26 to 50 of 96 Azure Sentinel Jobs in London

Senior Cyber Security Analyst

Hiring Organisation
Lightsource bp
Location
London, United Kingdom
Salary
£ 80 K
years in a Security Operations Center (SOC) or incident response role Advanced proficiency with Microsoft Defender XDR and expert-level knowledge of Microsoft Sentinel, including KQL query writing and analytics rule development Strong hands-on experience with Microsoft Defender for Endpoint, including policy configuration and threat investigation Demonstrable … experience responding to cyber threats and working in an Azure-focused cloud environment Proven experience with the Cyber Kill Chain, MITRE ATT&CK, and other security defence and intelligence frameworks Experience in stakeholder management and engagement at C-Suite level Experience working for Critical National Infrastructure (CNI) organizations ...

Senior Security Analyst

Location
Greater London, England, United Kingdom
moves effectively between operational incidents, control reviews, stakeholder requests, and security improvement initiatives. Key Responsibilities Investigate and respond to security alerts from Microsoft Sentinel, Microsoft Defender XDR, endpoint security tools, and other monitoring platforms; gather evidence, review logs, coordinate containment, and document findings through resolution. Manage security incidents … phishing‐submission review, policy tuning, and investigation of SPF, DKIM, and DMARC failures. Administer assigned Microsoft security platforms, including Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID, and Microsoft Purview, using least‐privilege and formal change‐management practices. Support the secure adoption and operation of approved artificial intelligence ...

Senior Security Analyst

Hiring Organisation
Brookfield Renewable
Location
London, United Kingdom
Salary
£ 70 K
independently, and moves effectively between operational incidents, control reviews, stakeholder requests, and security improvement initiatives.Key ResponsibilitiesInvestigate and respond to security alerts from Microsoft Sentinel, Microsoft Defender XDR, endpoint security tools, and other monitoring platforms; gather evidence, review logs, coordinate containment, and document findings through resolution.Manage security incidents, approvals … analysis, phishing-submission review, policy tuning, and investigation of SPF, DKIM, and DMARC failures.Administer assigned Microsoft security platforms, including Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID, and Microsoft Purview, using least-privilege and formal change-management practices.Support the secure adoption and operation of approved artificial intelligence ...

Security Operations Engineer

Hiring Organisation
CloudBees
Location
London, United Kingdom
Salary
£ 80 K
Required3+ years of experience in Security Operations, Detection Engineering or Security Engineering. Hands-on experience with enterprise SIEM platforms such as Splunk, Microsoft Sentinel, Elastic, Chronicle or QRadar. Experience building and tuning detection rules. Experience developing SOAR playbooks or security automation. Strong scripting skills using Python, PowerShell … similar languages. Experience working within cloud environments (AWS preferred; Azure or GCP experience also valued). Solid understanding of the MITRE ATT&CK framework. Experience supporting security incident response. Comfortable working with Git, APIs and engineering workflows. Excellent communication skills with both Security and Engineering teams.PreferredExperience with Detection ...

Senior Vulnerability Management Engineer

Location
Greater London, England, United Kingdom
exception and risk acceptance process: assess compensating controls, document residual risk, and obtain formal sign-off. Integrate VM tooling with SIEM (Splunk, Microsoft Sentinel), ITSM (ServiceNow VR module), and CMDB for automated ticket creation and asset correlation. Automate vulnerability reporting and remediation tracking using Python, REST APIs (Qualys … Automation and API integration: Python scripting, REST API calls to Qualys/Tenable/Rapid7; ServiceNow VR module configuration. SIEM integration: Splunk, Microsoft Sentinel – correlating vulnerability data with threat events. CMDB-driven asset correlation: ServiceNow CMDB, ensuring VM data reflects accurate asset inventory. Network and infrastructure knowledge sufficient ...

Cloud Platform Security Engineer Software engineering London

Location
Greater London, England, United Kingdom
here to architect secure cloud environments, build and enhance detection logic at scale, and drive measurable improvements to our security baseline across AWS, Azure, and GCP. You will partner closely with Engineering, GRC, Technology Risk and Security Operations - defining standards, fine tuning the SIEM, and progressively taking … detection engineering challenges across the organisation. What you’ll be responsible for Cloud Security Secure and continuously improve our multi-cloud estate (AWS, Azure, GCP) using cloud native tooling to keep our cloud infrastructure hardened and compliant Partner with Engineering and Security Operation team to make security ...

