• Home
  • Search Jobs
  • Register CV
  • Post a Job
  • Employer Pricing
  • Contact Us
  • Sign in
  • Sign up
  • Home
  • Search Jobs
  • Register CV
  • Post a Job
  • Employer Pricing
  • Contact Us
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

7 jobs found

Email me jobs like this
Refine Search
Current Search
cyber security engineer splunk siem linux
CGI
SOC Analyst
CGI Chippenham, Wiltshire
SOC Analyst Position Description At CGI, you'll help strengthen the cyber resilience of critical UK programmes by building the data and detection capabilities that underpin an effective Security Operations Centre. Joining our Space, Defence and Intelligence business, you'll work with customers and experienced colleagues to onboard secure cloud environments, engineer security data pipelines and develop practical detection content. This is an opportunity to take ownership of meaningful technical work while expanding your skills across Oracle Cloud, Elastic and other major cloud platforms. You'll have the freedom to explore better ways of detecting threats, with the guidance and support of a collaborative team around you. Whether you're developing your cyber career or ready for your next challenge, you can make a tangible contribution to protecting important services. CGI was recognised in the Sunday Times Best Places to Work List 2025 and has been named a UK 'Best Employer' by the Financial Times. We offer a competitive salary, excellent pension, private healthcare, plus a share scheme (3.5% + 3.5% matching) which makes you a CGI Partner not just an employee. We are committed to inclusivity, building a genuinely diverse community of tech talent and inspiring everyone to pursue careers in our sector, including our Armed Forces, and are proud to hold a Gold Award in recognition of our support of the Armed Forces Corporate Covenant. Join us and you'll be part of an open, friendly community of experts. We'll train and support you in taking your career wherever you want it to go. Due to the secure nature of the programme, you will need to hold UK Security Clearance or be eligible to go through this clearance. This role requires full-time onsite working in Chippenham within a restricted working environment. Applicants who already hold Security Clearance are welcomed and will need to be willing and eligible to progress to a higher level of clearance where required. Additional payments are available for full-time onsite working and for working within the restricted environment. Your future duties and responsibilities In this role, you will join CGI's Data and Detection Engineering team, supporting the onboarding of new customers into the Security Operations Centre (SOC). You'll work directly with customers to understand their environments and requirements before helping design how security data is ingested into Elastic. With a primary focus on Oracle Cloud and opportunities to build exposure to AWS, Microsoft Azure and Google Cloud, you'll develop detection logic and triage guidance that enables the SOC to identify and respond to potential threats effectively. You'll also contribute to day-to-day security monitoring and incident investigation, taking responsibility for assessing alerts, understanding their potential impact and escalating where appropriate. Working alongside experienced cyber professionals, you'll have opportunities to develop new approaches, broaden your technical knowledge and build practical experience across cloud security, SIEM and threat detection. • Engineer & Deliver: Design and support security data ingestion pipelines into Elastic for newly onboarded customers. • Develop & Detect: Draft detection rules against defined cyber security use cases and create clear SOC triage guides. • Engage & Onboard: Liaise directly with customers to gather the technical information required for successful SOC onboarding. • Monitor & Triage: Review security alerts from SIEM, intrusion detection, log monitoring and other security systems, assessing severity and potential impact. • Investigate & Escalate: Support security incident investigations and recommend appropriate containment, eradication or escalation actions. • Analyse & Respond: Monitor client environments, investigate alerts and respond to real or suspected cyber security incidents within agreed timescales. • Learn & Improve: Research emerging threats, technologies and security practices, sharing knowledge with colleagues and contributing to continuous improvement. • Support & Assure: Assist with security investigations, exercises, testing, change activities and first-line technical support. • Operate & Automate: Help ensure scheduled security jobs and automated processes operate correctly and reliably. Required qualifications to be successful in this role You'll have a technical foundation in cyber security, computing, software engineering, digital forensics or a related discipline, combined with an interest in developing hands-on expertise in security monitoring and detection engineering. You don't need to know every technology from day one: we're looking for technical aptitude, curiosity and sound judgement, together with the communication skills to work effectively with customers and colleagues in a secure environment. • A technical background or relevant qualification, such as Computer Science, Software Engineering, Cyber Security or Digital Forensics. • Knowledge or practical experience of SIEM technologies such as Elastic or Splunk. • An understanding of cyber security monitoring, alerts, incident triage or investigation. • A general understanding of IT technologies and operating environments, including Linux and/or other enterprise platforms. • Strong analytical and problem-solving skills with the ability to assess information and determine when escalation is required. • Strong written and verbal communication skills. • The confidence to engage directly with customers and collaborate effectively within a technical team. • An interest in cloud security, with Oracle Cloud experience advantageous and exposure to AWS, Azure or Google Cloud beneficial. • Existing UK Security Clearance is advantageous; you must be willing and eligible to progress to a higher level of clearance where required. Together, as owners, let's turn meaningful insights into action. Life at CGI is rooted in ownership, teamwork, respect and belonging. Here, you'll reach your full potential because You are invited to be an owner from day 1 as we work together to bring our Dream to life. That's why we call ourselves CGI Partners rather than employees. We benefit from our collective success and actively shape our company's strategy and direction. Your work creates value. You'll develop innovative solutions and build relationships with teammates and clients while accessing global capabilities to scale your ideas, embrace new opportunities, and benefit from expansive industry and technology expertise. You'll shape your career by joining a company built to grow and last. You'll be supported by leaders who care about your health and well-being and provide you with opportunities to deepen your skills and broaden your horizons. That same commitment to fairness extends to how we use technology. To support our recruitment team, AI tools may be used to help assess applications though they never replace human judgement. All hiring decisions remain entirely in the hands of our recruitment professionals. Come join our team-one of the largest IT and business consulting services firms in the world.
