virtual Desktop, Backup and Storage Infrastructure: Windows Server, Active Directory, Group Policy and virtualisation Networking: TCP/IP, DNS, DHCP, VLANs, VPNs, firewalls, switching and routing Security: Endpoint protection, Microsoft security technologies, email security, backup and disaster recovery Experience delivering Microsoft 365 migrations and infrastructure projects Experience with PowerShell, 3CX/VoIP, Linux, AWS or relevant Microsoft/CompTIA certifications would be advantageous, but isn't essential. You'll also need strong problem-solving and communication skills, with the confidence to take ownership of difficult technical issues and work effectively during major incidents. A full UK driving licence and access to your own vehicle are required due to occasional customer visits. Why join? £45,000-£50,000 salary, depending on experience Company-funded Microsoft and industry certifications Clear opportunities for technical development and career progression 25 days' holiday plus bank holidays Two additional paid charity volunteering days each year Pension scheme Free on-site parking Exposure to a broad range of customers, technologies and technical environments Hands-on involvement in challenging infrastructure and cloud projects Supportive technical team where you can contribute ideas and influence improvements This is an opportunity to become a key senior technical resource within a growing technology business, rather than simply working through support tickets. Apply now if you're an experienced 3rd Line Engineer looking for more ownership, technical variety and the opportunity to develop your career within a modern MSP environment.
Aug 21, 2026
Full time
3rd Line Support Engineer Location: Worcester, Worcestershire Salary: £45,000-£50,000 DOE Benefits: 25 days' holiday + bank holidays, funded certifications, pension, volunteering days, free parking and career progression Our client, a growing UK technology and managed services organisation, is looking for an experienced 3rd Line Engineer to join its technical team in Worcester. This is a great opportunity for someone who enjoys getting stuck into complex technical challenges, working across modern Microsoft technologies and taking real ownership of issues through to resolution. You'll act as a senior technical escalation point, supporting a varied customer base across Microsoft 365, Azure, networking, infrastructure and cyber security, while also getting involved in migrations, projects and service improvements. What you'll do Take ownership of complex 3rd line incidents and technical escalations through to resolution Troubleshoot Microsoft 365, Azure, Windows Server, networking and infrastructure issues Support and administer Microsoft 365 environments across multiple customers Contribute to cloud migrations, infrastructure upgrades and wider technical projects Support major incidents and help restore services quickly and effectively Mentor 1st and 2nd Line Engineers and share technical knowledge across the team Identify opportunities to improve reliability, automation, documentation and service delivery Work with customers, internal technical teams and third-party suppliers to resolve issues Carry out occasional customer-site visits for installations, projects and technical support You'll work closely with Helpdesk, Field and Project Engineers alongside technical management, giving you the opportunity to influence both day-to-day support and the wider technical service. What we're looking for You'll ideally have proven experience working at 3rd Line level within an MSP environment, with strong technical knowledge across: Microsoft 365: Exchange Online, Intune, Entra ID, Teams, SharePoint, OneDrive and Defender Azure: Azure administration, Virtual Machines, Azure Virtual Desktop, Backup and Storage Infrastructure: Windows Server, Active Directory, Group Policy and virtualisation Networking: TCP/IP, DNS, DHCP, VLANs, VPNs, firewalls, switching and routing Security: Endpoint protection, Microsoft security technologies, email security, backup and disaster recovery Experience delivering Microsoft 365 migrations and infrastructure projects Experience with PowerShell, 3CX/VoIP, Linux, AWS or relevant Microsoft/CompTIA certifications would be advantageous, but isn't essential. You'll also need strong problem-solving and communication skills, with the confidence to take ownership of difficult technical issues and work effectively during major incidents. A full UK driving licence and access to your own vehicle are required due to occasional customer visits. Why join? £45,000-£50,000 salary, depending on experience Company-funded Microsoft and industry certifications Clear opportunities for technical development and career progression 25 days' holiday plus bank holidays Two additional paid charity volunteering days each year Pension scheme Free on-site parking Exposure to a broad range of customers, technologies and technical environments Hands-on involvement in challenging infrastructure and cloud projects Supportive technical team where you can contribute ideas and influence improvements This is an opportunity to become a key senior technical resource within a growing technology business, rather than simply working through support tickets. Apply now if you're an experienced 3rd Line Engineer looking for more ownership, technical variety and the opportunity to develop your career within a modern MSP environment.
SOC Engineer Milton Keynes - Hybrid working SC Clearance Sponsorship Available £50,000 - £55,000 + Bonus We're seeking a hands-on SOC Engineer to join a growing Cyber Security Operations Centre supporting a diverse portfolio of customers across multiple sectors This is a specialist SOC Engineering position focused on building, maintaining, and optimising the tools, telemetry, detections, and automation that enable SOC Analysts to identify and respond to threats effectively. This is not a generalist cyber security role. Key Responsibilities Administer and optimise Microsoft Sentinel (or equivalent SIEM), including log ingestion, parsing, normalisation, and retention. Develop and maintain SOAR workflows and automation using Azure Logic Apps, Python, PowerShell, Bash, and KQL. Onboard and manage security telemetry from a range of data sources. Design, implement, and tune detection rules to improve alert quality and reduce false positives. Conduct proactive threat hunting using SIEM, EDR, and threat intelligence sources. Support incident investigations, containment, and response activities. Monitor and maintain the health of SOC tooling, sensors, agents, and log pipelines. Produce documentation, runbooks, and operational procedures. Skills & Experience Experience engineering and supporting SIEM platforms, ideally Microsoft Sentinel. Strong scripting and automation skills (Python, PowerShell, Bash, KQL). Experience with SOAR technologies and security automation. Knowledge of detection engineering and threat hunting. Strong understanding of Windows and Linux logging. Good networking knowledge including TCP/IP, DNS, firewalls, and proxies. Experience within a SOC, NOC, or 24/7 operational environment. Familiarity with MITRE ATT&CK, CVEs, and vulnerability management. Exposure to cloud security monitoring across Azure, AWS, or Microsoft 365. Desirable Certifications Microsoft SC-200 CompTIA Security+ / CySA+ ISC2 CC or CISSP GIAC GCIA CEH Cisco CyberOps or Fortinet certifications What's on Offer? Opportunity to work within a mature and growing SOC environment. Exposure to a wide range of customer environments and technologies. Security Clearance sponsorship available for eligible candidates. Clear opportunities to contribute to automation, detection engineering, and SOC improvement initiatives. Location: Milton Keynes (full-time onsite) Working Pattern: Shift rota including evenings, weekends, bank holidays on-call support. Due to the volume of applications received for positions, it will not be possible to respond to all applications and only applicants who are considered suitable for interview will be contacted. Proactive Appointments Limited operates as an employment agency and employment business and is an equal opportunities organisation We take our obligations to protect your personal data very seriously. Any information provided to us will be processed as detailed in our Privacy Notice, a copy of which can be found on our website
Aug 21, 2026
Full time
SOC Engineer Milton Keynes - Hybrid working SC Clearance Sponsorship Available £50,000 - £55,000 + Bonus We're seeking a hands-on SOC Engineer to join a growing Cyber Security Operations Centre supporting a diverse portfolio of customers across multiple sectors This is a specialist SOC Engineering position focused on building, maintaining, and optimising the tools, telemetry, detections, and automation that enable SOC Analysts to identify and respond to threats effectively. This is not a generalist cyber security role. Key Responsibilities Administer and optimise Microsoft Sentinel (or equivalent SIEM), including log ingestion, parsing, normalisation, and retention. Develop and maintain SOAR workflows and automation using Azure Logic Apps, Python, PowerShell, Bash, and KQL. Onboard and manage security telemetry from a range of data sources. Design, implement, and tune detection rules to improve alert quality and reduce false positives. Conduct proactive threat hunting using SIEM, EDR, and threat intelligence sources. Support incident investigations, containment, and response activities. Monitor and maintain the health of SOC tooling, sensors, agents, and log pipelines. Produce documentation, runbooks, and operational procedures. Skills & Experience Experience engineering and supporting SIEM platforms, ideally Microsoft Sentinel. Strong scripting and automation skills (Python, PowerShell, Bash, KQL). Experience with SOAR technologies and security automation. Knowledge of detection engineering and threat hunting. Strong understanding of Windows and Linux logging. Good networking knowledge including TCP/IP, DNS, firewalls, and proxies. Experience within a SOC, NOC, or 24/7 operational environment. Familiarity with MITRE ATT&CK, CVEs, and vulnerability management. Exposure to cloud security monitoring across Azure, AWS, or Microsoft 365. Desirable Certifications Microsoft SC-200 CompTIA Security+ / CySA+ ISC2 CC or CISSP GIAC GCIA CEH Cisco CyberOps or Fortinet certifications What's on Offer? Opportunity to work within a mature and growing SOC environment. Exposure to a wide range of customer environments and technologies. Security Clearance sponsorship available for eligible candidates. Clear opportunities to contribute to automation, detection engineering, and SOC improvement initiatives. Location: Milton Keynes (full-time onsite) Working Pattern: Shift rota including evenings, weekends, bank holidays on-call support. Due to the volume of applications received for positions, it will not be possible to respond to all applications and only applicants who are considered suitable for interview will be contacted. Proactive Appointments Limited operates as an employment agency and employment business and is an equal opportunities organisation We take our obligations to protect your personal data very seriously. Any information provided to us will be processed as detailed in our Privacy Notice, a copy of which can be found on our website
