• Home
  • Search Jobs
  • Register CV
  • Post a Job
  • Employer Pricing
  • Contact Us
  • Sign in
  • Sign up
  • Home
  • Search Jobs
  • Register CV
  • Post a Job
  • Employer Pricing
  • Contact Us
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

16 jobs found

Email me jobs like this
Refine Search
Current Search
soc engineer defender sentinel
Ibex Recruitment LTD
SOC Engineer
Ibex Recruitment LTD
We recruiting for an exciting opportunity within a highly regulated environment. We're looking forSOC Engineers(both Junior and Senior levels) to join a growing Cyber Security team, engineering and optimising Microsoft Sentinel, Defender XDR, and SOAR capabilities. This isn't a pure triage/analyst role we needengineerswho can build, tune, automate, and scale our detection platform click apply for full job details
Aug 24, 2026
Full time
We recruiting for an exciting opportunity within a highly regulated environment. We're looking forSOC Engineers(both Junior and Senior levels) to join a growing Cyber Security team, engineering and optimising Microsoft Sentinel, Defender XDR, and SOAR capabilities. This isn't a pure triage/analyst role we needengineerswho can build, tune, automate, and scale our detection platform click apply for full job details
EXPERIS
Senior SOC Engineer
EXPERIS
Senior SecOps Engineer - Microsoft Security UK Predominantly Remote Occasional presence in London Permanent We are partnering with a specialist Microsoft Security organisation looking to appoint two highly experienced Senior SecOps Engineers to its growing Microsoft Cyber Engineering team. This is not a traditional SOC Analyst position. We are looking for technically strong Microsoft Security Engineers with genuine hands-on experience designing, implementing, engineering and optimising Microsoft Sentinel and Defender solutions within enterprise customer environments. The organisation works extensively across the Microsoft Security portfolio and is looking for individuals who can bring significant technical depth while remaining hands-on with complex customer environments. The Role Working alongside Security Engineers, SOC Analysts and wider delivery teams, you will take responsibility for the implementation, optimisation and ongoing improvement of Microsoft security solutions. Responsibilities will include: Design, implementation and support of Microsoft Sentinel and Microsoft Defender / Defender XDR Engineering and optimisation of SIEM capabilities across enterprise environments Developing and tuning KQL queries, analytics and detection rules Designing and implementing SOC automation, playbooks and scripting Improving security event detection and response capabilities Conducting Microsoft tenant health checks, security audits and architecture reviews Analysing cloud security risks and recommending appropriate security controls Supporting complex incident triage and resolution Designing and documenting security engineering standards and processes Researching and implementing new Microsoft security capabilities Producing high-quality technical and customer-facing documentation Working directly with customers and technical stakeholders Supporting and mentoring more junior members of the engineering team Essential Experience To be considered, you should have strong commercial experience across the following: Microsoft Sentinel / Azure Sentinel Microsoft Defender / Defender XDR Strong KQL / Kusto Query Language capability Security Engineering, SOC Engineering or Microsoft Security Consulting SIEM engineering rather than solely alert monitoring or incident triage Detection engineering and security monitoring optimisation Automation, scripting, SOAR or Sentinel playbooks Cloud security assessments, controls and risk analysis Designing and documenting security processes Customer-facing technical delivery Candidates whose experience is predominantly L1/L2 SOC monitoring without hands-on Sentinel and Defender engineering are unlikely to be suitable for this position. Highly Desirable Experience across any of the following would be particularly valuable: Microsoft Purview Microsoft Defender for Endpoint Defender for Cloud Defender for Identity Defender for Office 365 Microsoft Entra ID Intune Azure security architecture Logic Apps / Sentinel playbooks PowerShell or Python MITRE ATT&CK Microsoft Security architecture and tenant assessments Previous experience working directly for Microsoft , or within a leading Microsoft Security Partner, MSSP or specialist Microsoft consultancy, would be highly advantageous. Microsoft Certifications Relevant Microsoft certifications are strongly preferred, particularly: SC-200 - Microsoft Security Operations Analyst AZ-500 - Azure Security Engineer Associate AZ-104 - Azure Administrator Associate AZ-305 - Azure Solutions Architect Expert Equivalent or additional Microsoft Security certifications will also be considered. The Opportunity This is an opportunity to join a highly specialised Microsoft Security environment rather than a broad IT or generalist cybersecurity function. You'll work alongside experienced security professionals on complex customer engagements, with significant exposure to the wider Microsoft Security ecosystem and continued investment in technical training and development. The position would particularly suit an established Microsoft Security Engineer who wants to remain technically hands-on while taking greater ownership of solution design, engineering standards, customer environments and the development of security operations capabilities. If your core expertise sits across Microsoft Sentinel, Defender and Security Operations Engineering , email your CV If you receive suspicious outreach claiming to be from us, please contact us via the ManpowerGroup website.
Aug 23, 2026
Full time
Senior SecOps Engineer - Microsoft Security UK Predominantly Remote Occasional presence in London Permanent We are partnering with a specialist Microsoft Security organisation looking to appoint two highly experienced Senior SecOps Engineers to its growing Microsoft Cyber Engineering team. This is not a traditional SOC Analyst position. We are looking for technically strong Microsoft Security Engineers with genuine hands-on experience designing, implementing, engineering and optimising Microsoft Sentinel and Defender solutions within enterprise customer environments. The organisation works extensively across the Microsoft Security portfolio and is looking for individuals who can bring significant technical depth while remaining hands-on with complex customer environments. The Role Working alongside Security Engineers, SOC Analysts and wider delivery teams, you will take responsibility for the implementation, optimisation and ongoing improvement of Microsoft security solutions. Responsibilities will include: Design, implementation and support of Microsoft Sentinel and Microsoft Defender / Defender XDR Engineering and optimisation of SIEM capabilities across enterprise environments Developing and tuning KQL queries, analytics and detection rules Designing and implementing SOC automation, playbooks and scripting Improving security event detection and response capabilities Conducting Microsoft tenant health checks, security audits and architecture reviews Analysing cloud security risks and recommending appropriate security controls Supporting complex incident triage and resolution Designing and documenting security engineering standards and processes Researching and implementing new Microsoft security capabilities Producing high-quality technical and customer-facing documentation Working directly with customers and technical stakeholders Supporting and mentoring more junior members of the engineering team Essential Experience To be considered, you should have strong commercial experience across the following: Microsoft Sentinel / Azure Sentinel Microsoft Defender / Defender XDR Strong KQL / Kusto Query Language capability Security Engineering, SOC Engineering or Microsoft Security Consulting SIEM engineering rather than solely alert monitoring or incident triage Detection engineering and security monitoring optimisation Automation, scripting, SOAR or Sentinel playbooks Cloud security assessments, controls and risk analysis Designing and documenting security processes Customer-facing technical delivery Candidates whose experience is predominantly L1/L2 SOC monitoring without hands-on Sentinel and Defender engineering are unlikely to be suitable for this position. Highly Desirable Experience across any of the following would be particularly valuable: Microsoft Purview Microsoft Defender for Endpoint Defender for Cloud Defender for Identity Defender for Office 365 Microsoft Entra ID Intune Azure security architecture Logic Apps / Sentinel playbooks PowerShell or Python MITRE ATT&CK Microsoft Security architecture and tenant assessments Previous experience working directly for Microsoft , or within a leading Microsoft Security Partner, MSSP or specialist Microsoft consultancy, would be highly advantageous. Microsoft Certifications Relevant Microsoft certifications are strongly preferred, particularly: SC-200 - Microsoft Security Operations Analyst AZ-500 - Azure Security Engineer Associate AZ-104 - Azure Administrator Associate AZ-305 - Azure Solutions Architect Expert Equivalent or additional Microsoft Security certifications will also be considered. The Opportunity This is an opportunity to join a highly specialised Microsoft Security environment rather than a broad IT or generalist cybersecurity function. You'll work alongside experienced security professionals on complex customer engagements, with significant exposure to the wider Microsoft Security ecosystem and continued investment in technical training and development. The position would particularly suit an established Microsoft Security Engineer who wants to remain technically hands-on while taking greater ownership of solution design, engineering standards, customer environments and the development of security operations capabilities. If your core expertise sits across Microsoft Sentinel, Defender and Security Operations Engineering , email your CV If you receive suspicious outreach claiming to be from us, please contact us via the ManpowerGroup website.
Reed Technology
Information Security Consultant
Reed Technology
Information Security & Assurance Officer Salary: up to 50,000 + 15% Project Uplift + Company Car/Car Allowance Location: Suffolk (onsite) REED Technology are recruiting for an Information Security & Assurance Officer to join a major UK infrastructure programme. This is a fantastic opportunity for an information security professional who enjoys balancing security governance, compliance and assurance with oversight of operational cyber security activities. You'll play a key role in maintaining the organisation's Information Security Management System (ISMS), ensuring compliance with recognised security frameworks, managing risk and assurance activities, and acting as a trusted adviser to both technical and non-technical stakeholders. This role would suit someone with experience in Information Security, GRC, Information Assurance or Cyber Security who is looking to develop their career within a highly regulated and complex environment. Key Responsibilities Own and maintain the Information Security Management System (ISMS) Ensure compliance with ISO 27001, GDPR and wider security governance requirements Develop and maintain security policies, standards and procedures Conduct security risk assessments and support internal and external audits Manage supplier and third-party security assurance activities Provide oversight of Microsoft 365 security controls, including identity and access management, MFA, endpoint protection and monitoring Work closely with SOC and security service providers to support incident management and response activities Produce security reports, dashboards and assurance documentation for senior stakeholders Deliver security awareness initiatives across the organisation Support continuous improvement of security controls, processes and governance frameworks About You We're interested in speaking with candidates who can demonstrate experience in: Information Security Governance, Risk and Compliance (GRC) Information Security Assurance and risk management ISO 27001 and Information Security Management Systems (ISMS) GDPR and data protection requirements Security audits, compliance reviews and assurance activities Supplier or third-party security assessments Security incident management and response processes Microsoft security technologies such as Defender, Sentinel, Entra ID or similar platforms Building strong relationships with stakeholders at all levels Desirable Experience Cyber Essentials or Cyber Essentials Plus NIST Cyber Security Framework Experience within infrastructure, utilities, energy, defence, engineering, financial services or other regulated sectors Professional certifications such as CISSP, CISM, ISO 27001 Lead Auditor/Implementer, Security+ or equivalent What's on Offer? 15% project uplift paid monthly Company car or car allowance Annual bonus Private medical insurance Life assurance Enhanced pension contributions 25 days annual leave plus bank holidays Additional holiday purchase scheme Professional memberships paid Ongoing training and development opportunities This is an excellent opportunity to join a high-profile programme where you'll have real ownership of information security governance and assurance, while contributing to the success of a nationally significant project. If you are interested, apply using the link provided.
