526 to 550 of 690 SIEM Jobs in England

L3 Security Analyst

Location
Newbury, England, United Kingdom
threats using cutting‐edge tools, collaborate with global teams on incident investigations, and mentor colleagues to uplift skills across the CSOC. From fine‐tuning SIEM systems and automating response actions to delivering insightful security reports and advisories, your expertise will help shape Vodafone’s resilience against evolving threats. This … least 4 years in security event analysis and incident response Strong technical knowledge of networking protocols, operating systems (Windows/Linux), and security technologies (SIEM, EDR, IDS/IPS, firewalls, proxies) Hands‐on experience with SIEM tuning and SOAR automation Familiarity with frameworks like MITRE ATT&CK and cyber kill ...

Blockchain Cyber Intelligence Vice President

Location
Greater London, England, United Kingdom
including network security, malware analysis, threat hunting, threat intelligence production, and security architecture and design, with proficiency in using Security Information and Event Management (SIEM) tools and advanced analytics techniques Advanced knowledge of network and infrastructure configuration/security, including experience in designing and implementing security solutions for on-prem ...

Blockchain Cyber Intelligence Vice President

Location
Greater London, England, United Kingdom
including network security, malware analysis, threat hunting, threat intelligence production, and security architecture and design, with proficiency in using Security Information and Event Management (SIEM) tools and advanced analytics techniques Advanced knowledge of network and infrastructure configuration/security, including experience in designing and implementing security solutions for on-prem ...

Senior Technical Trainer

Location
Reading, England, United Kingdom
Minimum 5+ years of experience with Cyber Security products or platforms, such as but not limited to Endpoint Security, Vulnerability Management, SIEM (Security Information and Event Management), Network Security, Firewall, UTMs, Compliance solutions, etc. Must have previous experience in designing and developing materials and writing assessments for technical training. Excellent ...

Security Architect - Microsoft Security

Hiring Organisation
Hackajob Ltd
Location
South West London, London, United Kingdom
Employment Type
Permanent, Work From Home
security capabilities, including: Microsoft Defender (Endpoint, Identity, Office 365, Cloud Apps) Microsoft Entra ID (P2), Conditional Access and identity protection Microsoft Sentinel (SIEM integration) Microsoft Purview Strong experience designing and implementing Microsoft Purview capabilities, including DLP, Information Protection, Insider Risk and eDiscovery Strong understanding of Zero Trust architecture principles, particularly … identity-driven security models Experience deploying and operating Defender and SIEM capabilities, integrated within a wider security ecosystem Experience conducting security design reviews and translating policy into practical controls Experience performing risk assessments aligned to recognised methodologies Strong understanding of cloud security concepts across IaaS, PaaS and SaaS, particularly within ...

Senior Cyber Security Engineer (EDR) Senior Security Engineer - Monitoring & Detection

Hiring Organisation
Sanderson Recruitment
Location
London, UK
Employment Type
Full-time
securing large-scale, cloud-based environments supporting critical public sector and government services. This is a hands-on engineering role focused on threat detection, SIEM engineering, security monitoring, log management, and SOC optimisation. You'll design and enhance detection capabilities, improve security visibility, and ensure organisations can rapidly identify and … that improve resilience while enabling faster, risk-based decision-making. What You'll Be DoingDetection Engineering & Threat MonitoringDevelop, tune, and maintain detection rules across SIEM, EDR, and threat detection platforms. Create and optimise detection logic using technologies such as Splunk and endpoint security solutions. Map detections against the MITRE ...

Senior Security Operations Engineer (SOC Engineer L3)

Location
Royal Leamington Spa, England, United Kingdom
Senior Security Operations Engineer (SOC Engineer L3) to join their security function. This is a highly technical role focused on SOC engineering, detection engineering, SIEM/SOAR, security automation and AI-driven security operations . You’ll design and improve security monitoring, detection, response and automation capabilities across a large … enterprise environment, with a particular focus on AI and agentic technologies . Key Responsibilities Design and optimise security monitoring, SIEM and detection capabilities . Onboard and manage security logs, including ingestion, parsing, normalisation and enrichment . Develop and tune detection rules, correlation searches and threat detection use cases . Build ...

