1 to 25 of 167 Permanent MITRE ATT&CK Jobs in England

Senior Security Engineering Consultant

Hiring Organisation
Nomios
Location
Basingstoke, United Kingdom
delivered in a consistent and scalable way. Working directly with customers, you will define detection strategies, design use cases aligned to MITRE ATT&CK, and guide improvements in visibility, coverage and response maturity. You will work closely with platform onboarding and engineering teams, supplementing them … rulesets across SIEM and XDR platformsDevelop and tune detection logic using KQL or equivalent query languagesDesign detection use cases aligned to MITRE ATT&CK and real-world attack techniquesMap customer log sources to detection use cases to assess coverage and identify gapsDesign and implement SOAR ...

Senior Detection and Response Engineer

Location
Cambridge, England, United Kingdom
improve security telemetry, alert enrichment, investigation workflows and response times. Conduct threat hunting using adversary behaviours, TTPs and frameworks such as MITRE ATT&CK, incorporating findings into security controls and detections. Create and continuously improve incident runbooks, playbooks and detection processes based on findings from … ability to write and develop queries for complex investigations. Understanding of adversary tactics, techniques and procedures (TTPs), offensive security concepts and MITRE ATT&CK principles. Practical knowledge of cloud environments and security controls, with the ability to apply detection and incident response practices across hybrid ...

Senior Security Engineering Consultant

Hiring Organisation
Infosec
Location
Basingstoke, Hampshire, South East, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£80,000
SIEM and XDR platforms Develop and tune detection logic using KQL or equivalent query languages Design detection use cases aligned to MITRE ATT&CK and real-world attack techniques Map customer log sources to detection use cases to assess coverage and identify gaps Design … consultant Lead workshops covering detection engineering, use case design and SOC maturity Guide customers on improving detection coverage and aligning to MITRE ATT&CK Clearly explain detection strategies, gaps and recommendations to both technical and non-technical stakeholders Work closely with platform onboarding and engineering ...

Senior Cyber Threat Intelligence (CTI) Analyst

Location
Greater London, England, United Kingdom
processes to improve the quality and relevance of CTI outputs. Analyse threat actor behaviour and map activity to frameworks such as MITRE ATT&CK to support defensive strategy and risk‐based decision‐making. Brief technical, business, and senior leadership stakeholders on cyber threats, trends, potential … function. Demonstrated experience conducting threat actor analysis, adversary tracking, campaign analysis, IOC/TTP analysis, and intelligence production, including use of MITRE ATT&CK or similar frameworks to structure analysis and communicate adversary behaviour. Strong understanding of the intelligence lifecycle, including requirements, collection, analysis, dissemination ...

Senior Security Engineering Consultant

Hiring Organisation
Matchtech
Location
Basingstoke, United Kingdom
rulesets across SIEM and XDR platformsDevelop and tune detection logic using KQL or equivalent query languagesDesign detection use cases aligned to MITRE ATT&CK and real-world attack techniquesMap customer log sources to detection use cases to assess coverage and identify gapsDesign and implement SOAR … trusted technical consultantLead workshops covering detection engineering, use case design and SOC maturityGuide customers on improving detection coverage and aligning to MITRE ATT&CKClearly explain detection strategies, gaps and recommendations to both technical and non-technical stakeholdersWork closely with platform onboarding and engineering teams to ensure smooth ...

SOC Subject Matter Expert (UK)

Location
Horsham, England, United Kingdom
designers to ensure intuitive interfaces that match SOC analyst mental models and workflow patterns. Providing technical consultation on threat detection logic, MITRE ATT&CK mapping, and security operations best practices. Supporting go-to-market activities by creating technical content, conducting product demonstrations, and engaging with … customers. Mentoring and educating internal teams on SOC operations, threat landscapes, and analyst workflows. Ensuring product features align with industry frameworks (MITRE ATT&CK, NIST, ISO 27001) and SOC maturity models. Act as a trusted SOC and cyber defence expert in customer meetings, workshops ...