Aug 21, 2026
Full time
Information Security & Assurance Officer Salary: up to 50,000 + 15% Project Uplift + Company Car/Car Allowance Location: Suffolk (onsite) REED Technology are recruiting for an Information Security & Assurance Officer to join a major UK infrastructure programme. This is a fantastic opportunity for an information security professional who enjoys balancing security governance, compliance and assurance with oversight of operational cyber security activities. You'll play a key role in maintaining the organisation's Information Security Management System (ISMS), ensuring compliance with recognised security frameworks, managing risk and assurance activities, and acting as a trusted adviser to both technical and non-technical stakeholders. This role would suit someone with experience in Information Security, GRC, Information Assurance or Cyber Security who is looking to develop their career within a highly regulated and complex environment. Key Responsibilities Own and maintain the Information Security Management System (ISMS) Ensure compliance with ISO 27001, GDPR and wider security governance requirements Develop and maintain security policies, standards and procedures Conduct security risk assessments and support internal and external audits Manage supplier and third-party security assurance activities Provide oversight of Microsoft 365 security controls, including identity and access management, MFA, endpoint protection and monitoring Work closely with SOC and security service providers to support incident management and response activities Produce security reports, dashboards and assurance documentation for senior stakeholders Deliver security awareness initiatives across the organisation Support continuous improvement of security controls, processes and governance frameworks About You We're interested in speaking with candidates who can demonstrate experience in: Information Security Governance, Risk and Compliance (GRC) Information Security Assurance and risk management ISO 27001 and Information Security Management Systems (ISMS) GDPR and data protection requirements Security audits, compliance reviews and assurance activities Supplier or third-party security assessments Security incident management and response processes Microsoft security technologies such as Defender, Sentinel, Entra ID or similar platforms Building strong relationships with stakeholders at all levels Desirable Experience Cyber Essentials or Cyber Essentials Plus NIST Cyber Security Framework Experience within infrastructure, utilities, energy, defence, engineering, financial services or other regulated sectors Professional certifications such as CISSP, CISM, ISO 27001 Lead Auditor/Implementer, Security+ or equivalent What's on Offer? 15% project uplift paid monthly Company car or car allowance Annual bonus Private medical insurance Life assurance Enhanced pension contributions 25 days annual leave plus bank holidays Additional holiday purchase scheme Professional memberships paid Ongoing training and development opportunities This is an excellent opportunity to join a high-profile programme where you'll have real ownership of information security governance and assurance, while contributing to the success of a nationally significant project. If you are interested, apply using the link provided.
Additional Resources
Threat Detection Engineer - Hybrid / Remote
Additional Resources City Of Westminster, London
Join a well-established biotech company using large-scale genetic data and AI to predict disease risk and advance precision healthcare. We re looking for a Threat Detection Engineer who thrives on innovation and technical ownership. This role is not a traditional SOC position, you ll focus on building high-impact detection capabilities, shaping how security protects sensitive genomic and AI-driven data at scale. This role offers hybrid / remote working options, a salary range of £60,000 - £80,000 and benefits. Why This Role is Exciting High autonomy: Lead projects from idea to deployment Innovation-driven: Develop cutting-edge detections beyond standard SIEM rules Collaborative: Work closely with internal teams and an outsourced SOC partner Mission-focused: Protect critical healthcare data that supports precision medicine Key Responsibilities Design and develop threat-led detections using threat intelligence and threat-hunting outputs Create novel analytic techniques for incident detection Collaborate with an MSP SOC to maintain and tune the detection catalogue Build automated reporting dashboards using Microsoft Sentinel workbooks Support security initiatives including ISO 27001 activities and KQL-based tasks Ensure monitoring coverage across cloud platforms, SaaS apps, and internal systems Contribute to documentation of processes, tools, and detection logic What You ll Bring Must-Have Skills & Experience: Previously worked as a Threat Detection Engineer or in a similar role. Strong proficiency in KQL and hands-on experience with Microsoft Sentinel Familiarity with Microsoft Defender tools (Endpoint & O365) Exposure to Azure cloud logging and Kubernetes environments Knowledge of attacker TTPs and MITRE ATT&CK frameworks Proactive, collaborative, and innovative mindset Desirable / Nice-to-Have: Experience with Python, Terraform, or CI/CD pipelines Familiarity with Microsoft Purview, Entra ID, DLP, or Insider Risk tools Understanding of ISO 27001, Agile ways of working Knowledge of statistics, data science, or AI/ML applied to cybersecurity Relevant certifications (MS-500, AZ-500, SC-series, Security+, GSOC, CCSK) Perks & Benefits Hybrid / remote working options Flexible benefits package Opportunity to innovate and make a real impact in threat detection Work in a small, fast-paced, highly collaborative team Contribute to advancing precision healthcare using genomic data and AI Ready to build next-generation threat detection and protect life-changing data Apply today! Important Information: We endeavour to process your personal data in a fair and transparent manner. In applying for this role, Additional Resources will be acting in your best interest and may contact you in relation to the role, either by email, phone, or text message. For more information see our Privacy Policy on our website. It is important you are aware of your individual rights and the provisions the company has put in place to protect your data. If you would like further information on the policy or GDPR please contact us. Additional Resources Ltd is an Employment Business and an Employment Agency as defined within The Conduct of Employment Agencies & Employment Businesses Regulations 2003.
Jul 31, 2026
Full time
Join a well-established biotech company using large-scale genetic data and AI to predict disease risk and advance precision healthcare. We re looking for a Threat Detection Engineer who thrives on innovation and technical ownership. This role is not a traditional SOC position, you ll focus on building high-impact detection capabilities, shaping how security protects sensitive genomic and AI-driven data at scale. This role offers hybrid / remote working options, a salary range of £60,000 - £80,000 and benefits. Why This Role is Exciting High autonomy: Lead projects from idea to deployment Innovation-driven: Develop cutting-edge detections beyond standard SIEM rules Collaborative: Work closely with internal teams and an outsourced SOC partner Mission-focused: Protect critical healthcare data that supports precision medicine Key Responsibilities Design and develop threat-led detections using threat intelligence and threat-hunting outputs Create novel analytic techniques for incident detection Collaborate with an MSP SOC to maintain and tune the detection catalogue Build automated reporting dashboards using Microsoft Sentinel workbooks Support security initiatives including ISO 27001 activities and KQL-based tasks Ensure monitoring coverage across cloud platforms, SaaS apps, and internal systems Contribute to documentation of processes, tools, and detection logic What You ll Bring Must-Have Skills & Experience: Previously worked as a Threat Detection Engineer or in a similar role. Strong proficiency in KQL and hands-on experience with Microsoft Sentinel Familiarity with Microsoft Defender tools (Endpoint & O365) Exposure to Azure cloud logging and Kubernetes environments Knowledge of attacker TTPs and MITRE ATT&CK frameworks Proactive, collaborative, and innovative mindset Desirable / Nice-to-Have: Experience with Python, Terraform, or CI/CD pipelines Familiarity with Microsoft Purview, Entra ID, DLP, or Insider Risk tools Understanding of ISO 27001, Agile ways of working Knowledge of statistics, data science, or AI/ML applied to cybersecurity Relevant certifications (MS-500, AZ-500, SC-series, Security+, GSOC, CCSK) Perks & Benefits Hybrid / remote working options Flexible benefits package Opportunity to innovate and make a real impact in threat detection Work in a small, fast-paced, highly collaborative team Contribute to advancing precision healthcare using genomic data and AI Ready to build next-generation threat detection and protect life-changing data Apply today! Important Information: We endeavour to process your personal data in a fair and transparent manner. In applying for this role, Additional Resources will be acting in your best interest and may contact you in relation to the role, either by email, phone, or text message. For more information see our Privacy Policy on our website. It is important you are aware of your individual rights and the provisions the company has put in place to protect your data. If you would like further information on the policy or GDPR please contact us. Additional Resources Ltd is an Employment Business and an Employment Agency as defined within The Conduct of Employment Agencies & Employment Businesses Regulations 2003.
Claranet Limited
Senior SOC Engineer
Claranet Limited Leeds, Yorkshire
Senior SOC Engineer - Microsoft Security We're looking for a senior SOC engineer to lead the design, delivery, and evolution of Microsoft-based security platforms within a fast-paced MSSP environment. This role combines hands-on engineering, customer engagement, and technical leadership to deliver high-quality, scalable security services. The Role You will take ownership of SOC-aligned platform engineering across the full lifecycle-from customer onboarding and solution design through to optimisation, maintenance, and continual improvement. You'll work closely with internal teams and customers to ensure security platforms are resilient, efficient, and aligned to evolving threat landscapes. A key part of the role is leading complex deployments and providing technical direction across SIEM, EDR, SOAR, and supporting technologies. You'll oversee platform health through proactive lifecycle management, including patching, upgrades, and service transitions, while driving improvements in detection, automation, and performance. You'll also act as a senior escalation point, mentoring engineers and helping to build capability across the team. Alongside delivery, you'll contribute to pre-sales activities, shaping solutions and supporting bids, demos, and customer discussions. Key Responsibilities Lead the design and implementation of SOC security platforms across customer environments Own end-to-end delivery, including onboarding, configuration, optimisation, and handover Manage platform lifecycle activities to maintain performance, stability, and operational readiness Drive continual improvement through enhancements to detection, automation, and scalability Act as a senior technical escalation point and mentor for the engineering team Maintain high-quality documentation, standards, and repeatable delivery practices Support pre-sales and stakeholder engagement with technical insight and solution design Core Experience & Skills You'll bring strong experience working in SOC or security engineering environments, with deep expertise in Microsoft security technologies and platform engineering. Strong hands-on experience with Microsoft Sentinel, Defender XDR, and Azure security services Proven ability to design and operate SIEM, EDR, SOAR, and log management solutions at scale Expertise in KQL for detection engineering, tuning, and performance optimisation Experience building and maintaining automation using Logic Apps and related tooling Solid understanding of telemetry pipelines, integration patterns, and security architecture Familiarity with frameworks such as MITRE ATT&CK and modern detection practices Strong troubleshooting and problem-solving skills across complex, integrated environments Experience in MSSP environments and working across multi-tenant platforms is highly desirable, particularly where you've contributed to service development, standardisation, and platform evolution. How You Work You're a confident communicator who can translate complex technical concepts into clear, actionable insights for both technical and non-technical audiences. You're comfortable leading engineering delivery, making decisions under pressure, and balancing customer needs with operational constraints. You thrive in collaborative environments, working closely with SOC analysts, detection engineers, sales teams, and optimisation specialists to deliver effective security outcomes. You also take an active role in mentoring others, supporting continuous learning and capability growth within the team. Additional Information You may be required to obtain UK security clearance (NPPV/SC) Some travel may be required for customer engagement and collaboration Growth & Development You'll be part of a team that values continuous development, with opportunities to progress into architectural, strategic, or leadership roles. Ongoing development is supported through certifications, complex project work, and involvement in shaping future SOC capabilities.
Jun 01, 2026
Full time
Senior SOC Engineer - Microsoft Security We're looking for a senior SOC engineer to lead the design, delivery, and evolution of Microsoft-based security platforms within a fast-paced MSSP environment. This role combines hands-on engineering, customer engagement, and technical leadership to deliver high-quality, scalable security services. The Role You will take ownership of SOC-aligned platform engineering across the full lifecycle-from customer onboarding and solution design through to optimisation, maintenance, and continual improvement. You'll work closely with internal teams and customers to ensure security platforms are resilient, efficient, and aligned to evolving threat landscapes. A key part of the role is leading complex deployments and providing technical direction across SIEM, EDR, SOAR, and supporting technologies. You'll oversee platform health through proactive lifecycle management, including patching, upgrades, and service transitions, while driving improvements in detection, automation, and performance. You'll also act as a senior escalation point, mentoring engineers and helping to build capability across the team. Alongside delivery, you'll contribute to pre-sales activities, shaping solutions and supporting bids, demos, and customer discussions. Key Responsibilities Lead the design and implementation of SOC security platforms across customer environments Own end-to-end delivery, including onboarding, configuration, optimisation, and handover Manage platform lifecycle activities to maintain performance, stability, and operational readiness Drive continual improvement through enhancements to detection, automation, and scalability Act as a senior technical escalation point and mentor for the engineering team Maintain high-quality documentation, standards, and repeatable delivery practices Support pre-sales and stakeholder engagement with technical insight and solution design Core Experience & Skills You'll bring strong experience working in SOC or security engineering environments, with deep expertise in Microsoft security technologies and platform engineering. Strong hands-on experience with Microsoft Sentinel, Defender XDR, and Azure security services Proven ability to design and operate SIEM, EDR, SOAR, and log management solutions at scale Expertise in KQL for detection engineering, tuning, and performance optimisation Experience building and maintaining automation using Logic Apps and related tooling Solid understanding of telemetry pipelines, integration patterns, and security architecture Familiarity with frameworks such as MITRE ATT&CK and modern detection practices Strong troubleshooting and problem-solving skills across complex, integrated environments Experience in MSSP environments and working across multi-tenant platforms is highly desirable, particularly where you've contributed to service development, standardisation, and platform evolution. How You Work You're a confident communicator who can translate complex technical concepts into clear, actionable insights for both technical and non-technical audiences. You're comfortable leading engineering delivery, making decisions under pressure, and balancing customer needs with operational constraints. You thrive in collaborative environments, working closely with SOC analysts, detection engineers, sales teams, and optimisation specialists to deliver effective security outcomes. You also take an active role in mentoring others, supporting continuous learning and capability growth within the team. Additional Information You may be required to obtain UK security clearance (NPPV/SC) Some travel may be required for customer engagement and collaboration Growth & Development You'll be part of a team that values continuous development, with opportunities to progress into architectural, strategic, or leadership roles. Ongoing development is supported through certifications, complex project work, and involvement in shaping future SOC capabilities.