Interim Cyber Security Officer

Location
Greater London, England, United Kingdom
and security data models. Serve as a technical escalation point for high‐severity security incidents, facilitating rapid investigation, containment, and remediation using EDR and SIEM tools. Develop and implement SOAR workflows to automate detection, response, and security operations processes. Conduct proactive threat hunting using SIEM/EDR data and MITRE … needed. Requirements Minimum of 5+ years’ experience in Cyber Security Engineering or SOC Tier 3 role. Strong hands‐on experience with endpoint security and SIEM platforms in enterprise environments. Experience supporting or working alongside managed SOC providers. At least 2 years’ experience in vulnerability assessment tools (desirable). Exposure ...

Senior Security Analyst (L3 SOC Analyst)

Location
City Of London, England, United Kingdom
coordinating containment, eradication and recovery activities with internal and external stakeholders. Design, develop and optimise detection rules, threat models and advanced monitoring capabilities across SIEM, EDR and cloud security platforms. Conduct proactive threat hunting activities using threat intelligence, behavioural analytics and industry frameworks to identify previously undetected threats. Develop and … operating in a senior SOC environment, including working in an L3 analyst, incident response, threat hunting or detection engineering capacity. Deep technical knowledge of SIEM, EDR, SOAR, cloud security, identity security, endpoint security and enterprise monitoring platforms. Proven experience leading the investigation and response to complex cyber security incidents and ...

Technical Security Architect

Location
England, United Kingdom
including HLDs, LLDs, architecture patterns and data-flow diagrams. Lead the refresh and evergreening of security technologies, including IAM, PAM, firewalls, EDR/XDR, SIEM, vulnerability management and cloud security. Evaluate new technologies through PoCs/PoVs and make clear, evidence-based recommendations. Design and review cloud, identity, network, perimeter … ability to influence both technical and senior stakeholders. CISSP (or equivalent) and TOGAF and/or SABSA. Desirable Zero Trust, DevSecOps, MITRE ATT&CK, SIEM, PAM, Kubernetes/container security, PKI and security automation experience. At DXC Technology, we believe strong connections and community are key to our success. ...

Cyber Security Engineer

Location
Greater London, England, United Kingdom
and security maturity improvements. Get exposure to AI security: Work around Copilot, AI agents, Purview, and data security compliance. Broad technical remit: Microsoft security, SIEM, incident response, cloud/SaaS security, identity, and network security. Room to grow: The team is investing in capability, and strong performers may have scope … management, remediation planning, reporting, and automation. Security incident triage, investigation, and response. Microsoft Defender, Entra ID/Active Directory, Conditional Access, and related controls. SIEM query building and KQL. Ransomware resilience, including backup and network segmentation. Cyber Essentials Plus and wider security maturity initiatives. AI, Copilot, Purview, and data security ...

24 x 7 Security Analyst

Hiring Organisation
LRQA
Location
Birmingham, UK
Employment Type
Full-time
shift team, you will use your expertise to detect and respond to a multitude of threats of differing capability and sophistication. You will use SIEM, EDR, Network Monitoring, bespoke tooling and Threat Intelligence solutions to triage suspicious events, provide context and an assessment of risk/threat to customers … Endpoint, Defender for Identity, Defender for Cloud Apps), including deployment, configuration, and day-to-day operational management within an enterprise environment. Knowledge of SIEM and EDR/EPP technologies, with a particular focus on leveraging Microsoft Sentinel and Defender to deliver threat detection, investigation, and response capabilities. Proven ability ...

Senior Cyber Security Engineer

Hiring Organisation
Checkout.com
Location
London, UK
Employment Type
Full-time
and progressively taking ownership of the tooling and procedures that keep security operations running. What you'll be responsible forSupporting and enhancing security tooling SIEM, EDR, DLP, vulnerability management, and automation platforms including configuration, tuning, and day-to-day maintenanceBuilding and improving operational procedures, runbooks, and playbooks so the team … looking for5+ years of hands-on experience in a Security Operations, SOC, or equivalent operational security rolePractical experience operating modern security tooling SIEM (e.g. Sentinel), Data Loss Prevention (DLP) tools, EDR, and vulnerability management platformsSolid understanding of security operations workflows: alert triage, incident handling, and vulnerability/finding remediation lifecyclesComfort ...