Cloud Platform Security Engineer Software engineering London

Location
Greater London, England, United Kingdom
modern SIEM platform (e.g. Sentinel) including KQL detection rules, workbooks, logging pipelines, and AI-assisted alert triage. Map detection coverage against MITRE ATT&CK tactics and techniques. Identify and close visibility gaps across the cloud estate. Maintain alignment to PCI DSS, SOC2, ISO27001 NIST … Python, PowerShell, or Bash for security automation. Strong grasp of PCI DSS, NIST CSF, SOC 2, ISO27001, CIS Benchmarks, and MITRE ATT&CK for Cloud. Nice to have AZ-500, AWS Certified Security – Specialty, or equivalent cloud security certification. Experience integrating ATT&CK ...

Cyber Security Engineer - Threat Detection

Location
City Of London, England, United Kingdom
health for assigned detection areas, including retiring logic that no longer earns its place Detection Coverage - Map detection coverage to the MITRE ATT&CK framework, identify gaps, and propose the telemetry or logic needed to close them Threat Intelligence Integration - Convert threat intelligence reporting into … ability to investigate suspicious activity end to end: read the logs, form a conclusion, and communicate it clearly Familiarity with the MITRE ATT&CK framework and the ability to reason about adversary tradecraft rather than only indicators Solid understanding of operating system internals, networking ...

Security Engineer

Hiring Organisation
NTT DATA
Location
Birmingham, United Kingdom
help define corrective actions to reduce future risks. Threat Modelling & Use Case Development Perform threat modeling using industry frameworks such as MITRE ATT&CK, STRIDE, or the Cyber Kill Chain.Design actionable SIEM use cases, detection rules, and workflows aligned with risk prioritization.Evaluate use-case effectiveness … scripting (e.g., Python, PowerShell) to automate tasks and build SOC efficiencies.Deep familiarity with cyber threat detection techniques related to frameworks like MITRE ATT&CK and vulnerability management.Experience managing ITIL processes, including Incident, Problem, and Change Management. Certifications Required CISSP, GIAC, SC-200, Splunk Power User ...

Security Operations Analyst (SOC analyst)

Location
Greater London, England, United Kingdom
playbooks, runbooks, and standard operating procedures. Stay current with the evolving threat landscape, attacker TTPs (mapped to frameworks such as MITRE ATT&CK), and industry best practices. Required Qualifications, Capabilities, and Skills Demonstrable experience in a SOC, incident response, or security analyst role (typically 2+ … across SIEM, EDR/XDR, and network security tooling. Working knowledge of common attack techniques, the cyber kill chain, and the MITRE ATT&CK framework. Strong understanding of core networking concepts (TCP/IP, DNS, HTTP/S, proxies, firewalls) and operating system internals (Windows ...

Senior SOC Analyst

Location
England, United Kingdom
Microsoft Sentinel, Splunk, QRadar, ArcSight, Exabeam, and LogRhythm . Ensure accurate mapping of detection content to recognised threat frameworks, including MITRE ATT&CK . Identify detection gaps, duplicate content and optimisation opportunities through detection engineering, threat hunting, and alert tuning activities. Support standardisation of monitoring … teams. Strong understanding of attacker tactics, techniques and procedures (TTPs). Experience mapping detections to recognised threat frameworks such as MITRE ATT&CK . Experience using KQL, SPL, SQL , or similar query languages for investigation, threat hunting, and alert validation. Ability to define escalation criteria ...

Senior Incident Response Consultant 2

Location
Oxford, England, United Kingdom
will be responsible for producing an executive summary‐style report, which will include a timeline of key events mapped to the MITRE ATT&CK framework. This comprehensive report will serve as a valuable resource for stakeholders, highlighting the steps taken to combat the cybersecurity incident … circumstances``` Occasionally willing to begin work early and/or stay late when warranted for customer engagements Strong grasp of the MITRE ATT&CK framework Enjoy mentoring and assisting in the development of junior analysts A team‐player attitude with a willingness to share knowledge ...

Security Consultant

Location
Greater London, England, United Kingdom
platforms. Creating and optimising detection logic using KQL and other query languages. Developing detection use cases aligned with the MITRE ATT&CK framework and current threat techniques. Assessing customer telemetry and identifying opportunities to improve visibility and detection coverage. Building SOAR automations, integrations and response … platforms such as Microsoft Logic Apps, Cortex XSOAR or equivalent. Python, PowerShell or other scripting languages for automation and API integration. MITRE ATT&CK and threat-informed detection engineering. XDR/EDR technologies including Microsoft Defender, CrowdStrike, Cortex XDR or SentinelOne. Azure security monitoring ...