Lead Cloud Solutions Architect

Hiring Organisation
ZENZO DIGITAL LTD
Location
City of London, London, United Kingdom
Employment Type
Permanent
writing and presenting solutions for new opportunities; scoping technical effort accurately; and giving prospects the confidence to choose us. Behind that sits genuine Azure depth, enough to design the solution yourself, guide the engineers who build it, and step in as the senior technical authority when a complex … proposals and signed engagements. Own the architecture. Produce high-level and low-level designs for secure, scalable, resilient cloud solutions primarily on Microsoft Azure and hand them into delivery with clarity and confidence. Act as senior technical authority. Be the escalation point our delivery and support teams call ...

Lead Cloud Solutions Architect - 1 Day a week in London

Hiring Organisation
Zenzo Digital
Location
London, United Kingdom
Employment Type
Full-Time
Salary
£85,000 - £100,000 per annum
writing and presenting solutions for new opportunities; scoping technical effort accurately; and giving prospects the confidence to choose us. Behind that sits genuine Azure depth, enough to design the solution yourself, guide the engineers who build it, and step in as the senior technical authority when a complex … proposals and signed engagements. • Own the architecture. Produce high-level and low-level designs for secure, scalable, resilient cloud solutions — primarily on Microsoft Azure — and hand them into delivery with clarity and confidence. • Act as senior technical authority. Be the escalation point our delivery and support teams call ...

Cyber Security Lead

Location
Greater London, England, United Kingdom
Doing You'll take technical ownership across a broad security landscape, including: Designing and implementing security architecture across Microsoft 365, Azure, Entra ID, Defender XDR, Sentinel and Purview Building modern security controls around Zero Trust, secure-by-design and automation Leading architecture reviews and threat modelling … external SOC partners Strengthening vulnerability and exposure management using threat intelligence, exploitability and business risk Automating security processes using Python, PowerShell, Logic Apps, Azure Functions and APIs Supporting technical controls and evidence for ISO 27001 and Cyber Essentials Plus Acting as a senior security SME and helping technology ...

Information Security Analyst - SecOps Detection

Hiring Organisation
Starling Bank
Location
London, United Kingdom
Salary
£ 80 K
analytics in our SIEM and other security platforms.Proactive Threat Hunting - Formulate hypotheses and hunt for undetected attacker TTPs across our cloud (AWS, GCP, Azure), SaaS, and endpoint environments.Purple Team - Collaborate with our Adversarial Simulation team in Purple Team exercises to test, validate, and improve detection logic and response.Incident … models like MITRE ATT&CK to prioritize and enhance detective controls.SIEM Expertise: Hands-on experience with SIEM platforms (e.g., Splunk, Google SecOps, Elastic, Sentinel) for rule/query creation and analytics.Threat Hunting: Experience conducting proactive threat hunts, defining hypotheses, and developing hunting methodologies.Cloud Security: Solid knowledge of security ...

Senior Cyber Security Analyst

Hiring Organisation
Tria Recruitment
Location
London, United Kingdom
Salary
£ 80 K
controls.Develop and maintain incident response procedures, playbooks and documentation aligned to industry best practice.Detection Engineering & Security AutomationConfigure, optimise and continuously improve Microsoft Sentinel and Microsoft Defender technologies.Develop and tune detection logic using KQL to identify emerging threats and attacker behaviours.Build and maintain automated SOAR workflows using Logic Apps … premise environments.Maintain high-quality technical documentation for detections, automations and operational workflows.Cloud Security & Secure-by-DesignSupport secure configuration and operational security across Azure and associated cloud services.Collaborate with infrastructure and engineering teams to embed secure-by-design principles.Evaluate configuration changes and ensure alignment with security standards and controls.Support ...

Cyber Security Analyst – Hybrid, MS Security Stack Expert

Location
Greater London, England, United Kingdom
across a global footprint. You will work on managing cyber incidents, threat hunting, vulnerability management and policy compliance using the Microsoft Security Stack (Azure Sentinel, Defender, Purview). #J-18808-Ljbffr ...

security engineer in legal services

Location
Greater London, England, United Kingdom
Authority standards, regulations, and principles Требования: Experience managing EDR platforms, configuring EDR policies, and tuning SIEM Experience with Microsoft Security, including Defender ATP, Azure Security Centre, Entra ID, Intune, and Conditional Access Experience configuring and managing next-generation firewalls, preferably Palo Alto Prisma or similar Experience with email … equivalent Experience with Identity and Access Management, including CyberArk, Entra ID, SSO, MFA, and PAM solutions Experience with SIEM tools such as Sentinel, Exabeam, Splunk, or equivalent Experience with vulnerability management using Tenable or equivalent enterprise toolsets Experience with scripting and automation, preferably PowerShell, and KQL or similar ...

