26 to 50 of 237 Threat Detection Jobs in the UK

Security Engineer

Location
Greater London, England, United Kingdom
passionate individual who enjoys building defences against today's cyber threats, targeting infrastructure, data, and employees. You should be able to analyze the current threat environment and Intigriti’s security posture, then design and implement controls in line with our risk appetite. This position requires strategic thinking, technical expertise … controls leveraging security tools, including EDR, SIEM, phishing simulation, and compliance solutions, among others. In addition, you will own and continuously improve Intigriti’s threat detection capabilities. This includes running day-to-day Security Operations Centre (SOC) activities, expanding log coverage, and building high-quality detections ...

Principal Microsoft Defender XDR, IRM & Deception Engineer

Hiring Organisation
WTW
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
Competitive salary
Deception Engineer, working within the Global Information and Cyber Security Defence (ICSD) function, is the technical leader for enterprise cyber deception and unified detection and response across the Microsoft security ecosystem. The role focuses on building, operating, and continuously evolving an enterprise-grade Insider Risk Management (IRM) and deception … Copilot. The role exists to detect adversaries earlier in the kill chain by deceiving attackers into engaging with high-fidelity traps, while delivering unified detection, automated investigation, and response across endpoint, identity, email, and cloud workloads. It combines deep deception engineering expertise with hands-on Defender XDR mastery ...

Cloud Security Engineer

Hiring Organisation
Kainos
Location
Belfast, UK
Employment Type
Full-time
security best practices and implementing controls for Cloud Security and governance. Implementation of automated security tooling to validate security requirements and identify potential issues. Threat Detection & Incident ResponseDefine threat detection and incident response processes and playbooks for cloud environments. Collaborate with the SOC to operationalise detection ...

SOC Team Lead

Location
Greater London, England, United Kingdom
Drive performance and operational excellence across Shared Service’s Cyber Services function Act as a technical escalation point and line manager Support threat analysis, incident response, and security assurance activities Foster a proactive culture of cyber hygiene and continuous improvement Collaborate across departments to strengthen Shared Service's security … threats and investigative escalations Ensure complex or unresolved cybersecurity issues are escalated appropriately Line manage Cyber Analysts, set objectives, and support development plans Share threat intelligence and cyber knowledge with junior colleagues Provide training and coaching on cyber operations tooling and security practices Contribute to root cause analysis ...

Cloud Security Engineer

Hiring Organisation
Hackajob Ltd
Location
Belfast, County Antrim, Northern Ireland, United Kingdom
Employment Type
Permanent
Salary
£70,000
security best practices and implementing controls for Cloud Security and governance. Implementation of automated security tooling to validate security requirements and identify potential issues. Threat Detection & Incident Response Define threat detection and incident response processes and playbooks for cloud environments. Collaborate with the SOC to operationalise … detection rules and incident handling. Compliance & Audit Support GRC in meeting evidence and compliance requirements for ISO27001, NCSC Cloud Security Principles, and SOC2. Reviewing the outputs from security tools and security practices. You will filter and prioritise these into security stories that can be understood and actioned ...

SOC Subject Matter Expert (UK)

Location
Horsham, England, United Kingdom
decision-making challenges. Working with UX designers to ensure intuitive interfaces that match SOC analyst mental models and workflow patterns. Providing technical consultation on threat detection logic, MITRE ATT&CK mapping, and security operations best practices. Supporting go-to-market activities by creating technical content, conducting product demonstrations … engaging with prospective customers. Mentoring and educating internal teams on SOC operations, threat landscapes, and analyst workflows. Ensuring product features align with industry frameworks (MITRE ATT&CK, NIST, ISO 27001) and SOC maturity models. Act as a trusted SOC and cyber defence expert in customer meetings, workshops, and solution ...

Platform Professional Services Sr. Consultant (Remote, ESP)

Hiring Organisation
CrowdStrike
Location
United Kingdom, UK
Employment Type
Full-time
future of cybersecurity starts with you. About the Role: CrowdStrike Services is seeking a Platform Professional Services Sr. Consultant specialised in AI for Detection and Response who would be responsible for the planning, deployment, implementation, and operational support of the CrowdStrike platform's AI capabilities. This role will focus … specifically on leveraging Falcon's Artificial Intelligence (AI) and Machine Learning (ML) technologies to enhance threat detection, automate response workflows, and maximise security outcomes for customers. The Platform Professional Services Senior Consultant will have responsibility for all aspects of the deployment from the initial customer engagement, planning, installation ...

