1 to 25 of 187 Permanent MITRE ATT&CK Jobs in the UK

Senior Security Engineering Consultant

Hiring Organisation
Nomios
Location
Basingstoke, United Kingdom
delivered in a consistent and scalable way. Working directly with customers, you will define detection strategies, design use cases aligned to MITRE ATT&CK, and guide improvements in visibility, coverage and response maturity. You will work closely with platform onboarding and engineering teams, supplementing them … rulesets across SIEM and XDR platformsDevelop and tune detection logic using KQL or equivalent query languagesDesign detection use cases aligned to MITRE ATT&CK and real-world attack techniquesMap customer log sources to detection use cases to assess coverage and identify gapsDesign and implement SOAR ...

Senior Detection and Response Engineer

Location
Cambridge, England, United Kingdom
improve security telemetry, alert enrichment, investigation workflows and response times. Conduct threat hunting using adversary behaviours, TTPs and frameworks such as MITRE ATT&CK, incorporating findings into security controls and detections. Create and continuously improve incident runbooks, playbooks and detection processes based on findings from … ability to write and develop queries for complex investigations. Understanding of adversary tactics, techniques and procedures (TTPs), offensive security concepts and MITRE ATT&CK principles. Practical knowledge of cloud environments and security controls, with the ability to apply detection and incident response practices across hybrid ...

Senior Security Engineering Consultant

Hiring Organisation
Infosec
Location
Basingstoke, Hampshire, South East, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£80,000
SIEM and XDR platforms Develop and tune detection logic using KQL or equivalent query languages Design detection use cases aligned to MITRE ATT&CK and real-world attack techniques Map customer log sources to detection use cases to assess coverage and identify gaps Design … consultant Lead workshops covering detection engineering, use case design and SOC maturity Guide customers on improving detection coverage and aligning to MITRE ATT&CK Clearly explain detection strategies, gaps and recommendations to both technical and non-technical stakeholders Work closely with platform onboarding and engineering ...

Senior Cyber Threat Intelligence (CTI) Analyst

Location
Greater London, England, United Kingdom
processes to improve the quality and relevance of CTI outputs. Analyse threat actor behaviour and map activity to frameworks such as MITRE ATT&CK to support defensive strategy and risk‐based decision‐making. Brief technical, business, and senior leadership stakeholders on cyber threats, trends, potential … function. Demonstrated experience conducting threat actor analysis, adversary tracking, campaign analysis, IOC/TTP analysis, and intelligence production, including use of MITRE ATT&CK or similar frameworks to structure analysis and communicate adversary behaviour. Strong understanding of the intelligence lifecycle, including requirements, collection, analysis, dissemination ...

Senior Cyber Threat Intelligence (CTI) Analyst

Location
United Kingdom
reporting processes to improve the quality and relevance of CTI outputs.Analyze threat actor behavior and map activity to frameworks such as MITRE ATT&CK to support defensive strategy and risk-based decision-making.Brief technical, business, and senior leadership stakeholders on cyber threats, trends, potential business … intelligence function.Demonstrated experience conducting threat actor analysis, adversary tracking, campaign analysis, IOC/TTP analysis, and intelligence production, including use of MITRE ATT&CK or similar frameworks to structure analysis and communicate adversary behavior.Strong understanding of the intelligence lifecycle, including requirements, collection, analysis, dissemination ...

Senior Security Engineering Consultant

Hiring Organisation
Matchtech
Location
Basingstoke, United Kingdom
rulesets across SIEM and XDR platformsDevelop and tune detection logic using KQL or equivalent query languagesDesign detection use cases aligned to MITRE ATT&CK and real-world attack techniquesMap customer log sources to detection use cases to assess coverage and identify gapsDesign and implement SOAR … trusted technical consultantLead workshops covering detection engineering, use case design and SOC maturityGuide customers on improving detection coverage and aligning to MITRE ATT&CKClearly explain detection strategies, gaps and recommendations to both technical and non-technical stakeholdersWork closely with platform onboarding and engineering teams to ensure smooth ...