EXPERIS
SOC Technical Lead
EXPERIS
Role Overview We are seeking an experienced and hands-on SOC Operations Technical Lead to lead a team of SOC Analysts operating in a 24/7/365 environment. This is a senior, technically focused leadership role within our Managed Security Services (MSSP) function, reporting directly to the Head of SOC Operations. You will act as the senior technical authority, driving excellence in threat detection, incident response, and security operations across a diverse, multi-client portfolio. While you will lead and mentor a team, this is not a purely managerial role. You will remain deeply involved in technical delivery, acting as an escalation point, leading complex investigations, and continuously improving SOC capabilities. Key Responsibilities Team Leadership & SOC Operations Lead day-to-day SOC operations across all shifts, ensuring consistent 24/7 coverage Manage shift schedules, handovers, and on-call rotations Act as the primary escalation point for security incidents and analyst queries Ensure high-quality triage, investigation, and response aligned to SOC processes Drive team development through training, coaching, and technical mentoring Ensure accurate and timely case management (HALO) and delivery against SLAs Technical Leadership & Continuous Improvement Provide expert guidance on threat detection, incident response, and threat hunting Lead escalations for complex or high-severity incidents across client environments Develop and optimise detection rules, playbooks, and automation Improve SOC tooling (SIEM, EDR/XDR, SOAR) and operational processes Design and maintain advanced detection use cases and correlation logic Client Engagement & Consulting Act as a trusted advisor to clients, supporting security reviews and incident analysis Translate technical findings into clear, actionable recommendations Support continuous improvement of client security posture Collaboration Work closely with Threat Intelligence, Engineering, and Incident Response teams Enhance detection capability through intelligence sharing and tool optimisation Align processes to strengthen overall security operations effectiveness Strategic Contribution Identify opportunities to enhance MSSP services and capabilities Monitor emerging threats, technologies, and industry trends Ensure compliance with regulatory standards and internal frameworks Skills & Experience Essential 7+ years in Security Operations, including 3-4 years in a senior/lead SOC role Strong hands-on experience with: SIEM (e.g. Microsoft Sentinel, CrowdStrike) EDR/XDR (e.g. CrowdStrike, Microsoft Defender, Carbon Black) SOAR and threat intelligence platforms Proven expertise in threat hunting and incident response Experience developing and tuning detection rules in multi-tenant environments Strong automation skills to improve SOC efficiency Excellent client-facing and communication skills Desirable Certifications such as CISSP, GIAC (GCIH, GCIA, GREM), SC-200 or SC-300 Experience in cloud security operations Background in MSSP or consulting environments Familiarity with frameworks such as NIST, ISO27001, or ITIL Key Competencies Strong technical depth with the ability to simplify complex concepts Excellent analytical and problem-solving skills under pressure Confident communicator with strong stakeholder engagement skills Collaborative leadership style with a focus on mentoring and development Ability to manage multiple priorities in a fast-paced SOC environment
May 26, 2026
Full time
Role Overview We are seeking an experienced and hands-on SOC Operations Technical Lead to lead a team of SOC Analysts operating in a 24/7/365 environment. This is a senior, technically focused leadership role within our Managed Security Services (MSSP) function, reporting directly to the Head of SOC Operations. You will act as the senior technical authority, driving excellence in threat detection, incident response, and security operations across a diverse, multi-client portfolio. While you will lead and mentor a team, this is not a purely managerial role. You will remain deeply involved in technical delivery, acting as an escalation point, leading complex investigations, and continuously improving SOC capabilities. Key Responsibilities Team Leadership & SOC Operations Lead day-to-day SOC operations across all shifts, ensuring consistent 24/7 coverage Manage shift schedules, handovers, and on-call rotations Act as the primary escalation point for security incidents and analyst queries Ensure high-quality triage, investigation, and response aligned to SOC processes Drive team development through training, coaching, and technical mentoring Ensure accurate and timely case management (HALO) and delivery against SLAs Technical Leadership & Continuous Improvement Provide expert guidance on threat detection, incident response, and threat hunting Lead escalations for complex or high-severity incidents across client environments Develop and optimise detection rules, playbooks, and automation Improve SOC tooling (SIEM, EDR/XDR, SOAR) and operational processes Design and maintain advanced detection use cases and correlation logic Client Engagement & Consulting Act as a trusted advisor to clients, supporting security reviews and incident analysis Translate technical findings into clear, actionable recommendations Support continuous improvement of client security posture Collaboration Work closely with Threat Intelligence, Engineering, and Incident Response teams Enhance detection capability through intelligence sharing and tool optimisation Align processes to strengthen overall security operations effectiveness Strategic Contribution Identify opportunities to enhance MSSP services and capabilities Monitor emerging threats, technologies, and industry trends Ensure compliance with regulatory standards and internal frameworks Skills & Experience Essential 7+ years in Security Operations, including 3-4 years in a senior/lead SOC role Strong hands-on experience with: SIEM (e.g. Microsoft Sentinel, CrowdStrike) EDR/XDR (e.g. CrowdStrike, Microsoft Defender, Carbon Black) SOAR and threat intelligence platforms Proven expertise in threat hunting and incident response Experience developing and tuning detection rules in multi-tenant environments Strong automation skills to improve SOC efficiency Excellent client-facing and communication skills Desirable Certifications such as CISSP, GIAC (GCIH, GCIA, GREM), SC-200 or SC-300 Experience in cloud security operations Background in MSSP or consulting environments Familiarity with frameworks such as NIST, ISO27001, or ITIL Key Competencies Strong technical depth with the ability to simplify complex concepts Excellent analytical and problem-solving skills under pressure Confident communicator with strong stakeholder engagement skills Collaborative leadership style with a focus on mentoring and development Ability to manage multiple priorities in a fast-paced SOC environment
Adecco
Cyber Threat Detection / SOC Analyst - SANS/GIAC
Adecco Wokingham, Berkshire
SOC / Cyber Threat Detection Analyst - SANS/GIAC Cyber Threat Detection Analyst Location: Wokingham, Berkshire (On-site) Salary: Competitive (dependent on experience) + excellent benefits & training Security Clearance: Ideally SC Cleared or eligible for SC Role Overview As a Cyber Threat Detection Analyst, you will play a hands-on role within an advanced cyber defence function, focused on proactive threat hunting, adversary behaviour analysis, and high-fidelity threat detection across enterprise environments. This role goes beyond reactive alert handling. You will actively hunt for malicious activity using telemetry, SIEM data, and threat intelligence, develop hypotheses based on MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs), and support incident management and response activities when threats are identified. We are open to experienced SOC Analysts where threat hunting, investigations, and proactive detection have formed a significant part of their role, and who are looking to further develop in a more hunting-led environment. This position is well suited to analysts who enjoy thinking like an attacker, have worked alongside or supported red team or purple team activities, and want to deepen their expertise in threat detection and detection engineering. Skills & Experience We're Seeking Experience in threat hunting, cyber threat detection, SOC, blue team, or cyber defence environments, with ideally around five years hands on experience. Strong hands-on experience using SIEM platforms, including: Microsoft Sentinel (KQL) Splunk (SPL) Elastic Security/Kibana (KQL, ESQL) Practical and operational understanding of MITRE ATT&CK, attacker techniques, and adversary tradecraft Experience working with Indicators of Compromise (IOCs) and threat intelligence feeds Solid experience across the security event life cycle, including detection, investigation, and incident management Hands-on experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike, SentinelOne, or Carbon Black Strong knowledge of networking fundamentals (TCP/IP, DNS, HTTP/S, Firewalls, VPNs, Proxy technologies) Experience analysing telemetry from Windows, Linux, identity, endpoint, and network sources Strong analytical mindset with the ability to clearly communicate findings, impact, and risk Key Responsibilities Conduct proactive threat hunting activities across log, endpoint, and network telemetry to identify suspicious, stealthy, or previously unknown threats Develop and execute hunt hypotheses aligned to MITRE ATT&CK TTPs, adversary behaviours, and emerging threat intelligence Write, refine, and optimise SIEM queries using KQL, SPL, Elastic/ESQL, and Kibana Query Language Perform IOC analysis, enrichment, and validation, integrating internal and external threat intelligence sources Lead investigations from initial detection through scoping, root cause analysis, and impact assessment Support incident management and incident response activities, including containment, remediation, escalation, and lessons learned Collaborate closely with SOC teams, incident responders, red teams, and purple teams to validate detections and improve defensive coverage Contribute to detection logic improvements, use-case development, and continuous enhancement of hunting methodologies Produce clear investigation write-ups, timelines, and recommendations for technical and non-technical stakeholders Security Certifications (Highly Beneficial) SANS/GIAC certifications, including but not limited to: GCIH - Incident Handler GCIA - Intrusion Analyst GCED - Enterprise Defender GCTI - Cyber Threat Intelligence GMON - Continuous Monitoring GDAT - Defending Advanced Threats GCAT - Advanced Threat Intelligence OSCP or equivalent offensive security qualifications Crest certifications, such as: Crest Practitioner Intrusion Analyst (CPIA) Crest Registered Intrusion Analyst (CRIA) Crest Certified Threat Intelligence Analyst (CCTIA) Crest Certified Blue Team Professional (CCBTP) Microsoft SC-200 or related detection and response certifications Other recognised cyber security or threat intelligence credentials
May 20, 2026
Full time
SOC / Cyber Threat Detection Analyst - SANS/GIAC Cyber Threat Detection Analyst Location: Wokingham, Berkshire (On-site) Salary: Competitive (dependent on experience) + excellent benefits & training Security Clearance: Ideally SC Cleared or eligible for SC Role Overview As a Cyber Threat Detection Analyst, you will play a hands-on role within an advanced cyber defence function, focused on proactive threat hunting, adversary behaviour analysis, and high-fidelity threat detection across enterprise environments. This role goes beyond reactive alert handling. You will actively hunt for malicious activity using telemetry, SIEM data, and threat intelligence, develop hypotheses based on MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs), and support incident management and response activities when threats are identified. We are open to experienced SOC Analysts where threat hunting, investigations, and proactive detection have formed a significant part of their role, and who are looking to further develop in a more hunting-led environment. This position is well suited to analysts who enjoy thinking like an attacker, have worked alongside or supported red team or purple team activities, and want to deepen their expertise in threat detection and detection engineering. Skills & Experience We're Seeking Experience in threat hunting, cyber threat detection, SOC, blue team, or cyber defence environments, with ideally around five years hands on experience. Strong hands-on experience using SIEM platforms, including: Microsoft Sentinel (KQL) Splunk (SPL) Elastic Security/Kibana (KQL, ESQL) Practical and operational understanding of MITRE ATT&CK, attacker techniques, and adversary tradecraft Experience working with Indicators of Compromise (IOCs) and threat intelligence feeds Solid experience across the security event life cycle, including detection, investigation, and incident management Hands-on experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike, SentinelOne, or Carbon Black Strong knowledge of networking fundamentals (TCP/IP, DNS, HTTP/S, Firewalls, VPNs, Proxy technologies) Experience analysing telemetry from Windows, Linux, identity, endpoint, and network sources Strong analytical mindset with the ability to clearly communicate findings, impact, and risk Key Responsibilities Conduct proactive threat hunting activities across log, endpoint, and network telemetry to identify suspicious, stealthy, or previously unknown threats Develop and execute hunt hypotheses aligned to MITRE ATT&CK TTPs, adversary behaviours, and emerging threat intelligence Write, refine, and optimise SIEM queries using KQL, SPL, Elastic/ESQL, and Kibana Query Language Perform IOC analysis, enrichment, and validation, integrating internal and external threat intelligence sources Lead investigations from initial detection through scoping, root cause analysis, and impact assessment Support incident management and incident response activities, including containment, remediation, escalation, and lessons learned Collaborate closely with SOC teams, incident responders, red teams, and purple teams to validate detections and improve defensive coverage Contribute to detection logic improvements, use-case development, and continuous enhancement of hunting methodologies Produce clear investigation write-ups, timelines, and recommendations for technical and non-technical stakeholders Security Certifications (Highly Beneficial) SANS/GIAC certifications, including but not limited to: GCIH - Incident Handler GCIA - Intrusion Analyst GCED - Enterprise Defender GCTI - Cyber Threat Intelligence GMON - Continuous Monitoring GDAT - Defending Advanced Threats GCAT - Advanced Threat Intelligence OSCP or equivalent offensive security qualifications Crest certifications, such as: Crest Practitioner Intrusion Analyst (CPIA) Crest Registered Intrusion Analyst (CRIA) Crest Certified Threat Intelligence Analyst (CCTIA) Crest Certified Blue Team Professional (CCBTP) Microsoft SC-200 or related detection and response certifications Other recognised cyber security or threat intelligence credentials
