276 to 300 of 349 SIEM Jobs in London

Elasticsearch Consultant

Location
Greater London, England, United Kingdom
Elastic SIEM Engineer We are seeking an experienced Elastic SIEM Engineer to design, implement and maintain security monitoring solutions using the Elastic Stack. The successful candidate will be responsible for developing scalable log-management and threat-detection capabilities across complex cloud and containerised environments. Key Responsibilities Design, deploy and support … Elastic SIEM solutions using Elasticsearch, Logstash and Kibana. Build and maintain log‐ingestion pipelines for infrastructure, applications, cloud platforms and security tools. Develop Kibana dashboards, alerts, detection rules and visualisations. Configure data parsing, enrichment, transformation and indexing within Logstash and Elasticsearch. Integrate Kafka to support reliable, high‐volume event streaming ...

Blockchain Security Operations Vice President

Location
Greater London, England, United Kingdom
multiple security domains, including network security, malware analysis, threat hunting, and security architecture and design, with proficiency in using Security Information and Event Management (SIEM) tools and advanced analytics techniques Advanced knowledge of network and infrastructure configuration/security, including experience in designing and implementing security solutions for on-prem ...

Blockchain Security Operations Vice President

Location
Greater London, England, United Kingdom
multiple security domains, including network security, malware analysis, threat hunting, and security architecture and design, with proficiency in using Security Information and Event Management (SIEM) tools and advanced analytics techniques Advanced knowledge of network and infrastructure configuration/security, including experience in designing and implementing security solutions for on-prem ...

Security Architect - Microsoft Security Platform

Hiring Organisation
Colt Telecom
Location
London, UK
Employment Type
Full-time
Microsoft 365 E5 security capabilities, including: Microsoft Defender (Endpoint, Identity, Office 365, Cloud Apps)Microsoft Entra ID (P2), Conditional Access and identity protectionMicrosoft Sentinel (SIEM integration)Microsoft PurviewStrong experience designing and implementing Microsoft Purview capabilities, including DLP, Information Protection, Insider Risk and eDiscovery Strong understanding of Zero Trust architecture principles … particularly identity-driven security models Experience deploying and operating Defender and SIEM capabilities, integrated within a wider security ecosystem Experience conducting security design reviews and translating policy into practical controls Experience performing risk assessments aligned to recognised methodologies Strong understanding of cloud security concepts across IaaS, PaaS and SaaS, particularly ...

Senior Cybersecurity Analyst - Social, Healthcare and Public Entities

Location
City of Westminster, England, United Kingdom
and participation in audit/certification such as: GDPR, NIST SP800-53, ISO 27001, NIST CSF, etc Experience evaluating logging activities for ingestion into SIEM as part of continuous monitoring plan Experience with security technologies and tooling, e.g. vulnerability scanners, firewalls, network monitors, IAM, SIEM, IDS/IPS Knowledge ...

Cyber Security Engineer

Hiring Organisation
Langley James
Location
London, UK
Employment Type
Full-time
reporting to the IT Security Officer, to implement and maintain robust security across their infrastructure. Key responsibilities include managing WAF/DDoS, security gateways, SIEM/SOAR/EDR, firewalls, MFA/SSO, MDM/MAM, vulnerability scans, and incident response. Key Responsibilities: Manage WAF/DDoS, web/email … security gateways, SIEM/SOAR/EDR (alert response), firewalls, MFA/SSO, MDM/MAM, vulnerability scans/remediation, security certificates, IDS/IPS, PAM, and deliver security awareness training. Remediate penetration test findings and contribute to ad-hoc projects. Essential Experience: Strong knowledge of CrowdStrike EDR, Mimecast ...

