1 to 25 of 135 Permanent MITRE ATT&CK Jobs in the UK

Senior Security Engineering Consultant

Hiring Organisation
Jobleads-UK
Location
Basingstoke, England, United Kingdom
delivered in a consistent and scalable way. Working directly with customers, you will define detection strategies, design use cases aligned to MITRE ATT&CK, and guide improvements in visibility, coverage and response maturity. You will work closely with platform onboarding and engineering teams, supplementing them … SIEM and XDR platforms Develop and tune detection logic using KQL or equivalent query languages Design detection use cases aligned to MITRE ATT&CK and real‐world attack techniques Map customer log sources to detection use cases to assess coverage and identify gaps Design ...

Senior Security Engineering Consultant

Hiring Organisation
Nomios
Location
Basingstoke, Hampshire, United Kingdom
Salary
£ 70 K
delivered in a consistent and scalable way. Working directly with customers, you will define detection strategies, design use cases aligned to MITRE ATT&CK, and guide improvements in visibility, coverage and response maturity. You will work closely with platform onboarding and engineering teams, supplementing them … rulesets across SIEM and XDR platformsDevelop and tune detection logic using KQL or equivalent query languagesDesign detection use cases aligned to MITRE ATT&CK and real-world attack techniquesMap customer log sources to detection use cases to assess coverage and identify gapsDesign and implement SOAR ...

Security Engineer

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
Operations Centre (SOC) activities, expanding log coverage, and building high-quality detections in our SIEM. You will use frameworks such as MITRE ATT&CK and MITRE D3FEND to assess threat scenarios, prioritize detection engineering work, and strengthen both preventative and detective controls. What … operations, including monitoring, triage, investigation, and response to security alerts. Assess the company threat landscape using MITRE ATT&CK and MITRE D3FEND to identify detection and mitigation opportunities. Connect and maintain log sources into our SIEM to ensure relevant coverage across corporate ...

SOC Subject Matter Expert (UK)

Hiring Organisation
Jobleads-UK
Location
Horsham, England, United Kingdom
designers to ensure intuitive interfaces that match SOC analyst mental models and workflow patterns. Providing technical consultation on threat detection logic, MITRE ATT&CK mapping, and security operations best practices. Supporting go-to-market activities by creating technical content, conducting product demonstrations, and engaging with … customers. Mentoring and educating internal teams on SOC operations, threat landscapes, and analyst workflows. Ensuring product features align with industry frameworks (MITRE ATT&CK, NIST, ISO 27001) and SOC maturity models. Act as a trusted SOC and cyber defence expert in customer meetings, workshops ...

Senior Cloud Security Engineer

Hiring Organisation
Checkout.com
Location
London, United Kingdom
Salary
£ 80 K
maintain modern SIEM platform (e.g. Sentinel) including KQL detection rules, workbooks, logging pipelines, and AI-assisted alert triage.Map detection coverage against MITRE ATT&CK tactics and techniques. Identify and close visibility gaps across the cloud estate.Maintain alignment to PCI DSS, SOC2, ISO27001 NIST … proficiency in Python, PowerShell, or Bash for security automation.Strong grasp of PCI DSS, NIST CSF, SOC 2, ISO27001, CIS Benchmarks, and MITRE ATT&CK for Cloud.Nice to haveAZ-500, AWS Certified Security – Specialty, or equivalent cloud security certification.Experience integrating ATT&CK Navigator ...

Cloud Platform Security Engineer Software engineering London

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
modern SIEM platform (e.g. Sentinel) including KQL detection rules, workbooks, logging pipelines, and AI-assisted alert triage. Map detection coverage against MITRE ATT&CK tactics and techniques. Identify and close visibility gaps across the cloud estate. Maintain alignment to PCI DSS, SOC2, ISO27001 NIST … Python, PowerShell, or Bash for security automation. Strong grasp of PCI DSS, NIST CSF, SOC 2, ISO27001, CIS Benchmarks, and MITRE ATT&CK for Cloud. Nice to have AZ-500, AWS Certified Security – Specialty, or equivalent cloud security certification. Experience integrating ATT&CK ...

