451 to 475 of 641 SIEM Jobs in England

Technical Specialist - Detection, Engineering and Automation

Location
Kingswood, England, United Kingdom
building, maintaining and enhancing the security tooling that underpins our detection and response functions. The ideal candidate will work deeply across technologies including SIEM, SOAR, EDR, email security and cloud security platforms, contributing engineering expertise to ensure these controls operate effectively and deliver high‐quality telemetry. You will be responsible … updates. Engineer and optimise SOAR automation and integrations to reduce manual analyst workload and streamline response processes. Onboard high‐value security logs into the SIEM from the backlog, ensuring quality, normalisation and integration into detection logic. Support SOC and CIRT during incidents by providing engineering expertise, rapid telemetry onboarding, and ...

Senior SOC Incident Lead & Detection Engineer

Location
Reading, England, United Kingdom
and automation within the SOC. You will own end-to-end incidents and provide senior technical depth across multiple toolchains. Key duties include designing SIEM detections aligned to MITRE ATT&CK, mentoring analysts, and driving improvements in detections and playbooks while working with Sentinel, Defender XDR, CrowdStrike, Entra #J ...

Account Executive

Location
City Of London, England, United Kingdom
action and decision while maintaining focus on achieving optimal outcomes as part of a collaborative development effort. Experience in enterprise security solutions (endpoint, SIEM, networking, etc). Seasoned with financial services sales (banking) or BFSI market. Team Player, Competitive, Optimistic, Enthusiastic, Trust Builder. #J-18808-Ljbffr ...

Cyber Security Manager

Hiring Organisation
Charles Simon Associates Ltd
Location
Birmingham, West Midlands, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£65,000
Cyber Security Lead (Entra ID, Defender, Purview, SIEM, SOC, Cyber Essentials Plus, ISO 27001, NIST, CISSP, Hands-On, 3rd Party Management) Permanent Home Based Charles Simon Associates are currently recruiting for a Technical Cyber Security Lead for one of our key clients, a fast-growing UK business with sites across … technical lead for security. The official title is Manager, but this isn't a people management role. They will manage the outsourced SOC and SIEM providers, choose the security tools the business uses going forward, lead Cyber Essentials Plus and ISO 27001 certification, and decide whether SOC and SIEM stay ...

Cyber Security Manager

Hiring Organisation
Charles Simon Associates Ltd
Location
Newcastle Upon Tyne, Tyne and Wear, North East, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£65,000
Cyber Security Lead (Entra ID, Defender, Purview, SIEM, SOC, Cyber Essentials Plus, ISO 27001, NIST, CISSP, Hands-On, 3rd Party Management) Permanent Home Based Charles Simon Associates are currently recruiting for a Technical Cyber Security Lead for one of our key clients, a fast-growing UK business with sites across … technical lead for security. The official title is Manager, but this isn't a people management role. They will manage the outsourced SOC and SIEM providers, choose the security tools the business uses going forward, lead Cyber Essentials Plus and ISO 27001 certification, and decide whether SOC and SIEM stay ...

Senior Application Engineer (SIEM)

Location
Bath, England, United Kingdom
critical defence, government and public sector services. What you will do as a Senior Application Engineer Support, configure, and enhance security tooling platforms (e.g. SIEM, EDR) that underpin threat detection and response Deliver engineering tasks within defined work packages, ensuring alignment with user needs, security requirements, and service-level objectives. … compliance with engineering governance, ITSM processes, and cyber security policies. What youll bring Solid experience in supporting, configuring, and enhancing security tooling platforms (e.g. SIEM, EDR, or similar) Ability to solve moderately complex application-related issues and contribute to secure, scalable solutions. Understanding of application lifecycle management, integration patterns, and ...

Principal Platform Engineer (Privileged Access Management)

Location
Yeovil, England, United Kingdom
gapped, defence)## ## Desirable:* Expertise with cloud platforms (AWS, Azure) and Infrastructure as Code* Experience integrating enterprise services (Active Directory, PKI, monitoring, SIEM)* Hands-on use of DevSecOps tools and CI/CD pipelines* Automation of account onboarding/offboarding (API-driven)* Integration with SIEM/SOC tooling ...