SIEM Security Engineer

Location
Birmingham, England, United Kingdom
maintaining the ingestion of our security information and event management (SIEM) system. Your focus will be on leveraging Elasticsearch and related technologies to enhance threat detection, incident response, and overall security posture. The role is hybrid (3 days in office) & based in Birmingham What you’ll be doing … scope of data ingestion. Support the configuration of Elasticsearch pipelines for data ingestion from various sources, primarily from Kafka Enhance data enrichment by integrating threat intelligence feeds and contextual information. Ingest data from various networking equipment, servers, firewalls and security appliances across multiple vendors. SIEM Solution Development Collaborate with ...

Cyber Security & Infrastructure Engineer

Hiring Organisation
Adria Solutions
Location
Newcastle-upon-Tyne, Tyne and Wear, North East, United Kingdom
Employment Type
Permanent
Salary
£50,000
role in protecting their systems, networks and data. This is a hands-on position offering the opportunity to work across cyber security, infrastructure, cloud, threat detection and incident response within a small, technically capable IT team. The Role As Cyber Security & Infrastructure Engineer, you will be responsible … security, resilience and operational performance. Key Responsibilities Monitor security alerts, investigate potential incidents and lead incident response activities Conduct forensic investigations and contribute to threat detection and intelligence activities Develop and refine security monitoring, detection rules and use cases Carry out vulnerability scanning and support remediation ...

Interim Cyber Security Officer

Location
Greater London, England, United Kingdom
CrowdStrike and Splunk platforms. The successful candidate will ensure the effective integration, configuration, and operational use of security tools to enhance threat detection, incident response, and overall security maturity. Additionally, the role involves providing technical leadership, mentoring, and knowledge transfer to bolster internal cyber capabilities during a period … point for high‐severity security incidents, facilitating rapid investigation, containment, and remediation using EDR and SIEM tools. Develop and implement SOAR workflows to automate detection, response, and security operations processes. Conduct proactive threat hunting using SIEM/EDR data and MITRE ATT&CK‐aligned techniques. Support vulnerability assessment ...

SOC Analyst - Active SC required

Location
Essex, England, United Kingdom
events using IBM QRadar SIEM Investigate and respond to security incidents across various platforms Manage the full incident lifecycle, from identification to resolution Conduct threat detection and analysis, along with threat hunting activities Perform detailed log analysis across multiple security platforms Produce incident reports and post-incident … insider threats If you are a SOC Analyst with a strong background in security operations and a keen eye for incident response and threat detection, our client wants to hear from you. This is a fantastic opportunity to contribute to a critical project within the Defence & Security sector. ...

Head of Cyber Defence

Hiring Organisation
IDEX Consulting
Location
London, UK
Employment Type
Full-time
cyber security leader responsible for developing and executing enterprise-wide cyber defence strategies to protect critical business systems, data, and infrastructure. Leads security operations, threat detection, incident response, and cyber resilience initiatives while ensuring alignment with organisational risk management objectives. Key ResponsibilitiesLead and manage the Cyber Defence function … overseeing security operations, threat intelligence, vulnerability management, and incident response capabilities. Develop and implement cyber defence strategies, policies, and procedures to protect against evolving cyber threats. Direct Security Operations Centre (SOC) activities, ensuring effective monitoring, detection, investigation, and response to security incidents. Oversee threat intelligence programmes, identifying ...

Security Operations Engineering Manager

Location
City Of London, England, United Kingdom
cyber incident response capability, strengthen our security operations and contribute to the resilience of our cloud-first banking platform against an evolving cyber threat landscape. What’s the Opportunity? This is an exciting opportunity to join our Information Security team in a role that combines hands-on cyber security … expertise with strategic oversight across incident response, threat detection, cloud security and technical assurance. Working across cloud and on-premise environments, you’ll identify and investigate emerging threats, assess technologies and architectures from a security perspective, and continually improve our defensive capabilities. You’ll work closely with technology ...