Infrastructure Security Engineer

Hiring Organisation
Blockchain
Location
London, UK
Employment Type
Full-time
ownership, and a drive to continuously improve the security posture of complex systems. Familiarity with some of the following: Cloudflare (DDoS protection, WAF), OSS SIEM tools (Splunk, Elastic, etc), Incident management platforms (e.g. Incident.io, PagerDuty)Familiarity with at least one of the following CI/CD systems (Github Actions, Concourse … governance frameworks (e.g., CIS Benchmarks, NIST, SOC2, ISO 27001, PCI DSS) and how to operationalize them. Hands-on experience with building and maintaining a SIEM comprised of open-source and hosted componentsExperience securing consumer-facing web and iOS/Android applicationsExperience designing policies and administering Vault & other Hashicorp products. Experience ...

Senior Attack Monitoring Analyst, GSOC

Hiring Organisation
London Stock Exchange Group
Location
London, UK
Employment Type
Full-time
candidate availability. RESPONSIBILITIES: Triage security events and employ a methodical and coherent response to security incidents adopting playbooks where necessary. Competently operate a chosen SIEM (e.g., Splunk/QRadar/LogRhythm) for incident investigations, or for the development of monitoring dashboards. Utilise playbooks, existing knowledge and accurate online resources … with current vulnerabilities, attacks, and countermeasures. Identify, respond and remediate cyber events generated through monitoring technologies. EXPERIENCE: Preferred experience with operating or administrating a SIEM (e.g., Splunk/QRadar/LogRhythm). Solid understanding of networks including the TCP/IP stack, typical organisation architectures, and common protocols abused ...

Senior CSIRT Analyst

Hiring Organisation
G Research
Location
London, UK
Employment Type
Full-time
technology landscape, including high-performance compute clusters, Kubernetes and containerised infrastructures, and corporate Windows environments. You will use cloud-native security tooling and multi-SIEM operations, such as Elastic, Azure, AWS, to strengthen detection and response capabilities. You will also participate in purple team and red team exercises, continuously validating … role include: Investigating and responding to complex security incidents across cloud, hybrid, and on-premise environmentsProactively hunting for threats and developing detection logic across SIEM and cloud security systemsParticipating in red and purple team exercises to test, validate and enhance detection and response capabilitiesDeveloping and maintaining automation workflows using tools ...

Senior CSIRT Analyst

Location
Greater London, England, United Kingdom
technology landscape, including high-performance compute clusters, Kubernetes and containerised infrastructures, and corporate Windows environments. You will use cloud-native security tooling and multi-SIEM operations, such as Elastic, Azure, AWS, to strengthen detection and response capabilities. You will also participate in purple team and red team exercises, continuously validating … include: Investigating and responding to complex security incidents across cloud, hybrid, and on-premise environments Proactively hunting for threats and developing detection logic across SIEM and cloud security systems Participating in red and purple team exercises to test, validate and enhance detection and response capabilities Developing and maintaining automation workflows ...

Senior Systems Engineer

Location
Greater London, England, United Kingdom
VLAN, 802.1X, SSL, and related protocols. OT Security: Strong Knowledge with securing operational technology environments, addressing unique threats and vulnerabilities inICS/SCADA systems. SIEM : Strong Understanding of SIEM technologies for log management, log analysis, and event correlation. Authentication & Access Control: Proficient in 802.1x, RADIUS, LDAP, AD, smart cards, and ...

Analyst, Information Security

Hiring Organisation
Sony Pictures Entertainment
Location
Greater London, United Kingdom
Employment Type
Full Time
help protect SPE's employees, productions, intellectual property, business operations, and technology environment. What you'll do: Monitor, review, and triage security alerts from SIEM, EDR, email security, identity, cloud, and other security platforms under the direction of senior analysts. Support investigation of suspected security events, including phishing, malware, credential … understanding of networking, operating systems, identity and access management, endpoint security, cloud services, email security, and common cybersecurity threats. Security operations exposure: Familiarity with SIEM, EDR, ticketing/case management, email security, vulnerability management, or log analysis tools preferred. Incident response discipline: Ability to follow playbooks, document investigative steps, preserve ...

Information Security Operations Manager

Location
Greater London, England, United Kingdom
Job Title: Information Security Operations Manager Reporting to: Information Technology Location:Head Office, White City Place, West London Contract Type: Full time, 37.5 hours per week About Us: ME+EM is one of the UK’s ...