Aug 24, 2026
Full time
SOC Analyst Position Description At CGI, you'll help strengthen the cyber resilience of critical UK programmes by building the data and detection capabilities that underpin an effective Security Operations Centre. Joining our Space, Defence and Intelligence business, you'll work with customers and experienced colleagues to onboard secure cloud environments, engineer security data pipelines and develop practical detection content. This is an opportunity to take ownership of meaningful technical work while expanding your skills across Oracle Cloud, Elastic and other major cloud platforms. You'll have the freedom to explore better ways of detecting threats, with the guidance and support of a collaborative team around you. Whether you're developing your cyber career or ready for your next challenge, you can make a tangible contribution to protecting important services. CGI was recognised in the Sunday Times Best Places to Work List 2025 and has been named a UK 'Best Employer' by the Financial Times. We offer a competitive salary, excellent pension, private healthcare, plus a share scheme (3.5% + 3.5% matching) which makes you a CGI Partner not just an employee. We are committed to inclusivity, building a genuinely diverse community of tech talent and inspiring everyone to pursue careers in our sector, including our Armed Forces, and are proud to hold a Gold Award in recognition of our support of the Armed Forces Corporate Covenant. Join us and you'll be part of an open, friendly community of experts. We'll train and support you in taking your career wherever you want it to go. Due to the secure nature of the programme, you will need to hold UK Security Clearance or be eligible to go through this clearance. This role requires full-time onsite working in Chippenham within a restricted working environment. Applicants who already hold Security Clearance are welcomed and will need to be willing and eligible to progress to a higher level of clearance where required. Additional payments are available for full-time onsite working and for working within the restricted environment. Your future duties and responsibilities In this role, you will join CGI's Data and Detection Engineering team, supporting the onboarding of new customers into the Security Operations Centre (SOC). You'll work directly with customers to understand their environments and requirements before helping design how security data is ingested into Elastic. With a primary focus on Oracle Cloud and opportunities to build exposure to AWS, Microsoft Azure and Google Cloud, you'll develop detection logic and triage guidance that enables the SOC to identify and respond to potential threats effectively. You'll also contribute to day-to-day security monitoring and incident investigation, taking responsibility for assessing alerts, understanding their potential impact and escalating where appropriate. Working alongside experienced cyber professionals, you'll have opportunities to develop new approaches, broaden your technical knowledge and build practical experience across cloud security, SIEM and threat detection. • Engineer & Deliver: Design and support security data ingestion pipelines into Elastic for newly onboarded customers. • Develop & Detect: Draft detection rules against defined cyber security use cases and create clear SOC triage guides. • Engage & Onboard: Liaise directly with customers to gather the technical information required for successful SOC onboarding. • Monitor & Triage: Review security alerts from SIEM, intrusion detection, log monitoring and other security systems, assessing severity and potential impact. • Investigate & Escalate: Support security incident investigations and recommend appropriate containment, eradication or escalation actions. • Analyse & Respond: Monitor client environments, investigate alerts and respond to real or suspected cyber security incidents within agreed timescales. • Learn & Improve: Research emerging threats, technologies and security practices, sharing knowledge with colleagues and contributing to continuous improvement. • Support & Assure: Assist with security investigations, exercises, testing, change activities and first-line technical support. • Operate & Automate: Help ensure scheduled security jobs and automated processes operate correctly and reliably. Required qualifications to be successful in this role You'll have a technical foundation in cyber security, computing, software engineering, digital forensics or a related discipline, combined with an interest in developing hands-on expertise in security monitoring and detection engineering. You don't need to know every technology from day one: we're looking for technical aptitude, curiosity and sound judgement, together with the communication skills to work effectively with customers and colleagues in a secure environment. • A technical background or relevant qualification, such as Computer Science, Software Engineering, Cyber Security or Digital Forensics. • Knowledge or practical experience of SIEM technologies such as Elastic or Splunk. • An understanding of cyber security monitoring, alerts, incident triage or investigation. • A general understanding of IT technologies and operating environments, including Linux and/or other enterprise platforms. • Strong analytical and problem-solving skills with the ability to assess information and determine when escalation is required. • Strong written and verbal communication skills. • The confidence to engage directly with customers and collaborate effectively within a technical team. • An interest in cloud security, with Oracle Cloud experience advantageous and exposure to AWS, Azure or Google Cloud beneficial. • Existing UK Security Clearance is advantageous; you must be willing and eligible to progress to a higher level of clearance where required. Together, as owners, let's turn meaningful insights into action. Life at CGI is rooted in ownership, teamwork, respect and belonging. Here, you'll reach your full potential because You are invited to be an owner from day 1 as we work together to bring our Dream to life. That's why we call ourselves CGI Partners rather than employees. We benefit from our collective success and actively shape our company's strategy and direction. Your work creates value. You'll develop innovative solutions and build relationships with teammates and clients while accessing global capabilities to scale your ideas, embrace new opportunities, and benefit from expansive industry and technology expertise. You'll shape your career by joining a company built to grow and last. You'll be supported by leaders who care about your health and well-being and provide you with opportunities to deepen your skills and broaden your horizons. That same commitment to fairness extends to how we use technology. To support our recruitment team, AI tools may be used to help assess applications though they never replace human judgement. All hiring decisions remain entirely in the hands of our recruitment professionals. Come join our team-one of the largest IT and business consulting services firms in the world.
Exalto Consulting
Cyber Security Engineer/Specialist
Exalto Consulting
Cyber Security Engineer/Specialist Permanent Up to £80,000 (+ Benefits) Hybrid Working (2 3 days per week Onsite) Surrey Help Shape Enterprise Cyber Security on a Global Scale We're looking for an experienced Cyber Security Engineer/Specialist to join a global organisation where security is a genuine business priority, not simply a compliance exercise. This is an opportunity to play a key role in protecting a complex enterprise environment, helping to identify, assess and mitigate sophisticated cyber threats while influencing the organisation's long-term security strategy. Working alongside infrastructure, architecture and operational teams, you'll strengthen enterprise security capabilities, improve cyber resilience and help safeguard critical business systems across an international environment. If you're looking for a role where you can make a real impact while continuing to develop your career within a stable organisation, we'd love to hear from you. The Role This is an enterprise Cyber Security position focused on proactive threat mitigation, security improvement and risk reduction rather than purely operational support. You'll be responsible for strengthening the organisation's security posture through threat assessment, vulnerability management, incident response and continuous security improvement initiatives. Key responsibilities include: Enterprise Threat Management Identify, assess and mitigate cyber threats across enterprise infrastructure and business systems Conduct proactive threat assessments and vulnerability analysis Develop and implement security controls and remediation strategies Monitor emerging threats and recommend appropriate defensive measures Enhance threat detection, monitoring and incident response capabilities Develop and maintain incident response playbooks and operational procedures Work closely with third-party security providers during incidents and security assessments Security Engineering & Risk Support enterprise security architecture and secure design initiatives Contribute to cyber risk management and governance activities Assess third-party and