SOC Subject Matter Expert (UK)

Location
Horsham, England, United Kingdom
designers to ensure intuitive interfaces that match SOC analyst mental models and workflow patterns. Providing technical consultation on threat detection logic, MITRE ATT&CK mapping, and security operations best practices. Supporting go-to-market activities by creating technical content, conducting product demonstrations, and engaging with … customers. Mentoring and educating internal teams on SOC operations, threat landscapes, and analyst workflows. Ensuring product features align with industry frameworks (MITRE ATT&CK, NIST, ISO 27001) and SOC maturity models. Act as a trusted SOC and cyber defence expert in customer meetings, workshops ...

Principal Analyst Detection Engineering - Technology Vendor

Location
United Kingdom
Head of Security Operations, the successful candidate will lead the detection function, reducing false positives, maturing rule sets aligned to MITRE ATT&CK, and applying threat intelligence to stay ahead of the evolving threat landscape. The role also involves managing and mentoring a small team … strategy for detections across a wide range of security technologies Build and manage rule packs based on technology feeds utilising the MITRE ATT&CK framework Utilise threat intelligence reports to continually refine detections against the current threat landscape Ratify log source receipt pre and post ...

Cloud Platform Security Engineer Software engineering London

Location
Greater London, England, United Kingdom
modern SIEM platform (e.g. Sentinel) including KQL detection rules, workbooks, logging pipelines, and AI-assisted alert triage. Map detection coverage against MITRE ATT&CK tactics and techniques. Identify and close visibility gaps across the cloud estate. Maintain alignment to PCI DSS, SOC2, ISO27001 NIST … Python, PowerShell, or Bash for security automation. Strong grasp of PCI DSS, NIST CSF, SOC 2, ISO27001, CIS Benchmarks, and MITRE ATT&CK for Cloud. Nice to have AZ-500, AWS Certified Security – Specialty, or equivalent cloud security certification. Experience integrating ATT&CK ...

Cyber Security Engineer - Threat Detection

Location
City Of London, England, United Kingdom
health for assigned detection areas, including retiring logic that no longer earns its place Detection Coverage - Map detection coverage to the MITRE ATT&CK framework, identify gaps, and propose the telemetry or logic needed to close them Threat Intelligence Integration - Convert threat intelligence reporting into … ability to investigate suspicious activity end to end: read the logs, form a conclusion, and communicate it clearly Familiarity with the MITRE ATT&CK framework and the ability to reason about adversary tradecraft rather than only indicators Solid understanding of operating system internals, networking ...

Senior SOC Engineer

Location
Glasgow, Lanarkshire, United Kingdom
with threat intelligence teams to enhance detection logic. Threat Modelling & Use Case Development Lead threat modelling exercises using frameworks such as MITRE ATT&CK, STRIDE, and Cyber Kill Chain. Translate threat models into actionable detection use cases and SIEM rules. Prioritise detection engineering based … Python or PowerShell for automation. Deep understanding of threat detection, incident response, and the cyber kill chain. Familiarity with frameworks including MITRE ATT&CK, NIST, and CIS. Strong communication, analytical, and presentation skills. Solid understanding of network traffic flows, vulnerability management, and penetration testing principles. ...

Security Engineer

Hiring Organisation
NTT DATA
Location
Birmingham, United Kingdom
help define corrective actions to reduce future risks. Threat Modelling & Use Case Development Perform threat modeling using industry frameworks such as MITRE ATT&CK, STRIDE, or the Cyber Kill Chain.Design actionable SIEM use cases, detection rules, and workflows aligned with risk prioritization.Evaluate use-case effectiveness … scripting (e.g., Python, PowerShell) to automate tasks and build SOC efficiencies.Deep familiarity with cyber threat detection techniques related to frameworks like MITRE ATT&CK and vulnerability management.Experience managing ITIL processes, including Incident, Problem, and Change Management. Certifications Required CISSP, GIAC, SC-200, Splunk Power User ...

Security Operations Analyst (SOC analyst)

Location
Greater London, England, United Kingdom
playbooks, runbooks, and standard operating procedures. Stay current with the evolving threat landscape, attacker TTPs (mapped to frameworks such as MITRE ATT&CK), and industry best practices. Required Qualifications, Capabilities, and Skills Demonstrable experience in a SOC, incident response, or security analyst role (typically 2+ … across SIEM, EDR/XDR, and network security tooling. Working knowledge of common attack techniques, the cyber kill chain, and the MITRE ATT&CK framework. Strong understanding of core networking concepts (TCP/IP, DNS, HTTP/S, proxies, firewalls) and operating system internals (Windows ...