Information Security Analyst - SecOps Detection

Location
Greater London, England, United Kingdom
SIEM and other security platforms. Proactive Threat Hunting - Formulate hypotheses and hunt for undetected attacker TTPs across our cloud (AWS, GCP, Azure), SaaS, and endpoint environments. Purple Team - Collaborate with our Adversarial Simulation team in Purple Team exercises to test, validate, and improve detection logic and response. Incident … like MITRE ATT&CK to prioritize and enhance detective controls. SIEM Expertise: Hands-on experience with SIEM platforms (e.g., Splunk, Google SecOps, Elastic, Sentinel) for rule/query creation and analytics. Threat Hunting: Experience conducting proactive threat hunts, defining hypotheses, and developing hunting methodologies. Cloud Security: Solid knowledge ...

IAM Engineer

Hiring Organisation
Sanderson Recruitment
Location
London, United Kingdom
Employment Type
Permanent
Salary
£75,000
traditional Active Directory services towards a cloud-first Entra ID architecture Design and manage hybrid identity solutions across Active Directory, Entra ID and Azure Implement and enhance SSO, Conditional Access, MFA and passwordless authentication capabilities Drive identity governance initiatives including RBAC, PIM, access reviews and entitlement management Lead … level presentations Support the retirement of legacy authentication methods and infrastructure services Automate IAM and infrastructure processes using PowerShell, Microsoft Graph API and Azure tooling Provide technical leadership across identity-related projects and mentor colleagues where required Required Experience 5+ years' experience in Identity & Access Management, Infrastructure Engineering ...

SOC Engineer: SIEM & Cloud Logs Specialist

Location
Greater London, England, United Kingdom
Hamilton Barnes Associates Limited is seeking a SOC Engineer to onboard clients to SIEM platforms such as Azure Sentinel and Chronicle, integrating log sources and ensuring reliable security telemetry. You will help shape onboarding standards and troubleshoot system availability while supporting Windows and Unix/Linux ...

Security Detection Engineer

Hiring Organisation
McCabe & Barton
Location
London, United Kingdom
Employment Type
Contract
Initial 6-Month Contract We are looking for an experienced Security Detection Engineer to take ownership of detection engineering, and threat hunting across Azure and GCP environments. This is a hands-on opportunity for a security professional with strong SIEM, cloud security, and automation expertise who can operate … independently in a fast-paced environment. Key Responsibilities Detection Engineering & SIEM Uplift Design and implement detection rules in Datadog (or Sentinel/SIEM equivalent) Support UEBA (User & Entity Behaviour Analytics) to catch compromise early Use Claude Code to develop detection logic and correlation rules Build AI-powered anomaly ...

AMBG - Cloud Security & Exposure Management Architect

Location
Greater London, England, United Kingdom
control improvements, and reporting outputs against agreed engagement milestones. Contribute to solution architecture and pre-sales deal shaping for cloud security, Microsoft Defender, Sentinel, Entra, Defender for Cloud, and exposure management opportunities while building trusted relationships with client security, cloud, and operations stakeholders during delivery and pre-sales … engagements. Design, implement, and integrate cloud security, exposure management, threat detection, and security operations capabilities, including Microsoft Sentinel, Defender for Cloud, Defender XDR, and related Microsoft Security technologies. Understand threat modelling, attack paths, cloud misconfigurations, identity risks, vulnerabilities, and how to prioritise remediation based on exploitability and business ...

Security Team Lead

Location
Greater London, England, United Kingdom
security engineers (currently 3) Act as the senior escalation point for security incidents and decision-making Work across a modern Microsoft/Azure environment , driving improvements in M365 security and identity Influence how security is delivered across our sites, combining internal and client-facing services … governance Translate regulatory obligations (FCA, PRA, ISO 27001, Lloyd’s) into practical, measurable controls Hands-On Security Engineering Implement and optimise controls across Azure, M365, and infrastructure environments Lead hardening initiatives across IAM, PAM, AD, and network security Drive security automation and DevSecOps practices Lead real-time response ...