Principal Security Engineer

Hiring Organisation
Jobleads-UK
Location
St Albans, England, United Kingdom
Engineering: Build, tune and maintain detection rules, correlation logic and alerting across SIEM and EDR. Engineer high-fidelity detections mapped to MITRE ATT&CK. Continuously reduce false positives and expand coverage. Automation: Engineer automation for security operations at scale — scripting (Python, Bash, PowerShell) for response orchestration, access … security events, perform root cause analysis, and apply threat intelligence to improve defensive posture. Understand attacker TTPs and operationalise frameworks like MITRE ATT&CK and NIST CSF. Vulnerability Management: Own the vulnerability management programme end to end — scanning, prioritisation, remediation tracking, SLA enforcement and executive ...

Senior Cyber Security Analyst

Hiring Organisation
Lightsource bp
Location
London, United Kingdom
Salary
£ 80 K
related toolsets to detect signs of compromise and investigate security events to completion Proactively conduct threat hunting using threat intelligence frameworks (MITRE ATT&CK, Cyber Kill Chain) and available security platforms to identify and mitigate emerging threats Assess new and evolving cyber threats … Demonstrable experience responding to cyber threats and working in an Azure-focused cloud environment Proven experience with the Cyber Kill Chain, MITRE ATT&CK, and other security defence and intelligence frameworks Experience in stakeholder management and engagement at C-Suite level Experience working for Critical ...

Security Operations Engineer

Hiring Organisation
CloudBees
Location
London, United Kingdom
Salary
£ 80 K
Create high-fidelity detections using operational threat intelligence, incident learnings and purple team findings. Measure and improve detection coverage using the MITRE ATT&CK framework. Continuously reduce false positives while improving visibility into emerging attacker techniques.SOAR & Automation EngineeringDesign and maintain SOAR playbooks that automate alert … similar languages. Experience working within cloud environments (AWS preferred; Azure or GCP experience also valued). Solid understanding of the MITRE ATT&CK framework. Experience supporting security incident response. Comfortable working with Git, APIs and engineering workflows. Excellent communication skills with both Security and Engineering ...

SOC Automation Engineer

Hiring Organisation
Claranet Limited
Location
Leeds, West Yorkshire, England, United Kingdom
Employment Type
Full-Time
Salary
Salary negotiable
dependencies, and error handling Ensure consistency and usability for wider teams Strategic Contribution Support use cases aligned to threat modelling and MITRE ATT&CK Contribute to automation playbooks and response strategies Stay current with tools, frameworks, and emerging threats Collaboration Embed automation into SOC workflows … platforms Proficiency in scripting (e.g., Python, PowerShell) Experience working with APIs, webhooks, and authentication methods Knowledge of threat frameworks (e.g., MITRE ATT&CK) Understanding of cloud security, identity, and event-driven automation Strong communication and analytical skills Security clearance (NPPV and/ ...

Security Operations Analyst (Assistant Vice President)

Hiring Organisation
Jefferies Financial Group
Location
London, United Kingdom
Salary
£ 100 K
candidate will possess strong analytical skills, solid knowledge in cybersecurity, networking, cloud technologies, security frameworks such as NIST and/or MITRE ATT&CK, and hands-on experience with enterprise security tools and platforms. This role requires a minimum of 4 years of experience … other email-based threats.Monitor Data Leak Protection (DLP) tools and investigate potential unauthorized data exfiltration events.Conduct threat hunting activities using MITRE ATT&CK framework to proactively identify adversary techniques within the environment.Collaborate with IT, Infrastructure, networking, and application teams to investigate security events and support ...

Senior Incident Response Consultant, Rapid Response

Hiring Organisation
Jobleads-UK
Location
Oxford, England, United Kingdom
will be responsible for producing an executive summary-style report, which will include a timeline of key events mapped to the MITRE ATT&CK framework. This comprehensive report will serve as a valuable resource for stakeholders, highlighting the steps taken to combat the cybersecurity incident … circumstances Occasionally willing to begin work early and/or stay late when warranted for customer engagements Strong grasp of the MITRE ATT&CK framework Enjoy mentoring and assisting in the development of junior analysts A team-player attitude with a willingness to share knowledge ...

Security and Privacy Operations Analyst

Hiring Organisation
Knight Frank
Location
London, United Kingdom
Salary
£ 80 K
experience writing KQL queries, PowerShell, or CLI commands.Exposure to automation or playbooks (Logic Apps, Defender workflows).Knowledge of frameworks such as MITRE ATT&CK or NIST CSF.Relevant certifications such as:SC‐900, SC‐200 (or working toward), AZ‐900, AZ‐500CISSP, CIPP/E, CompTIA … experience writing KQL queries, PowerShell, or CLI commands.Exposure to automation or playbooks (Logic Apps, Defender workflows).Knowledge of frameworks such as MITRE ATT&CK or NIST CSF.Relevant certifications such as:SC‐900, SC‐200 (or working toward), AZ‐900, AZ‐500CISSP, CIPP/E, CompTIA ...