Senior SOC Analyst

Location
England, United Kingdom
Microsoft Sentinel, Splunk, QRadar, ArcSight, Exabeam, and LogRhythm . Ensure accurate mapping of detection content to recognised threat frameworks, including MITRE ATT&CK . Identify detection gaps, duplicate content and optimisation opportunities through detection engineering, threat hunting, and alert tuning activities. Support standardisation of monitoring … teams. Strong understanding of attacker tactics, techniques and procedures (TTPs). Experience mapping detections to recognised threat frameworks such as MITRE ATT&CK . Experience using KQL, SPL, SQL , or similar query languages for investigation, threat hunting, and alert validation. Ability to define escalation criteria ...

Senior Incident Response Consultant 2

Location
Oxford, England, United Kingdom
will be responsible for producing an executive summary‐style report, which will include a timeline of key events mapped to the MITRE ATT&CK framework. This comprehensive report will serve as a valuable resource for stakeholders, highlighting the steps taken to combat the cybersecurity incident … circumstances``` Occasionally willing to begin work early and/or stay late when warranted for customer engagements Strong grasp of the MITRE ATT&CK framework Enjoy mentoring and assisting in the development of junior analysts A team‐player attitude with a willingness to share knowledge ...

Security Consultant

Location
Greater London, England, United Kingdom
platforms. Creating and optimising detection logic using KQL and other query languages. Developing detection use cases aligned with the MITRE ATT&CK framework and current threat techniques. Assessing customer telemetry and identifying opportunities to improve visibility and detection coverage. Building SOAR automations, integrations and response … platforms such as Microsoft Logic Apps, Cortex XSOAR or equivalent. Python, PowerShell or other scripting languages for automation and API integration. MITRE ATT&CK and threat-informed detection engineering. XDR/EDR technologies including Microsoft Defender, CrowdStrike, Cortex XDR or SentinelOne. Azure security monitoring ...

Security Operations Engineer

Hiring Organisation
CloudBees
Location
London, UK
Employment Type
Full-time
Create high-fidelity detections using operational threat intelligence, incident learnings and purple team findings. Measure and improve detection coverage using the MITRE ATT&CK framework. Continuously reduce false positives while improving visibility into emerging attacker techniques. SOAR & Automation EngineeringDesign and maintain SOAR playbooks that automate … similar languages. Experience working within cloud environments (AWS preferred; Azure or GCP experience also valued). Solid understanding of the MITRE ATT&CK framework. Experience supporting security incident response. Comfortable working with Git, APIs and engineering workflows. Excellent communication skills with both Security and Engineering ...

SOC Team Lead

Location
Greater London, England, United Kingdom
familiarity with Sentinel, Defender, Splunk, or CrowdStrike Desirable: experience contributing to GRC or ISO standards Desirable: knowledge of ITIL, NIST, or MITRE ATT&CK frameworks Desirable: understanding of customer impact and stakeholder management within cyber contexts Awareness of applicable regulations and frameworks such as NCSC … Mentoring Relationship Building Stakeholder Management Certifications & Qualifications CompTIA Security+ CISSP Industry Keywords Cyber Hygiene NIST ISO27001 Cyber Essentials Plus GRC ITIL MITRE ATT&CK NCSC Tools & Technologies SIEM EDR Sentinel Defender Splunk CrowdStrike #J-18808-Ljbffr ...

Senior Incident Response Consultant, Rapid Response

Location
Oxford, England, United Kingdom
will be responsible for producing an executive summary-style report, which will include a timeline of key events mapped to the MITRE ATT&CK framework. This comprehensive report will serve as a valuable resource for stakeholders, highlighting the steps taken to combat the cybersecurity incident … circumstances Occasionally willing to begin work early and/or stay late when warranted for customer engagements Strong grasp of the MITRE ATT&CK framework Enjoy mentoring and assisting in the development of junior analysts A team-player attitude with a willingness to share knowledge ...