Claranet Limited
Senior SOC Engineer
Claranet Limited Leeds, Yorkshire
Senior SOC Engineer - Microsoft Security We're looking for a senior SOC engineer to lead the design, delivery, and evolution of Microsoft-based security platforms within a fast-paced MSSP environment. This role combines hands-on engineering, customer engagement, and technical leadership to deliver high-quality, scalable security services. The Role You will take ownership of SOC-aligned platform engineering across the full lifecycle-from customer onboarding and solution design through to optimisation, maintenance, and continual improvement. You'll work closely with internal teams and customers to ensure security platforms are resilient, efficient, and aligned to evolving threat landscapes. A key part of the role is leading complex deployments and providing technical direction across SIEM, EDR, SOAR, and supporting technologies. You'll oversee platform health through proactive lifecycle management, including patching, upgrades, and service transitions, while driving improvements in detection, automation, and performance. You'll also act as a senior escalation point, mentoring engineers and helping to build capability across the team. Alongside delivery, you'll contribute to pre-sales activities, shaping solutions and supporting bids, demos, and customer discussions. Key Responsibilities Lead the design and implementation of SOC security platforms across customer environments Own end-to-end delivery, including onboarding, configuration, optimisation, and handover Manage platform lifecycle activities to maintain performance, stability, and operational readiness Drive continual improvement through enhancements to detection, automation, and scalability Act as a senior technical escalation point and mentor for the engineering team Maintain high-quality documentation, standards, and repeatable delivery practices Support pre-sales and stakeholder engagement with technical insight and solution design Core Experience & Skills You'll bring strong experience working in SOC or security engineering environments, with deep expertise in Microsoft security technologies and platform engineering. Strong hands-on experience with Microsoft Sentinel, Defender XDR, and Azure security services Proven ability to design and operate SIEM, EDR, SOAR, and log management solutions at scale Expertise in KQL for detection engineering, tuning, and performance optimisation Experience building and maintaining automation using Logic Apps and related tooling Solid understanding of telemetry pipelines, integration patterns, and security architecture Familiarity with frameworks such as MITRE ATT&CK and modern detection practices Strong troubleshooting and problem-solving skills across complex, integrated environments Experience in MSSP environments and working across multi-tenant platforms is highly desirable, particularly where you've contributed to service development, standardisation, and platform evolution. How You Work You're a confident communicator who can translate complex technical concepts into clear, actionable insights for both technical and non-technical audiences. You're comfortable leading engineering delivery, making decisions under pressure, and balancing customer needs with operational constraints. You thrive in collaborative environments, working closely with SOC analysts, detection engineers, sales teams, and optimisation specialists to deliver effective security outcomes. You also take an active role in mentoring others, supporting continuous learning and capability growth within the team. Additional Information You may be required to obtain UK security clearance (NPPV/SC) Some travel may be required for customer engagement and collaboration Growth & Development You'll be part of a team that values continuous development, with opportunities to progress into architectural, strategic, or leadership roles. Ongoing development is supported through certifications, complex project work, and involvement in shaping future SOC capabilities.
May 19, 2026
Full time
Senior SOC Engineer - Microsoft Security We're looking for a senior SOC engineer to lead the design, delivery, and evolution of Microsoft-based security platforms within a fast-paced MSSP environment. This role combines hands-on engineering, customer engagement, and technical leadership to deliver high-quality, scalable security services. The Role You will take ownership of SOC-aligned platform engineering across the full lifecycle-from customer onboarding and solution design through to optimisation, maintenance, and continual improvement. You'll work closely with internal teams and customers to ensure security platforms are resilient, efficient, and aligned to evolving threat landscapes. A key part of the role is leading complex deployments and providing technical direction across SIEM, EDR, SOAR, and supporting technologies. You'll oversee platform health through proactive lifecycle management, including patching, upgrades, and service transitions, while driving improvements in detection, automation, and performance. You'll also act as a senior escalation point, mentoring engineers and helping to build capability across the team. Alongside delivery, you'll contribute to pre-sales activities, shaping solutions and supporting bids, demos, and customer discussions. Key Responsibilities Lead the design and implementation of SOC security platforms across customer environments Own end-to-end delivery, including onboarding, configuration, optimisation, and handover Manage platform lifecycle activities to maintain performance, stability, and operational readiness Drive continual improvement through enhancements to detection, automation, and scalability Act as a senior technical escalation point and mentor for the engineering team Maintain high-quality documentation, standards, and repeatable delivery practices Support pre-sales and stakeholder engagement with technical insight and solution design Core Experience & Skills You'll bring strong experience working in SOC or security engineering environments, with deep expertise in Microsoft security technologies and platform engineering. Strong hands-on experience with Microsoft Sentinel, Defender XDR, and Azure security services Proven ability to design and operate SIEM, EDR, SOAR, and log management solutions at scale Expertise in KQL for detection engineering, tuning, and performance optimisation Experience building and maintaining automation using Logic Apps and related tooling Solid understanding of telemetry pipelines, integration patterns, and security architecture Familiarity with frameworks such as MITRE ATT&CK and modern detection practices Strong troubleshooting and problem-solving skills across complex, integrated environments Experience in MSSP environments and working across multi-tenant platforms is highly desirable, particularly where you've contributed to service development, standardisation, and platform evolution. How You Work You're a confident communicator who can translate complex technical concepts into clear, actionable insights for both technical and non-technical audiences. You're comfortable leading engineering delivery, making decisions under pressure, and balancing customer needs with operational constraints. You thrive in collaborative environments, working closely with SOC analysts, detection engineers, sales teams, and optimisation specialists to deliver effective security outcomes. You also take an active role in mentoring others, supporting continuous learning and capability growth within the team. Additional Information You may be required to obtain UK security clearance (NPPV/SC) Some travel may be required for customer engagement and collaboration Growth & Development You'll be part of a team that values continuous development, with opportunities to progress into architectural, strategic, or leadership roles. Ongoing development is supported through certifications, complex project work, and involvement in shaping future SOC capabilities.
Additional Resources Ltd
Threat Detection Engineer - Hybrid / Remote
Additional Resources Ltd
Join a well-established biotech company using large-scale genetic data and AI to predict disease risk and advance precision healthcare. We're looking for a Threat Detection Engineer who thrives on innovation and technical ownership. This role is not a traditional SOC position, you'll focus on building high-impact detection capabilities, shaping how security protects sensitive genomic and AI-driven data at scale. This role offers hybrid / remote working options, a salary range of £60,000 - £80,000 and benefits. Why This Role is Exciting High autonomy: Lead projects from idea to deployment Innovation-driven: Develop cutting-edge detections beyond standard SIEM rules Collaborative: Work closely with internal teams and an outsourced SOC partner Mission-focused: Protect critical healthcare data that supports precision medicine Key Responsibilities Design and develop threat-led detections using threat intelligence and threat-hunting outputs Create novel analytic techniques for incident detection Collaborate with an MSP SOC to maintain and tune the detection catalogue Build automated reporting dashboards using Microsoft Sentinel workbooks Support security initiatives including ISO 27001 activities and KQL-based tasks Ensure monitoring coverage across cloud platforms, SaaS apps, and internal systems Contribute to documentation of processes, tools, and detection logic What You'll Bring Must-Have Skills & Experience: Previously worked as a Threat Detection Engineer or in a similar role. Strong proficiency in KQL and hands-on experience with Microsoft Sentinel Familiarity with Microsoft Defender tools (Endpoint & O365) Exposure to Azure cloud logging and Kubernetes environments Knowledge of attacker TTPs and MITRE ATT&CK frameworks Proactive, collaborative, and innovative mindset Desirable / Nice-to-Have: Experience with Python, Terraform, or CI/CD pipelines Familiarity with Microsoft Purview, Entra ID, DLP, or Insider Risk tools Understanding of ISO 27001, Agile ways of working Knowledge of statistics, data science, or AI/ML applied to cybersecurity Relevant certifications (MS-500, AZ-500, SC-series, Security+, GSOC, CCSK) Perks & Benefits Hybrid / remote working options Flexible benefits package Opportunity to innovate and make a real impact in threat detection Work in a small, fast-paced, highly collaborative team Contribute to advancing precision healthcare using genomic data and AI Ready to build next-generation threat detection and protect life-changing data Apply today! Important Information: We endeavour to process your personal data in a fair and transparent manner. In applying for this role, Additional Resources will be acting in your best interest and may contact you in relation to the role, either by email, phone, or text message. For more information see our Privacy Policy on our website. It is important you are aware of your individual rights and the provisions the company has put in place to protect your data. If you would like further information on the policy or GDPR please contact us. Additional Resources Ltd is an Employment Business and an Employment Agency as defined within The Conduct of Employment Agencies & Employment Businesses Regulations 2003.
May 18, 2026
Full time
Join a well-established biotech company using large-scale genetic data and AI to predict disease risk and advance precision healthcare. We're looking for a Threat Detection Engineer who thrives on innovation and technical ownership. This role is not a traditional SOC position, you'll focus on building high-impact detection capabilities, shaping how security protects sensitive genomic and AI-driven data at scale. This role offers hybrid / remote working options, a salary range of £60,000 - £80,000 and benefits. Why This Role is Exciting High autonomy: Lead projects from idea to deployment Innovation-driven: Develop cutting-edge detections beyond standard SIEM rules Collaborative: Work closely with internal teams and an outsourced SOC partner Mission-focused: Protect critical healthcare data that supports precision medicine Key Responsibilities Design and develop threat-led detections using threat intelligence and threat-hunting outputs Create novel analytic techniques for incident detection Collaborate with an MSP SOC to maintain and tune the detection catalogue Build automated reporting dashboards using Microsoft Sentinel workbooks Support security initiatives including ISO 27001 activities and KQL-based tasks Ensure monitoring coverage across cloud platforms, SaaS apps, and internal systems Contribute to documentation of processes, tools, and detection logic What You'll Bring Must-Have Skills & Experience: Previously worked as a Threat Detection Engineer or in a similar role. Strong proficiency in KQL and hands-on experience with Microsoft Sentinel Familiarity with Microsoft Defender tools (Endpoint & O365) Exposure to Azure cloud logging and Kubernetes environments Knowledge of attacker TTPs and MITRE ATT&CK frameworks Proactive, collaborative, and innovative mindset Desirable / Nice-to-Have: Experience with Python, Terraform, or CI/CD pipelines Familiarity with Microsoft Purview, Entra ID, DLP, or Insider Risk tools Understanding of ISO 27001, Agile ways of working Knowledge of statistics, data science, or AI/ML applied to cybersecurity Relevant certifications (MS-500, AZ-500, SC-series, Security+, GSOC, CCSK) Perks & Benefits Hybrid / remote working options Flexible benefits package Opportunity to innovate and make a real impact in threat detection Work in a small, fast-paced, highly collaborative team Contribute to advancing precision healthcare using genomic data and AI Ready to build next-generation threat detection and protect life-changing data Apply today! Important Information: We endeavour to process your personal data in a fair and transparent manner. In applying for this role, Additional Resources will be acting in your best interest and may contact you in relation to the role, either by email, phone, or text message. For more information see our Privacy Policy on our website. It is important you are aware of your individual rights and the provisions the company has put in place to protect your data. If you would like further information on the policy or GDPR please contact us. Additional Resources Ltd is an Employment Business and an Employment Agency as defined within The Conduct of Employment Agencies & Employment Businesses Regulations 2003.