Threat Response Technology and Capabilities Product Owner

Hiring Organisation
Appcast
Location
London, UK
Respond/Recover), NIST SP 800-61r3, MITRE ATT&CK, and D3FEND.• Set roadmap and strategy for SOAR platforms (Splunk SOAR, Microsoft Sentinel SOAR/Logic Apps), case management, evidence collection, and response orchestration.• Define and oversee SOAR playbook automation builds, documentation, and execution• Define … across the full IR lifecycle: triage, scoping, containment, eradication, recovery, evidence handling, post-incident review.• Strong DFIR background covering endpoint, network, cloud (AWS, Azure, GCP), identity, and SaaS forensics.• Working proficiency in Python and PowerShell. Comfort reviewing and directing code without being the primary developer.• Experience with ...

Vulnerability Management Engineer

Hiring Organisation
McCabe & Barton
Location
London, United Kingdom
Employment Type
Contract
Contract Rate
Up to £800 per day
IR35 6-month contract Role Overview We are seeking an experienced Vulnerability Management Engineer to own vulnerability discovery, prioritisation, and remediation tracking across Azure and GCP environments during a critical integration programme. This role requires strong Azure expertise, with GCP experience desirable. You will work closely … identify, prioritise, and remediate security vulnerabilities while leveraging Infrastructure-as-Code and automation to improve security outcomes. Responsibilities Vulnerability Discovery & Triage Scan Azure and GCP infrastructure for known vulnerabilities using Datadog, Sentinel, or equivalent tooling. Integrate with SCA/SBOM tools such as Snyk for dependency ...

3rd Line Engineer

Location
Greater London, England, United Kingdom
scalability, and performance to meet the growth needs of ME+EM. Investigate and diagnose advanced software, hardware, and network problems, utilising expert knowledge of Azure, Google Cloud and Hyper‐V infrastructure to troubleshoot and identify root causes and implement effective solutions. Collaborate with second‐line engineers, vendors, and other … evaluating their potential impact and recommending innovative solutions to address business needs. Skills IT-related degree or equivalent professional experience CCNA or Microsoft Azure Administrator (AZ-104) certified — essential Experience in a third‐line, cloud, or network infrastructure role Proven experience designing and implementing backup & disaster recovery strategies ...

Senior Security Engineer - Contract

Hiring Organisation
Flagstone
Location
London, United Kingdom
Salary
£ 80 K
talk about you.About the teamSecurity Engineering is a team of five covering cloud security, detection, and security operations. They work directly in the Azure estate and are close to the infrastructure, not abstracted behind a policy layer. The team runs Microsoft Sentinel, Defender XDR, and Defender … cloud security, detection tooling, and incident response, without being narrowly specialised. You own meaningful parts of the security stack, contribute hands-on to Azure cloud hardening, and show up reliably when incidents need investigating or pen test cycles need coordinating. You're energised by visible impact, your work ...

Head of Cloud Engineering

Location
Greater London, England, United Kingdom
complex cloud transformation, security modernisation, and AI adoption programmes. Support pre-sales activities, workshops, proof of concepts, and executive presentations. Technology & Innovation Microsoft Azure Microsoft 365 Security Microsoft Defender Suite Microsoft Sentinel Microsoft Entra Microsoft Copilot for Security Microsoft Purview AWS Security Google Cloud Security … Access) Microsoft 365 Defender (Defender for Endpoint, Defender for Office 365, Defender for Identity, Defender for Cloud Apps) Microsoft Defender for Cloud Microsoft Sentinel Microsoft Copilot for Security Microsoft Intune AWS Security Services Google Cloud Platform Security Zero Trust Architectures DevSecOps CNAP platforms (like Wiz and Palo Alto ...

Senior Security Engineer - Contract

Location
Greater London, England, United Kingdom
about you. About the teamSecurity Engineering is a team of five covering cloud security, detection, and security operations. They work directly in the Azure estate and are close to the infrastructure, not abstracted behind a policy layer. The team runs Microsoft Sentinel, Defender XDR, and Defender … cloud security, detection tooling, and incident response, without being narrowly specialised. You own meaningful parts of the security stack, contribute hands‐on to Azure cloud hardening, and show up reliably when incidents need investigating or pen test cycles need coordinating. You're energised by visible impact, your work ...