DIG - Level 1 SOC Cyber Analyst

Location
Hereford, England, United Kingdom
escalation playbooks; suggest improvements based on recurring issues or inefficiencies. Threat Awareness: Maintain awareness of current cyber threats, attacker techniques (MITRE ATT&CK), and industry trends relevant to the organisations threat landscape. About You: Previous experience in a SOC, IT Operations, or security support role. … systems. Working knowledge of SIEM platforms (e.g. Microsoft sentinel, Splunk, Elastic, QRadar). Awareness of security frameworks and methodologies (NIST CSF, MITRE ATT&CK, ISO27001). #J-18808-Ljbffr ...

SOC Shift Lead

Hiring Organisation
Sopra Steria
Location
United Kingdom
Employment Type
Permanent
Salary
GBP Annual
Analyse network traffic, endpoint activity, logs and alerts to uncover malicious behaviour. Drive continuous improvement of detection capabilities aligned to the MITRE ATT&CK framework. Enhance SOC processes, tooling, playbooks and operational effectiveness. Mentor and develop analysts, helping build the next generation of cyber security … mentoring analysts in an operational security environment. It would be great if you had: Detection engineering or threat-informed defence experience. MITRE ATT&CK framework knowledge. Python, PowerShell or Bash scripting skills. Malware analysis or reverse engineering exposure. CREST, Blue Team Level 1 or similar ...

Interim Cyber Security Officer

Location
Greater London, England, United Kingdom
implement SOAR workflows to automate detection, response, and security operations processes. Conduct proactive threat hunting using SIEM/EDR data and MITRE ATT&CK‐aligned techniques. Support vulnerability assessment and security scanning activities using relevant tools. Provide input into penetration testing activities and interpret findings … Security (ES). Solid understanding of network protocols, cloud security (AWS/Azure), and threat detection methodologies. Working knowledge of the MITRE ATT&CK framework. Experience building automation or SOAR playbooks for security operations. CrowdStrike certifications (CCFA/CCFR/CCSE – any combination preferred). ...

Senior Cyber Security Engineer (EDR) Senior Security Engineer – Monitoring & Detection

Hiring Organisation
Sanderson Recruitment
Location
London, United Kingdom
threat detection platforms.Create and optimise detection logic using technologies such as Splunk and endpoint security solutions.Map detections against the MITRE ATT&CK framework to ensure comprehensive threat coverage.Continuously improve detection quality by analysing alert fidelity, false positives, and operational effectiveness.Validate detections through testing, simulation exercises … more of the following:Splunk and SPLYARA rule developmentEDR detection engineeringSIEM content development and tuningExperience mapping detections to the MITRE ATT&CK framework.Strong understanding of modern security principles including Zero Trust, identity-first security, secrets management, and network segmentation.Desirable ExperienceExperience with Cribl and security data ...

Senior Cyber Security Engineer (EDR)

Hiring Organisation
Sanderson Government and Defence
Location
Manchester, North West, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£85,000
threat detection platforms. Create and optimise detection logic using technologies such as Splunk and endpoint security solutions. Map detections against the MITRE ATT&CK framework to ensure comprehensive threat coverage. Continuously improve detection quality by analysing alert fidelity, false positives, and operational effectiveness. Validate detections … following: Splunk and SPL YARA rule development EDR detection engineering SIEM content development and tuning Experience mapping detections to the MITRE ATT&CK framework. Strong understanding of modern security principles including Zero Trust, identity-first security, secrets management, and network segmentation. Desirable Experience Experience with ...

Senior Detection and Response Engineer

Location
United Kingdom
improve security telemetry, alert enrichment, investigation workflows and response times. Conduct threat hunting using adversary behaviours, TTPs and frameworks such as MITRE ATT&CK, incorporating findings into security controls and detections. Create and continuously improve incident runbooks, playbooks and detection processes based on findings from … ability to write and develop queries for complex investigations. Understanding of adversary tactics, techniques and procedures (TTPs), offensive security concepts and MITRE ATT&CK principles. Practical knowledge of cloud environments and security controls, with the ability to apply detection and incident response practices across hybrid ...