Hays Specialist Recruitment Limited
Principal Cyber Security Engineer
Hays Specialist Recruitment Limited
PRINCIPAL CYBERSECURITY ENGINEER SC Cleared - UK Only - (Sponsorship is unavailable) you must hold SC Clearance.Provide expert advice on the defences against cyber threats, data breaches, and emerging risks. This includes offering guidance on the selection, design, justification, implementation, and operational management of cybersecurity strategies, technologies, and standards. Contribute to the development and refinement of controls and processes to ensure the safety, confidentiality, integrity, availability, and overall security of data stored on systems. You will be responsible for identifying gaps in existing cybersecurity policies and procedures and, in collaboration with security, network, information governance, and technical leads, developing new measures to address these gaps. KEY RESPONSIBILITIES: You will work closely with system and service owners, as well as internal and external stakeholders, to design, implement, and enforce appropriate protective and detective security controls, policies, and procedures. The role includes the administration and operational management of security tooling and SIEM platforms, with responsibility for monitoring, detecting, and responding to cyber threats, intrusions, and unauthorised or suspicious activity. This includes Microsoft Sentinel (data and source tuning, creation and maintenance of workbooks and connectors, and threat intelligence review), Microsoft Defender for Endpoint and Defender for Cloud, and Darktrace, including system and model tuning, email module management, and configuration of autonomous response actions. You will be responsible for incident response activities, including triaging security alerts, investigating incidents, coordinating escalation and remediation, and conducting root cause analysis. You must be able to communicate effectively about security incidents and cyber risks to both technical and non-technical stakeholders. The role works closely with the Security Operations Centre (SOC) partner, supporting the assessment and investigation of alerts and contributing to the development and refinement of incident response plans and playbooks. You will support vulnerability management activities, including vulnerability assessments, annual audits, and penetration testing. This includes preparing and presenting incident, threat, and compliance reporting to stakeholders at all levels, including compiling a monthly SIRO report. Continuous improvement is a core responsibility. You will conduct post-incident reviews, recommend control and process improvements, and contribute to the creation and maintenance of cybersecurity governance documentation. You will also research emerging cyber threats and mitigation strategies and provide reports or presentations to senior stakeholders as required. The role supports cybersecurity training and awareness initiatives, promoting a strong security culture and helping to upskill colleagues in cybersecurity best practices. You will also collaborate with solution architects and project teams to ensure security is embedded into system and application designs, supporting secure architecture and delivery from the outset. Compliance & Framework Alignment: Ensure security operations align with regulatory standards and frameworks such as NIST, ISO 27001, and NCSC CAF. Person SpecificationEssential: Demonstrated experience with Microsoft Sentinel, Microsoft Defender for Endpoint/Cloud SIEM tools, threat intelligence platforms, and vulnerability management. Technical experience securing Microsoft Azure and Amazon Web Services cloud environments as well as on-premise/virtual Microsoft technologies. Strong analytical, communication, and problem-solving skills, including the ability to produce clear technical and non-technical reports. Ability to analyse and interpret security events/logs and perform remediation work to address security issues. Desirable: Recognised cybersecurity certifications (e.g., CompTIA Security+, CEH, GIAC, CISSP). Experience with DarkTrace Qualifications Bachelor's degree in Cybersecurity or Computer Science Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at hays.co.uk
May 07, 2026
Full time
PRINCIPAL CYBERSECURITY ENGINEER SC Cleared - UK Only - (Sponsorship is unavailable) you must hold SC Clearance.Provide expert advice on the defences against cyber threats, data breaches, and emerging risks. This includes offering guidance on the selection, design, justification, implementation, and operational management of cybersecurity strategies, technologies, and standards. Contribute to the development and refinement of controls and processes to ensure the safety, confidentiality, integrity, availability, and overall security of data stored on systems. You will be responsible for identifying gaps in existing cybersecurity policies and procedures and, in collaboration with security, network, information governance, and technical leads, developing new measures to address these gaps. KEY RESPONSIBILITIES: You will work closely with system and service owners, as well as internal and external stakeholders, to design, implement, and enforce appropriate protective and detective security controls, policies, and procedures. The role includes the administration and operational management of security tooling and SIEM platforms, with responsibility for monitoring, detecting, and responding to cyber threats, intrusions, and unauthorised or suspicious activity. This includes Microsoft Sentinel (data and source tuning, creation and maintenance of workbooks and connectors, and threat intelligence review), Microsoft Defender for Endpoint and Defender for Cloud, and Darktrace, including system and model tuning, email module management, and configuration of autonomous response actions. You will be responsible for incident response activities, including triaging security alerts, investigating incidents, coordinating escalation and remediation, and conducting root cause analysis. You must be able to communicate effectively about security incidents and cyber risks to both technical and non-technical stakeholders. The role works closely with the Security Operations Centre (SOC) partner, supporting the assessment and investigation of alerts and contributing to the development and refinement of incident response plans and playbooks. You will support vulnerability management activities, including vulnerability assessments, annual audits, and penetration testing. This includes preparing and presenting incident, threat, and compliance reporting to stakeholders at all levels, including compiling a monthly SIRO report. Continuous improvement is a core responsibility. You will conduct post-incident reviews, recommend control and process improvements, and contribute to the creation and maintenance of cybersecurity governance documentation. You will also research emerging cyber threats and mitigation strategies and provide reports or presentations to senior stakeholders as required. The role supports cybersecurity training and awareness initiatives, promoting a strong security culture and helping to upskill colleagues in cybersecurity best practices. You will also collaborate with solution architects and project teams to ensure security is embedded into system and application designs, supporting secure architecture and delivery from the outset. Compliance & Framework Alignment: Ensure security operations align with regulatory standards and frameworks such as NIST, ISO 27001, and NCSC CAF. Person SpecificationEssential: Demonstrated experience with Microsoft Sentinel, Microsoft Defender for Endpoint/Cloud SIEM tools, threat intelligence platforms, and vulnerability management. Technical experience securing Microsoft Azure and Amazon Web Services cloud environments as well as on-premise/virtual Microsoft technologies. Strong analytical, communication, and problem-solving skills, including the ability to produce clear technical and non-technical reports. Ability to analyse and interpret security events/logs and perform remediation work to address security issues. Desirable: Recognised cybersecurity certifications (e.g., CompTIA Security+, CEH, GIAC, CISSP). Experience with DarkTrace Qualifications Bachelor's degree in Cybersecurity or Computer Science Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at hays.co.uk
Sopra Steria
Senior Detection Engineer
Sopra Steria Farnborough, Hampshire
Are you a Detection Engineer ready to take on the fight against modern adversaries? Join a well-established SOC working with high-profile Defence clients, where your expertise genuinely matters. In this hands-on technical role, you'll own the end-to-end design, development and maturity of detection logic across SIEM platforms-engineering effective responses to real-world attacker techniques. You'll operate with a high degree of autonomy, acting as a trusted SME across multiple secure environments within a complex MSSP setting. This is a standout opportunity to advance your career at the sharp end of cyber defence. Location: Hybrid working - 2 days per week in our Farnborough office. Security: You must hold or be eligible for SC Clearance. What you'll be doing: ? Design, build, test and continuously refine advanced SIEM detection logic, including rules, correlations and analytics. Research emerging threats, vulnerabilities and adversary TTPs, mapping them to MITRE ATT&CK to close detection and visibility gaps. Tune and validate detections to minimise false positives and deliver high-fidelity alerts for SOC analysts. Act as a technical authority, providing expert guidance to SOC Analysts, Architects and Engineers to strengthen overall detection capability. Define, implement and maintain technical detection standards across environments. Clearly communicate complex technical risks and detection logic to both technical teams and non-technical stakeholders. What you'll bring: Deep SIEM expertise, building advanced detection logic, automation and complex queries in Splunk (SPL) and Microsoft Sentinel (KQL). A proven track record delivering complex detection engineering projects within enterprise or MSSP environments. Strong analytical skills, with the ability to break down sophisticated attacks into actionable detection patterns. Confidence to own technical delivery end-to-end, driving work through to completion with minimal escalation. Expert knowledge of MITRE ATT&CK, with real-world application in detection engineering. A BSc in Computer Science, IT, or a related discipline. Solid scripting skills in Python, PowerShell, or similar, supporting automation and data manipulation. Experience developing detections in QRadar and/or conducting EDR-focused threat hunting (e.g. CrowdStrike, Microsoft Defender for Endpoint). Broad infrastructure awareness across Cloud (Azure/AWS), on-prem, and SaaS / PaaS / IaaS environments. If you are interested in this role but not sure if your skills and experience are exactly what we're looking for, please do apply, we'd love to hear from you! Employment Type: Full-time, Permanent. Location: Hybrid: 2 days per week in Farnborough. Security Clearance Level: SC Cleared or eligible. Internal Recruiter: Jane. Salary: To £65,000. Benefits: 25 days annual leave with the choice to buy additional days, health cash plan, life assurance and pension. Sopra Steria: Our Aerospace, Defence and Security business designs, develops and deploys digital solutions to Central Government clients. The work we do makes a real difference to the client's goal of National Security, and we operate in a unique and privileged environment. We are given time for professional development activities, and we coach and mentor our colleagues, sharing knowledge and learning from each other. We foster a culture in which employees feel valued and supported and have pride in their work for the customer, delivering outstanding rates of customer satisfaction in the UK's most complex safety- and security-critical markets.
May 03, 2026
Full time
Are you a Detection Engineer ready to take on the fight against modern adversaries? Join a well-established SOC working with high-profile Defence clients, where your expertise genuinely matters. In this hands-on technical role, you'll own the end-to-end design, development and maturity of detection logic across SIEM platforms-engineering effective responses to real-world attacker techniques. You'll operate with a high degree of autonomy, acting as a trusted SME across multiple secure environments within a complex MSSP setting. This is a standout opportunity to advance your career at the sharp end of cyber defence. Location: Hybrid working - 2 days per week in our Farnborough office. Security: You must hold or be eligible for SC Clearance. What you'll be doing: ? Design, build, test and continuously refine advanced SIEM detection logic, including rules, correlations and analytics. Research emerging threats, vulnerabilities and adversary TTPs, mapping them to MITRE ATT&CK to close detection and visibility gaps. Tune and validate detections to minimise false positives and deliver high-fidelity alerts for SOC analysts. Act as a technical authority, providing expert guidance to SOC Analysts, Architects and Engineers to strengthen overall detection capability. Define, implement and maintain technical detection standards across environments. Clearly communicate complex technical risks and detection logic to both technical teams and non-technical stakeholders. What you'll bring: Deep SIEM expertise, building advanced detection logic, automation and complex queries in Splunk (SPL) and Microsoft Sentinel (KQL). A proven track record delivering complex detection engineering projects within enterprise or MSSP environments. Strong analytical skills, with the ability to break down sophisticated attacks into actionable detection patterns. Confidence to own technical delivery end-to-end, driving work through to completion with minimal escalation. Expert knowledge of MITRE ATT&CK, with real-world application in detection engineering. A BSc in Computer Science, IT, or a related discipline. Solid scripting skills in Python, PowerShell, or similar, supporting automation and data manipulation. Experience developing detections in QRadar and/or conducting EDR-focused threat hunting (e.g. CrowdStrike, Microsoft Defender for Endpoint). Broad infrastructure awareness across Cloud (Azure/AWS), on-prem, and SaaS / PaaS / IaaS environments. If you are interested in this role but not sure if your skills and experience are exactly what we're looking for, please do apply, we'd love to hear from you! Employment Type: Full-time, Permanent. Location: Hybrid: 2 days per week in Farnborough. Security Clearance Level: SC Cleared or eligible. Internal Recruiter: Jane. Salary: To £65,000. Benefits: 25 days annual leave with the choice to buy additional days, health cash plan, life assurance and pension. Sopra Steria: Our Aerospace, Defence and Security business designs, develops and deploys digital solutions to Central Government clients. The work we do makes a real difference to the client's goal of National Security, and we operate in a unique and privileged environment. We are given time for professional development activities, and we coach and mentor our colleagues, sharing knowledge and learning from each other. We foster a culture in which employees feel valued and supported and have pride in their work for the customer, delivering outstanding rates of customer satisfaction in the UK's most complex safety- and security-critical markets.
