301 to 325 of 349 SIEM Jobs in London

Senior Attack Monitoring Analyst, GSOC

Location
Greater London, England, United Kingdom
candidate availability. RESPONSIBILITIES Triage security events and employ a methodical and coherent response to security incidents adopting playbooks where necessary. Competently operate a chosen SIEM (e.g., Splunk/QRadar/LogRhythm) for incident investigations, or for the development of monitoring dashboards. Utilise playbooks, existing knowledge and accurate online resources … with current vulnerabilities, attacks, and countermeasures. Identify, respond and remediate cyber events generated through monitoring technologies. EXPERIENCE Preferred experience with operating or administrating a SIEM (e.g., Splunk/QRadar/LogRhythm). Solid understanding of networks including the TCP/IP stack, typical organisation architectures, and common protocols abused ...

Security Engineer

Location
Greater London, England, United Kingdom
design and build the platform that feeds Outerlimit security telemetry from the Global portal into the tools our customers run their security operations in (SIEM, SOAR, XDR etc). Today we discover shadow AI, enforce policy at the appliance and MCP gateway, and record every tool call an agent attempts. … Platform Build signed, idempotent event delivery with bounded retry, dead-lettering and replay Build a cursor-paginated pull and export API to carry bulk SIEM and XDR telemetry Build native connectors for destinations such as Microsoft Sentinel, Splunk and XSIAM Build self-service API key and webhook management ...

Cyber Security Manager

Location
Greater London, England, United Kingdom
posture while ensuring exceptional service delivery. This is a highly visible role that combines cyber security expertise, customer engagement and service leadership across SOC, SIEM, MDR, threat intelligence and incident response services. What You’ll Be Doing Act as the primary customer contact for managed cyber security services. Lead service … security data into meaningful business insights, recommendations and executive reports. Drive Customer Success Plans and Continuous Service Improvement initiatives. Monitor service performance across SOC, SIEM, MDR, EDR/XDR, vulnerability management and threat intelligence services. Coordinate the response to major security incidents, managing communications, escalations and stakeholder engagement. Identify security ...

Security Operations Architect

Location
City Of London, England, United Kingdom
background in solution design and development for security operations Experience with Architecture Frameworks (ideally TOGAF) and developing HLD and LLD documents Technical expertise in SIEM and SOAR tooling, such as Google SecOps or similar Proficiency with EDR, XDR, and NDR tools like Crowdstrike or Microsoft Defender Experience working within Agile … DevOps, or Kanban delivery models KEY SKILLS Security Operations Architect, Cyber Security, SIEM, SOAR, EDR, XDR, Solution Design, TOGAF, HLD, LLD, Google SecOps, NSD #J-18808-Ljbffr ...

Senior Platform Engineer (United Kingdom)

Location
Greater London, England, United Kingdom
partners and security teams. Build and manage CI/CD pipelines that integrate DevSecOps best practices from development through to deployment. Integrate and maintain SIEM and security tooling, ensuring observability and compliance across all deployed systems. Design, develop, and debug microservices in Go (Golang), with a focus on performance, security … classified environments. Experience building and maintaining secure CI/CD pipelines and integrating security throughout the SDLC. Hands-on experience implementing or managing SIEM, monitoring, and alerting systems. Understanding of REST APIs, authentication flows, event-driven architecture, and microservice patterns. IAC and technical experience with Pulumi, Terrraform, argo and flux ...

Senior Platform Engineer (United Kingdom)

Location
Greater London, England, United Kingdom
What You’ll Do Build and manage CI/CD pipelines that integrate DevSecOps best practices from development through to deployment. Integrate and maintain SIEM and security tooling, ensuring observability and compliance across all deployed systems. Build and implement scalable, secure cloud infrastructure using Kubernetes and Pulumi (Go-based), ensuring … classified environments. Experience building and maintaining secure CI/CD pipelines and integrating security throughout the SDLC. Hands‐on experience implementing or managing SIEM, monitoring, and alerting systems. Understanding of REST APIs, authentication flows, event‐driven architecture, and microservice patterns. Excellent written and verbal communication skills, with strong documentation habits. ...