Junior IT & AI Support Engineer Location: Bicester, Oxfordshire (Hybrid) Salary: £30,000 - £35,000 (depending on experience) Job Type: Permanent, Full-Time Launch your IT career at the forefront of engineering, sustainability and Artificial Intelligence. Are you a Computer Science, Computing or IT graduate looking for more than a standard helpdesk role? This is an outstanding opportunity to build your career with an internationally respected engineering consultancy, working on real AI projects, not just resetting passwords. About the Company Our client is recognised for developing innovative, sustainable engineering solutions that help organisations improve performance while reducing environmental impact. Their work combines world-class engineering, advanced simulation and high-performance computing (HPC) to solve complex technical challenges across a range of industries. Working closely with an experienced Head of IT, you'll join a small, collaborative team with genuine exposure to enterprise IT infrastructure, cloud technologies, cybersecurity and AI implementation projects that will help shape the future of the business. Why This Role Stands Out You'll benefit from direct mentoring from an experienced Head of IT, hands-on exposure to AI implementation and digital transformation projects, and real experience supporting high-performance computing (HPC) environments. There are genuine career progression opportunities, hybrid working, and a friendly, supportive and innovative team environment to grow in. Key Responsibilities You'll provide first-line IT support across the business, troubleshooting hardware, software and network issues, and setting up and maintaining laptops, desktops, mobile devices and peripherals. You'll support Microsoft 365 (Outlook, Teams, SharePoint, OneDrive, Intune), create and manage user accounts, permissions and access requests, install software and carry out routine maintenance, and maintain IT documentation and asset registers. The role also involves supporting cybersecurity initiatives and device security, liaising with third-party IT suppliers, assisting with IT procurement and equipment deployment, and supporting business continuity and disaster recovery activities. AI & Digital Transformation Alongside core IT support, you'll get involved in researching and evaluating emerging AI technologies, assisting with the implementation and testing of AI solutions, and supporting workflow automation projects. You'll create user guides and training documentation, help colleagues adopt new technologies, and keep up to date with the latest developments in AI, identifying opportunities for continuous improvement along the way. About You We're looking for enthusiasm, curiosity and a genuine passion for technology. You may be a recent graduate in Computing, Computer Science, IT or a related discipline, or someone with 1-2 years' experience in an IT Support or Helpdesk role. You'll be interested in Artificial Intelligence and emerging technologies, and friendly, approachable and confident communicating with colleagues at all levels. Desirable Skills Ideally you'll have knowledge of Microsoft Windows, Microsoft 365, Microsoft Entra ID (Azure AD) or Active Directory, and Microsoft Intune, along with basic networking principles. Experience with PowerShell or Python, Microsoft Power Platform, Google Workspace or Google Cloud Platform, and AI tools such as Microsoft Copilot, ChatGPT or Perplexity would all be advantageous, as would familiarity with the Linux command line. Don't worry if you haven't worked with every technology listed if you're technically curious, enjoy learning and have a positive attitude, we'd love to hear from you. Is This You? If you're looking for more than resetting passwords, somewhere that will invest in your development, expose you to cutting-edge technology and give you a genuine part to play in the future of AI within an innovative engineering business apply today. Please note: If you have not heard from us within two weeks of your application, unfortunately you have not been selected on this occasion. Chiltern Park Recruitment is proud to be an equal opportunities employer. All applicants must have the permanent right to work in the UK in order to be considered for this position.
Jul 31, 2026
Full time
Junior IT & AI Support Engineer Location: Bicester, Oxfordshire (Hybrid) Salary: £30,000 - £35,000 (depending on experience) Job Type: Permanent, Full-Time Launch your IT career at the forefront of engineering, sustainability and Artificial Intelligence. Are you a Computer Science, Computing or IT graduate looking for more than a standard helpdesk role? This is an outstanding opportunity to build your career with an internationally respected engineering consultancy, working on real AI projects, not just resetting passwords. About the Company Our client is recognised for developing innovative, sustainable engineering solutions that help organisations improve performance while reducing environmental impact. Their work combines world-class engineering, advanced simulation and high-performance computing (HPC) to solve complex technical challenges across a range of industries. Working closely with an experienced Head of IT, you'll join a small, collaborative team with genuine exposure to enterprise IT infrastructure, cloud technologies, cybersecurity and AI implementation projects that will help shape the future of the business. Why This Role Stands Out You'll benefit from direct mentoring from an experienced Head of IT, hands-on exposure to AI implementation and digital transformation projects, and real experience supporting high-performance computing (HPC) environments. There are genuine career progression opportunities, hybrid working, and a friendly, supportive and innovative team environment to grow in. Key Responsibilities You'll provide first-line IT support across the business, troubleshooting hardware, software and network issues, and setting up and maintaining laptops, desktops, mobile devices and peripherals. You'll support Microsoft 365 (Outlook, Teams, SharePoint, OneDrive, Intune), create and manage user accounts, permissions and access requests, install software and carry out routine maintenance, and maintain IT documentation and asset registers. The role also involves supporting cybersecurity initiatives and device security, liaising with third-party IT suppliers, assisting with IT procurement and equipment deployment, and supporting business continuity and disaster recovery activities. AI & Digital Transformation Alongside core IT support, you'll get involved in researching and evaluating emerging AI technologies, assisting with the implementation and testing of AI solutions, and supporting workflow automation projects. You'll create user guides and training documentation, help colleagues adopt new technologies, and keep up to date with the latest developments in AI, identifying opportunities for continuous improvement along the way. About You We're looking for enthusiasm, curiosity and a genuine passion for technology. You may be a recent graduate in Computing, Computer Science, IT or a related discipline, or someone with 1-2 years' experience in an IT Support or Helpdesk role. You'll be interested in Artificial Intelligence and emerging technologies, and friendly, approachable and confident communicating with colleagues at all levels. Desirable Skills Ideally you'll have knowledge of Microsoft Windows, Microsoft 365, Microsoft Entra ID (Azure AD) or Active Directory, and Microsoft Intune, along with basic networking principles. Experience with PowerShell or Python, Microsoft Power Platform, Google Workspace or Google Cloud Platform, and AI tools such as Microsoft Copilot, ChatGPT or Perplexity would all be advantageous, as would familiarity with the Linux command line. Don't worry if you haven't worked with every technology listed if you're technically curious, enjoy learning and have a positive attitude, we'd love to hear from you. Is This You? If you're looking for more than resetting passwords, somewhere that will invest in your development, expose you to cutting-edge technology and give you a genuine part to play in the future of AI within an innovative engineering business apply today. Please note: If you have not heard from us within two weeks of your application, unfortunately you have not been selected on this occasion. Chiltern Park Recruitment is proud to be an equal opportunities employer. All applicants must have the permanent right to work in the UK in order to be considered for this position.