Precise Placements
SOC Engineer - 6 Month FTC
Precise Placements
SOC Engineer - SIEM, Exabeam, SOAR, EDR, IDS/IPS, MITRE, Azure, SC-200, SC-100, Our leading global law firm client are currently looking to take on a new SOC Engineer (SIEM, Exabeam, SOAR, EDR, IDS/IPS, MITRE, Azure, SC-200, SC-100) to join their team on a contractual basis. The firm are an extremely modern law firm which offer a healthy hybrid working solution 2-3 days per week in London and offer a great deal of autonomy and technical exposure. This SOC Engineer (SIEM, Exabeam, SOAR, EDR, IDS/IPS, MITRE, Azure, SC-200, SC-100) role, will be responsible for the enhancement of existing SIEM platform and improve performance, coverage and fidelity by conducting regular assessments of the SIEM architecture. To be considered for this SOC Engineer (SIEM, Exabeam, SOAR, EDR, IDS/IPS, MITRE, Azure, SC-200, SC-100)Defender) role, it's ideal you have: 3 + years within a similar role Ideal but not required law firm experience Security qualifications such as CISSP, CISM, CEH, CompTIA Sec+ or others SIEM Engineering & Maturity Enhance and optimise the existing SIEM platform to improve performance, coverage, and fidelity. Conduct regular assessments of SIEM architecture and propose improvements to ingestion pipelines, parsing rules, correlation logic, and storage management. Implement automation and orchestration components (SOAR) to streamline incident response activities. Log Source Onboarding & Integration Identify, prioritise, and onboard new log sources from cloud, on-prem, network, endpoint, identity, and application platforms. Develop and maintain custom parsers, connectors, and ingestion playbooks. Work with internal teams and vendors to ensure high-quality, reliable telemetry and error-free ingestion. Use Case & Detection Content Development Design, implement, test, and tune detection use cases based on attacker techniques (MITRE ATT&CK), threat intelligence, and risk appetite. Build correlation rules, anomaly-based detections, dashboards, and alerting workflows. Regularly review detection efficacy and reduce false positives through tuning and logic refinement. SOC Support & Incident Response Work closely with SOC analysts to validate and refine detection logic. Support incident investigations through SIEM searches, enrichment, and data modelling. Provide technical SME support for complex incidents that require deep SIEM or log knowledge. Documentation & Governance Maintain high-quality documentation covering data models, feed onboarding, use cases, correlation logic, and architecture. Ensure alignment with internal controls, compliance requirements, and industry standards. Education, Skills & Experience Technical Expertise Hands-on experience with leading SIEM platforms (e.g., Exabeam, LogRhythm, ArcSight, Microsoft Sentinel, Splunk, QRadar, Elastic). Strong understanding of log formats (JSON, syslog, XML, CEF, etc.) and ingestion technologies (Syslog, API, Event Hubs, Kafka, Agents). Practical knowledge of detection engineering, threat modelling, and attacker behaviour analysis. Experience building and tuning correlation rules, searches, and dashboards. Familiarity with SOAR platforms and automation workflows. Security Knowledge Strong understanding of networking, Windows/Linux systems, Cloud platforms (Azure/AWS/GCP), identity systems, and endpoint protection technologies (e.g. SentinelOne and Microsoft Defender) Knowledge of MITRE ATT&CK, cyber kill chain, and threat hunting methodologies. Must Have Level 4 or higher qualification in a computing subject, or equivalent experience IT experience including both IT Infrastructure and Information Security roles Relevant professional certifications that validate the fundamental skills required to perform the role, e.g. GIAC (GCIA,GCDA,GMON) Microsoft SC-200/SC-100, CompTIA Secure Infrastructure Specialist (CSIS), SSCP/CISSP etc Strong skill level in scripting technologies, including Python, MS PowerShell and PowerApps Ability to conduct research into Infrastructure issues and products as required Self-starting with strong interpersonal, written, and oral communication skills. Ability to engage colleagues at all levels and project a solid, professional attitude consistently. Nice to have Data Loss Prevention Secure Remote Access solutions Network Security solutions Open Source and Cyber Threat Intelligence Suitable experience working with the market leading technology vendor product suites Experience in software-defined and cloud services such as SaaS, IaaS, PaaS and DaaS Experience in Disaster Recovery Management and Business Continuity Knowledge of applicable data privacy practices and laws
May 03, 2026
Contractor
SOC Engineer - SIEM, Exabeam, SOAR, EDR, IDS/IPS, MITRE, Azure, SC-200, SC-100, Our leading global law firm client are currently looking to take on a new SOC Engineer (SIEM, Exabeam, SOAR, EDR, IDS/IPS, MITRE, Azure, SC-200, SC-100) to join their team on a contractual basis. The firm are an extremely modern law firm which offer a healthy hybrid working solution 2-3 days per week in London and offer a great deal of autonomy and technical exposure. This SOC Engineer (SIEM, Exabeam, SOAR, EDR, IDS/IPS, MITRE, Azure, SC-200, SC-100) role, will be responsible for the enhancement of existing SIEM platform and improve performance, coverage and fidelity by conducting regular assessments of the SIEM architecture. To be considered for this SOC Engineer (SIEM, Exabeam, SOAR, EDR, IDS/IPS, MITRE, Azure, SC-200, SC-100)Defender) role, it's ideal you have: 3 + years within a similar role Ideal but not required law firm experience Security qualifications such as CISSP, CISM, CEH, CompTIA Sec+ or others SIEM Engineering & Maturity Enhance and optimise the existing SIEM platform to improve performance, coverage, and fidelity. Conduct regular assessments of SIEM architecture and propose improvements to ingestion pipelines, parsing rules, correlation logic, and storage management. Implement automation and orchestration components (SOAR) to streamline incident response activities. Log Source Onboarding & Integration Identify, prioritise, and onboard new log sources from cloud, on-prem, network, endpoint, identity, and application platforms. Develop and maintain custom parsers, connectors, and ingestion playbooks. Work with internal teams and vendors to ensure high-quality, reliable telemetry and error-free ingestion. Use Case & Detection Content Development Design, implement, test, and tune detection use cases based on attacker techniques (MITRE ATT&CK), threat intelligence, and risk appetite. Build correlation rules, anomaly-based detections, dashboards, and alerting workflows. Regularly review detection efficacy and reduce false positives through tuning and logic refinement. SOC Support & Incident Response Work closely with SOC analysts to validate and refine detection logic. Support incident investigations through SIEM searches, enrichment, and data modelling. Provide technical SME support for complex incidents that require deep SIEM or log knowledge. Documentation & Governance Maintain high-quality documentation covering data models, feed onboarding, use cases, correlation logic, and architecture. Ensure alignment with internal controls, compliance requirements, and industry standards. Education, Skills & Experience Technical Expertise Hands-on experience with leading SIEM platforms (e.g., Exabeam, LogRhythm, ArcSight, Microsoft Sentinel, Splunk, QRadar, Elastic). Strong understanding of log formats (JSON, syslog, XML, CEF, etc.) and ingestion technologies (Syslog, API, Event Hubs, Kafka, Agents). Practical knowledge of detection engineering, threat modelling, and attacker behaviour analysis. Experience building and tuning correlation rules, searches, and dashboards. Familiarity with SOAR platforms and automation workflows. Security Knowledge Strong understanding of networking, Windows/Linux systems, Cloud platforms (Azure/AWS/GCP), identity systems, and endpoint protection technologies (e.g. SentinelOne and Microsoft Defender) Knowledge of MITRE ATT&CK, cyber kill chain, and threat hunting methodologies. Must Have Level 4 or higher qualification in a computing subject, or equivalent experience IT experience including both IT Infrastructure and Information Security roles Relevant professional certifications that validate the fundamental skills required to perform the role, e.g. GIAC (GCIA,GCDA,GMON) Microsoft SC-200/SC-100, CompTIA Secure Infrastructure Specialist (CSIS), SSCP/CISSP etc Strong skill level in scripting technologies, including Python, MS PowerShell and PowerApps Ability to conduct research into Infrastructure issues and products as required Self-starting with strong interpersonal, written, and oral communication skills. Ability to engage colleagues at all levels and project a solid, professional attitude consistently. Nice to have Data Loss Prevention Secure Remote Access solutions Network Security solutions Open Source and Cyber Threat Intelligence Suitable experience working with the market leading technology vendor product suites Experience in software-defined and cloud services such as SaaS, IaaS, PaaS and DaaS Experience in Disaster Recovery Management and Business Continuity Knowledge of applicable data privacy practices and laws
SGN
Technology Security Analyst
SGN Glasgow, Lanarkshire
Technology Security Analyst Glasgow, Edinburgh, Portsmouth £55.5k-£66.7k per annum (Dependent on skills & qualifications) Full-time Joint-contribution pension from 6% (12% total) - Enhanced maternity & family leave - Life assurance - HolidayPlus - Virtual GP & Employee Assistance Programme plus retail and leisure discounts & many more. REQ5619 We are looking for a Security Operations Analyst to join us and ensure our IT and OT networks are secure and compliant. You will act as an SGN Security subject matter expert and act as the primary contact when assisting with Security incident remediation. We deliver safety, warmth, and comfort to homes and businesses. Every role, whether in the office or on the front line, plays a key part in this mission. Here's how you will contribute Providing support to different Security functions, including OT Security, Governance Risk and Compliance, Security Assurance and other key business needs Ensuring security metrics are well documented and presented at monthly reviews Being a subject matter expert and remaining up to date on cutting-edge technology, providing technical/nontechnical security support to the wider SGN Security team and organisation Working alongside third-party network vendors, coordinating security activities Support with varied tasks, including internal and external audits, penetration testing activities and input into Incident & Lessons Learnt calls to identify solutions Ensuring security policies are enforced and completing routine technical vulnerability assessments, working with IT Security Leads to propose and coordinate delivery of mitigating actions and required solutions Attend head office in Portsmouth at least once a quarter What you will need We're looking for a blend of skills and attributes that make you a great fit for this role. If you don't tick every box, don't worry - we provide tailored learning and development programs to help you grow and succeed with us. You hold a degree or equivalent career experience in a relevant discipline Experience with cloud computing services (IaaS, PaaS, SaaS), in particular AWS, MS Sentinel and Defender Proven experience in some or all of the following Sec Ops domain areas: Monitoring, investigating & performing triage on security alerts, Threat & Vulnerability Management, Security Incident handling, Security Intelligence analysis, SOC Tools administration & Security Forensics, Security Engineering You have good understanding and experience of Cyber Security Frameworks and standards (NCSC security principles, NIST Framework, ISO 27001, ISO27005, IEC62443 etc) You have great attention to detail, a confident communicator across various business levels and decision-maker when required Having experience in a cyber security role, IT support role and/or a background in infrastructure/endpoint support is essential Not sure you meet every requirement? Research shows some people - particularly women and those from underrepresented backgrounds - may hesitate to apply unless they meet every criteria. At SGN, we value diverse backgrounds, experiences and perspectives. If this role interests you but you're not sure you tick every box, we'd still love to hear from you. You might be just who we're looking for - now or in the future. Why SGN? SGN leads pioneering research and development for a energy system. Our innovative technologies are transforming the gas industry while keeping people safe and warm. We are an award-winning employer, including CCA Gold Awards for Great Places to Work and Inclusivity and Accessibility , and a proud Gold member of the Armed Forces Covenant. If you require any accommodations or support during the application process, reach out to us. We're here to help ensure an inclusive and accessible experience for everyone.