supply chain security risks Support penetration testing, vulnerability management and security assurance programmes Produce meaningful security metrics and KPI reporting for stakeholders Ensure alignment with recognised security frameworks and regulatory requirements Security Improvement Collaborate with infrastructure, cloud and engineering teams to embed security best practice Participate in Red Team / Blue Team exercises and cyber resilience testing Support business continuity and disaster recovery planning Champion continuous improvement across the organisation's security capability Communicate technical security risks clearly to both technical and business stakeholders What You'll Bring We're looking for someone who enjoys solving complex security challenges within large enterprise environments. You'll ideally have: A minimum of 5 years' experience in Cyber Security or Information Security Strong experience protecting enterprise environments against modern cyber threats Experience designing and implementing security controls to reduce organisational risk Excellent knowledge of enterprise security technologies and security operations Experience with SIEM platforms, incident response and threat detection Strong understanding of vulnerability management and security remediation Experience working with recognised security frameworks including: NIST ISO 27001 CIS Controls Cyber Essentials Knowledge of MITRE ATT&CK, Cyber Kill Chain and modern threat intelligence methodologies Excellent analytical, troubleshooting and stakeholder management skills Technical Environment Experience with several of the following technologies would be advantageous: Microsoft Defender Splunk Qualys Azure Security AWS Microsoft 365 Security PowerShell Python Kubernetes Windows Server Linux SOAR platforms Data Loss Prevention (DLP) DevSecOps practices Experience with AI-driven threat detection technologies would also be beneficial. Qualifications Ideally you'll hold one of the following: CISSP (preferred) CISM GIAC Certification CEH However, we recognise that exceptional enterprise Cyber Security experience is just as valuable. If you've developed your expertise through hands-on experience and hold certifications such as CompTIA Security+ , we'd still be keen to hear from you. Ideal Background We'd particularly like to speak with professionals currently working as: Senior Cyber Security Engineer Cyber Security Engineer Information Security Engineer Security Operations Engineer Threat Detection Engineer Cyber Defence Engineer Blue Team Engineer Senior SOC Engineer Security Consultant Experience within large enterprise or global organisations would be highly desirable. Why Join? You'll become part of a collaborative Cyber Security team within a business that continues to invest heavily in technology and security. In return, you'll benefit from: Competitive salary up to £80,000 (+ benefits) Hybrid working (2 3 days onsite in Surrey) Exposure to enterprise-scale security technologies Opportunities to influence security strategy Ongoing investment in professional development and certifications Long-term career progression within a stable global organisation A supportive and collaborative working culture Ready to Make an Impact? If you're passionate about enterprise Cyber Security, enjoy solving complex security challenges and want to help shape the future of Cyber Security within a global organisation, we'd love to hear from you. If you are passionate about cybersecurity, threat management and strengthening enterprise security capabilities, we would love to hear from you.
Jul 31, 2026
Full time
Cyber Security Engineer/Specialist Permanent Up to £80,000 (+ Benefits) Hybrid Working (2 3 days per week Onsite) Surrey Help Shape Enterprise Cyber Security on a Global Scale We're looking for an experienced Cyber Security Engineer/Specialist to join a global organisation where security is a genuine business priority, not simply a compliance exercise. This is an opportunity to play a key role in protecting a complex enterprise environment, helping to identify, assess and mitigate sophisticated cyber threats while influencing the organisation's long-term security strategy. Working alongside infrastructure, architecture and operational teams, you'll strengthen enterprise security capabilities, improve cyber resilience and help safeguard critical business systems across an international environment. If you're looking for a role where you can make a real impact while continuing to develop your career within a stable organisation, we'd love to hear from you. The Role This is an enterprise Cyber Security position focused on proactive threat mitigation, security improvement and risk reduction rather than purely operational support. You'll be responsible for strengthening the organisation's security posture through threat assessment, vulnerability management, incident response and continuous security improvement initiatives. Key responsibilities include: Enterprise Threat Management Identify, assess and mitigate cyber threats across enterprise infrastructure and business systems Conduct proactive threat assessments and vulnerability analysis Develop and implement security controls and remediation strategies Monitor emerging threats and recommend appropriate defensive measures Enhance threat detection, monitoring and incident response capabilities Develop and maintain incident response playbooks and operational procedures Work closely with third-party security providers during incidents and security assessments Security Engineering & Risk Support enterprise security architecture and secure design initiatives Contribute to cyber risk management and governance activities Assess third-party and supply chain security risks Support penetration testing, vulnerability management and security assurance programmes Produce meaningful security metrics and KPI reporting for stakeholders Ensure alignment with recognised security frameworks and regulatory requirements Security Improvement Collaborate with infrastructure, cloud and engineering teams to embed security best practice Participate in Red Team / Blue Team exercises and cyber resilience testing Support business continuity and disaster recovery planning Champion continuous improvement across the organisation's security capability Communicate technical security risks clearly to both technical and business stakeholders What You'll Bring We're looking for someone who enjoys solving complex security challenges within large enterprise environments. You'll ideally have: A minimum of 5 years' experience in Cyber Security or Information Security Strong experience protecting enterprise environments against modern cyber threats Experience designing and implementing security controls to reduce organisational risk Excellent knowledge of enterprise security technologies and security operations Experience with SIEM platforms, incident response and threat detection Strong understanding of vulnerability management and security remediation Experience working with recognised security frameworks including: NIST ISO 27001 CIS Controls Cyber Essentials Knowledge of MITRE ATT&CK, Cyber Kill Chain and modern threat intelligence methodologies Excellent analytical, troubleshooting and stakeholder management skills Technical Environment Experience with several of the following technologies would be advantageous: Microsoft Defender Splunk Qualys Azure Security AWS Microsoft 365 Security PowerShell Python Kubernetes Windows Server Linux SOAR platforms Data Loss Prevention (DLP) DevSecOps practices Experience with AI-driven threat detection technologies would also be beneficial. Qualifications Ideally you'll hold one of the following: CISSP (preferred) CISM GIAC Certification CEH However, we recognise that exceptional enterprise Cyber Security experience is just as valuable. If you've developed your expertise through hands-on experience and hold certifications such as CompTIA Security+ , we'd still be keen to hear from you. Ideal Background We'd particularly like to speak with professionals currently working as: Senior Cyber Security Engineer Cyber Security Engineer Information Security Engineer Security Operations Engineer Threat Detection Engineer Cyber Defence Engineer Blue Team Engineer Senior SOC Engineer Security Consultant Experience within large enterprise or global organisations would be highly desirable. Why Join? You'll become part of a collaborative Cyber Security team within a business that continues to invest heavily in technology and security. In return, you'll benefit from: Competitive salary up to £80,000 (+ benefits) Hybrid working (2 3 days onsite in Surrey) Exposure to enterprise-scale security technologies Opportunities to influence security strategy Ongoing investment in professional development and certifications Long-term career progression within a stable global organisation A supportive and collaborative working culture Ready to Make an Impact? If you're passionate about enterprise Cyber Security, enjoy solving complex security challenges and want to help shape the future of Cyber Security within a global organisation, we'd love to hear from you. If you are passionate about cybersecurity, threat management and strengthening enterprise security capabilities, we would love to hear from you.