Cloud Security Engineer - Manchester - National Security West

Hiring Organisation
Hackajob Ltd
Location
Manchester, North West, United Kingdom
Employment Type
Permanent, Part Time, Work From Home
Salary
£95,000
date with the latest releases and best practices. Experience with AWS security services and implementing cloud security best practices, including identity, monitoring, threat detection and data protection. Understanding of Security Operations, including monitoring, alerting, incident response, threat detection, and SIEM platforms such as Microsoft Sentinel … such as Microsoft Sentinel and Splunk. Leveraging AWS security services and promoting security best practices across engineering and development teams. Supporting incident response investigations, threat hunting activities and security improvement initiatives. Developing reusable implementation patterns, standards and automation to improve consistency and security across projects. Managing software configuration, source ...

Cloud Security Engineer - Leeds - National Security West

Hiring Organisation
Hackajob Ltd
Location
Leeds, West Yorkshire, Yorkshire, United Kingdom
Employment Type
Permanent, Part Time, Work From Home
Salary
£95,000
date with the latest releases and best practices. Experience with AWS security services and implementing cloud security best practices, including identity, monitoring, threat detection and data protection. Understanding of Security Operations, including monitoring, alerting, incident response, threat detection, and SIEM platforms such as Microsoft Sentinel … such as Microsoft Sentinel and Splunk. Leveraging AWS security services and promoting security best practices across engineering and development teams. Supporting incident response investigations, threat hunting activities and security improvement initiatives. Developing reusable implementation patterns, standards and automation to improve consistency and security across projects. Managing software configuration, source ...

Cloud Security Engineer - London - National Security West

Hiring Organisation
Hackajob Ltd
Location
Manchester, North West, United Kingdom
Employment Type
Permanent, Part Time, Work From Home
Salary
£95,000
date with the latest releases and best practices. Experience with AWS security services and implementing cloud security best practices, including identity, monitoring, threat detection and data protection. Understanding of Security Operations, including monitoring, alerting, incident response, threat detection, and SIEM platforms such as Microsoft Sentinel … such as Microsoft Sentinel and Splunk. Leveraging AWS security services and promoting security best practices across engineering and development teams. Supporting incident response investigations, threat hunting activities and security improvement initiatives. Developing reusable implementation patterns, standards and automation to improve consistency and security across projects. Managing software configuration, source ...

Cloud Security Engineer – Gloucester- National Security West

Hiring Organisation
BAE Systems
Location
City and Borough of Leeds, United Kingdom
Employment Type
Full Time
date with the latest releases and best practices. Experience with AWS security services and implementing cloud security best practices, including identity, monitoring, threat detection and data protection. Understanding of Security Operations, including monitoring, alerting, incident response, threat detection, and SIEM platforms such as Microsoft Sentinel … such as Microsoft Sentinel and Splunk. Leveraging AWS security services and promoting security best practices across engineering and development teams. Supporting incident response investigations, threat hunting activities and security improvement initiatives. Developing reusable implementation patterns, standards and automation to improve consistency and security across projects. Managing software configuration, source ...

Security Consultant

Location
Newcastle upon Tyne, England, United Kingdom
gaps, and define pragmatic remediation roadmaps aligned to business priorities. Lead and support security architecture reviews across cloud, applications, infrastructure, IAM, data protection and detection/response domains. Provide expert consulting to customers on security strategy, risk reduction, control design, and security operating model improvements. Challenge weak security assumptions … monitoring patterns, and guardrails. Partner with engineering, platform, DevOps and operations teams to embed security into delivery pipelines and infrastructure as code practices. Support threat detection, incident response readiness, use-case tuning, and post-incident improvement activities. Contribute to security standards, policies, patterns, reusable accelerators, and client-facing ...