24 x 7 Security Analyst

Location
Birmingham, England, United Kingdom
shift team, you will use your expertise to detect and respond to a multitude of threats of differing capability and sophistication. You will use SIEM, EDR, Network Monitoring, bespoke tooling and Threat Intelligence solutions to triage suspicious events, provide context and an assessment of risk/threat to customers … Endpoint, Defender for Identity, Defender for Cloud Apps), including deployment, configuration, and day‐to‐day operational management within an enterprise environment. Knowledge of SIEM and EDR/EPP technologies , with a particular focus on leveraging Microsoft Sentinel and Defender to deliver threat detection, investigation, and response capabilities. Proven ability ...

Senior Security Engineer

Location
Greater London, England, United Kingdom
and maintain detection coverage for cloud‐native threats (privilege escalation, unusual API activity, lateral movement, data exfiltration, and more). Leverage CloudTrail, GuardDuty, and SIEM integrations to maintain visibility across the AWS estate. Align detection logic with MITRE ATT&CK for Cloud. Vulnerability & Configuration Management: Own vulnerability management for cloud … and integrating security scanning into CI/CD workflows. Good experience with container and image security - scanning, runtime protection, supply chain risk. Experience with SIEM and detection engineering - building and tuning cloud‐native detection rules, threat hunting across CloudTrail and application logs. Familiarity with automation platforms and AI‐driven security ...

Senior Cyber Security Analyst

Location
Corsham, England, United Kingdom
clients and stakeholders Communicate security findings and trends directly to clients Support vulnerability management analysis and remediation efforts Lead false‐positive reduction and SIEM tuning activities Mentor and support development of Tier 1 and junior analysts Contribute to SOC process improvement and operational efficiency Participate in incident response activities … Looking For Strong experience within a SOC or cyber security operations environment Proven ability to investigate and analyse complex security incidents Experience with SIEM platforms, threat intelligence, and security tooling Strong stakeholder and client communication skills Ability to mentor and develop junior team members Proactive approach to problem‐solving and ...

Cyber Security Engineer

Location
Beverley, England, United Kingdom
problem solving and influencing best practice, this role offers real scope to make an impact. What you will be doing Monitor, develop and optimise SIEM and threat detection systems Investigate security incidents, coordinating response, containment and escalation Conduct vulnerability scanning and support remediation across the IT estate Work closely with … Proven experience in a cyber security or infrastructure security role Strong understanding of security principles, threat detection and risk-based thinking Experience with SIEM platforms, vulnerability management tools and detection response technologies such as EDR, XDR or MDR Knowledge of cyber security frameworks such as ISO 27001 or NIST Understanding ...

Senior Security Engineering Consultant

Hiring Organisation
Infosec
Location
Basingstoke, Hampshire, South East, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£80,000
Operations domain, focused on helping customers improve and automate their SOC functions, tooling, and detection capabilities. Key Responsibilities: Design and deliver detection rulesets across SIEM and XDR platforms Develop and tune detection logic using KQL or equivalent query languages Design detection use cases aligned to MITRE ATT&CK and real … detection approaches Identify gaps in telemetry, logging and enrichment, and provide recommendations to strengthen detection outcomes Job Requirements: Strong hands-on experience with SIEM engineering, including developing and tuning detection rules, with Microsoft Sentinel preferred Experience writing detection logic using KQL or similar query languages Proven experience designing and implementing ...

IT SOC Analyst

Location
Lutterworth, England, United Kingdom
Westfield Health Cash plan & Lifestyle benefits – Discount on selected stores. Responsibilities Include Monitor information systems for malicious activity using Security Incident and Event Management (SIEM) toolsets. Prioritising according to their criticality and escalating potential or confirmed incidents. Triage and investigate security-related tickets from business users and third-party security … providers. Limiting business disruption from malicious activity by containing and eradicating malicious activity from information systems. Support the development of SIEM and SOAR solutions. Ensure all investigative activity is correctly documented in ticketing systems and followed up with the relevant support teams. Perform research on the latest security/cyber ...