Senior Cyber Consultant

Hiring Organisation
Reed Technology
Location
United Kingdom
Employment Type
Permanent
Salary
GBP Annual
developing detection content, automating security processes, and improving SOC effectiveness. You will lead detection engineering initiatives, create use cases aligned to MITRE ATT&CK, develop response playbooks, and implement Detection-as-Code best practices. Key Requirements Experience with SIEM platforms (Microsoft Sentinel preferred) Strong … detection engineering skills SOAR automation and playbook development experience Python and/or PowerShell scripting XDR/EDR experience Knowledge of MITRE ATT&CK and threat detection methodologies Azure security and cloud telemetry exposure Previous consultancy or customer-facing experience What's on Offer ...

SOC Shift Lead

Hiring Organisation
Sopra Steria
Location
Farnborough, Hampshire, South East, United Kingdom
Employment Type
Permanent
Salary
£65,000
Analyse network traffic, endpoint activity, logs and alerts to uncover malicious behaviour. Drive continuous improvement of detection capabilities aligned to the MITRE ATT&CK framework. Enhance SOC processes, tooling, playbooks and operational effectiveness. Mentor and develop analysts, helping build the next generation of cyber security … mentoring analysts in an operational security environment. It would be great if you had: Detection engineering or threat-informed defence experience. MITRE ATT&CK framework knowledge. Python, PowerShell or Bash scripting skills. Malware analysis or reverse engineering exposure. CREST, Blue Team Level 1 or similar ...

Interim Cyber Security Officer

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
implement SOAR workflows to automate detection, response, and security operations processes. Conduct proactive threat hunting using SIEM/EDR data and MITRE ATT&CK‐aligned techniques. Support vulnerability assessment and security scanning activities using relevant tools. Provide input into penetration testing activities and interpret findings … Security (ES). Solid understanding of network protocols, cloud security (AWS/Azure), and threat detection methodologies. Working knowledge of the MITRE ATT&CK framework. Experience building automation or SOAR playbooks for security operations. CrowdStrike certifications (CCFA/CCFR/CCSE – any combination preferred). ...

Threat Hunting & Detection Engineering Analyst

Hiring Organisation
Anson Mccade
Location
Cheltenham, Gloucestershire, South West, United Kingdom
Employment Type
Permanent
Salary
£60,000
maintain threat detection use cases aligned to real-world attack scenarios Build and tune detection logic using industry frameworks such as MITRE ATT&CK Conduct proactive, hypothesis-led threat hunting across client environments Analyse telemetry, threat intelligence and security data to identify suspicious activity Develop … threats and improving security operations. You'll ideally have experience with: Threat Hunting Detection Engineering Security Operations Centres (SOC) SIEM technologies MITRE ATT&CK Framework Threat Intelligence Detection rule creation and tuning Security telemetry analysis Incident detection and investigation Writing detection use cases and playbooks ...

Security Detection & Response II

Hiring Organisation
Bank of America
Location
Cheshire West and Chester, United Kingdom
Employment Type
Full Time
will build, validate, tune, and optimize detection logic and coverage, leveraging attacker tactics, techniques, and procedures (TTPs) and frameworks such as MITRE ATT&CK to improve accuracy and reduce false positives Execute and coordinate security event response activities, including containment, isolation, escalation, and remediation, applying … paths, including credential theft, privilege escalation, and session/token abuse Considerable understanding of attacker tactics, techniques, and procedures (TTPs), including MITRE ATT&CK Record of improving operational effectiveness, including reducing alert noise, improving detection coverage, and decreasing mean time to detect and respond Great ...

Cyber Threat Intelligence Expert – SOC | Threat Hunting | Incident Response

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
assessments. SupportSOC operations with threat context and priority setting. Identifyand monitor Indicators of Compromise (IOCs) and Tactics, Techniques &Procedures (TTPs) using MITRE ATT&CK framework. Collaborateon play-book development and threat detection use cases. Performattribution and malware behavioural analysis to inform decision-making. Leadthreat actor … e.g., MISP, Anomali, ThreatConnect) Strongknowledge of malware families, TTPs, and IOC tracking Experienceusing SIEM, SOAR, and endpoint detection tools Workingknowledge of MITRE ATT&CK, Cyber Kill Chain, and Diamond Model Abilityto produce high-quality, executive-ready threat reports Desired Skills Certificationssuch as GCTI, GREM, GCIA ...