Cyber Security Engineer (Cyber Security) Location: South Manchester, Altrincham, CheshireSalary: Up to £55k plus benefits About the Role We are looking for a skilled and motivated IT Security Engineer / Cyber Security to join a growing cyber security team based in Altrincham, South Manchester. You will play a key role in protecting critical systems, improving security posture, and supporting incident response across a modern hybrid IT environment. This is a hands-on technical role where you'll work closely with infrastructure, cloud, and SOC teams to detect, prevent, and respond to security threats. Key Responsibilities Monitor and respond to security alerts across SIEM and EDR platforms Manage and tune security tools including firewalls, WAFs, and endpoint protection Investigate and support response to security incidents Perform vulnerability assessments and remediation tracking Support implementation of security controls across cloud and on-prem environments Contribute to security policies, standards, and procedures Assist with threat detection engineering and rule tuning Required Skills & Experience Strong understanding of core security technologies (NGFW, WAF, EDR, SIEM) Experience in a SOC, security engineering, or infrastructure security role Good knowledge of networking and common attack types (e.g. SQL injection, phishing, malware) Experience with log analysis and incident investigation Familiarity with Windows and/or Linux environments Understanding of OWASP Top 10 security risks Ability to work in a fast-paced, incident-driven environment Desirable Security certifications such as CompTIA Security+, GIAC GSEC, or ISC2 certifications Experience with cloud platforms such as Amazon Web Services, Microsoft Azure, or Google Cloud Scripting experience (PowerShell, Python, or Bash) Exposure to threat hunting or SIEM rule development What's On Offer Salary up to £55,000 depending on experience Opportunity to work with modern security tools and technologies Training and certification support Career progression within a growing security function Collaborative and supportive technical team environment To apply, please send your CV to Alex or call for more details.Erin Associates welcomes applications from people of all ethnicities, genders, sexual orientations, and disabilities. Please inform us if you require any reasonable adjustments at any stage of the application process.
May 25, 2026
Full time
Cyber Security Engineer (Cyber Security) Location: South Manchester, Altrincham, CheshireSalary: Up to £55k plus benefits About the Role We are looking for a skilled and motivated IT Security Engineer / Cyber Security to join a growing cyber security team based in Altrincham, South Manchester. You will play a key role in protecting critical systems, improving security posture, and supporting incident response across a modern hybrid IT environment. This is a hands-on technical role where you'll work closely with infrastructure, cloud, and SOC teams to detect, prevent, and respond to security threats. Key Responsibilities Monitor and respond to security alerts across SIEM and EDR platforms Manage and tune security tools including firewalls, WAFs, and endpoint protection Investigate and support response to security incidents Perform vulnerability assessments and remediation tracking Support implementation of security controls across cloud and on-prem environments Contribute to security policies, standards, and procedures Assist with threat detection engineering and rule tuning Required Skills & Experience Strong understanding of core security technologies (NGFW, WAF, EDR, SIEM) Experience in a SOC, security engineering, or infrastructure security role Good knowledge of networking and common attack types (e.g. SQL injection, phishing, malware) Experience with log analysis and incident investigation Familiarity with Windows and/or Linux environments Understanding of OWASP Top 10 security risks Ability to work in a fast-paced, incident-driven environment Desirable Security certifications such as CompTIA Security+, GIAC GSEC, or ISC2 certifications Experience with cloud platforms such as Amazon Web Services, Microsoft Azure, or Google Cloud Scripting experience (PowerShell, Python, or Bash) Exposure to threat hunting or SIEM rule development What's On Offer Salary up to £55,000 depending on experience Opportunity to work with modern security tools and technologies Training and certification support Career progression within a growing security function Collaborative and supportive technical team environment To apply, please send your CV to Alex or call for more details.Erin Associates welcomes applications from people of all ethnicities, genders, sexual orientations, and disabilities. Please inform us if you require any reasonable adjustments at any stage of the application process.
Security Engineer (Cyber Security) Location: South ManchesterSalary: Up to £55k plus benefits About the Role We are looking for a skilled and motivated Security Engineer to join a growing cyber security team based in South Manchester. You will play a key role in protecting critical systems, improving security posture, and supporting incident response across a modern hybrid IT environment. This is a hands-on technical role where you'll work closely with infrastructure, cloud, and SOC teams to detect, prevent, and respond to security threats. Key Responsibilities Monitor and respond to security alerts across SIEM and EDR platforms Manage and tune security tools including firewalls, WAFs, and endpoint protection Investigate and support response to security incidents Perform vulnerability assessments and remediation tracking Support implementation of security controls across cloud and on-prem environments Contribute to security policies, standards, and procedures Assist with threat detection engineering and rule tuning Required Skills & Experience Strong understanding of core security technologies (NGFW, WAF, EDR, SIEM) Experience in a SOC, security engineering, or infrastructure security role Good knowledge of networking and common attack types (e.g. SQL injection, phishing, malware) Experience with log analysis and incident investigation Familiarity with Windows and/or Linux environments Understanding of OWASP Top 10 security risks Ability to work in a fast-paced, incident-driven environment Desirable Security certifications such as CompTIA Security+, GIAC GSEC, or ISC2 certifications Experience with cloud platforms such as Amazon Web Services, Microsoft Azure, or Google Cloud Scripting experience (PowerShell, Python, or Bash) Exposure to threat hunting or SIEM rule development What's On Offer Salary up to £55,000 depending on experience Opportunity to work with modern security tools and technologies Training and certification support Career progression within a growing security function Collaborative and supportive technical team environment To apply, please send your CV to Alex or call for more details.Erin Associates welcomes applications from people of all ethnicities, genders, sexual orientations, and disabilities. Please inform us if you require any reasonable adjustments at any stage of the application process.
May 22, 2026
Full time
Security Engineer (Cyber Security) Location: South ManchesterSalary: Up to £55k plus benefits About the Role We are looking for a skilled and motivated Security Engineer to join a growing cyber security team based in South Manchester. You will play a key role in protecting critical systems, improving security posture, and supporting incident response across a modern hybrid IT environment. This is a hands-on technical role where you'll work closely with infrastructure, cloud, and SOC teams to detect, prevent, and respond to security threats. Key Responsibilities Monitor and respond to security alerts across SIEM and EDR platforms Manage and tune security tools including firewalls, WAFs, and endpoint protection Investigate and support response to security incidents Perform vulnerability assessments and remediation tracking Support implementation of security controls across cloud and on-prem environments Contribute to security policies, standards, and procedures Assist with threat detection engineering and rule tuning Required Skills & Experience Strong understanding of core security technologies (NGFW, WAF, EDR, SIEM) Experience in a SOC, security engineering, or infrastructure security role Good knowledge of networking and common attack types (e.g. SQL injection, phishing, malware) Experience with log analysis and incident investigation Familiarity with Windows and/or Linux environments Understanding of OWASP Top 10 security risks Ability to work in a fast-paced, incident-driven environment Desirable Security certifications such as CompTIA Security+, GIAC GSEC, or ISC2 certifications Experience with cloud platforms such as Amazon Web Services, Microsoft Azure, or Google Cloud Scripting experience (PowerShell, Python, or Bash) Exposure to threat hunting or SIEM rule development What's On Offer Salary up to £55,000 depending on experience Opportunity to work with modern security tools and technologies Training and certification support Career progression within a growing security function Collaborative and supportive technical team environment To apply, please send your CV to Alex or call for more details.Erin Associates welcomes applications from people of all ethnicities, genders, sexual orientations, and disabilities. Please inform us if you require any reasonable adjustments at any stage of the application process.
Senior Security Engineer, reporting to the IT Security Officer, you will work as part of a 3-person IT Security team. As the Senior Security Engineer, you should have at least 5 years security team leadership and project management. You will implement and maintain robust security systems and protocols across the IT infrastructure. You will conduct risk assessments and vulnerability scans, mitigate vulnerabilities identified in penetration testing, and implement preventative measures to protect against cyber threats. You will monitor the security infrastructure and detect and respond to potential threats. You will mentor and develop the IT security engineer and collaborate with the IT team to ensure compliance with security standards and best practices; you will essentially be a key technical leader in safeguarding sensitive data and systems. Key Responsibilities/Duties Manage the Secure Web Gateway Manage the Email Security Gateway Carry out vulnerability scans, identify risks, and remediation. Manage the perimeter and VPN firewalls. Manage MFA and SSO. Manage MDM\MAM and Conditional Access Manage security certificates and keys. Deliver Cyber Security Awareness Training Remediate vulnerabilities and weaknesses identified during penetration testing.Experience - EssentialThe successful candidate will have a good working knowledge and experience in managing the majority of the following technology stack CrowdStrike EDR Mimecast Mail Security Gateway Duo Okta Rapid7 IVM, Tenable IO or Nessus Palo Alto Firewalls and Panorama InTune and Conditional Access Entra ID, Purview, Defender, Active Directory, DNS, GPOExperience - DesiredExperience using the following technology stack would be advantageous; understanding the principles is required. Cisco Secure Access Cisco Umbrella Cisco ASA Digicert Certificates and Microsoft Certificate Services Ivanti patching Kali Linux (NMAP, Metasploit, BurpSuite, John etc) Microsoft Purview Candidate Profile Desired Education: CISM, CISSP, OSCP or other penetration testing qualifications. Industry: Financial services, SOC, Pentesting is desirable Personal Skills: Excellent inter-personal, written and verbal communication skills The ability to handle multiple priorities, tasks and projects simultaneously Clear and precise verbal and written communication Ability to deliver presentations to staff Cross functional influence, engagement and collaboration skills Location and Hours The position is usually based in our London Head Office, which is currently located in High Holborn. Hours: The team works on a shift pattern to ensure cover from : (0730 to 1630 (2 days working from home), and 0830 to 1730 (3 days working in the office There will be periods of the weekend and out-of-hours work.