Adecco
Cyber Threat Detection / SOC Analyst - SANS/GIAC
Adecco Wokingham, Berkshire
SOC / Cyber Threat Detection Analyst - SANS/GIAC Cyber Threat Detection Analyst Location: Wokingham, Berkshire (On-site) Salary: Competitive (dependent on experience) + excellent benefits & training Security Clearance: Ideally SC Cleared or eligible for SC Role Overview As a Cyber Threat Detection Analyst, you will play a hands-on role within an advanced cyber defence function, focused on proactive threat hunting, adversary behaviour analysis, and high-fidelity threat detection across enterprise environments. This role goes beyond reactive alert handling. You will actively hunt for malicious activity using telemetry, SIEM data, and threat intelligence, develop hypotheses based on MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs), and support incident management and response activities when threats are identified. We are open to experienced SOC Analysts where threat hunting, investigations, and proactive detection have formed a significant part of their role, and who are looking to further develop in a more hunting-led environment. This position is well suited to analysts who enjoy thinking like an attacker, have worked alongside or supported red team or purple team activities, and want to deepen their expertise in threat detection and detection engineering. Skills & Experience We're Seeking Experience in threat hunting, cyber threat detection, SOC, blue team, or cyber defence environments, with ideally around five years hands on experience. Strong hands-on experience using SIEM platforms, including: Microsoft Sentinel (KQL) Splunk (SPL) Elastic Security/Kibana (KQL, ESQL) Practical and operational understanding of MITRE ATT&CK, attacker techniques, and adversary tradecraft Experience working with Indicators of Compromise (IOCs) and threat intelligence feeds Solid experience across the security event life cycle, including detection, investigation, and incident management Hands-on experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike, SentinelOne, or Carbon Black Strong knowledge of networking fundamentals (TCP/IP, DNS, HTTP/S, Firewalls, VPNs, Proxy technologies) Experience analysing telemetry from Windows, Linux, identity, endpoint, and network sources Strong analytical mindset with the ability to clearly communicate findings, impact, and risk Key Responsibilities Conduct proactive threat hunting activities across log, endpoint, and network telemetry to identify suspicious, stealthy, or previously unknown threats Develop and execute hunt hypotheses aligned to MITRE ATT&CK TTPs, adversary behaviours, and emerging threat intelligence Write, refine, and optimise SIEM queries using KQL, SPL, Elastic/ESQL, and Kibana Query Language Perform IOC analysis, enrichment, and validation, integrating internal and external threat intelligence sources Lead investigations from initial detection through scoping, root cause analysis, and impact assessment Support incident management and incident response activities, including containment, remediation, escalation, and lessons learned Collaborate closely with SOC teams, incident responders, red teams, and purple teams to validate detections and improve defensive coverage Contribute to detection logic improvements, use-case development, and continuous enhancement of hunting methodologies Produce clear investigation write-ups, timelines, and recommendations for technical and non-technical stakeholders Security Certifications (Highly Beneficial) SANS/GIAC certifications, including but not limited to: GCIH - Incident Handler GCIA - Intrusion Analyst GCED - Enterprise Defender GCTI - Cyber Threat Intelligence GMON - Continuous Monitoring GDAT - Defending Advanced Threats GCAT - Advanced Threat Intelligence OSCP or equivalent offensive security qualifications Crest certifications, such as: Crest Practitioner Intrusion Analyst (CPIA) Crest Registered Intrusion Analyst (CRIA) Crest Certified Threat Intelligence Analyst (CCTIA) Crest Certified Blue Team Professional (CCBTP) Microsoft SC-200 or related detection and response certifications Other recognised cyber security or threat intelligence credentials
May 20, 2026
Full time
SOC / Cyber Threat Detection Analyst - SANS/GIAC Cyber Threat Detection Analyst Location: Wokingham, Berkshire (On-site) Salary: Competitive (dependent on experience) + excellent benefits & training Security Clearance: Ideally SC Cleared or eligible for SC Role Overview As a Cyber Threat Detection Analyst, you will play a hands-on role within an advanced cyber defence function, focused on proactive threat hunting, adversary behaviour analysis, and high-fidelity threat detection across enterprise environments. This role goes beyond reactive alert handling. You will actively hunt for malicious activity using telemetry, SIEM data, and threat intelligence, develop hypotheses based on MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs), and support incident management and response activities when threats are identified. We are open to experienced SOC Analysts where threat hunting, investigations, and proactive detection have formed a significant part of their role, and who are looking to further develop in a more hunting-led environment. This position is well suited to analysts who enjoy thinking like an attacker, have worked alongside or supported red team or purple team activities, and want to deepen their expertise in threat detection and detection engineering. Skills & Experience We're Seeking Experience in threat hunting, cyber threat detection, SOC, blue team, or cyber defence environments, with ideally around five years hands on experience. Strong hands-on experience using SIEM platforms, including: Microsoft Sentinel (KQL) Splunk (SPL) Elastic Security/Kibana (KQL, ESQL) Practical and operational understanding of MITRE ATT&CK, attacker techniques, and adversary tradecraft Experience working with Indicators of Compromise (IOCs) and threat intelligence feeds Solid experience across the security event life cycle, including detection, investigation, and incident management Hands-on experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike, SentinelOne, or Carbon Black Strong knowledge of networking fundamentals (TCP/IP, DNS, HTTP/S, Firewalls, VPNs, Proxy technologies) Experience analysing telemetry from Windows, Linux, identity, endpoint, and network sources Strong analytical mindset with the ability to clearly communicate findings, impact, and risk Key Responsibilities Conduct proactive threat hunting activities across log, endpoint, and network telemetry to identify suspicious, stealthy, or previously unknown threats Develop and execute hunt hypotheses aligned to MITRE ATT&CK TTPs, adversary behaviours, and emerging threat intelligence Write, refine, and optimise SIEM queries using KQL, SPL, Elastic/ESQL, and Kibana Query Language Perform IOC analysis, enrichment, and validation, integrating internal and external threat intelligence sources Lead investigations from initial detection through scoping, root cause analysis, and impact assessment Support incident management and incident response activities, including containment, remediation, escalation, and lessons learned Collaborate closely with SOC teams, incident responders, red teams, and purple teams to validate detections and improve defensive coverage Contribute to detection logic improvements, use-case development, and continuous enhancement of hunting methodologies Produce clear investigation write-ups, timelines, and recommendations for technical and non-technical stakeholders Security Certifications (Highly Beneficial) SANS/GIAC certifications, including but not limited to: GCIH - Incident Handler GCIA - Intrusion Analyst GCED - Enterprise Defender GCTI - Cyber Threat Intelligence GMON - Continuous Monitoring GDAT - Defending Advanced Threats GCAT - Advanced Threat Intelligence OSCP or equivalent offensive security qualifications Crest certifications, such as: Crest Practitioner Intrusion Analyst (CPIA) Crest Registered Intrusion Analyst (CRIA) Crest Certified Threat Intelligence Analyst (CCTIA) Crest Certified Blue Team Professional (CCBTP) Microsoft SC-200 or related detection and response certifications Other recognised cyber security or threat intelligence credentials