2nd/3rd Line Security Analyst - Reading

Hiring Organisation
Xact Placements Limited
Location
Reading, Berkshire, England, United Kingdom
Employment Type
Full-Time
Salary
£50,000 - £60,000 per annum
sign-ins, malicious OAuth consent, mailbox access), including session/token revocation Design, build and test SIEM detection rules mapped to MITRE ATT&CK, and tune out false positives without blanket whitelisting Build automation for SOC processes - enrichment, ticketing, containment - using Python, Logic Apps, APIs … security incidents from triage through to closure Hands-on experience writing and tuning SIEM detection logic, with a solid understanding of MITRE ATT&CK and KQL (or equivalent) Practical scripting/automation experience (Python, Logic Apps, REST APIs) or hands-on SOAR platform configuration Working ...

Senior Detection & Threat Engineer

Hiring Organisation
Checkout.com
Location
London, United Kingdom
Salary
£ 80 K
proactive threat hunting based on attacker behaviour, not vendor alertsTranslating threat intelligence and incident learnings into durable, reusable detectionsMapping detections to MITRE ATT&CK and real-world attack pathsReducing alert fatigue through logic refinement, correlation, and contextual enrichmentAdvising and supporting during high-severity security incidents … plane, SaaS)Familiarity with threat intelligence platforms and frameworks such as PCI DSS, NIST CSF, SOC 2, ISO27001, CIS Benchmarks, and MITRE ATT&CK for Cloud.Additional InformationBring all of you to workWe create the conditions for high performers to thrive, through real ownership, fewer blockers ...

Senior Cyber Detection and Response Engineer

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
build and continuously improve detection content, managed as code and version-controlled, mapping coverage to adversary tactics and techniques using the MITRE ATT&CK framework and prioritising the techniques most relevant to a financial services SaaS provider. Telemetry and visibility – maintain a clear view … detections. Working knowledge of cloud security and native cloud telemetry sources (AWS and/or Azure). Practical use of the MITRE ATT&CK framework to structure detection coverage and gap analysis. Hands-on experience building and operating SOAR playbooks and response automation, orchestrating across ...

Senior Cyber Security Analyst (OWASP / SAST /DAST )

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
support remediation of application security issues. Threat Modelling & Security Risk Assessments – Conduct threat modelling exercises using frameworks such as STRIDE or MITRE ATT&CK, identify potential security threats, vulnerabilities and attack scenarios within applications and supporting infrastructure, perform structured security risk assessments and provide remediation … Lifecycle (SSDLC) OWASP Top 10 and secure coding practices Application security testing (SAST/DAST/SCA) Threat modelling methodologies (STRIDE, MITRE ATT&CK) Vulnerability management and remediation Secure architecture and design reviews DevSecOps and CI/CD security integration API security and modern application ...

Senior Analyst - Tactical Intelligence

Hiring Organisation
NCC Group
Location
London, United Kingdom
Salary
£ 80 K
campaigns, providing context-rich assessments that combine technical findings with geopolitical and regional context.Map observed threat activity to established frameworks (e.g., MITRE ATT&CK) and produce structured intelligence outputs using formats such as STIX/TAXII.Conduct technical analysis of malware samples to support intelligence assessments … infrastructure analysis.Strong understanding of networking protocols (e.g., TCP/IP, DNS) and how adversaries leverage network infrastructure.Familiarity with frameworks such as MITRE ATT&CK and structured intelligence formats, including STIX/TAXII.Experience supporting or interfacing with DFIR and SOC teams in an operational capacity.Understanding ...

Security Engineer x24 - Banking & FInance

Hiring Organisation
Jobleads-UK
Location
Greater Manchester, England, United Kingdom
cloud environments Perform threat modelling by deconstructing technical solutions, identifying threats and vulnerabilities using recognised methodologies such as STRIDE and MITRE ATT&CK Analyse risks and benefits of design options to support safe architectural decisions, defining security testing requirements and assessing findings Communicate technical security … APIs and containerised microservices Up-to-date knowledge of emerging threats with practical experience applying threat modelling frameworks including STRIDE and MITRE ATT&CK Strong understanding of cybersecurity domains across endpoint, network, cryptography, information management, and IAM in enterprise environments Awareness of industry security standards ...