Security Operations Engineer

Hiring Organisation
CloudBees
Location
London, UK
Employment Type
Full-time
Create high-fidelity detections using operational threat intelligence, incident learnings and purple team findings. Measure and improve detection coverage using the MITRE ATT&CK framework. Continuously reduce false positives while improving visibility into emerging attacker techniques. SOAR & Automation EngineeringDesign and maintain SOAR playbooks that automate … similar languages. Experience working within cloud environments (AWS preferred; Azure or GCP experience also valued). Solid understanding of the MITRE ATT&CK framework. Experience supporting security incident response. Comfortable working with Git, APIs and engineering workflows. Excellent communication skills with both Security and Engineering ...

SOC Team Lead

Location
Greater London, England, United Kingdom
familiarity with Sentinel, Defender, Splunk, or CrowdStrike Desirable: experience contributing to GRC or ISO standards Desirable: knowledge of ITIL, NIST, or MITRE ATT&CK frameworks Desirable: understanding of customer impact and stakeholder management within cyber contexts Awareness of applicable regulations and frameworks such as NCSC … Mentoring Relationship Building Stakeholder Management Certifications & Qualifications CompTIA Security+ CISSP Industry Keywords Cyber Hygiene NIST ISO27001 Cyber Essentials Plus GRC ITIL MITRE ATT&CK NCSC Tools & Technologies SIEM EDR Sentinel Defender Splunk CrowdStrike #J-18808-Ljbffr ...

Senior Incident Response Consultant, Rapid Response

Location
Oxford, England, United Kingdom
will be responsible for producing an executive summary-style report, which will include a timeline of key events mapped to the MITRE ATT&CK framework. This comprehensive report will serve as a valuable resource for stakeholders, highlighting the steps taken to combat the cybersecurity incident … circumstances Occasionally willing to begin work early and/or stay late when warranted for customer engagements Strong grasp of the MITRE ATT&CK framework Enjoy mentoring and assisting in the development of junior analysts A team-player attitude with a willingness to share knowledge ...

DIG - Level 1 SOC Cyber Analyst

Location
Hereford, England, United Kingdom
escalation playbooks; suggest improvements based on recurring issues or inefficiencies. Threat Awareness: Maintain awareness of current cyber threats, attacker techniques (MITRE ATT&CK), and industry trends relevant to the organisations threat landscape. About You: Previous experience in a SOC, IT Operations, or security support role. … systems. Working knowledge of SIEM platforms (e.g. Microsoft sentinel, Splunk, Elastic, QRadar). Awareness of security frameworks and methodologies (NIST CSF, MITRE ATT&CK, ISO27001). #J-18808-Ljbffr ...

Interim Cyber Security Officer

Location
Greater London, England, United Kingdom
implement SOAR workflows to automate detection, response, and security operations processes. Conduct proactive threat hunting using SIEM/EDR data and MITRE ATT&CK‐aligned techniques. Support vulnerability assessment and security scanning activities using relevant tools. Provide input into penetration testing activities and interpret findings … Security (ES). Solid understanding of network protocols, cloud security (AWS/Azure), and threat detection methodologies. Working knowledge of the MITRE ATT&CK framework. Experience building automation or SOAR playbooks for security operations. CrowdStrike certifications (CCFA/CCFR/CCSE – any combination preferred). ...

Senior Cyber Security Engineer (EDR) Senior Security Engineer – Monitoring & Detection

Hiring Organisation
Sanderson Recruitment
Location
London, United Kingdom
threat detection platforms.Create and optimise detection logic using technologies such as Splunk and endpoint security solutions.Map detections against the MITRE ATT&CK framework to ensure comprehensive threat coverage.Continuously improve detection quality by analysing alert fidelity, false positives, and operational effectiveness.Validate detections through testing, simulation exercises … more of the following:Splunk and SPLYARA rule developmentEDR detection engineeringSIEM content development and tuningExperience mapping detections to the MITRE ATT&CK framework.Strong understanding of modern security principles including Zero Trust, identity-first security, secrets management, and network segmentation.Desirable ExperienceExperience with Cribl and security data ...