May 21, 2026
Full time
Senior Security Engineer, reporting to the IT Security Officer, you will work as part of a 3-person IT Security team. As the Senior Security Engineer, you should have at least 5 years security team leadership and project management. You will implement and maintain robust security systems and protocols across the IT infrastructure. You will conduct risk assessments and vulnerability scans, mitigate vulnerabilities identified in penetration testing, and implement preventative measures to protect against cyber threats. You will monitor the security infrastructure and detect and respond to potential threats. You will mentor and develop the IT security engineer and collaborate with the IT team to ensure compliance with security standards and best practices; you will essentially be a key technical leader in safeguarding sensitive data and systems. Key Responsibilities/Duties Manage the Secure Web Gateway Manage the Email Security Gateway Carry out vulnerability scans, identify risks, and remediation. Manage the perimeter and VPN firewalls. Manage MFA and SSO. Manage MDM\MAM and Conditional Access Manage security certificates and keys. Deliver Cyber Security Awareness Training Remediate vulnerabilities and weaknesses identified during penetration testing.Experience - EssentialThe successful candidate will have a good working knowledge and experience in managing the majority of the following technology stack CrowdStrike EDR Mimecast Mail Security Gateway Duo Okta Rapid7 IVM, Tenable IO or Nessus Palo Alto Firewalls and Panorama InTune and Conditional Access Entra ID, Purview, Defender, Active Directory, DNS, GPOExperience - DesiredExperience using the following technology stack would be advantageous; understanding the principles is required. Cisco Secure Access Cisco Umbrella Cisco ASA Digicert Certificates and Microsoft Certificate Services Ivanti patching Kali Linux (NMAP, Metasploit, BurpSuite, John etc) Microsoft Purview Candidate Profile Desired Education: CISM, CISSP, OSCP or other penetration testing qualifications. Industry: Financial services, SOC, Pentesting is desirable Personal Skills: Excellent inter-personal, written and verbal communication skills The ability to handle multiple priorities, tasks and projects simultaneously Clear and precise verbal and written communication Ability to deliver presentations to staff Cross functional influence, engagement and collaboration skills Location and Hours The position is usually based in our London Head Office, which is currently located in High Holborn. Hours: The team works on a shift pattern to ensure cover from : (0730 to 1630 (2 days working from home), and 0830 to 1730 (3 days working in the office There will be periods of the weekend and out-of-hours work.
SOC / Cyber Threat Detection Analyst - SANS/GIAC Cyber Threat Detection Analyst Location: Wokingham, Berkshire (On-site) Salary: Competitive (dependent on experience) + excellent benefits & training Security Clearance: Ideally SC Cleared or eligible for SC Role Overview As a Cyber Threat Detection Analyst, you will play a hands-on role within an advanced cyber defence function, focused on proactive threat hunting, adversary behaviour analysis, and high-fidelity threat detection across enterprise environments. This role goes beyond reactive alert handling. You will actively hunt for malicious activity using telemetry, SIEM data, and threat intelligence, develop hypotheses based on MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs), and support incident management and response activities when threats are identified. We are open to experienced SOC Analysts where threat hunting, investigations, and proactive detection have formed a significant part of their role, and who are looking to further develop in a more hunting-led environment. This position is well suited to analysts who enjoy thinking like an attacker, have worked alongside or supported red team or purple team activities, and want to deepen their expertise in threat detection and detection engineering. Skills & Experience We're Seeking Experience in threat hunting, cyber threat detection, SOC, blue team, or cyber defence environments, with ideally around five years hands on experience. Strong hands-on experience using SIEM platforms, including: Microsoft Sentinel (KQL) Splunk (SPL) Elastic Security/Kibana (KQL, ESQL) Practical and operational understanding of MITRE ATT&CK, attacker techniques, and adversary tradecraft Experience working with Indicators of Compromise (IOCs) and threat intelligence feeds Solid experience across the security event life cycle, including detection, investigation, and incident management Hands-on experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike, SentinelOne, or Carbon Black Strong knowledge of networking fundamentals (TCP/IP, DNS, HTTP/S, Firewalls, VPNs, Proxy technologies) Experience analysing telemetry from Windows, Linux, identity, endpoint, and network sources Strong analytical mindset with the ability to clearly communicate findings, impact, and risk Key Responsibilities Conduct proactive threat hunting activities across log, endpoint, and network telemetry to identify suspicious, stealthy, or previously unknown threats Develop and execute hunt hypotheses aligned to MITRE ATT&CK TTPs, adversary behaviours, and emerging threat intelligence Write, refine, and optimise SIEM queries using KQL, SPL, Elastic/ESQL, and Kibana Query Language Perform IOC analysis, enrichment, and validation, integrating internal and external threat intelligence sources Lead investigations from initial detection through scoping, root cause analysis, and impact assessment Support incident management and incident response activities, including containment, remediation, escalation, and lessons learned Collaborate closely with SOC teams, incident responders, red teams, and purple teams to validate detections and improve defensive coverage Contribute to detection logic improvements, use-case development, and continuous enhancement of hunting methodologies Produce clear investigation write-ups, timelines, and recommendations for technical and non-technical stakeholders Security Certifications (Highly Beneficial) SANS/GIAC certifications, including but not limited to: GCIH - Incident Handler GCIA - Intrusion Analyst GCED - Enterprise Defender GCTI - Cyber Threat Intelligence GMON - Continuous Monitoring GDAT - Defending Advanced Threats GCAT - Advanced Threat Intelligence OSCP or equivalent offensive security qualifications Crest certifications, such as: Crest Practitioner Intrusion Analyst (CPIA) Crest Registered Intrusion Analyst (CRIA) Crest Certified Threat Intelligence Analyst (CCTIA) Crest Certified Blue Team Professional (CCBTP) Microsoft SC-200 or related detection and response certifications Other recognised cyber security or threat intelligence credentials
May 20, 2026
Full time
SOC / Cyber Threat Detection Analyst - SANS/GIAC Cyber Threat Detection Analyst Location: Wokingham, Berkshire (On-site) Salary: Competitive (dependent on experience) + excellent benefits & training Security Clearance: Ideally SC Cleared or eligible for SC Role Overview As a Cyber Threat Detection Analyst, you will play a hands-on role within an advanced cyber defence function, focused on proactive threat hunting, adversary behaviour analysis, and high-fidelity threat detection across enterprise environments. This role goes beyond reactive alert handling. You will actively hunt for malicious activity using telemetry, SIEM data, and threat intelligence, develop hypotheses based on MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs), and support incident management and response activities when threats are identified. We are open to experienced SOC Analysts where threat hunting, investigations, and proactive detection have formed a significant part of their role, and who are looking to further develop in a more hunting-led environment. This position is well suited to analysts who enjoy thinking like an attacker, have worked alongside or supported red team or purple team activities, and want to deepen their expertise in threat detection and detection engineering. Skills & Experience We're Seeking Experience in threat hunting, cyber threat detection, SOC, blue team, or cyber defence environments, with ideally around five years hands on experience. Strong hands-on experience using SIEM platforms, including: Microsoft Sentinel (KQL) Splunk (SPL) Elastic Security/Kibana (KQL, ESQL) Practical and operational understanding of MITRE ATT&CK, attacker techniques, and adversary tradecraft Experience working with Indicators of Compromise (IOCs) and threat intelligence feeds Solid experience across the security event life cycle, including detection, investigation, and incident management Hands-on experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike, SentinelOne, or Carbon Black Strong knowledge of networking fundamentals (TCP/IP, DNS, HTTP/S, Firewalls, VPNs, Proxy technologies) Experience analysing telemetry from Windows, Linux, identity, endpoint, and network sources Strong analytical mindset with the ability to clearly communicate findings, impact, and risk Key Responsibilities Conduct proactive threat hunting activities across log, endpoint, and network telemetry to identify suspicious, stealthy, or previously unknown threats Develop and execute hunt hypotheses aligned to MITRE ATT&CK TTPs, adversary behaviours, and emerging threat intelligence Write, refine, and optimise SIEM queries using KQL, SPL, Elastic/ESQL, and Kibana Query Language Perform IOC analysis, enrichment, and validation, integrating internal and external threat intelligence sources Lead investigations from initial detection through scoping, root cause analysis, and impact assessment Support incident management and incident response activities, including containment, remediation, escalation, and lessons learned Collaborate closely with SOC teams, incident responders, red teams, and purple teams to validate detections and improve defensive coverage Contribute to detection logic improvements, use-case development, and continuous enhancement of hunting methodologies Produce clear investigation write-ups, timelines, and recommendations for technical and non-technical stakeholders Security Certifications (Highly Beneficial) SANS/GIAC certifications, including but not limited to: GCIH - Incident Handler GCIA - Intrusion Analyst GCED - Enterprise Defender GCTI - Cyber Threat Intelligence GMON - Continuous Monitoring GDAT - Defending Advanced Threats GCAT - Advanced Threat Intelligence OSCP or equivalent offensive security qualifications Crest certifications, such as: Crest Practitioner Intrusion Analyst (CPIA) Crest Registered Intrusion Analyst (CRIA) Crest Certified Threat Intelligence Analyst (CCTIA) Crest Certified Blue Team Professional (CCBTP) Microsoft SC-200 or related detection and response certifications Other recognised cyber security or threat intelligence credentials