Senior Security Engineer - Detection & Response New London, UK

Location
Greater London, England, United Kingdom
develop, test, and deploy high-fidelity rule-based and anomaly-based detections-as-code Detect and respond to cyber threats using security data lake, SIEM, and cloud platforms Respond to alerts, cyber threats, and drive end-to-end incident response investigations Perform digital forensic investigations to include collection and analysis … automate detection and response operations Conduct threat hunts across corporate, cloud and product environments Support data engineering workflows for core security data lake and SIEM platforms Be an active member of D&R on-call rotations Coach and mentor security engineers within the detection & response team We’d love ...

Senior Security Engineer - Detection & Response

Hiring Organisation
Klaviyo
Location
Greater London, United Kingdom
Employment Type
Full Time
Salary
84000 to 126000 GBP Annually
develop, test, and deploy high-fidelity rule-based and anomaly-based detections-as-code Detect and respond to cyber threats using security data lake, SIEM, and cloud platforms Respond to alerts, cyber threats, and drive end-to-end incident response investigations Perform digital forensic investigations to include collection and analysis … automate detection and response operations Conduct threat hunts across corporate, cloud and product environments Support data engineering workflows for core security data lake and SIEM platforms Be an active member of D&R on-call rotations Coach and mentor security engineers within the detection & response team We’d love ...

Security Operations Center (SOC) Designer

Location
Greater London, England, United Kingdom
software, and network components. Develop and maintain the SOC's layout, including physical and virtual configurations. Evaluate, select, and integrate security technologies such as SIEM, IDS/IPS, firewalls, and endpoint protection systems. Ensure seamless integration of security tools and platforms to enable efficient data collection, analysis, and response. Develop … and conduct workshops to ensure the SOC team is well-equipped to handle security incidents. Skills and Qualifications Extensive knowledge of security technologies, including SIEM, IDS/IPS, firewalls, endpoint protection, and threat intelligence platforms. Experience with network architecture, operating systems, and security protocols. Proven experience in designing and implementing ...

Security Engineer (Institutional Trading)

Location
Greater London, England, United Kingdom
and maintain monitoring for FinOps‐specific security signals such as abnormal order patterns, signature misuse, unusual settlements. You will integrate these signals into our SIEM/SOAR for real‐time response. Support secrets and key‐management hygiene. You will ensure app/service keys are stored in KMS/Vault … expertise in Threat Modeling. Ability to perform structured reviews (e.g., STRIDE) of complex data flows and operational processes. Experience with observability and detection tooling (SIEM, logs, metrics) and ability to write basic detection rules. Practical experience with KMS/HSM, secrets management platforms (Vault, 1Password, AWS/ ...

Security Engineer, Institutional Trading

Hiring Organisation
Blockchain
Location
London, UK
Employment Type
Full-time
and maintain monitoring for FinOps-specific security signals such as abnormal order patterns, signature misuse, unusual settlements. You will integrate these signals into our SIEM/SOAR for real-time response. Support secrets and key-management hygiene. You will ensure app/service keys are stored in KMS/Vault … expertise in Threat Modeling. Ability to perform structured reviews (e.g., STRIDE) of complex data flows and operational processes. Experience with observability and detection tooling (SIEM, logs, metrics) and ability to write basic detection rules. Practical experience with KMS/HSM, secrets management platforms (Vault, 1Password, AWS/ ...

Account Executive

Location
City Of London, England, United Kingdom
close that gap. Our mission is to enable security teams to decide and act faster across the entire threat lifecycle. The Securonix Unified Defense SIEM is the industry’s first platform powered by agentic AI and designed with a human-in-the-loop philosophy. It unifies detection, investigation, and response … result is a CyberOps experience that scales as threats evolve. Securonix is recognized as a six-time Leader in the Gartner Magic Quadrant for SIEM and a Customers’ Choice on Gartner Peer Insights. The company has been featured by leading publications including WIRED, Dark Reading, and Fortune for its innovation ...