Principal Security Consultant (AIR)

Location
Biggin Hill, England, United Kingdom
Remediation (AIR) consulting team. This is a senior, customer facing role focused on helping enterprise clients design, build, and optimise security operations capabilities - spanning SIEM, Identity, and Endpoint Detection & Response (EDR) technologies. As a Principal Consultant, you operate at the intersection of deep technical expertise and strategic advisory. You will … stand in front of client management. Responsibilities Engagement Delivery Lead the end-to-end design and delivery of AIR engagements - including greenfield SOC builds, SIEM platform implementations (Microsoft Sentinel, Splunk), EDR deployments, and managed security service transitions. Produce high-quality, client-ready deliverables: High Level Designs, Low Level Designs, Statements ...

Senior Cyber Security Engineer (EDR)

Hiring Organisation
Sanderson Government and Defence
Location
Manchester, North West, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£85,000
securing large-scale, cloud-based environments supporting critical public sector and government services. This is a hands-on engineering role focused on threat detection, SIEM engineering, security monitoring, log management, and SOC optimisation . You'll design and enhance detection capabilities, improve security visibility, and ensure organisations can rapidly identify … resilience while enabling faster, risk-based decision-making. What You'll Be Doing Detection Engineering & Threat Monitoring Develop, tune, and maintain detection rules across SIEM, EDR, and threat detection platforms. Create and optimise detection logic using technologies such as Splunk and endpoint security solutions. Map detections against the MITRE ...

Security Consultant

Location
Greater London, England, United Kingdom
facing consultancy role where you'll work with a wide range of organisations to design, develop and optimise detection and response capabilities across leading SIEM, XDR and SOAR technologies. You'll combine deep technical expertise with strong consulting skills, helping customers improve their security maturity through practical, scalable solutions. What … doing You'll play a key role in delivering detection engineering engagements, including: Designing and implementing high-quality detection rules across SIEM and XDR platforms. Creating and optimising detection logic using KQL and other query languages. Developing detection use cases aligned with the MITRE ATT&CK framework and current threat ...

Senior Security Engineering Consultant

Hiring Organisation
Matchtech
Location
Basingstoke, Hampshire, UK
Employment Type
Full-time
Operations domain, focused on helping customers improve and automate their SOC functions, tooling, and detection capabilities. Key Responsibilities: Design and deliver detection rulesets across SIEM and XDR platformsDevelop and tune detection logic using KQL or equivalent query languagesDesign detection use cases aligned to MITRE ATT&CK and real-world attack … and validation of detection approachesIdentify gaps in telemetry, logging and enrichment, and provide recommendations to strengthen detection outcomesJob Requirements: Strong hands-on experience with SIEM engineering, including developing and tuning detection rules, with Microsoft Sentinel preferredExperience writing detection logic using KQL or similar query languagesProven experience designing and implementing SOAR ...

Senior Security Engineer

Location
Gateshead, England, United Kingdom
implementatie en het beheer van specifieke security-oplossingen. Je bent de kartrekker voor onder andere het opzetten van ons nieuwe SOC, Microsoft Sentinel (SIEM) voor actieve threat detection en het beheren van Microsoft Defender for Cloud voor vulnerability management. Je analyseert en volgt security-incidenten op, en bent de drijvende … kracht achter de (versnelde) implementatie van een Security Operations Center (SOC). Ontwikkelen en onderhouden van detectieregels en playbooks (met SOAR/SIEM-tools); Samenwerken met collega’s om incidenten snel en effectief te mitigeren; Continu verbeteren van onze monitoring- en responsprocessen; Rapporteren van bevindingen en adviseren over structurele verbeteringen ...

Lead SOC Architect

Hiring Organisation
Anson Mccade
Location
Central London, London, United Kingdom
Employment Type
Permanent
concepts, CONOPS and high/low-level architecture designs • Working directly with senior client and government stakeholders • Designing and integrating security technologies including SIEM, SOAR, EDR, Threat Intelligence and Vulnerability Management • Assessing existing SOC capabilities and developing security maturity • Designing scalable, resilient on-prem and cloud security architectures • Supporting accreditation … deployment and operation They're looking for: • Strong experience in SOC architecture and security operations • Hands-on architectural experience across at least two of SIEM, SOAR, EDR, Vulnerability Management or Threat Intelligence • Strong understanding of security operations, threat detection and incident response • Experience designing both on-prem and cloud security ...