2nd Line Support Engineer (Onsite Support) £35,000 - £45,000 Reading, Berkshire Are you an experienced 2nd Line Engineer looking for your next opportunity within a security-led MSP? This is a permanent position requiring SC and NPPV3 security clearance - candidates without current clearance must be eligible and willing to undergo vetting. The Role You will be supporting a portfolio of customer environments, maintaining and monitoring cloud services, virtualised infrastructure, and Microsoft platforms. You'll work closely with the wider engineering team and service desk to resolve incidents, contribute to continuous improvement, and deliver excellent customer outcomes. Key Responsibilities Build, maintain, support and monitor VMware/Nutanix/ProxMox infrastructure Administer Microsoft Server 2022, Active Directory, DNS, and M365 environments Support endpoint devices, basic networking, and 3rd party applications Maintain EDR/MDR, backups, and resilience solutions Raise and resolve tickets effectively Skills and Experience Proven experience supporting Windows desktops, servers, and Linux environments Hands-on experience with virtual infrastructure and local area networks Experience working in a regulated or controlled environment Strong communication skills and a customer-first mindset Organised, detail-oriented and able to prioritise workload effectively Salary: £35,000 - £45,000 depending on experience
May 18, 2026
Full time
2nd Line Support Engineer (Onsite Support) £35,000 - £45,000 Reading, Berkshire Are you an experienced 2nd Line Engineer looking for your next opportunity within a security-led MSP? This is a permanent position requiring SC and NPPV3 security clearance - candidates without current clearance must be eligible and willing to undergo vetting. The Role You will be supporting a portfolio of customer environments, maintaining and monitoring cloud services, virtualised infrastructure, and Microsoft platforms. You'll work closely with the wider engineering team and service desk to resolve incidents, contribute to continuous improvement, and deliver excellent customer outcomes. Key Responsibilities Build, maintain, support and monitor VMware/Nutanix/ProxMox infrastructure Administer Microsoft Server 2022, Active Directory, DNS, and M365 environments Support endpoint devices, basic networking, and 3rd party applications Maintain EDR/MDR, backups, and resilience solutions Raise and resolve tickets effectively Skills and Experience Proven experience supporting Windows desktops, servers, and Linux environments Hands-on experience with virtual infrastructure and local area networks Experience working in a regulated or controlled environment Strong communication skills and a customer-first mindset Organised, detail-oriented and able to prioritise workload effectively Salary: £35,000 - £45,000 depending on experience
2nd Line Support Engineer £35,000 - £45,000 Home-Based with regular site visits Are you an experienced 2nd Line Engineer looking for your next opportunity within a security-led MSP? This is a permanent position requiring SC and NPPV3 security clearance - candidates without current clearance must be eligible and willing to undergo vetting. The Role You will be supporting a portfolio of customer environments, maintaining and monitoring cloud services, virtualised infrastructure, and Microsoft platforms. You'll work closely with the wider engineering team and service desk to resolve incidents, contribute to continuous improvement, and deliver excellent customer outcomes. Key Responsibilities Build, maintain, support and monitor VMware/Nutanix/ProxMox infrastructure Administer Microsoft Server 2022, Active Directory, DNS, and M365 environments Support endpoint devices, basic networking, and 3rd party applications Maintain EDR/MDR, backups, and resilience solutions Raise and resolve tickets effectively Skills and Experience Proven experience supporting Windows desktops, servers, and Linux environments Hands-on experience with virtual infrastructure and local area networks Experience working in a regulated or controlled environment Strong communication skills and a customer-first mindset Organised, detail-oriented and able to prioritise workload effectively Salary: £35,000 - £45,000 depending on experience
May 18, 2026
Full time
2nd Line Support Engineer £35,000 - £45,000 Home-Based with regular site visits Are you an experienced 2nd Line Engineer looking for your next opportunity within a security-led MSP? This is a permanent position requiring SC and NPPV3 security clearance - candidates without current clearance must be eligible and willing to undergo vetting. The Role You will be supporting a portfolio of customer environments, maintaining and monitoring cloud services, virtualised infrastructure, and Microsoft platforms. You'll work closely with the wider engineering team and service desk to resolve incidents, contribute to continuous improvement, and deliver excellent customer outcomes. Key Responsibilities Build, maintain, support and monitor VMware/Nutanix/ProxMox infrastructure Administer Microsoft Server 2022, Active Directory, DNS, and M365 environments Support endpoint devices, basic networking, and 3rd party applications Maintain EDR/MDR, backups, and resilience solutions Raise and resolve tickets effectively Skills and Experience Proven experience supporting Windows desktops, servers, and Linux environments Hands-on experience with virtual infrastructure and local area networks Experience working in a regulated or controlled environment Strong communication skills and a customer-first mindset Organised, detail-oriented and able to prioritise workload effectively Salary: £35,000 - £45,000 depending on experience
SOC Engineer - SIEM, Exabeam, SOAR, EDR, IDS/IPS, MITRE, Azure, SC-200, SC-100, Our leading global law firm client are currently looking to take on a new SOC Engineer (SIEM, Exabeam, SOAR, EDR, IDS/IPS, MITRE, Azure, SC-200, SC-100) to join their team on a contractual basis. The firm are an extremely modern law firm which offer a healthy hybrid working solution 2-3 days per week in London and offer a great deal of autonomy and technical exposure. This SOC Engineer (SIEM, Exabeam, SOAR, EDR, IDS/IPS, MITRE, Azure, SC-200, SC-100) role, will be responsible for the enhancement of existing SIEM platform and improve performance, coverage and fidelity by conducting regular assessments of the SIEM architecture. To be considered for this SOC Engineer (SIEM, Exabeam, SOAR, EDR, IDS/IPS, MITRE, Azure, SC-200, SC-100)Defender) role, it's ideal you have: 3 + years within a similar role Ideal but not required law firm experience Security qualifications such as CISSP, CISM, CEH, CompTIA Sec+ or others SIEM Engineering & Maturity Enhance and optimise the existing SIEM platform to improve performance, coverage, and fidelity. Conduct regular assessments of SIEM architecture and propose improvements to ingestion pipelines, parsing rules, correlation logic, and storage management. Implement automation and orchestration components (SOAR) to streamline incident response activities. Log Source Onboarding & Integration Identify, prioritise, and onboard new log sources from cloud, on-prem, network, endpoint, identity, and application platforms. Develop and maintain custom parsers, connectors, and ingestion playbooks. Work with internal teams and vendors to ensure high-quality, reliable telemetry and error-free ingestion. Use Case & Detection Content Development Design, implement, test, and tune detection use cases based on attacker techniques (MITRE ATT&CK), threat intelligence, and risk appetite. Build correlation rules, anomaly-based detections, dashboards, and alerting workflows. Regularly review detection efficacy and reduce false positives through tuning and logic refinement. SOC Support & Incident Response Work closely with SOC analysts to validate and refine detection logic. Support incident investigations through SIEM searches, enrichment, and data modelling. Provide technical SME support for complex incidents that require deep SIEM or log knowledge. Documentation & Governance Maintain high-quality documentation covering data models, feed onboarding, use cases, correlation logic, and architecture. Ensure alignment with internal controls, compliance requirements, and industry standards. Education, Skills & Experience Technical Expertise Hands-on experience with leading SIEM platforms (e.g., Exabeam, LogRhythm, ArcSight, Microsoft Sentinel, Splunk, QRadar, Elastic). Strong understanding of log formats (JSON, syslog, XML, CEF, etc.) and ingestion technologies (Syslog, API, Event