Proactive Appointments
SOC Engineer
Proactive Appointments Milton Keynes, Buckinghamshire
SOC Engineer Milton Keynes We are seeking a hands-on SOC Engineer with strong SIEM and security monitoring experience to join a fast-paced Cyber Security Operations Centre. This role requires both soft and technical skills, focused on the engineering, optimisation, and support of SOC tooling, telemetry, and detection capabilities to improve threat visibility and incident response across hybrid environments. Key Responsibilities Operate, support, and tune SIEM and security monitoring platforms, including Graylog and Splunk. Maintain and optimise log ingestion pipelines across multiple data sources. Develop and refine detection rules, alerts, dashboards, and SOC playbooks. Support incident response, investigation, and containment activities. Automate SOC processes and workflows using scripting tools such as PowerShell, Python, or Bash. Integrate new systems and infrastructure into SOC monitoring and visibility. Work closely with cyber engineering and infrastructure teams to improve security telemetry and operational resilience. Skills & Experience Experience working with SIEM, detection, response, and log management platforms. Strong understanding of networking concepts including TCP/IP, DNS, firewalls, and proxies. Knowledge of Windows and Linux systems administration, logging, and monitoring. Experience in SOC, NOC, or other 24/7 operational environments. Scripting and automation experience (PowerShell, Python, Bash). Familiarity with cloud and on-premise infrastructure monitoring. Understanding of security frameworks and detection methodologies. Additional Information Must be eligible to obtain Security Clearance (SC). Due to the volume of applications received for positions, it will not be possible to respond to all applications and only applicants who are considered suitable for interview will be contacted. Proactive Appointments Limited operates as an employment agency and employment business and is an equal opportunities organisation We take our obligations to protect your personal data very seriously. Any information provided to us will be processed as detailed in our Privacy Notice, a copy of which can be found on our website
May 20, 2026
Full time
SOC Engineer Milton Keynes We are seeking a hands-on SOC Engineer with strong SIEM and security monitoring experience to join a fast-paced Cyber Security Operations Centre. This role requires both soft and technical skills, focused on the engineering, optimisation, and support of SOC tooling, telemetry, and detection capabilities to improve threat visibility and incident response across hybrid environments. Key Responsibilities Operate, support, and tune SIEM and security monitoring platforms, including Graylog and Splunk. Maintain and optimise log ingestion pipelines across multiple data sources. Develop and refine detection rules, alerts, dashboards, and SOC playbooks. Support incident response, investigation, and containment activities. Automate SOC processes and workflows using scripting tools such as PowerShell, Python, or Bash. Integrate new systems and infrastructure into SOC monitoring and visibility. Work closely with cyber engineering and infrastructure teams to improve security telemetry and operational resilience. Skills & Experience Experience working with SIEM, detection, response, and log management platforms. Strong understanding of networking concepts including TCP/IP, DNS, firewalls, and proxies. Knowledge of Windows and Linux systems administration, logging, and monitoring. Experience in SOC, NOC, or other 24/7 operational environments. Scripting and automation experience (PowerShell, Python, Bash). Familiarity with cloud and on-premise infrastructure monitoring. Understanding of security frameworks and detection methodologies. Additional Information Must be eligible to obtain Security Clearance (SC). Due to the volume of applications received for positions, it will not be possible to respond to all applications and only applicants who are considered suitable for interview will be contacted. Proactive Appointments Limited operates as an employment agency and employment business and is an equal opportunities organisation We take our obligations to protect your personal data very seriously. Any information provided to us will be processed as detailed in our Privacy Notice, a copy of which can be found on our website
Precise Placements
SOC Engineer - 6 Month FTC
Precise Placements
SOC Engineer - SIEM, Exabeam, SOAR, EDR, IDS/IPS, MITRE, Azure, SC-200, SC-100, Our leading global law firm client are currently looking to take on a new SOC Engineer (SIEM, Exabeam, SOAR, EDR, IDS/IPS, MITRE, Azure, SC-200, SC-100) to join their team on a contractual basis. The firm are an extremely modern law firm which offer a healthy hybrid working solution 2-3 days per week in London and offer a great deal of autonomy and technical exposure. This SOC Engineer (SIEM, Exabeam, SOAR, EDR, IDS/IPS, MITRE, Azure, SC-200, SC-100) role, will be responsible for the enhancement of existing SIEM platform and improve performance, coverage and fidelity by conducting regular assessments of the SIEM architecture. To be considered for this SOC Engineer (SIEM, Exabeam, SOAR, EDR, IDS/IPS, MITRE, Azure, SC-200, SC-100)Defender) role, it's ideal you have: 3 + years within a similar role Ideal but not required law firm experience Security qualifications such as CISSP, CISM, CEH, CompTIA Sec+ or others SIEM Engineering & Maturity Enhance and optimise the existing SIEM platform to improve performance, coverage, and fidelity. Conduct regular assessments of SIEM architecture and propose improvements to ingestion pipelines, parsing rules, correlation logic, and storage management. Implement automation and orchestration components (SOAR) to streamline incident response activities. Log Source Onboarding & Integration Identify, prioritise, and onboard new log sources from cloud, on-prem, network, endpoint, identity, and application platforms. Develop and maintain custom parsers, connectors, and ingestion playbooks. Work with internal teams and vendors to ensure high-quality, reliable telemetry and error-free ingestion. Use Case & Detection Content Development Design, implement, test, and tune detection use cases based on attacker techniques (MITRE ATT&CK), threat intelligence, and risk appetite. Build correlation rules, anomaly-based detections, dashboards, and alerting workflows. Regularly review detection efficacy and reduce false positives through tuning and logic refinement. SOC Support & Incident Response Work closely with SOC analysts to validate and refine detection logic. Support incident investigations through SIEM searches, enrichment, and data modelling. Provide technical SME support for complex incidents that require deep SIEM or log knowledge. Documentation & Governance Maintain high-quality documentation covering data models, feed onboarding, use cases, correlation logic, and architecture. Ensure alignment with internal controls, compliance requirements, and industry standards. Education, Skills & Experience Technical Expertise Hands-on experience with leading SIEM platforms (e.g., Exabeam, LogRhythm, ArcSight, Microsoft Sentinel, Splunk, QRadar, Elastic). Strong understanding of log formats (JSON, syslog, XML, CEF, etc.) and ingestion technologies (Syslog, API, Event Hubs, Kafka, Agents). Practical knowledge of detection engineering, threat modelling, and attacker behaviour analysis. Experience building and tuning correlation rules, searches, and dashboards. Familiarity with SOAR platforms and automation workflows. Security Knowledge Strong understanding of networking, Windows/Linux systems, Cloud platforms (Azure/AWS/GCP), identity systems, and endpoint protection technologies (e.g. SentinelOne and Microsoft Defender) Knowledge of MITRE ATT&CK, cyber kill chain, and threat hunting methodologies. Must Have Level 4 or higher qualification in a computing subject, or equivalent experience IT experience including both IT Infrastructure and Information Security roles Relevant professional certifications that validate the fundamental skills required to perform the role, e.g. GIAC (GCIA,GCDA,GMON) Microsoft SC-200/SC-100, CompTIA Secure Infrastructure Specialist (CSIS), SSCP/CISSP etc Strong skill level in scripting technologies, including Python, MS PowerShell and PowerApps Ability to conduct research into Infrastructure issues and products as required Self-starting with strong interpersonal, written, and oral communication skills. Ability to engage colleagues at all levels and project a solid, professional attitude consistently. Nice to have Data Loss Prevention Secure Remote Access solutions Network Security solutions Open Source and Cyber Threat Intelligence Suitable experience working with the market leading technology vendor product suites Experience in software-defined and cloud services such as SaaS, IaaS, PaaS and DaaS Experience in Disaster Recovery Management and Business Continuity Knowledge of applicable data privacy practices and laws
May 03, 2026
Contractor
SOC Engineer - SIEM, Exabeam, SOAR, EDR, IDS/IPS, MITRE, Azure, SC-200, SC-100, Our leading global law firm client are currently looking to take on a new SOC Engineer (SIEM, Exabeam, SOAR, EDR, IDS/IPS, MITRE, Azure, SC-200, SC-100) to join their team on a contractual basis. The firm are an extremely modern law firm which offer a healthy hybrid working solution 2-3 days per week in London and offer a great deal of autonomy and technical exposure. This SOC Engineer (SIEM, Exabeam, SOAR, EDR, IDS/IPS, MITRE, Azure, SC-200, SC-100) role, will be responsible for the enhancement of existing SIEM platform and improve performance, coverage and fidelity by conducting regular assessments of the SIEM architecture. To be considered for this SOC Engineer (SIEM, Exabeam, SOAR, EDR, IDS/IPS, MITRE, Azure, SC-200, SC-100)Defender) role, it's ideal you have: 3 + years within a similar role Ideal but not required law firm experience Security qualifications such as CISSP, CISM, CEH, CompTIA Sec+ or others SIEM Engineering & Maturity Enhance and optimise the existing SIEM platform to improve performance, coverage, and fidelity. Conduct regular assessments of SIEM architecture and propose improvements to ingestion pipelines, parsing rules, correlation logic, and storage management. Implement automation and orchestration components (SOAR) to streamline incident response activities. Log Source Onboarding & Integration Identify, prioritise, and onboard new log sources from cloud, on-prem, network, endpoint, identity, and application platforms. Develop and maintain custom parsers, connectors, and ingestion playbooks. Work with internal teams and vendors to ensure high-quality, reliable telemetry and error-free ingestion. Use Case & Detection Content Development Design, implement, test, and tune detection use cases based on attacker techniques (MITRE ATT&CK), threat intelligence, and risk appetite. Build correlation rules, anomaly-based detections, dashboards, and alerting workflows. Regularly review detection efficacy and reduce false positives through tuning and logic refinement. SOC Support & Incident Response Work closely with SOC analysts to validate and refine detection logic. Support incident investigations through SIEM searches, enrichment, and data modelling. Provide technical SME support for complex incidents that require deep SIEM or log knowledge. Documentation & Governance Maintain high-quality documentation covering data models, feed onboarding, use cases, correlation logic, and architecture. Ensure alignment with internal controls, compliance requirements, and industry standards. Education, Skills & Experience Technical Expertise Hands-on experience with leading SIEM platforms (e.g., Exabeam, LogRhythm, ArcSight, Microsoft Sentinel, Splunk, QRadar, Elastic). Strong understanding of log formats (JSON, syslog, XML, CEF, etc.) and ingestion technologies (Syslog, API, Event Hubs, Kafka, Agents). Practical knowledge of detection engineering, threat modelling, and attacker behaviour analysis. Experience building and tuning correlation rules, searches, and dashboards. Familiarity with SOAR platforms and automation workflows. Security Knowledge Strong understanding of networking, Windows/Linux systems, Cloud platforms (Azure/AWS/GCP), identity systems, and endpoint protection technologies (e.g. SentinelOne and Microsoft Defender) Knowledge of MITRE ATT&CK, cyber kill chain, and threat hunting methodologies. Must Have Level 4 or higher qualification in a computing subject, or equivalent experience IT experience including both IT Infrastructure and Information Security roles Relevant professional certifications that validate the fundamental skills required to perform the role, e.g. GIAC (GCIA,GCDA,GMON) Microsoft SC-200/SC-100, CompTIA Secure Infrastructure Specialist (CSIS), SSCP/CISSP etc Strong skill level in scripting technologies, including Python, MS PowerShell and PowerApps Ability to conduct research into Infrastructure issues and products as required Self-starting with strong interpersonal, written, and oral communication skills. Ability to engage colleagues at all levels and project a solid, professional attitude consistently. Nice to have Data Loss Prevention Secure Remote Access solutions Network Security solutions Open Source and Cyber Threat Intelligence Suitable experience working with the market leading technology vendor product suites Experience in software-defined and cloud services such as SaaS, IaaS, PaaS and DaaS Experience in Disaster Recovery Management and Business Continuity Knowledge of applicable data privacy practices and laws
Adecco
SOC / Cyber Threat Detection Analyst - SANS/GIAC
Adecco Wokingham, Berkshire
SOC / Cyber Threat Detection Analyst - SANS/GIAC Cyber Threat Detection Analyst Location: Wokingham, Berkshire (On-site) Salary: Competitive (dependent on experience) + excellent benefits & training Security Clearance: Ideally SC Cleared or eligible for SC Role Overview As a Cyber Threat Detection Analyst, you will play a hands-on role within an advanced cyber defence function, focused on proactive threat hunting, adversary behaviour analysis, and high-fidelity threat detection across enterprise environments. This role goes beyond reactive alert handling. You will actively hunt for malicious activity using telemetry, SIEM data, and threat intelligence, develop hypotheses based on MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs), and support incident management and response activities when threats are identified. We are open to experienced SOC Analysts where threat hunting, investigations, and proactive detection have formed a significant part of their role, and who are looking to further develop in a more hunting-led environment. This position is well suited to analysts who enjoy thinking like an attacker, have worked alongside or supported red team or purple team activities, and want to deepen their expertise in threat detection and detection engineering. Skills & Experience We're Seeking Experience in threat