Security Architect

Location
Greater London, England, United Kingdom
solutions in alignment with enterprise architecture principles and security policies. Design and architect security solutions across multiple domains, including: Security Information and Event Management (SIEM) Identity and Access Management (IAM) Endpoint Security (EDR, MDM, Endpoint Management tools) Cloud and On-Premises Security Architectures Create high-level and detailed architectural designs … Qualifications & Skills Demonstrated experience creating high-level security solution designs and authoring detailed technical documentation. Proven expertise in designing solutions across multiple security domains including DLP, SIEM, IAM, and Endpoint Security. Strong background in security architecture or solution design , with at least 3+ years in a dedicated security architecture role. ...

Security Operations Specialist

Location
Greater London, England, United Kingdom
clear and effective stakeholder communication, and mentoring other members of the SOC team. What you will do Support SOC Manager to deliver the following SIEM, IR tools platform management including all design, implementation and administration activities Use cases preparation and implementation, connector deployment, maintenance & health checks Responsible for operational activities … Unix shell) Experience working in all phases of the SDLC Deep understanding and experience using cyber security operations, security monitoring, endpoint (EDR), Network, and SIEM Tools Prior SOC experience a plus Extensive knowledge of network and server security protocols, technologies, and products Industry recognized certifications (CISSP, GCIH, GCFA, OSCP ...

Security Platform Engineer, Google Cloud Public Sector

Location
City of Westminster, England, United Kingdom
custom exploits, adversary emulation scenarios, or security automation frameworks for internal testing. Knowledge of cloud-native logging, monitoring, and Security Information and Event Management (SIEM) integration for detecting sophisticated adversary tactics. Understanding of Kubernetes attack surfaces, including container escapes, privilege escalation, and lateral movement techniques. Current and active UK Developed ...

Senior IT Security Analyst (11276)

Location
Greater London, England, United Kingdom
infrastructure teams with firewall configuration, network boundary protection, IDS/IPS and other security controls. Monitor and help configure our security technology landscape, including SIEM, endpoint protection, privileged access management and multi-factor authentication. Carry out regular reviews of security configurations, processes and controls to identify opportunities for improvement. Work … information security frameworks and security solutions, alongside a genuine interest in emerging threats and technologies. You’ll ideally have experience across areas such as: SIEM, vulnerability scanning and endpoint protection. Firewalls, IDS/IPS, Web Application Firewalls and network security. Infrastructure security, hardening and vulnerability/patch management. Windows Server ...

Senior Security Engineer (Infrastructure)

Location
City Of London, England, United Kingdom
environments Support security architecture and hardening initiatives across servers, operating systems, cloud platforms, Kubernetes and infrastructure services Support implementation, tuning and operational maturity of SIEM, alerting and security monitoring platforms Support Layer 7 and web security initiatives including WAF, reverse proxy, API protection and edge security controls Support implementation and … switching, firewalling and network segmentation principles Experience with edge and web security platforms such as Cloudflare, Akamai or similar technologies Experience implementing and managing SIEM, logging, monitoring and security detection platforms Strong understanding of infrastructure hardening, IAM, privileged access management and secrets management Experience securing Kubernetes, containerised workloads and cloud ...

Technology Delivery Lead: Cyber Security

Location
Greater London, England, United Kingdom
security, engineering, architecture, technology and client workstreams to maintain momentum, resolve delivery blockers and oversee initiatives across areas including IAM, cloud security, endpoint protection, SIEM, application security, vulnerability management and Zero Trust Own project governance, including RAID management, status reporting, decision tracking, change control and escalation, maintaining appropriate human review … including planning, RAID management, governance, financial tracking, resource coordination and stakeholder reporting Good understanding of security domains such as IAM, cloud security, endpoint protection, SIEM, application security and vulnerability management, alongside working knowledge of frameworks such as NIST, ISO 27001 and OWASP Experience coordinating delivery across cloud, on-premise ...