Hubs, Kafka, Agents). Practical knowledge of detection engineering, threat modelling, and attacker behaviour analysis. Experience building and tuning correlation rules, searches, and dashboards. Familiarity with SOAR platforms and automation workflows. Security Knowledge Strong understanding of networking, Windows/Linux systems, Cloud platforms (Azure/AWS/GCP), identity systems, and endpoint protection technologies (e.g. SentinelOne and Microsoft Defender) Knowledge of MITRE ATT&CK, cyber kill chain, and threat hunting methodologies. Must Have Level 4 or higher qualification in a computing subject, or equivalent experience IT experience including both IT Infrastructure and Information Security roles Relevant professional certifications that validate the fundamental skills required to perform the role, e.g. GIAC (GCIA,GCDA,GMON) Microsoft SC-200/SC-100, CompTIA Secure Infrastructure Specialist (CSIS), SSCP/CISSP etc Strong skill level in scripting technologies, including Python, MS PowerShell and PowerApps Ability to conduct research into Infrastructure issues and products as required Self-starting with strong interpersonal, written, and oral communication skills. Ability to engage colleagues at all levels and project a solid, professional attitude consistently. Nice to have Data Loss Prevention Secure Remote Access solutions Network Security solutions Open Source and Cyber Threat Intelligence Suitable experience working with the market leading technology vendor product suites Experience in software-defined and cloud services such as SaaS, IaaS, PaaS and DaaS Experience in Disaster Recovery Management and Business Continuity Knowledge of applicable data privacy practices and laws
May 03, 2026
Contractor
SOC Engineer - SIEM, Exabeam, SOAR, EDR, IDS/IPS, MITRE, Azure, SC-200, SC-100, Our leading global law firm client are currently looking to take on a new SOC Engineer (SIEM, Exabeam, SOAR, EDR, IDS/IPS, MITRE, Azure, SC-200, SC-100) to join their team on a contractual basis. The firm are an extremely modern law firm which offer a healthy hybrid working solution 2-3 days per week in London and offer a great deal of autonomy and technical exposure. This SOC Engineer (SIEM, Exabeam, SOAR, EDR, IDS/IPS, MITRE, Azure, SC-200, SC-100) role, will be responsible for the enhancement of existing SIEM platform and improve performance, coverage and fidelity by conducting regular assessments of the SIEM architecture. To be considered for this SOC Engineer (SIEM, Exabeam, SOAR, EDR, IDS/IPS, MITRE, Azure, SC-200, SC-100)Defender) role, it's ideal you have: 3 + years within a similar role Ideal but not required law firm experience Security qualifications such as CISSP, CISM, CEH, CompTIA Sec+ or others SIEM Engineering & Maturity Enhance and optimise the existing SIEM platform to improve performance, coverage, and fidelity. Conduct regular assessments of SIEM architecture and propose improvements to ingestion pipelines, parsing rules, correlation logic, and storage management. Implement automation and orchestration components (SOAR) to streamline incident response activities. Log Source Onboarding & Integration Identify, prioritise, and onboard new log sources from cloud, on-prem, network, endpoint, identity, and application platforms. Develop and maintain custom parsers, connectors, and ingestion playbooks. Work with internal teams and vendors to ensure high-quality, reliable telemetry and error-free ingestion. Use Case & Detection Content Development Design, implement, test, and tune detection use cases based on attacker techniques (MITRE ATT&CK), threat intelligence, and risk appetite. Build correlation rules, anomaly-based detections, dashboards, and alerting workflows. Regularly review detection efficacy and reduce false positives through tuning and logic refinement. SOC Support & Incident Response Work closely with SOC analysts to validate and refine detection logic. Support incident investigations through SIEM searches, enrichment, and data modelling. Provide technical SME support for complex incidents that require deep SIEM or log knowledge. Documentation & Governance Maintain high-quality documentation covering data models, feed onboarding, use cases, correlation logic, and architecture. Ensure alignment with internal controls, compliance requirements, and industry standards. Education, Skills & Experience Technical Expertise Hands-on experience with leading SIEM platforms (e.g., Exabeam, LogRhythm, ArcSight, Microsoft Sentinel, Splunk, QRadar, Elastic). Strong understanding of log formats (JSON, syslog, XML, CEF, etc.) and ingestion technologies (Syslog, API, Event Hubs, Kafka, Agents). Practical knowledge of detection engineering, threat modelling, and attacker behaviour analysis. Experience building and tuning correlation rules, searches, and dashboards. Familiarity with SOAR platforms and automation workflows. Security Knowledge Strong understanding of networking, Windows/Linux systems, Cloud platforms (Azure/AWS/GCP), identity systems, and endpoint protection technologies (e.g. SentinelOne and Microsoft Defender) Knowledge of MITRE ATT&CK, cyber kill chain, and threat hunting methodologies. Must Have Level 4 or higher qualification in a computing subject, or equivalent experience IT experience including both IT Infrastructure and Information Security roles Relevant professional certifications that validate the fundamental skills required to perform the role, e.g. GIAC (GCIA,GCDA,GMON) Microsoft SC-200/SC-100, CompTIA Secure Infrastructure Specialist (CSIS), SSCP/CISSP etc Strong skill level in scripting technologies, including Python, MS PowerShell and PowerApps Ability to conduct research into Infrastructure issues and products as required Self-starting with strong interpersonal, written, and oral communication skills. Ability to engage colleagues at all levels and project a solid, professional attitude consistently. Nice to have Data Loss Prevention Secure Remote Access solutions Network Security solutions Open Source and Cyber Threat Intelligence Suitable experience working with the market leading technology vendor product suites Experience in software-defined and cloud services such as SaaS, IaaS, PaaS and DaaS Experience in Disaster Recovery Management and Business Continuity Knowledge of applicable data privacy practices and laws
Network Infrastructure & Security Engineer Milton Keynes (hybrid considered) Salary: £60,000 + Bonuses + Benefits We are seeking a hands-on Network Infrastructure & Security Engineer to support and improve a mix of cloud and on-prem environments. You'll work across systems, networking, and security, contributing to both operations and design. Responsibilities Manage AWS/Azure infrastructure Support Windows/Linux systems and virtualisation (VMware, Hyper-V, KVM, Proxmox) Maintain networking (firewalls, routing, switching, VPNs) Implement monitoring, logging, and backup solutions (e.g. Zabbix, Graylog, Veeam) Support security tooling (Cloudflare WAF/Zero Trust, vulnerability scanning, patching, PKI) Administer Microsoft 365 Produce technical documentation (HLD/LLD) Skills & Experience Strong infrastructure background across cloud and on-prem Experience with monitoring, logging, and backup tools Knowledge of networking and security principles Familiarity with vulnerability management and VPNs Desirable ITIL processes SIEM/EDR tools (e.g. Microsoft Sentinel/Defender) Scripting (PowerShell, Bash, Python) Jira/Confluence, IBM i Due to the volume of applications received for positions, it will not be possible to respond to all applications and only applicants who are considered suitable for interview will be contacted. Proactive Appointments Limited operates as an employment agency and employment business and is an equal opportunities organisation We take our obligations to protect your personal data very seriously. Any information provided to us will be processed as detailed in our Privacy Notice, a copy of which can be found on our website
May 03, 2026
Full time
Network Infrastructure & Security Engineer Milton Keynes (hybrid considered) Salary: £60,000 + Bonuses + Benefits We are seeking a hands-on Network Infrastructure & Security Engineer to support and improve a mix of cloud and on-prem environments. You'll work across systems, networking, and security, contributing to both operations and design. Responsibilities Manage AWS/Azure infrastructure Support Windows/Linux systems and virtualisation (VMware, Hyper-V, KVM, Proxmox) Maintain networking (firewalls, routing, switching, VPNs) Implement monitoring, logging, and backup solutions (e.g. Zabbix, Graylog, Veeam) Support security tooling (Cloudflare WAF/Zero Trust, vulnerability scanning, patching, PKI) Administer Microsoft 365 Produce technical documentation (HLD/LLD) Skills & Experience Strong infrastructure background across cloud and on-prem Experience with monitoring, logging, and backup tools Knowledge of networking and security principles Familiarity with vulnerability management and VPNs Desirable ITIL processes SIEM/EDR tools (e.g. Microsoft Sentinel/Defender) Scripting (PowerShell, Bash, Python) Jira/Confluence, IBM i Due to the volume of applications received for positions, it will not be possible to respond to all applications and only applicants who are considered suitable for interview will be contacted. Proactive Appointments Limited operates as an employment agency and employment business and is an equal opportunities organisation We take our obligations to protect your personal data very seriously. Any information provided to us will be processed as detailed in our Privacy Notice, a copy of which can be found on our website