CSOC Lead

Location
Cheltenham, England, United Kingdom
Incident Response Lead for major cyber security events, coordinating technical investigations, containment and remediation activities. Lead advanced threat hunting and digital forensic investigations using SIEM, EDR, network telemetry and threat intelligence sources. Work closely with global CSOC teams to improve cyber defence capabilities, operational processes and detection methodologies. Provide clear … . Proven success leading teams, projects or operational cyber security functions. Strong incident response, cyber threat hunting and digital forensics expertise. Experience using commercial SIEM, EDR and network analysis platforms. Strong understanding of network protocols and traffic analysis across the OSI model. Experience working with cyber threat intelligence methodologies and ...

Senior SOC Engineer (Sentinel One)

Hiring Organisation
Claranet
Location
City, London, United Kingdom
Employment Type
Permanent
Salary
GBP Annual
engineering team. Key Responsibilities Lead the implementation and optimisation of SentinelOne-based SOC solutions for new and existing customers. Design, deploy, and support SIEM, XDR, EDR, SOAR, and telemetry solutions across cloud, hybrid, and on-premises environments. Act as the senior technical escalation point for complex engineering challenges. Drive continuous … experience in Security Engineering, SOC Engineering, or a similar cyber security role. Strong hands-on experience with the SentinelOne Singularity platform, including XDR, AI SIEM, and EDR technologies. Experience integrating and onboarding log sources across cloud, hybrid, and on-premises environments. Knowledge of automation, API integrations, telemetry pipelines, and security ...

Senior SOC Engineer (Sentinel One)

Hiring Organisation
Claranet
Location
WC2E, Covent Garden, Greater London, United Kingdom
Employment Type
Permanent
engineering team. Key Responsibilities Lead the implementation and optimisation of SentinelOne-based SOC solutions for new and existing customers. Design, deploy, and support SIEM, XDR, EDR, SOAR, and telemetry solutions across cloud, hybrid, and on-premises environments. Act as the senior technical escalation point for complex engineering challenges. Drive continuous … experience in Security Engineering, SOC Engineering, or a similar cyber security role. Strong hands-on experience with the SentinelOne Singularity platform, including XDR, AI SIEM, and EDR technologies. Experience integrating and onboarding log sources across cloud, hybrid, and on-premises environments. Knowledge of automation, API integrations, telemetry pipelines, and security ...

Senior Sales Engineer

Location
Greater London, England, United Kingdom
demos, and solution walkthroughs for enterprise security teams across the UK and Europe Run structured technical discovery to understand customer security posture, existing tooling (SIEM, EDR, SOAR, identity), and integration needs Design and validate customer-specific solutions that meet technical, security, compliance, and business requirements Serve as the primary technical … and CISOs in complex enterprise sales cycles Strong understanding of modern security architecture: identity, endpoint, network, and cloud (AWS, Azure, GCP) Strong knowledge of SIEM, EDR/XDR, SOAR, and common log sources (CloudTrail, Okta, endpoint telemetry, etc.) Familiarity with detection frameworks (MITRE ATT&CK) and threat modeling Comfort with ...

Lead Threat Detection Engineer

Location
Greater London, England, United Kingdom
class looks like. What you’ll be doing: Own and improve the threat detection lifecycle across a complex cloud estate Build and enhance SIEM detection rules, use cases and monitoring Automate manual detection and remediation processes Develop threat intelligence and threat-hunting capabilities Improve security monitoring across AWS, GCP and … and help upskill others across the security function What we’re looking for: Experience building detections rather than purely responding to SOC alerts Strong SIEM experience – Microsoft Sentinel, Splunk or similar Cloud security experience across AWS, GCP and/or Azure KQL, SPL or similar querying experience Python scripting/ ...

Platform Engineer – Monitoring, Observability & SIEM (MONSO)

Location
Greater London, England, United Kingdom
Platform Engineer – Monitoring, Observability & SIEM (MONSO) For our SPEAR Technology (Security, Platform Engineering, Automation and Runtime) division in London we are looking to hire a: Platform Engineer – Monitoring, Observability & SIEM (MONSO) Like solving puzzles with an inquisitive mind? Think outside the box and challenge the status quo? Prefer simplicity over … other teams to do more themselves—such as empower-ing our SOC/CyberSec team to develop (including AI-assisted workflows), test, and deploy SIEM use cases independently via CI/CD. The platform spans Splunk Enterprise on-prem (running on Kubernetes), Splunk Observability Cloud, and SolarWinds , with future expansion ...