Cyber AI Engineer - Remote

Hiring Organisation
CBSbutler Holdings Limited trading as CBSbutler
Location
London, United Kingdom
Employment Type
Contract
Contract Rate
£400 - £425/day
orchestration and knowledge retrieval Developing AI solutions using Python and modern AI frameworks Working with vector databases and retrieval technologies Integrating AI capabilities with SIEM, SOAR and wider cyber platforms Designing prompts and optimising LLM performance Building proofs-of-concept and technical prototypes Developing evaluation frameworks to test model performance … systems Python development Vector databases and knowledge retrieval AI evaluation and model testing API integration and secure software engineering Cyber Security/SOC environments SIEM/SOAR technologies Rapid prototyping and PoC development You don't need to have done everything above. Strong practical GenAI engineering experience combined with ...

Senior Defensive Content Engineer

Location
Greater London, England, United Kingdom
have created content, make sure to share with us some details along with your application. Technology tools & weapons you’ll be using: SIEM, EDR, Wireshark, Windows, Linux, VMware, Cloud Platforms Interesting resources you should check Explore our insights on Threat Ranges to understand the core environments you will be building. … unlock the role of the Senior Defensive Content Engineer at Hack The Box: Tooling & Technical Mastery: Expert proficiency with defensive security tools (e.g., SIEM, EDR, Wireshark, Volatility, Autopsy, IDA) and core domains such as detection engineering, digital forensics, and malware analysis. Content Engineering Experience: Proven track record of designing content ...

Cyber Security Analyst

Hiring Organisation
VIQU IT
Location
London, Portsoken, United Kingdom
Employment Type
Contract
Contract Rate
£350 - £400/day
IR35 My Client is looking for a Cyber Security Analyst to support day-to-day BAU security operations, with a primary focus on Rapid7, SIEM monitoring, vulnerability management and security investigations . They have quite a few backlog of alerts, so they are looking for someone with strong SIEM, vulnerability … and investigation skills. Key Skills & Experience from the Cyber Security Analyst: Strong hands-on experience with Rapid7 and SIEM platforms . (Monitoring alerts and investigation) Proven experience in alert triage, security investigations and vulnerability management . Strong Mimecast administration experience (Email review, releasing, whitelisting, sandboxing) Good working knowledge of Microsoft ...

Cyber Security Project Manager

Location
Greater London, England, United Kingdom
quality requirements. Establish relationships between business services, applications, infrastructure, OT systems, information assets and accountable owners. Coordinate integration with asset-discovery, ITSM, vulnerability management, SIEM, network management, cloud and other enterprise platforms. Oversee asset discovery and reconciliation across corporate, operational and field environments. Develop safe and proportionate approaches … . Experience with enterprise CMDB/ITSM platforms. Experience with OT asset-discovery or industrial cyber-monitoring technologies. Experience integrating CMDB, vulnerability-management, SIEM and enterprise architecture platforms. Knowledge of the NCSC Cyber Assessment Framework, IEC 62443, ISO 27001, ISO 55001 or ITIL . Experience developing information asset registers, data ...

Security Engineer

Location
Greater London, England, United Kingdom
broad generalist security engineering role in a Microsoft environment. You'll work across identity and access management, cloud security, vulnerability management, and SIEM/detection, with an early focus on improving SSO and access management, strengthening joiner/mover/leaver processes, reducing reliance on traditional VPN access and improving … security controls, automating manual processes and working closely with IT, Engineering and senior stakeholders. Experience across areas such as Entra ID, AWS/GCP, SIEM, vulnerability management, Zero Trust or security automation would be beneficial. A great opportunity for a Security Engineer ready to take broader technical ownership ...

Lead Security Engineer

Hiring Organisation
Barclay Simpson Corporate Governance Recruitment
Location
London, UK
Employment Type
Full-time
broad generalist security engineering role in a Microsoft environment. You'll work across identity and access, Zero Trust, cloud security, vulnerability management, SIEM/detection and application security, with an early focus on improving SSO and access management, strengthening joiner/mover/leaver processes, reducing reliance on traditional … security controls, automating manual processes and working closely with IT, Engineering and senior stakeholders. Experience across areas such as Entra ID, AWS/GCP, SIEM, vulnerability management, Zero Trust or security automation would be particularly relevant. A great opportunity for a strong Security Engineer ready to take broader technical ownership ...