Network Infrastructure & Security Engineer Milton Keynes (hybrid / remote working) Salary: £60,000 - £65,000 + Bonuses + Benefits We are seeking a hands-on Network & Infrastructure Engineer to support and improve a mix of cloud and on-prem environments. You'll work across systems, networking, and security, contributing to both operations and design. Responsibilities Manage AWS/Azure infrastructure Support Windows/Linux systems and virtualisation (VMware, Hyper-V, KVM, Proxmox) Maintain networking (firewalls, routing, switching, VPNs) Implement monitoring, logging, and backup solutions (e.g. Zabbix, Graylog, Veeam) Support security tooling (Cloudflare WAF/Zero Trust, vulnerability scanning, patching, PKI) Administer Microsoft 365 Produce technical documentation (HLD/LLD) Skills & Experience Strong infrastructure background across cloud and on-prem Experience with monitoring, logging, and backup tools Knowledge of networking and security principles Familiarity with vulnerability management and VPNs Desirable ITIL processes SIEM/EDR tools (e.g. Microsoft Sentinel/Defender) Scripting (PowerShell, Bash, Python) Due to the volume of applications received for positions, it will not be possible to respond to all applications and only applicants who are considered suitable for interview will be contacted. Proactive Appointments Limited operates as an employment agency and employment business and is an equal opportunities organisation We take our obligations to protect your personal data very seriously. Any information provided to us will be processed as detailed in our Privacy Notice, a copy of which can be found on our website
May 03, 2026
Full time
Network Infrastructure & Security Engineer Milton Keynes (hybrid / remote working) Salary: £60,000 - £65,000 + Bonuses + Benefits We are seeking a hands-on Network & Infrastructure Engineer to support and improve a mix of cloud and on-prem environments. You'll work across systems, networking, and security, contributing to both operations and design. Responsibilities Manage AWS/Azure infrastructure Support Windows/Linux systems and virtualisation (VMware, Hyper-V, KVM, Proxmox) Maintain networking (firewalls, routing, switching, VPNs) Implement monitoring, logging, and backup solutions (e.g. Zabbix, Graylog, Veeam) Support security tooling (Cloudflare WAF/Zero Trust, vulnerability scanning, patching, PKI) Administer Microsoft 365 Produce technical documentation (HLD/LLD) Skills & Experience Strong infrastructure background across cloud and on-prem Experience with monitoring, logging, and backup tools Knowledge of networking and security principles Familiarity with vulnerability management and VPNs Desirable ITIL processes SIEM/EDR tools (e.g. Microsoft Sentinel/Defender) Scripting (PowerShell, Bash, Python) Due to the volume of applications received for positions, it will not be possible to respond to all applications and only applicants who are considered suitable for interview will be contacted. Proactive Appointments Limited operates as an employment agency and employment business and is an equal opportunities organisation We take our obligations to protect your personal data very seriously. Any information provided to us will be processed as detailed in our Privacy Notice, a copy of which can be found on our website
SOC / Cyber Threat Detection Analyst - SANS/GIAC Cyber Threat Detection Analyst Location: Wokingham, Berkshire (On-site) Salary: Competitive (dependent on experience) + excellent benefits & training Security Clearance: Ideally SC Cleared or eligible for SC Role Overview As a Cyber Threat Detection Analyst, you will play a hands-on role within an advanced cyber defence function, focused on proactive threat hunting, adversary behaviour analysis, and high-fidelity threat detection across enterprise environments. This role goes beyond reactive alert handling. You will actively hunt for malicious activity using telemetry, SIEM data, and threat intelligence, develop hypotheses based on MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs), and support incident management and response activities when threats are identified. We are open to experienced SOC Analysts where threat hunting, investigations, and proactive detection have formed a significant part of their role, and who are looking to further develop in a more hunting-led environment. This position is well suited to analysts who enjoy thinking like an attacker, have worked alongside or supported red team or purple team activities, and want to deepen their expertise in threat detection and detection engineering. Skills & Experience We're Seeking Experience in threat hunting, cyber threat detection, SOC, blue team, or cyber defence environments, with ideally around five years hands on experience. Strong hands-on experience using SIEM platforms, including: Microsoft Sentinel (KQL) Splunk (SPL) Elastic Security/Kibana (KQL, ESQL) Practical and operational understanding of MITRE ATT&CK, attacker techniques, and adversary tradecraft Experience working with Indicators of Compromise (IOCs) and threat intelligence feeds Solid experience across the security event life cycle, including detection, investigation, and incident management Hands-on experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike, SentinelOne, or Carbon Black Strong knowledge of networking fundamentals (TCP/IP, DNS, HTTP/S, Firewalls, VPNs, Proxy technologies) Experience analysing telemetry from Windows, Linux, identity, endpoint, and network sources Strong analytical mindset with the ability to clearly communicate findings, impact, and risk Key Responsibilities Conduct proactive threat hunting activities across log, endpoint, and network telemetry to identify suspicious, stealthy, or previously unknown threats Develop and execute hunt hypotheses aligned to MITRE ATT&CK TTPs, adversary behaviours, and emerging threat intelligence Write, refine, and optimise SIEM queries using KQL, SPL, Elastic/ESQL, and Kibana Query Language Perform IOC analysis, enrichment, and validation, integrating internal and external threat intelligence sources Lead investigations from initial detection through scoping, root cause analysis, and impact assessment Support incident management and incident response activities, including containment, remediation, escalation, and lessons learned Collaborate closely with SOC teams, incident responders, red teams, and purple teams to validate detections and improve defensive coverage Contribute to detection logic improvements, use-case development, and continuous enhancement of hunting methodologies Produce clear investigation write-ups, timelines, and recommendations for technical and non-technical stakeholders Security Certifications (Highly Beneficial) SANS/GIAC certifications, including but not limited to: GCIH - Incident Handler GCIA - Intrusion Analyst GCED - Enterprise Defender GCTI - Cyber Threat Intelligence GMON - Continuous Monitoring GDAT - Defending Advanced Threats GCAT - Advanced Threat Intelligence OSCP or equivalent offensive security qualifications Crest certifications, such as: Crest Practitioner Intrusion Analyst (CPIA) Crest Registered Intrusion Analyst (CRIA) Crest Certified Threat Intelligence Analyst (CCTIA) Crest Certified Blue Team Professional (CCBTP) Microsoft SC-200 or related detection and response certifications Other recognised cyber security or threat intelligence credentials
Apr 30, 2026
Full time
SOC / Cyber Threat Detection Analyst - SANS/GIAC Cyber Threat Detection Analyst Location: Wokingham, Berkshire (On-site) Salary: Competitive (dependent on experience) + excellent benefits & training Security Clearance: Ideally SC Cleared or eligible for SC Role Overview As a Cyber Threat Detection Analyst, you will play a hands-on role within an advanced cyber defence function, focused on proactive threat hunting, adversary behaviour analysis, and high-fidelity threat detection across enterprise environments. This role goes beyond reactive alert handling. You will actively hunt for malicious activity using telemetry, SIEM data, and threat intelligence, develop hypotheses based on MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs), and support incident management and response activities when threats are identified. We are open to experienced SOC Analysts where threat hunting, investigations, and proactive detection have formed a significant part of their role, and who are looking to further develop in a more hunting-led environment. This position is well suited to analysts who enjoy thinking like an attacker, have worked alongside or supported red team or purple team activities, and want to deepen their expertise in threat detection and detection engineering. Skills & Experience We're Seeking Experience in threat hunting, cyber threat detection, SOC, blue team, or cyber defence environments, with ideally around five years hands on experience. Strong hands-on experience using SIEM platforms, including: Microsoft Sentinel (KQL) Splunk (SPL) Elastic Security/Kibana (KQL, ESQL) Practical and operational understanding of MITRE ATT&CK, attacker techniques, and adversary tradecraft Experience working with Indicators of Compromise (IOCs) and threat intelligence feeds Solid experience across the security event life cycle, including detection, investigation, and incident management Hands-on experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike, SentinelOne, or Carbon Black Strong knowledge of networking fundamentals (TCP/IP, DNS, HTTP/S, Firewalls, VPNs, Proxy technologies) Experience analysing telemetry from Windows, Linux, identity, endpoint, and network sources Strong analytical mindset with the ability to clearly communicate findings, impact, and risk Key Responsibilities Conduct proactive threat hunting activities across log, endpoint, and network telemetry to identify suspicious, stealthy, or previously unknown threats Develop and execute hunt hypotheses aligned to MITRE