Senior Developer Experience Security Engineer

Location
Greater London, England, United Kingdom
and monitoring are consistent, high-quality, and provided as a standard capability for all teams. Define and implement platform-wide security use cases (e.g. SIEM detections, alerts, and signals) that scale across teams without bespoke configuration Work as part of a virtual SOC with the Security Operations Team to support … security for networks, systems, web applications, APIs and databases. Good understanding of secure software development practices. Familiarity with security tools and technologies, such as SIEM, IDS/IPS, WAF and vulnerability scanners. Knowledge of common adversarial Tactics, Techniques and Procedures (Mitre Att&ck TTPs). Knowledge of security standards and ...

Senior Developer Experience Security Engineer

Hiring Organisation
Motorway
Location
London, UK
Employment Type
Full-time
and monitoring are consistent, high-quality, and provided as a standard capability for all teams. Define and implement platform-wide security use cases (e.g. SIEM detections, alerts, and signals) that scale across teams without bespoke configurationWork as part of a virtual SOC with the Security Operations Team to support … security for networks, systems, web applications, APIs and databases. Good understanding of secure software development practices. Familiarity with security tools and technologies, such as SIEM, IDS/IPS, WAF and vulnerability scanners. Knowledge of common adversarial Tactics, Techniques and Procedures (Mitre Att&ck TTPs).Knowledge of security standards and frameworks ...

Senior Cloud Security Engineer

Hiring Organisation
Checkout.com
Location
London, UK
Employment Type
Full-time
design phase and ongoing operations of our multi-cloud posture, define guardrails and policy-as-code standards, and support the strengthening of our SIEM and detection capability. You'll take on the most complex and ambiguous cloud security challenges in the business, and hold engineers to best practices. This … benchmarks, and holding engineering teams accountable to remediation outcomes. Work with Security Operations to shape cloud logging and detection requirements, ensuring our SIEM has the right visibility across the estate. Collaborate with senior stakeholders to articulate security risks and mitigations in terms that support business decision-making. Skills and Experience ...

Lead Technical Engineer (SOC)

Location
London, United Kingdom
and support cloud, on-premises VM, and container-based hosting. Design and configure network security devices, routers, switches, VLANs, DNS, and identity management. Lead SIEM onboarding activities, ensuring solutions support high data ingest rates. Develop test procedures covering functional and non-functional requirements. Maintain requirements and user stories, ensuring traceability … technical engineering, SOC deployment, or security infrastructure. Proven experience designing, building, and deploying SOC solutions for previous clients. Experience with at least two of SIEM, SOAR, EDR, Vulnerability Management, or Threat Intelligence. Strong experience deploying and configuring applications in cloud and/or on-premises environments, particularly for high data ...

Senior Sales Engineer

Hiring Organisation
Sumo Logic
Location
London, UK
Employment Type
Full-time
with experience leading projects and/or working with customersHands on knowledge of Security related products, technologies, and sources such as IDS/IPS, SIEM/Log Management, Network/Endpoint Security, Threat Detection, Incident Response, MSSP/MDR, Threat Feeds, CASB, etcExperience with open source collections (Telegraf, FluentBit, FluentD … increasing complexity of modern cybersecurity and cloud operations challenges, we empower digital teams to move from reaction to readiness—combining agentic AI-powered SIEM and log analytics into a single platform to detect, investigate, and resolve modern challenges. Customers around the world rely on Sumo Logic for trusted insights ...

Senior Solutions Engineer

Location
Greater London, England, United Kingdom
experience leading projects and/or working with customers Hands on knowledge of Security related products, technologies, and sources such as IDS/IPS, SIEM/Log Management, Network/Endpoint Security, Threat Detection, Incident Response, MSSP/MDR, Threat Feeds, CASB, etc Experience with open source collections (Telegraf, FluentBit … increasing complexity of modern cybersecurity and cloud operations challenges, we empower digital teams to move from reaction to readiness- combining agentic AI-powered SIEM and log analytics into a single platform to detect, investigate, and resolve modern challenges. Customers around the world rely on Sumo Logic for trusted insights ...