Senior Cyber Security Analyst

Hiring Organisation
Tria Recruitment
Location
London, UK
Employment Type
Full-time
leading cyber incidents operationally, technically and commercially from end-to-end. You will act as a senior technical subject matter expert across incident response, detection engineering, cloud security and vulnerability management, while also providing calm, structured leadership during high-pressure situations. The environment is heavily Microsoft-focused, with particular … secure-by-design principlesDetection engineering and automationThreat and vulnerability managementYou will work closely with global technology and cyber teams to continuously improve monitoring, detection, response and remediation capabilities across hybrid cloud and on-premise environments. Key ResponsibilitiesIncident Response & Major Incident ManagementLead the end-to-end management of cyber security ...

Blockchain Security Operations Vice President

Location
City Of London, England, United Kingdom
Embrace the challenge of securing institutional blockchain infrastructure at scale, driving operational excellence across on-chain monitoring operations, and implementing cutting-edge detection capabilities for smart contract and digital asset security. As a Blockchain Security Operations Vice President in Cybersecurity & Tech Controls, you will contribute significantly to safeguarding … environment and driving continuous improvement in the firm. Job responsibilities Execute and influence the design of comprehensive security strategies, policies, and procedures to enhance threat detection capabilities and protect the organization's digital assets, smart contracts, and blockchain infrastructure from cybersecurity threats Proactively monitor and analyze complex ...

Cyber Security Engineer

Hiring Organisation
Certain Advantage
Location
Stevenage, Hertfordshire, United Kingdom
Employment Type
Full-Time
Salary
£92.11 per hour
utilising a wide variety of security platforms including but not limited to; SIEM (Security Information Event Management), Network Packet Capture platform, Anti Malicious Code, Threat Detection technologies and platforms across the in-scope UK networks. The SOC Threat Detection Analyst key responsibilities are: Accountable ...

Cyber Security Engineer

Hiring Organisation
Certain Advantage
Location
Stevenage, Hertfordshire, South East, United Kingdom
Employment Type
Contract, Work From Home
Contract Rate
£92.11 per hour, Benefits Overtime Rate
utilising a wide variety of security platforms including but not limited to; SIEM (Security Information Event Management), Network Packet Capture platform, Anti Malicious Code, Threat Detection technologies and platforms across the in-scope UK networks. The SOC Threat Detection Analyst key responsibilities are: Accountable ...

Security Architect - Entra ID/MS/Azure

Location
Greater London, England, United Kingdom
secured. Define security requirements for endpoint, email, Microsoft 365, data, application and network architectures . Establish appropriate requirements for security logging, monitoring, alerting, threat detection and incident response. Review technical architecture and solution designs, identifying security weaknesses, control gaps, dependencies and areas requiring further assurance. Assess migration strategies … policies, information-security standards, data-protection obligations and relevant regulatory or assurance requirements. Maintain appropriate security architecture documentation, including HLDs, security principles, control matrices, threat models, risk assessments, exception records and architecture decision records . Provide clear security recommendations and risk-based advice to programme leadership and senior stakeholders. ...

Director, R&D, Email & Collaboration Threat Protection

Hiring Organisation
Mimecast
Location
London, UK
Employment Type
Full-time
Director, R&D, Email & Collaboration Threat Protection About MimecastMimecast is a leading cybersecurity company that helps organizations protect their people, data, and communications from today's most sophisticated threats. With over 42,000 customers worldwide, we analyze more than 18 billion security events daily to stop attacks before they … both an organization's greatest asset and its most significant security vulnerability. Our platform addresses the human element of cybersecurity by combining advanced threat detection, awareness training, and Incydr risk management to reduce the likelihood and impact of human-caused security incidents. AI-First Engineering at MimecastMimecast ...

Senior Incident Response Consultant, Rapid Response

Location
Oxford, England, United Kingdom
organizations wherever they are in their security maturity and grows with them to defeat cyberattacks. Its solutions combine machine learning, automation, and real-time threat intelligence with frontline human expertise from Sophos X-Ops to deliver advanced, 24/7 threat monitoring, detection, and response. Sophos offers … industry-leading managed detection and response (MDR) alongside a comprehensive portfolio of cybersecurity technologies — including endpoint, network, email, and cloud security, extended detection and response (XDR), identity threat detection and response (ITDR), and next-gen SIEM. Together with expert advisory services, these capabilities help organizations proactively ...