ATT&CK TTPs, adversary behaviours, and emerging threat intelligence Write, refine, and optimise SIEM queries using KQL, SPL, Elastic/ESQL, and Kibana Query Language Perform IOC analysis, enrichment, and validation, integrating internal and external threat intelligence sources Lead investigations from initial detection through scoping, root cause analysis, and impact assessment Support incident management and incident response activities, including containment, remediation, escalation, and lessons learned Collaborate closely with SOC teams, incident responders, red teams, and purple teams to validate detections and improve defensive coverage Contribute to detection logic improvements, use-case development, and continuous enhancement of hunting methodologies Produce clear investigation write-ups, timelines, and recommendations for technical and non-technical stakeholders Security Certifications (Highly Beneficial) SANS/GIAC certifications, including but not limited to: GCIH - Incident Handler GCIA - Intrusion Analyst GCED - Enterprise Defender GCTI - Cyber Threat Intelligence GMON - Continuous Monitoring GDAT - Defending Advanced Threats GCAT - Advanced Threat Intelligence OSCP or equivalent offensive security qualifications Crest certifications, such as: Crest Practitioner Intrusion Analyst (CPIA) Crest Registered Intrusion Analyst (CRIA) Crest Certified Threat Intelligence Analyst (CCTIA) Crest Certified Blue Team Professional (CCBTP) Microsoft SC-200 or related detection and response certifications Other recognised cyber security or threat intelligence credentials
SOC / Cyber Threat Detection Analyst - SANS/GIAC Cyber Threat Detection Analyst Location: Wokingham, Berkshire (On-site) Salary: Competitive (dependent on experience) + excellent benefits & training Security Clearance: Ideally SC Cleared or eligible for SC Role Overview As a Cyber Threat Detection Analyst, you will play a hands-on role within an advanced cyber defence function, focused on proactive threat hunting, adversary behaviour analysis, and high-fidelity threat detection across enterprise environments. This role goes beyond reactive alert handling. You will actively hunt for malicious activity using telemetry, SIEM data, and threat intelligence, develop hypotheses based on MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs), and support incident management and response activities when threats are identified. We are open to experienced SOC Analysts where threat hunting, investigations, and proactive detection have formed a significant part of their role, and who are looking to further develop in a more hunting-led environment. This position is well suited to analysts who enjoy thinking like an attacker, have worked alongside or supported red team or purple team activities, and want to deepen their expertise in threat detection and detection engineering. Skills & Experience We're Seeking Experience in threat hunting, cyber threat detection, SOC, blue team, or cyber defence environments, with ideally around five years hands on experience. Strong hands-on experience using SIEM platforms, including: Microsoft Sentinel (KQL) Splunk (SPL) Elastic Security/Kibana (KQL, ESQL) Practical and operational understanding of MITRE ATT&CK, attacker techniques, and adversary tradecraft Experience working with Indicators of Compromise (IOCs) and threat intelligence feeds Solid experience across the security event life cycle, including detection, investigation, and incident management Hands-on experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike, SentinelOne, or Carbon Black Strong knowledge of networking fundamentals (TCP/IP, DNS, HTTP/S, Firewalls, VPNs, Proxy technologies) Experience analysing telemetry from Windows, Linux, identity, endpoint, and network sources Strong analytical mindset with the ability to clearly communicate findings, impact, and risk Key Responsibilities Conduct proactive threat hunting activities across log, endpoint, and network telemetry to identify suspicious, stealthy, or previously unknown threats Develop and execute hunt hypotheses aligned to MITRE ATT&CK TTPs, adversary behaviours, and emerging threat intelligence Write, refine, and optimise SIEM queries using KQL, SPL, Elastic/ESQL, and Kibana Query Language Perform IOC analysis, enrichment, and validation, integrating internal and external threat intelligence sources Lead investigations from initial detection through scoping, root cause analysis, and impact assessment Support incident management and incident response activities, including containment, remediation, escalation, and lessons learned Collaborate closely with SOC teams, incident responders, red teams, and purple teams to validate detections and improve defensive coverage Contribute to detection logic improvements, use-case development, and continuous enhancement of hunting methodologies Produce clear investigation write-ups, timelines, and recommendations for technical and non-technical stakeholders Security Certifications (Highly Beneficial) SANS/GIAC certifications, including but not limited to: GCIH - Incident Handler GCIA - Intrusion Analyst GCED - Enterprise Defender GCTI - Cyber Threat Intelligence GMON - Continuous Monitoring GDAT - Defending Advanced Threats GCAT - Advanced Threat Intelligence OSCP or equivalent offensive security qualifications Crest certifications, such as: Crest Practitioner Intrusion Analyst (CPIA) Crest Registered Intrusion Analyst (CRIA) Crest Certified Threat Intelligence Analyst (CCTIA) Crest Certified Blue Team Professional (CCBTP) Microsoft SC-200 or related detection and response certifications Other recognised cyber security or threat intelligence credentials
Apr 30, 2026
Full time
SOC / Cyber Threat Detection Analyst - SANS/GIAC Cyber Threat Detection Analyst Location: Wokingham, Berkshire (On-site) Salary: Competitive (dependent on experience) + excellent benefits & training Security Clearance: Ideally SC Cleared or eligible for SC Role Overview As a Cyber Threat Detection Analyst, you will play a hands-on role within an advanced cyber defence function, focused on proactive threat hunting, adversary behaviour analysis, and high-fidelity threat detection across enterprise environments. This role goes beyond reactive alert handling. You will actively hunt for malicious activity using telemetry, SIEM data, and threat intelligence, develop hypotheses based on MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs), and support incident management and response activities when threats are identified. We are open to experienced SOC Analysts where threat hunting, investigations, and proactive detection have formed a significant part of their role, and who are looking to further develop in a more hunting-led environment. This position is well suited to analysts who enjoy thinking like an attacker, have worked alongside or supported red team or purple team activities, and want to deepen their expertise in threat detection and detection engineering. Skills & Experience We're Seeking Experience in threat hunting, cyber threat detection, SOC, blue team, or cyber defence environments, with ideally around five years hands on experience. Strong hands-on experience using SIEM platforms, including: Microsoft Sentinel (KQL) Splunk (SPL) Elastic Security/Kibana (KQL, ESQL) Practical and operational understanding of MITRE ATT&CK, attacker techniques, and adversary tradecraft Experience working with Indicators of Compromise (IOCs) and threat intelligence feeds Solid experience across the security event life cycle, including detection, investigation, and incident management Hands-on experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike, SentinelOne, or Carbon Black Strong knowledge of networking fundamentals (TCP/IP, DNS, HTTP/S, Firewalls, VPNs, Proxy technologies) Experience analysing telemetry from Windows, Linux, identity, endpoint, and network sources Strong analytical mindset with the ability to clearly communicate findings, impact, and risk Key Responsibilities Conduct proactive threat hunting activities across log, endpoint, and network telemetry to identify suspicious, stealthy, or previously unknown threats Develop and execute hunt hypotheses aligned to MITRE ATT&CK TTPs, adversary behaviours, and emerging threat intelligence Write, refine, and optimise SIEM queries using KQL, SPL, Elastic/ESQL, and Kibana Query Language Perform IOC analysis, enrichment, and validation, integrating internal and external threat intelligence sources Lead investigations from initial detection through scoping, root cause analysis, and impact assessment Support incident management and incident response activities, including containment, remediation, escalation, and lessons learned Collaborate closely with SOC teams, incident responders, red teams, and purple teams to validate detections and improve defensive coverage Contribute to detection logic improvements, use-case development, and continuous enhancement of hunting methodologies Produce clear investigation write-ups, timelines, and recommendations for technical and non-technical stakeholders Security Certifications (Highly Beneficial) SANS/GIAC certifications, including but not limited to: GCIH - Incident Handler GCIA - Intrusion Analyst GCED - Enterprise Defender GCTI - Cyber Threat Intelligence GMON - Continuous Monitoring GDAT - Defending Advanced Threats GCAT - Advanced Threat Intelligence OSCP or equivalent offensive security qualifications Crest certifications, such as: Crest Practitioner Intrusion Analyst (CPIA) Crest Registered Intrusion Analyst (CRIA) Crest Certified Threat Intelligence Analyst (CCTIA) Crest Certified Blue Team Professional (CCBTP) Microsoft SC-200 or related detection and response certifications Other recognised cyber security or threat intelligence credentials