SOC Subject Matter Expert (UK)

Location
Horsham, England, United Kingdom
Team Lead Deep understanding of end‐to‐end SOC operations including alert triage, incident response, threat hunting, and case management Extensive experience with SIEM platforms, security orchestration tools, and the broader SOC technology stack Strong knowledge of threat detection methodologies, alert correlation, and incident prioritisation frameworks Expert‐level understanding … tool evaluation, selection, or implementation projects. Experience with security automation, SOAR platforms, or playbook development. Experience working with or partnering with SOC/SIEM/EDR vendors and MSSP (Managed Security Service Provider) vendors. Familiarity with product management principles, agile methodologies, or requirements gathering processes. Experience presenting to executive leadership ...

IT Operations & Cyber Lead

Location
Greater London, England, United Kingdom
and access provisioning in partnership with ITSM. Implement, operate and continually improve cyber defences across endpoints and SaaS platforms: vulnerability management, EDR/SIEM, and incident response. Manage vendors and core infrastructure partners, ensuring cost-effective delivery, timely patching, and contract governance. Maintain secure, high-performance connectivity for offices, labs … Okta or similar) Endpoint Management (Intune, Jamf, or similar) Corporate Networking (LAN/Wi-Fi/VPN/firewalls) Cyber Security Operations (EDR, SIEM, vulnerability management, incident response) Demonstrated ability to define and enforce standards and processes that combine agility with control. Strong vendor and stakeholder-management capability. Excellent communication ...

GreyMatter Specialist

Location
Harrow, England, United Kingdom
uncommon? (not required) Certifications such as Network+, Security+, CySA+ 1-3 years' experience as a Security/Network Administrator or equivalent knowledge Prior SIEM experience and/or administration Hands‐on experience with parsing data, log formats, regular expressions Scripting experience (bash, PowerShell, python) Multiple OS experience (mac, windows) Knowledge … various security methodologies and processes, and technical security solutions (SIEM, IDS/IPS, Firewall Solutions, Offensive Security tools) #J-18808-Ljbffr ...

Senior SOC Analyst – DV Clearance

Location
Greater London, England, United Kingdom
with strong monitoring, analysis, and incident triage capabilities within a Security Operations Centre environment. SOC Analyst - Key Responsibilities Monitor and analyse security alerts from SIEM and security tooling platforms Perform triage and investigation of security events and potential incidents Conduct threat hunting and identify indicators of compromise Escalate and coordinate … Analyst - Required Skills and Experience Active DV clearance Experience working within a SOC environment (Level 2 or Level 3 preferred) Strong knowledge of SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, or ArcSight Understanding of network protocols, attack techniques, and cyber threat methodologies Experience investigating security incidents across Windows and ...

Senior Security Architect - SecOps and Vulnerability Management

Location
Greater London, England, United Kingdom
globally, supporting audit, regulatory, and risk initiatives, with a focus on cloud computing and emerging technologies. Job Responsibilities: Design, scale, and manage the enterprise SIEM architecture to provide centralized visibility and high-fidelity threat detection across all corporate and cloud infrastructure. Develop and influence advanced SIEM correlation rules, custom data … testing, remediation quality, and traceability/auditability in line with resiliency expectations. Required Qualifications, Capabilities, and Skills: Hands‐on experience advising and influencing enterprise SIEM platforms (e.g., Microsoft Sentinel, Splunk, Chronicle/SecOps). Must be proficient in writing/reviewing advanced detection logic (KQL, SPL, or YARA rules). ...

Security Monitoring & Detection Engineering Lead

Location
Manchester, England, United Kingdom
Detection Engineering, translating CDO priorities into a clear roadmap for monitoring, detection, investigation and response. Lead the architecture, engineering and continued development of our SIEM solution, ensuring the SIEM remains resilient, scalable, cost-effective and aligned with AJ Bell’s technology estate and threat profile. Define and govern the onboarding … risks and capability constraints to the Head of Cyber Defence Operations, providing clear recommendations and action plans. Skills & Experience Extensive experience across security monitoring, SIEM engineering, detection engineering and incident response within a complex enterprise environment. A strong record of designing, building, operating and evolving Microsoft Sentinel as a production ...