May 03, 2026
Full time
Technology Security Analyst Glasgow, Edinburgh, Portsmouth £55.5k-£66.7k per annum (Dependent on skills & qualifications) Full-time Joint-contribution pension from 6% (12% total) - Enhanced maternity & family leave - Life assurance - HolidayPlus - Virtual GP & Employee Assistance Programme plus retail and leisure discounts & many more. REQ5619 We are looking for a Security Operations Analyst to join us and ensure our IT and OT networks are secure and compliant. You will act as an SGN Security subject matter expert and act as the primary contact when assisting with Security incident remediation. We deliver safety, warmth, and comfort to homes and businesses. Every role, whether in the office or on the front line, plays a key part in this mission. Here's how you will contribute Providing support to different Security functions, including OT Security, Governance Risk and Compliance, Security Assurance and other key business needs Ensuring security metrics are well documented and presented at monthly reviews Being a subject matter expert and remaining up to date on cutting-edge technology, providing technical/nontechnical security support to the wider SGN Security team and organisation Working alongside third-party network vendors, coordinating security activities Support with varied tasks, including internal and external audits, penetration testing activities and input into Incident & Lessons Learnt calls to identify solutions Ensuring security policies are enforced and completing routine technical vulnerability assessments, working with IT Security Leads to propose and coordinate delivery of mitigating actions and required solutions Attend head office in Portsmouth at least once a quarter What you will need We're looking for a blend of skills and attributes that make you a great fit for this role. If you don't tick every box, don't worry - we provide tailored learning and development programs to help you grow and succeed with us. You hold a degree or equivalent career experience in a relevant discipline Experience with cloud computing services (IaaS, PaaS, SaaS), in particular AWS, MS Sentinel and Defender Proven experience in some or all of the following Sec Ops domain areas: Monitoring, investigating & performing triage on security alerts, Threat & Vulnerability Management, Security Incident handling, Security Intelligence analysis, SOC Tools administration & Security Forensics, Security Engineering You have good understanding and experience of Cyber Security Frameworks and standards (NCSC security principles, NIST Framework, ISO 27001, ISO27005, IEC62443 etc) You have great attention to detail, a confident communicator across various business levels and decision-maker when required Having experience in a cyber security role, IT support role and/or a background in infrastructure/endpoint support is essential Not sure you meet every requirement? Research shows some people - particularly women and those from underrepresented backgrounds - may hesitate to apply unless they meet every criteria. At SGN, we value diverse backgrounds, experiences and perspectives. If this role interests you but you're not sure you tick every box, we'd still love to hear from you. You might be just who we're looking for - now or in the future. Why SGN? SGN leads pioneering research and development for a energy system. Our innovative technologies are transforming the gas industry while keeping people safe and warm. We are an award-winning employer, including CCA Gold Awards for Great Places to Work and Inclusivity and Accessibility , and a proud Gold member of the Armed Forces Covenant. If you require any accommodations or support during the application process, reach out to us. We're here to help ensure an inclusive and accessible experience for everyone.
Adecco
SOC / Cyber Threat Detection Analyst - SANS/GIAC
Adecco Wokingham, Berkshire
SOC / Cyber Threat Detection Analyst - SANS/GIAC Cyber Threat Detection Analyst Location: Wokingham, Berkshire (On-site) Salary: Competitive (dependent on experience) + excellent benefits & training Security Clearance: Ideally SC Cleared or eligible for SC Role Overview As a Cyber Threat Detection Analyst, you will play a hands-on role within an advanced cyber defence function, focused on proactive threat hunting, adversary behaviour analysis, and high-fidelity threat detection across enterprise environments. This role goes beyond reactive alert handling. You will actively hunt for malicious activity using telemetry, SIEM data, and threat intelligence, develop hypotheses based on MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs), and support incident management and response activities when threats are identified. We are open to experienced SOC Analysts where threat hunting, investigations, and proactive detection have formed a significant part of their role, and who are looking to further develop in a more hunting-led environment. This position is well suited to analysts who enjoy thinking like an attacker, have worked alongside or supported red team or purple team activities, and want to deepen their expertise in threat detection and detection engineering. Skills & Experience We're Seeking Experience in threat hunting, cyber threat detection, SOC, blue team, or cyber defence environments, with ideally around five years hands on experience. Strong hands-on experience using SIEM platforms, including: Microsoft Sentinel (KQL) Splunk (SPL) Elastic Security/Kibana (KQL, ESQL) Practical and operational understanding of MITRE ATT&CK, attacker techniques, and adversary tradecraft Experience working with Indicators of Compromise (IOCs) and threat intelligence feeds Solid experience across the security event life cycle, including detection, investigation, and incident management Hands-on experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike, SentinelOne, or Carbon Black Strong knowledge of networking fundamentals (TCP/IP, DNS, HTTP/S, Firewalls, VPNs, Proxy technologies) Experience analysing telemetry from Windows, Linux, identity, endpoint, and network sources Strong analytical mindset with the ability to clearly communicate findings, impact, and risk Key Responsibilities Conduct proactive threat hunting activities across log, endpoint, and network telemetry to identify suspicious, stealthy, or previously unknown threats Develop and execute hunt hypotheses aligned to MITRE ATT&CK TTPs, adversary behaviours, and emerging threat intelligence Write, refine, and optimise SIEM queries using KQL, SPL, Elastic/ESQL, and Kibana Query Language Perform IOC analysis, enrichment, and validation, integrating internal and external threat intelligence sources Lead investigations from initial detection through scoping, root cause analysis, and impact assessment Support incident management and incident response activities, including containment, remediation, escalation, and lessons learned Collaborate closely with SOC teams, incident responders, red teams, and purple teams to validate detections and improve defensive coverage Contribute to detection logic improvements, use-case development, and continuous enhancement of hunting methodologies Produce clear investigation write-ups, timelines, and recommendations for technical and non-technical stakeholders Security Certifications (Highly Beneficial) SANS/GIAC certifications, including but not limited to: GCIH - Incident Handler GCIA - Intrusion Analyst GCED - Enterprise Defender GCTI - Cyber Threat Intelligence GMON - Continuous Monitoring GDAT - Defending Advanced Threats GCAT - Advanced Threat Intelligence OSCP or equivalent offensive security qualifications Crest certifications, such as: Crest Practitioner Intrusion Analyst (CPIA) Crest Registered Intrusion Analyst (CRIA) Crest Certified Threat Intelligence Analyst (CCTIA) Crest Certified Blue Team Professional (CCBTP) Microsoft SC-200 or related detection and response certifications Other recognised cyber security or threat intelligence credentials
Apr 30, 2026
Full time
SOC / Cyber Threat Detection Analyst - SANS/GIAC Cyber Threat Detection Analyst Location: Wokingham, Berkshire (On-site) Salary: Competitive (dependent on experience) + excellent benefits & training Security Clearance: Ideally SC Cleared or eligible for SC Role Overview As a Cyber Threat Detection Analyst, you will play a hands-on role within an advanced cyber defence function, focused on proactive threat hunting, adversary behaviour analysis, and high-fidelity threat detection across enterprise environments. This role goes beyond reactive alert handling. You will actively hunt for malicious activity using telemetry, SIEM data, and threat intelligence, develop hypotheses based on MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs), and support incident management and response activities when threats are identified. We are open to experienced SOC Analysts where threat hunting, investigations, and proactive detection have formed a significant part of their role, and who are looking to further develop in a more hunting-led environment. This position is well suited to analysts who enjoy thinking like an attacker, have worked alongside or supported red team or purple team activities, and want to deepen their expertise in threat detection and detection engineering. Skills & Experience We're Seeking Experience in threat hunting, cyber threat detection, SOC, blue team, or cyber defence environments, with ideally around five years hands on experience. Strong hands-on experience using SIEM platforms, including: Microsoft Sentinel (KQL) Splunk (SPL) Elastic Security/Kibana (KQL, ESQL) Practical and operational understanding of MITRE ATT&CK, attacker techniques, and adversary tradecraft Experience working with Indicators of Compromise (IOCs) and threat intelligence feeds Solid experience across the security event life cycle, including detection, investigation, and incident management Hands-on experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike, SentinelOne, or Carbon Black Strong knowledge of networking fundamentals (TCP/IP, DNS, HTTP/S, Firewalls, VPNs, Proxy technologies) Experience analysing telemetry from Windows, Linux, identity, endpoint, and network sources Strong analytical mindset with the ability to clearly communicate findings, impact, and risk Key Responsibilities Conduct proactive threat hunting activities across log, endpoint, and network telemetry to identify suspicious, stealthy, or previously unknown threats Develop and execute hunt hypotheses aligned to MITRE ATT&CK TTPs, adversary behaviours, and emerging threat intelligence Write, refine, and optimise SIEM queries using KQL, SPL, Elastic/ESQL, and Kibana Query Language Perform IOC analysis, enrichment, and validation, integrating internal and external threat intelligence sources Lead investigations from initial detection through scoping, root cause analysis, and impact assessment Support incident management and incident response activities, including containment, remediation, escalation, and lessons learned Collaborate closely with SOC teams, incident responders, red teams, and purple teams to validate detections and improve defensive coverage Contribute to detection logic improvements, use-case development, and continuous enhancement of hunting methodologies Produce clear investigation write-ups, timelines, and recommendations for technical and non-technical stakeholders Security Certifications (Highly Beneficial) SANS/GIAC certifications, including but not limited to: GCIH - Incident Handler GCIA - Intrusion Analyst GCED - Enterprise Defender GCTI - Cyber Threat Intelligence GMON - Continuous Monitoring GDAT - Defending Advanced Threats GCAT - Advanced Threat Intelligence OSCP or equivalent offensive security qualifications Crest certifications, such as: Crest Practitioner Intrusion Analyst (CPIA) Crest Registered Intrusion Analyst (CRIA) Crest Certified Threat Intelligence Analyst (CCTIA) Crest Certified Blue Team Professional (CCBTP) Microsoft SC-200 or related detection and response certifications Other recognised cyber security or threat intelligence credentials
EXPERIS
SOC Technical Lead
EXPERIS
Role Overview We are seeking an experienced and hands-on SOC Operations Technical Lead to lead a team of SOC Analysts operating in a 24/7/365 environment. This is a senior, technically focused leadership role within our Managed Security Services (MSSP) function, reporting directly to the Head of SOC Operations. You will act as the senior technical authority, driving excellence in threat detection, incident response, and security operations across a diverse, multi-client portfolio. While you will lead and mentor a team, this is not a purely managerial role. You will remain deeply involved in technical delivery, acting as an escalation point, leading complex investigations, and continuously improving SOC capabilities. Key Responsibilities Team Leadership & SOC Operations Lead day-to-day SOC operations across all shifts, ensuring consistent 24/7 coverage Manage shift schedules, handovers, and on-call rotations Act as the primary escalation point for security incidents and analyst queries Ensure high-quality triage, investigation, and response aligned to SOC processes Drive team development through training, coaching, and technical mentoring Ensure accurate and timely case management (HALO) and delivery against SLAs Technical Leadership & Continuous Improvement Provide expert guidance on threat detection, incident response, and threat hunting Lead escalations for complex or high-severity incidents across client environments Develop and optimise detection rules, playbooks, and automation Improve SOC tooling (SIEM, EDR/XDR, SOAR) and operational processes Design and maintain advanced detection use cases and correlation logic Client Engagement & Consulting Act as a trusted advisor to clients, supporting security reviews and incident analysis Translate technical findings into clear, actionable recommendations Support continuous improvement of client security posture Collaboration Work closely with Threat Intelligence, Engineering, and Incident Response teams Enhance detection capability through intelligence sharing and tool optimisation Align processes to strengthen overall security operations effectiveness Strategic Contribution Identify opportunities to enhance MSSP services and capabilities Monitor emerging threats, technologies, and industry trends Ensure compliance with regulatory standards and internal frameworks Skills & Experience Essential 7+ years in Security Operations, including 3-4 years in a senior/lead SOC role Strong hands-on experience with: SIEM (e.g. Microsoft Sentinel, CrowdStrike) EDR/XDR (e.g. CrowdStrike, Microsoft Defender, Carbon Black) SOAR and threat intelligence platforms Proven expertise in threat hunting and incident response Experience developing and tuning detection rules in multi-tenant environments Strong automation skills to improve SOC efficiency Excellent client-facing and communication skills Desirable Certifications such as CISSP, GIAC (GCIH, GCIA, GREM), SC-200 or SC-300 Experience in cloud security operations Background in MSSP or consulting environments Familiarity with frameworks such as NIST, ISO27001, or ITIL Key Competencies Strong technical depth with the ability to simplify complex concepts Excellent analytical and problem-solving skills under pressure Confident communicator with strong stakeholder engagement skills Collaborative leadership style with a focus on mentoring and development Ability to manage multiple priorities in a fast-paced SOC environment