hunting, cyber threat detection, SOC, blue team, or cyber defence environments, with ideally around five years hands on experience. Strong hands-on experience using SIEM platforms, including: Microsoft Sentinel (KQL) Splunk (SPL) Elastic Security/Kibana (KQL, ESQL) Practical and operational understanding of MITRE ATT&CK, attacker techniques, and adversary tradecraft Experience working with Indicators of Compromise (IOCs) and threat intelligence feeds Solid experience across the security event life cycle, including detection, investigation, and incident management Hands-on experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike, SentinelOne, or Carbon Black Strong knowledge of networking fundamentals (TCP/IP, DNS, HTTP/S, Firewalls, VPNs, Proxy technologies) Experience analysing telemetry from Windows, Linux, identity, endpoint, and network sources Strong analytical mindset with the ability to clearly communicate findings, impact, and risk Key Responsibilities Conduct proactive threat hunting activities across log, endpoint, and network telemetry to identify suspicious, stealthy, or previously unknown threats Develop and execute hunt hypotheses aligned to MITRE ATT&CK TTPs, adversary behaviours, and emerging threat intelligence Write, refine, and optimise SIEM queries using KQL, SPL, Elastic/ESQL, and Kibana Query Language Perform IOC analysis, enrichment, and validation, integrating internal and external threat intelligence sources Lead investigations from initial detection through scoping, root cause analysis, and impact assessment Support incident management and incident response activities, including containment, remediation, escalation, and lessons learned Collaborate closely with SOC teams, incident responders, red teams, and purple teams to validate detections and improve defensive coverage Contribute to detection logic improvements, use-case development, and continuous enhancement of hunting methodologies Produce clear investigation write-ups, timelines, and recommendations for technical and non-technical stakeholders Security Certifications (Highly Beneficial) SANS/GIAC certifications, including but not limited to: GCIH - Incident Handler GCIA - Intrusion Analyst GCED - Enterprise Defender GCTI - Cyber Threat Intelligence GMON - Continuous Monitoring GDAT - Defending Advanced Threats GCAT - Advanced Threat Intelligence OSCP or equivalent offensive security qualifications Crest certifications, such as: Crest Practitioner Intrusion Analyst (CPIA) Crest Registered Intrusion Analyst (CRIA) Crest Certified Threat Intelligence Analyst (CCTIA) Crest Certified Blue Team Professional (CCBTP) Microsoft SC-200 or related detection and response certifications Other recognised cyber security or threat intelligence credentials
Apr 30, 2026
Full time
SOC / Cyber Threat Detection Analyst - SANS/GIAC Cyber Threat Detection Analyst Location: Wokingham, Berkshire (On-site) Salary: Competitive (dependent on experience) + excellent benefits & training Security Clearance: Ideally SC Cleared or eligible for SC Role Overview As a Cyber Threat Detection Analyst, you will play a hands-on role within an advanced cyber defence function, focused on proactive threat hunting, adversary behaviour analysis, and high-fidelity threat detection across enterprise environments. This role goes beyond reactive alert handling. You will actively hunt for malicious activity using telemetry, SIEM data, and threat intelligence, develop hypotheses based on MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs), and support incident management and response activities when threats are identified. We are open to experienced SOC Analysts where threat hunting, investigations, and proactive detection have formed a significant part of their role, and who are looking to further develop in a more hunting-led environment. This position is well suited to analysts who enjoy thinking like an attacker, have worked alongside or supported red team or purple team activities, and want to deepen their expertise in threat detection and detection engineering. Skills & Experience We're Seeking Experience in threat hunting, cyber threat detection, SOC, blue team, or cyber defence environments, with ideally around five years hands on experience. Strong hands-on experience using SIEM platforms, including: Microsoft Sentinel (KQL) Splunk (SPL) Elastic Security/Kibana (KQL, ESQL) Practical and operational understanding of MITRE ATT&CK, attacker techniques, and adversary tradecraft Experience working with Indicators of Compromise (IOCs) and threat intelligence feeds Solid experience across the security event life cycle, including detection, investigation, and incident management Hands-on experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike, SentinelOne, or Carbon Black Strong knowledge of networking fundamentals (TCP/IP, DNS, HTTP/S, Firewalls, VPNs, Proxy technologies) Experience analysing telemetry from Windows, Linux, identity, endpoint, and network sources Strong analytical mindset with the ability to clearly communicate findings, impact, and risk Key Responsibilities Conduct proactive threat hunting activities across log, endpoint, and network telemetry to identify suspicious, stealthy, or previously unknown threats Develop and execute hunt hypotheses aligned to MITRE ATT&CK TTPs, adversary behaviours, and emerging threat intelligence Write, refine, and optimise SIEM queries using KQL, SPL, Elastic/ESQL, and Kibana Query Language Perform IOC analysis, enrichment, and validation, integrating internal and external threat intelligence sources Lead investigations from initial detection through scoping, root cause analysis, and impact assessment Support incident management and incident response activities, including containment, remediation, escalation, and lessons learned Collaborate closely with SOC teams, incident responders, red teams, and purple teams to validate detections and improve defensive coverage Contribute to detection logic improvements, use-case development, and continuous enhancement of hunting methodologies Produce clear investigation write-ups, timelines, and recommendations for technical and non-technical stakeholders Security Certifications (Highly Beneficial) SANS/GIAC certifications, including but not limited to: GCIH - Incident Handler GCIA - Intrusion Analyst GCED - Enterprise Defender GCTI - Cyber Threat Intelligence GMON - Continuous Monitoring GDAT - Defending Advanced Threats GCAT - Advanced Threat Intelligence OSCP or equivalent offensive security qualifications Crest certifications, such as: Crest Practitioner Intrusion Analyst (CPIA) Crest Registered Intrusion Analyst (CRIA) Crest Certified Threat Intelligence Analyst (CCTIA) Crest Certified Blue Team Professional (CCBTP) Microsoft SC-200 or related detection and response certifications Other recognised cyber security or threat intelligence credentials
Adecco
Cyber Threat Detection / SOC Analyst - SANS/GIAC
Adecco Wokingham, Berkshire