Senior Cyber Security Engineer (EDR)

Hiring Organisation
Sanderson Government and Defence
Location
Manchester, North West, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£85,000
threat detection platforms. Create and optimise detection logic using technologies such as Splunk and endpoint security solutions. Map detections against the MITRE ATT&CK framework to ensure comprehensive threat coverage. Continuously improve detection quality by analysing alert fidelity, false positives, and operational effectiveness. Validate detections … following: Splunk and SPL YARA rule development EDR detection engineering SIEM content development and tuning Experience mapping detections to the MITRE ATT&CK framework. Strong understanding of modern security principles including Zero Trust, identity-first security, secrets management, and network segmentation. Desirable Experience Experience with ...

Senior Security Engineer

Hiring Organisation
Docebo
Location
London, United Kingdom
exfiltration, and more). Leverage CloudTrail, GuardDuty, and SIEM integrations to maintain visibility across the AWS estate. Align detection logic with MITRE ATT&CK for Cloud.Vulnerability & Configuration Management: Own vulnerability management for cloud workloads — prioritizing findings from cloud configuration assessments, and runtime protection tools. Drive … multi-cloud exposure is a plus.In-depth knowledge of information security principles and cybersecurity frameworks relevant to cloud environments: MITRE ATT&CK for Cloud, CIS Benchmarks, AWS Well-Architected Security Pillar, NIST CSF, SOC 2, ISO 27001.Willingness and ability to participate in an on-call ...

Senior Security Engineer

Location
Greater London, England, United Kingdom
exfiltration, and more). Leverage CloudTrail, GuardDuty, and SIEM integrations to maintain visibility across the AWS estate. Align detection logic with MITRE ATT&CK for Cloud. Vulnerability & Configuration Management: Own vulnerability management for cloud workloads - prioritizing findings from cloud configuration assessments, and runtime protection tools. … multi‐cloud exposure is a plus. In‐depth knowledge of information security principles and cybersecurity frameworks relevant to cloud environments: MITRE ATT&CK for Cloud, CIS Benchmarks, AWS Well‐Architected Security Pillar, NIST CSF, SOC 2, ISO 27001. Willingness and ability to participate ...

2nd/3rd Line Security Analyst - Reading

Hiring Organisation
Xact Placements Limited
Location
Reading, Berkshire, United Kingdom
Employment Type
Full-Time
Salary
£50,000 - £60,000 per annum
sign-ins, malicious OAuth consent, mailbox access), including session/token revocation Design, build and test SIEM detection rules mapped to MITRE ATT&CK, and tune out false positives without blanket whitelisting Build automation for SOC processes - enrichment, ticketing, containment - using Python, Logic Apps, APIs … security incidents from triage through to closure Hands-on experience writing and tuning SIEM detection logic, with a solid understanding of MITRE ATT&CK and KQL (or equivalent) Practical scripting/automation experience (Python, Logic Apps, REST APIs) or hands-on SOAR platform configuration Working ...

Senior Detection & Threat Engineer

Hiring Organisation
Checkout.com
Location
London, UK
Employment Type
Full-time
proactive threat hunting based on attacker behaviour, not vendor alertsTranslating threat intelligence and incident learnings into durable, reusable detectionsMapping detections to MITRE ATT&CK and real-world attack pathsReducing alert fatigue through logic refinement, correlation, and contextual enrichmentAdvising and supporting during high-severity security incidents … plane, SaaS)Familiarity with threat intelligence platforms and frameworks such as PCI DSS, NIST CSF, SOC 2, ISO27001, CIS Benchmarks, and MITRE ATT&CK for Cloud. Additional InformationBring all of you to workWe create the conditions for high performers to thrive, through real ownership, fewer ...

Senior Cyber Detection and Response Engineer

Location
Greater London, England, United Kingdom
build and continuously improve detection content, managed as code and version-controlled, mapping coverage to adversary tactics and techniques using the MITRE ATT&CK framework and prioritising the techniques most relevant to a financial services SaaS provider. Telemetry and visibility – maintain a clear view … detections. Working knowledge of cloud security and native cloud telemetry sources (AWS and/or Azure). Practical use of the MITRE ATT&CK framework to structure detection coverage and gap analysis. Hands-on experience building and operating SOAR playbooks and response automation, orchestrating across ...