Staff / Senior Staff Security Engineer, Vinted Pay

Location
Greater London, England, United Kingdom
Vinted Pay builds, not a parallel workstream. Find and close the operational blind spots: run deep technical reviews of our AWS infrastructure, payment pipelines, SIEM and logging, and vulnerability management tooling (e.g. Wiz), and fix what you find - prioritised by exposure, not by finding count. Own PCI DSS and data … and translate technical risk into business consequence for senior audiences, internal and external. Comfortable in our stack - Ruby on Rails, Go, MySQL, Temporal, AWS, SIEM and CSPM tooling - or eager to learn it, with a real interest in security and privacy as a field and the appetite to keep growing ...

Technical Leader - Splunk Security

Location
Greater London, England, United Kingdom
advisors for sophisticated, multi-functional security initiatives at regional and global scale. We lead the compose, planning, and delivery of tailored Splunk solutions—including SIEM, SOAR, and AI-driven security operations—that address critical customer security needs. We partner with senior customer leaders to guide security adoption journeys, optimize threat … response, and ensure solutions deliver measurable business value. Your Impact Technical Leadership: Provide authority guidance within the Splunk security domain, exhibiting deep expertise in SIEM, SOAR, and Observability integrations. Strategic Advisory: Lead sophisticated, multi-functional security projects, acting as a trusted partner to CISO and IT leadership. Solution Delivery: Lead ...

Staff / Senior Staff Security Engineer, Vinted Pay

Hiring Organisation
Vinted
Location
London, UK
Employment Type
Full-time
Vinted Pay builds, not a parallel workstream. Find and close the operational blind spots: run deep technical reviews of our AWS infrastructure, payment pipelines, SIEM and logging, and vulnerability management tooling (e.g. Wiz), and fix what you find - prioritised by exposure, not by finding count. Own PCI DSS and data … and translate technical risk into business consequence for senior audiences, internal and external. Comfortable in our stack - Ruby on Rails, Go, MySQL, Temporal, AWS, SIEM and CSPM tooling - or eager to learn it, with a real interest in security and privacy as a field and the appetite to keep growing ...

Cyber Security Analyst L4

Location
Greater London, England, United Kingdom
London, United Kingdom | Posted on 05/13/2026 The Security Operations Analyst is a member of the Security Operations team,reporting to the Security Operations Lead. The purpose of this role is tomaintain ...

Hybrid Security Engineer - Cloud, SIEM (London, 6m FTC)

Location
Greater London, England, United Kingdom
seeking a Senior Security Engineer in London with strong Microsoft, Azure, cloud and enterprise security experience. The role involves building security controls for SIEM and PKI/BYOK integrations, and configuring Defender for Cloud and Purview across a complex environment. You will lead technical delivery, often guiding a small team ...

Cyber Security Manager

Hiring Organisation
Nexus Jobs
Location
London, UK
Employment Type
Full-time
industry standards. This role covers information protection, including data loss protection and data classification, and threat protection, including security information and event management (SIEM), user and entity behaviour analytics (UEBA), point products like anti-virus (AV) and intrusion detection system/intrusion prevention system (IDS/IPS) and penetration testing. … ISO27001, PCI and GDPR. Possibly a certified ethical hackerKnowledge of Security technologies is essential, such as network appliances, firewall administration, AD, IAM, PAM, SIEM, UEBA, AV, IDS/IPS and MDM solutions Understanding of common frameworks, such as ITIL or LEAN is preferredGood exposure of user environment management, including desktops ...

Data Analytics Engineer

Hiring Organisation
Intec Select Ltd
Location
London, Billingsgate, United Kingdom
Employment Type
Contract
Contract Rate
£650 - £750/day
Data Analytics Engineer | Splunk & Cribl | SIEM Pipelines We're hiring a Data Analytics Engineer to lead the migration, optimisation and secure operation of log ingestion and observability pipelines, with a focus on moving log sources from Splunk ingestion to Cribl Stream/Edge. The role Lead the migration … and maintain Cribl and Splunk configs: transformations, field normalisation, masking, enrichment Work with SOC, IR and threat detection teams so security logs reach the SIEM reliably and are tuned for detection Monitor and resolve pipeline and SIEM issues, and report on ingest reduction, cost savings, pipeline health and event loss ...