Security Monitoring & Detection Engineering Lead

Location
Greater London, England, United Kingdom
Detection Engineering, translating CDO priorities into a clear roadmap for monitoring, detection, investigation and response. Lead the architecture, engineering and continued development of our SIEM solution, ensuring the SIEM remains resilient, scalable, cost-effective and aligned with AJ Bell’s technology estate and threat profile. Define and govern the onboarding … risks and capability constraints to the Head of Cyber Defence Operations, providing clear recommendations and action plans. Skills & Experience Extensive experience across security monitoring, SIEM engineering, detection engineering and incident response within a complex enterprise environment. A strong record of designing, building, operating and evolving Microsoft Sentinel as a production ...

SOC - Cyber Threat Operations Specialist

Hiring Organisation
Certain Advantage
Location
Stevenage, Hertfordshire, South East, United Kingdom
Employment Type
Contract, Work From Home
Contract Rate
£85 per hour, Benefits Overtime Rate
required eventually . A background working as a Cyber Security Engineer, SOC Engineer, SOC Analyst, Senior SOC Analyst, Cyber Security Analyst, Security Operations Engineer, SIEM Engineer, SIEM Analyst, Threat Detection Engineer, Security Infrastructure Engineer would be well suited to this position. Rate: £85.00 per hour Location: Stevenage Hybrid/Remote … Threat hunting, analysis, monitoring, Optimising, reporting, alerting and investigation activity utilising a wide variety of security platforms including AI/ML and behavioural analytics, SIEM (Security Information Event Management), Network Packet Capture platform, Anti Malicious Code, Threat Detection technologies and platforms across the UK Network Perimeter working with the best ...

Security Platform Engineer, UK Security Operations

Hiring Organisation
Google
Location
London, UK
Employment Type
Full-time
Deploy, configure, and manage cloud security platform tools and technologies, including Security Information and Event Management (SIEM), Intrusion Detection/Prevention Systems (IDS/IPS), and Cloud Workload Protection Platforms (CWPP).Develop and implement security monitoring and logging strategies. Investigate and analyse security incidents, including identifying root causes, determining … detection and anomaly detection. Experience with service mesh security concepts (e.g., Istio, Linkerd) and workload identity. Experience in detection engineering, logging pipeline development, or SIEM tuning in containerised environments. Experience in contributing to security-focused open-source projects or internal security platform tooling. As a part of the UK Security ...

Information Security Manager with Network Engineering Skills

Hiring Organisation
Nexus Jobs
Location
London, UK
Employment Type
Full-time
similar)Cyber Security Network Control Incident Investigation with the assistance of group cyber security experts – Tier 1, Tier 2 to 3 preferred, using LogRhythm SIEM a bonusHost End Point Protection (Symantec)Host IPSPreferred Skills and KnowledgeVulnerability Management (Scanning for Vulnerabilities and classifying the risk, CIS Benchmark Scanning and compliance) – Using … and disadvantagesSecurity Zone Design and considerationsNetwork and Security Architecture Design and ConsiderationsUnderstanding of Information Security (Confidentiality, Integrity, Availability), MITRE ATT&CK, NIST, ISO 27001, SIEM use cases for key controls etcRisk Management in Cyber Security, SSL Blind spots, what causes them and how to mitigateMalware/Ransomware and ...

Security Platform Engineer, UK Security Operations

Location
Greater London, England, United Kingdom
detection and anomaly detection. Experience with service mesh security concepts (e.g., Istio, Linkerd) and workload identity. Experience in detection engineering, logging pipeline development, or SIEM tuning in containerised environments. Experience in contributing to security-focused open-source projects or internal security platform tooling. About the job As a part … ensure security incidents can be swiftly resolved. Responsibilities Deploy, configure, and manage cloud security platform tools and technologies, including Security Information and Event Management (SIEM), Intrusion Detection/Prevention Systems (IDS/IPS), and Cloud Workload Protection Platforms (CWPP). Develop and implement security monitoring and logging strategies. Investigate and ...

Lead Security Architecture & SOC Transformation

Location
Greater London, England, United Kingdom
protective monitoring and SOC transformation engagements across enterprise environments. The role demands progression through architecture, engineering, SOC or consultancy roles and delivering enterprise-scale SIEM, EDR/XDR and managed security service changes. The successful candidate will own engagements from discovery and target-state design through migration, assurance and service ...