Apr 30, 2026
Full time
Role Overview We are seeking an experienced and hands-on SOC Operations Technical Lead to lead a team of SOC Analysts operating in a 24/7/365 environment. This is a senior, technically focused leadership role within our Managed Security Services (MSSP) function, reporting directly to the Head of SOC Operations. You will act as the senior technical authority, driving excellence in threat detection, incident response, and security operations across a diverse, multi-client portfolio. While you will lead and mentor a team, this is not a purely managerial role. You will remain deeply involved in technical delivery, acting as an escalation point, leading complex investigations, and continuously improving SOC capabilities. Key Responsibilities Team Leadership & SOC Operations Lead day-to-day SOC operations across all shifts, ensuring consistent 24/7 coverage Manage shift schedules, handovers, and on-call rotations Act as the primary escalation point for security incidents and analyst queries Ensure high-quality triage, investigation, and response aligned to SOC processes Drive team development through training, coaching, and technical mentoring Ensure accurate and timely case management (HALO) and delivery against SLAs Technical Leadership & Continuous Improvement Provide expert guidance on threat detection, incident response, and threat hunting Lead escalations for complex or high-severity incidents across client environments Develop and optimise detection rules, playbooks, and automation Improve SOC tooling (SIEM, EDR/XDR, SOAR) and operational processes Design and maintain advanced detection use cases and correlation logic Client Engagement & Consulting Act as a trusted advisor to clients, supporting security reviews and incident analysis Translate technical findings into clear, actionable recommendations Support continuous improvement of client security posture Collaboration Work closely with Threat Intelligence, Engineering, and Incident Response teams Enhance detection capability through intelligence sharing and tool optimisation Align processes to strengthen overall security operations effectiveness Strategic Contribution Identify opportunities to enhance MSSP services and capabilities Monitor emerging threats, technologies, and industry trends Ensure compliance with regulatory standards and internal frameworks Skills & Experience Essential 7+ years in Security Operations, including 3-4 years in a senior/lead SOC role Strong hands-on experience with: SIEM (e.g. Microsoft Sentinel, CrowdStrike) EDR/XDR (e.g. CrowdStrike, Microsoft Defender, Carbon Black) SOAR and threat intelligence platforms Proven expertise in threat hunting and incident response Experience developing and tuning detection rules in multi-tenant environments Strong automation skills to improve SOC efficiency Excellent client-facing and communication skills Desirable Certifications such as CISSP, GIAC (GCIH, GCIA, GREM), SC-200 or SC-300 Experience in cloud security operations Background in MSSP or consulting environments Familiarity with frameworks such as NIST, ISO27001, or ITIL Key Competencies Strong technical depth with the ability to simplify complex concepts Excellent analytical and problem-solving skills under pressure Confident communicator with strong stakeholder engagement skills Collaborative leadership style with a focus on mentoring and development Ability to manage multiple priorities in a fast-paced SOC environment
Adecco
Cyber Threat Detection / SOC Analyst - SANS/GIAC
Adecco Wokingham, Berkshire
SOC / Cyber Threat Detection Analyst - SANS/GIAC Cyber Threat Detection Analyst Location: Wokingham, Berkshire (On-site) Salary: Competitive (dependent on experience) + excellent benefits & training Security Clearance: Ideally SC Cleared or eligible for SC Role Overview As a Cyber Threat Detection Analyst, you will play a hands-on role within an advanced cyber defence function, focused on proactive threat hunting, adversary behaviour analysis, and high-fidelity threat detection across enterprise environments. This role goes beyond reactive alert handling. You will actively hunt for malicious activity using telemetry, SIEM data, and threat intelligence, develop hypotheses based on MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs), and support incident management and response activities when threats are identified. We are open to experienced SOC Analysts where threat hunting, investigations, and proactive detection have formed a significant part of their role, and who are looking to further develop in a more hunting-led environment. This position is well suited to analysts who enjoy thinking like an attacker, have worked alongside or supported red team or purple team activities, and want to deepen their expertise in threat detection and detection engineering. Skills & Experience We're Seeking Experience in threat hunting, cyber threat detection, SOC, blue team, or cyber defence environments, with ideally around five years hands on experience. Strong hands-on experience using SIEM platforms, including: Microsoft Sentinel (KQL) Splunk (SPL) Elastic Security/Kibana (KQL, ESQL) Practical and operational understanding of MITRE ATT&CK, attacker techniques, and adversary tradecraft Experience working with Indicators of Compromise (IOCs) and threat intelligence feeds Solid experience across the security event life cycle, including detection, investigation, and incident management Hands-on experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike, SentinelOne, or Carbon Black Strong knowledge of networking fundamentals (TCP/IP, DNS, HTTP/S, Firewalls, VPNs, Proxy technologies) Experience analysing telemetry from Windows, Linux, identity, endpoint, and network sources Strong analytical mindset with the ability to clearly communicate findings, impact, and risk Key Responsibilities Conduct proactive threat hunting activities across log, endpoint, and network telemetry to identify suspicious, stealthy, or previously unknown threats Develop and execute hunt hypotheses aligned to MITRE ATT&CK TTPs, adversary behaviours, and emerging threat intelligence Write, refine, and optimise SIEM queries using KQL, SPL, Elastic/ESQL, and Kibana Query Language Perform IOC analysis, enrichment, and validation, integrating internal and external threat intelligence sources Lead investigations from initial detection through scoping, root cause analysis, and impact assessment Support incident management and incident response activities, including containment, remediation, escalation, and lessons learned Collaborate closely with SOC teams, incident responders, red teams, and purple teams to validate detections and improve defensive coverage Contribute to detection logic improvements, use-case development, and continuous enhancement of hunting methodologies Produce clear investigation write-ups, timelines, and recommendations for technical and non-technical stakeholders Security Certifications (Highly Beneficial) SANS/GIAC certifications, including but not limited to: GCIH - Incident Handler GCIA - Intrusion Analyst GCED - Enterprise Defender GCTI - Cyber Threat Intelligence GMON - Continuous Monitoring GDAT - Defending Advanced Threats GCAT - Advanced Threat Intelligence OSCP or equivalent offensive security qualifications Crest certifications, such as: Crest Practitioner Intrusion Analyst (CPIA) Crest Registered Intrusion Analyst (CRIA) Crest Certified Threat Intelligence Analyst (CCTIA) Crest Certified Blue Team Professional (CCBTP) Microsoft SC-200 or related detection and response certifications Other recognised cyber security or threat intelligence credentials
Apr 30, 2026
Full time
SOC / Cyber Threat Detection Analyst - SANS/GIAC Cyber Threat Detection Analyst Location: Wokingham, Berkshire (On-site) Salary: Competitive (dependent on experience) + excellent benefits & training Security Clearance: Ideally SC Cleared or eligible for SC Role Overview As a Cyber Threat Detection Analyst, you will play a hands-on role within an advanced cyber defence function, focused on proactive threat hunting, adversary behaviour analysis, and high-fidelity threat detection across enterprise environments. This role goes beyond reactive alert handling. You will actively hunt for malicious activity using telemetry, SIEM data, and threat intelligence, develop hypotheses based on MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs), and support incident management and response activities when threats are identified. We are open to experienced SOC Analysts where threat hunting, investigations, and proactive detection have formed a significant part of their role, and who are looking to further develop in a more hunting-led environment. This position is well suited to analysts who enjoy thinking like an attacker, have worked alongside or supported red team or purple team activities, and want to deepen their expertise in threat detection and detection engineering. Skills & Experience We're Seeking Experience in threat hunting, cyber threat detection, SOC, blue team, or cyber defence environments, with ideally around five years hands on experience. Strong hands-on experience using SIEM platforms, including: Microsoft Sentinel (KQL) Splunk (SPL) Elastic Security/Kibana (KQL, ESQL) Practical and operational understanding of MITRE ATT&CK, attacker techniques, and adversary tradecraft Experience working with Indicators of Compromise (IOCs) and threat intelligence feeds Solid experience across the security event life cycle, including detection, investigation, and incident management Hands-on experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike, SentinelOne, or Carbon Black Strong knowledge of networking fundamentals (TCP/IP, DNS, HTTP/S, Firewalls, VPNs, Proxy technologies) Experience analysing telemetry from Windows, Linux, identity, endpoint, and network sources Strong analytical mindset with the ability to clearly communicate findings, impact, and risk Key Responsibilities Conduct proactive threat hunting activities across log, endpoint, and network telemetry to identify suspicious, stealthy, or previously unknown threats Develop and execute hunt hypotheses aligned to MITRE ATT&CK TTPs, adversary behaviours, and emerging threat intelligence Write, refine, and optimise SIEM queries using KQL, SPL, Elastic/ESQL, and Kibana Query Language Perform IOC analysis, enrichment, and validation, integrating internal and external threat intelligence sources Lead investigations from initial detection through scoping, root cause analysis, and impact assessment Support incident management and incident response activities, including containment, remediation, escalation, and lessons learned Collaborate closely with SOC teams, incident responders, red teams, and purple teams to validate detections and improve defensive coverage Contribute to detection logic improvements, use-case development, and continuous enhancement of hunting methodologies Produce clear investigation write-ups, timelines, and recommendations for technical and non-technical stakeholders Security Certifications (Highly Beneficial) SANS/GIAC certifications, including but not limited to: GCIH - Incident Handler GCIA - Intrusion Analyst GCED - Enterprise Defender GCTI - Cyber Threat Intelligence GMON - Continuous Monitoring GDAT - Defending Advanced Threats GCAT - Advanced Threat Intelligence OSCP or equivalent offensive security qualifications Crest certifications, such as: Crest Practitioner Intrusion Analyst (CPIA) Crest Registered Intrusion Analyst (CRIA) Crest Certified Threat Intelligence Analyst (CCTIA) Crest Certified Blue Team Professional (CCBTP) Microsoft SC-200 or related detection and response certifications Other recognised cyber security or threat intelligence credentials

Modal Window

  • Home
  • Contact
  • About Us
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • Facebook
  • Twitter
  • Google Plus
  • LinkedIn
Parent and Partner sites: IT Job Board | Jobs Near Me | RightTalent.co.uk | Quantity Surveyor jobs | Building Surveyor jobs | Construction Recruitment | Talent Recruiter | Construction Job Board | Property jobs | myJobsnearme.com | Jobs near me
© 2008-2026 Jobsite Jobs | Designed by Web Design Agency