SIEM Management & Optimization: Design, implement, and maintain Microsoft Sentinel workspaces, connectors, analytics rules, and playbooks Develop advanced KQL queries for threat hunting and reporting Optimize SIEM performance, cost, and data retention policies Troubleshoot log ingestion and parsing issues Log Source Integration: Onboard and configure critical log sources (AD, firewalls, servers, cloud infrastructure) Manage event collection and forwarding infrastructure Implement … data filtering and custom log parsing Threat Detection & Use Case Development: Develop and refine detection rules based on threat intelligence and attack patterns Continuously improve detection efficacy and reduce false positives Security Monitoring & Incident Response: Monitor systems for anomalies and malicious activity Contribute to threat hunting and incident response playbooks Provide expert guidance on securing applications and infrastructure Security … Directory, Windows/Linux systems, and cloud platforms (Azure, AWS, GCP) Proficiency in scripting (PowerShell, Python) Familiarity with security frameworks (MITRE ATT&CK, NIST, Kill Chain) Experience with EDR, DLP, Proxy, and SEG tools Desirable Qualifications Certifications: AZ-500, SC-200, SC-900, CompTIA Security+, CISSP, GCIA, GCIH, GCFA, CCSP Experience with SOAR playbooks, YARA rules, STIX, and YAML Participation More ❯
with overall cloud strategy Required Skills & Experience: Proven expertise in Microsoft 365 security technologies (Defender suite, Purview, Entra ID, Intune) Strong knowledge of Zero Trust principles, conditional access and datalossprevention Experience working in regulated enterprise environments Hands-on experience with Sentinel, Log Analytics and KQL is a plus Relevant certifications (SC-200, MS-500, AZ More ❯
Milton Keynes, Buckinghamshire, England, United Kingdom Hybrid / WFH Options
Lorien
team that is responsible for the continued availability and support of a hybrid on-premise and cloud infrastructure. Specifically, working within IT infrastructure support, providing support for Cloud and Data Centre infrastructure by drawing upon their wealth of practical and technical experience. Key Responsibilities Develop strong relationships with the Business Units Respond to the Business Units' requirements as appropriate … working with cloud, server, desktop, network and telephony providers. Good knowledge of PowerShell and Tanium. Good knowledge of IT security practices and the implementation of tools that provide MFA, DLP, proxy services, encryption, event logging and alerting. Demonstrate examples of similar successful positions in the past. Be highly collaborative with the current team, management structure and business leaders. Demonstrate a More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
Morgan Law
basis to provide expert technical leadership in the design, build and continual improvement of Microsoft Power Platform "Service Packs." These will consolidate Finance, HR, Contracts, Risk and Service-performance data into intuitive Power Apps and analytical dashboards-enabling decision-makers across the Council to access timely insight, drive efficiency and evidence outcomes. They need to develop a management suite … end-to-end delivery of model-driven and canvas Power Apps, custom connectors, Dataverse schema and Azure integration components. Configure role-based security, datalossprevention (DLP) policies and automated tests; manage DevOps release pipelines. Organisational Control & Development Continually review procedures, automate manual processes and exploit new Power Platform capabilities (e.g. Co-Pilot, AI Builder) to maximise More ❯