SOC / Cyber Threat Detection Analyst - SANS/GIAC Cyber Threat Detection Analyst Location: Wokingham, Berkshire (On-site) Salary: Competitive (dependent on experience) + excellent benefits & training Security Clearance: Ideally SC Cleared or eligible for SC Role Overview As a Cyber Threat Detection Analyst, you will play a hands-on role within an advanced cyber defence function, focused on proactive threat hunting, adversary behaviour analysis, and high-fidelity threat detection across enterprise environments. This role goes beyond reactive alert handling. You will actively hunt for malicious activity using telemetry, SIEM data, and threat intelligence, develop hypotheses based on MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs), and support incident management and response activities when threats are identified. We are open to experienced SOC Analysts where threat hunting, investigations, and proactive detection have formed a significant part of their role, and who are looking to further develop in a more hunting-led environment. This position is well suited to analysts who enjoy thinking like an attacker, have worked alongside or supported red team or purple team activities, and want to deepen their expertise in threat detection and detection engineering. Skills & Experience We're Seeking Experience in threat hunting, cyber threat detection, SOC, blue team, or cyber defence environments, with ideally around five years hands on experience. Strong hands-on experience using SIEM platforms, including: Microsoft Sentinel (KQL) Splunk (SPL) Elastic Security/Kibana (KQL, ESQL) Practical and operational understanding of MITRE ATT&CK, attacker techniques, and adversary tradecraft Experience working with Indicators of Compromise (IOCs) and threat intelligence feeds Solid experience across the security event life cycle, including detection, investigation, and incident management Hands-on experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike, SentinelOne, or Carbon Black Strong knowledge of networking fundamentals (TCP/IP, DNS, HTTP/S, Firewalls, VPNs, Proxy technologies) Experience analysing telemetry from Windows, Linux, identity, endpoint, and network sources Strong analytical mindset with the ability to clearly communicate findings, impact, and risk Key Responsibilities Conduct proactive threat hunting activities across log, endpoint, and network telemetry to identify suspicious, stealthy, or previously unknown threats Develop and execute hunt hypotheses aligned to MITRE ATT&CK TTPs, adversary behaviours, and emerging threat intelligence Write, refine, and optimise SIEM queries using KQL, SPL, Elastic/ESQL, and Kibana Query Language Perform IOC analysis, enrichment, and validation, integrating internal and external threat intelligence sources Lead investigations from initial detection through scoping, root cause analysis, and impact assessment Support incident management and incident response activities, including containment, remediation, escalation, and lessons learned Collaborate closely with SOC teams, incident responders, red teams, and purple teams to validate detections and improve defensive coverage Contribute to detection logic improvements, use-case development, and continuous enhancement of hunting methodologies Produce clear investigation write-ups, timelines, and recommendations for technical and non-technical stakeholders Security Certifications (Highly Beneficial) SANS/GIAC certifications, including but not limited to: GCIH - Incident Handler GCIA - Intrusion Analyst GCED - Enterprise Defender GCTI - Cyber Threat Intelligence GMON - Continuous Monitoring GDAT - Defending Advanced Threats GCAT - Advanced Threat Intelligence OSCP or equivalent offensive security qualifications Crest certifications, such as: Crest Practitioner Intrusion Analyst (CPIA) Crest Registered Intrusion Analyst (CRIA) Crest Certified Threat Intelligence Analyst (CCTIA) Crest Certified Blue Team Professional (CCBTP) Microsoft SC-200 or related detection and response certifications Other recognised cyber security or threat intelligence credentials
Apr 30, 2026
Full time
SOC / Cyber Threat Detection Analyst - SANS/GIAC Cyber Threat Detection Analyst Location: Wokingham, Berkshire (On-site) Salary: Competitive (dependent on experience) + excellent benefits & training Security Clearance: Ideally SC Cleared or eligible for SC Role Overview As a Cyber Threat Detection Analyst, you will play a hands-on role within an advanced cyber defence function, focused on proactive threat hunting, adversary behaviour analysis, and high-fidelity threat detection across enterprise environments. This role goes beyond reactive alert handling. You will actively hunt for malicious activity using telemetry, SIEM data, and threat intelligence, develop hypotheses based on MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs), and support incident management and response activities when threats are identified. We are open to experienced SOC Analysts where threat hunting, investigations, and proactive detection have formed a significant part of their role, and who are looking to further develop in a more hunting-led environment. This position is well suited to analysts who enjoy thinking like an attacker, have worked alongside or supported red team or purple team activities, and want to deepen their expertise in threat detection and detection engineering. Skills & Experience We're Seeking Experience in threat hunting, cyber threat detection, SOC, blue team, or cyber defence environments, with ideally around five years hands on experience. Strong hands-on experience using SIEM platforms, including: Microsoft Sentinel (KQL) Splunk (SPL) Elastic Security/Kibana (KQL, ESQL) Practical and operational understanding of MITRE ATT&CK, attacker techniques, and adversary tradecraft Experience working with Indicators of Compromise (IOCs) and threat intelligence feeds Solid experience across the security event life cycle, including detection, investigation, and incident management Hands-on experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike, SentinelOne, or Carbon Black Strong knowledge of networking fundamentals (TCP/IP, DNS, HTTP/S, Firewalls, VPNs, Proxy technologies) Experience analysing telemetry from Windows, Linux, identity, endpoint, and network sources Strong analytical mindset with the ability to clearly communicate findings, impact, and risk Key Responsibilities Conduct proactive threat hunting activities across log, endpoint, and network telemetry to identify suspicious, stealthy, or previously unknown threats Develop and execute hunt hypotheses aligned to MITRE ATT&CK TTPs, adversary behaviours, and emerging threat intelligence Write, refine, and optimise SIEM queries using KQL, SPL, Elastic/ESQL, and Kibana Query Language Perform IOC analysis, enrichment, and validation, integrating internal and external threat intelligence sources Lead investigations from initial detection through scoping, root cause analysis, and impact assessment Support incident management and incident response activities, including containment, remediation, escalation, and lessons learned Collaborate closely with SOC teams, incident responders, red teams, and purple teams to validate detections and improve defensive coverage Contribute to detection logic improvements, use-case development, and continuous enhancement of hunting methodologies Produce clear investigation write-ups, timelines, and recommendations for technical and non-technical stakeholders Security Certifications (Highly Beneficial) SANS/GIAC certifications, including but not limited to: GCIH - Incident Handler GCIA - Intrusion Analyst GCED - Enterprise Defender GCTI - Cyber Threat Intelligence GMON - Continuous Monitoring GDAT - Defending Advanced Threats GCAT - Advanced Threat Intelligence OSCP or equivalent offensive security qualifications Crest certifications, such as: Crest Practitioner Intrusion Analyst (CPIA) Crest Registered Intrusion Analyst (CRIA) Crest Certified Threat Intelligence Analyst (CCTIA) Crest Certified Blue Team Professional (CCBTP) Microsoft SC-200 or related detection and response certifications Other recognised cyber security or threat intelligence credentials

Modal Window

  • Home
  • Contact
  • About Us
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • Facebook
  • Twitter
  • Google Plus
  • LinkedIn
Parent and Partner sites: IT Job Board | Jobs Near Me | RightTalent.co.uk | Quantity Surveyor jobs | Building Surveyor jobs | Construction Recruitment | Talent Recruiter | Construction Job Board | Property jobs | myJobsnearme.com | Jobs near me
© 2008-2026 Jobsite Jobs | Designed by Web Design Agency