501 to 525 of 652 SIEM Jobs in England

Cyber Security Engineer

Location
Greater London, England, United Kingdom
and security maturity improvements. Get exposure to AI security: Work around Copilot, AI agents, Purview, and data security compliance. Broad technical remit: Microsoft security, SIEM, incident response, cloud/SaaS security, identity, and network security. Room to grow: The team is investing in capability, and strong performers may have scope … management, remediation planning, reporting, and automation. Security incident triage, investigation, and response. Microsoft Defender, Entra ID/Active Directory, Conditional Access, and related controls. SIEM query building and KQL. Ransomware resilience, including backup and network segmentation. Cyber Essentials Plus and wider security maturity initiatives. AI, Copilot, Purview, and data security ...

24 x 7 Security Analyst

Hiring Organisation
LRQA
Location
Birmingham, UK
Employment Type
Full-time
shift team, you will use your expertise to detect and respond to a multitude of threats of differing capability and sophistication. You will use SIEM, EDR, Network Monitoring, bespoke tooling and Threat Intelligence solutions to triage suspicious events, provide context and an assessment of risk/threat to customers … Endpoint, Defender for Identity, Defender for Cloud Apps), including deployment, configuration, and day-to-day operational management within an enterprise environment. Knowledge of SIEM and EDR/EPP technologies, with a particular focus on leveraging Microsoft Sentinel and Defender to deliver threat detection, investigation, and response capabilities. Proven ability ...

Senior Cyber Security Engineer

Hiring Organisation
Checkout.com
Location
London, UK
Employment Type
Full-time
and progressively taking ownership of the tooling and procedures that keep security operations running. What you'll be responsible forSupporting and enhancing security tooling SIEM, EDR, DLP, vulnerability management, and automation platforms including configuration, tuning, and day-to-day maintenanceBuilding and improving operational procedures, runbooks, and playbooks so the team … looking for5+ years of hands-on experience in a Security Operations, SOC, or equivalent operational security rolePractical experience operating modern security tooling SIEM (e.g. Sentinel), Data Loss Prevention (DLP) tools, EDR, and vulnerability management platformsSolid understanding of security operations workflows: alert triage, incident handling, and vulnerability/finding remediation lifecyclesComfort ...

Principal Security Consultant (AIR)

Location
Biggin Hill, England, United Kingdom
Remediation (AIR) consulting team. This is a senior, customer facing role focused on helping enterprise clients design, build, and optimise security operations capabilities - spanning SIEM, Identity, and Endpoint Detection & Response (EDR) technologies. As a Principal Consultant, you operate at the intersection of deep technical expertise and strategic advisory. You will … stand in front of client management. Responsibilities Engagement Delivery Lead the end-to-end design and delivery of AIR engagements - including greenfield SOC builds, SIEM platform implementations (Microsoft Sentinel, Splunk), EDR deployments, and managed security service transitions. Produce high-quality, client-ready deliverables: High Level Designs, Low Level Designs, Statements ...

Senior Cyber Security Engineer (EDR)

Hiring Organisation
Sanderson Government and Defence
Location
Manchester, North West, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£85,000
securing large-scale, cloud-based environments supporting critical public sector and government services. This is a hands-on engineering role focused on threat detection, SIEM engineering, security monitoring, log management, and SOC optimisation . You'll design and enhance detection capabilities, improve security visibility, and ensure organisations can rapidly identify … resilience while enabling faster, risk-based decision-making. What You'll Be Doing Detection Engineering & Threat Monitoring Develop, tune, and maintain detection rules across SIEM, EDR, and threat detection platforms. Create and optimise detection logic using technologies such as Splunk and endpoint security solutions. Map detections against the MITRE ...

Security Consultant

Location
Greater London, England, United Kingdom
facing consultancy role where you'll work with a wide range of organisations to design, develop and optimise detection and response capabilities across leading SIEM, XDR and SOAR technologies. You'll combine deep technical expertise with strong consulting skills, helping customers improve their security maturity through practical, scalable solutions. What … doing You'll play a key role in delivering detection engineering engagements, including: Designing and implementing high-quality detection rules across SIEM and XDR platforms. Creating and optimising detection logic using KQL and other query languages. Developing detection use cases aligned with the MITRE ATT&CK framework and current threat ...

Senior Security Engineer

Location
Gateshead, England, United Kingdom
implementatie en het beheer van specifieke security-oplossingen. Je bent de kartrekker voor onder andere het opzetten van ons nieuwe SOC, Microsoft Sentinel (SIEM) voor actieve threat detection en het beheren van Microsoft Defender for Cloud voor vulnerability management. Je analyseert en volgt security-incidenten op, en bent de drijvende … kracht achter de (versnelde) implementatie van een Security Operations Center (SOC). Ontwikkelen en onderhouden van detectieregels en playbooks (met SOAR/SIEM-tools); Samenwerken met collega’s om incidenten snel en effectief te mitigeren; Continu verbeteren van onze monitoring- en responsprocessen; Rapporteren van bevindingen en adviseren over structurele verbeteringen ...

Lead SOC Architect

Hiring Organisation
Anson Mccade
Location
Central London, London, United Kingdom
Employment Type
Permanent
concepts, CONOPS and high/low-level architecture designs • Working directly with senior client and government stakeholders • Designing and integrating security technologies including SIEM, SOAR, EDR, Threat Intelligence and Vulnerability Management • Assessing existing SOC capabilities and developing security maturity • Designing scalable, resilient on-prem and cloud security architectures • Supporting accreditation … deployment and operation They're looking for: • Strong experience in SOC architecture and security operations • Hands-on architectural experience across at least two of SIEM, SOAR, EDR, Vulnerability Management or Threat Intelligence • Strong understanding of security operations, threat detection and incident response • Experience designing both on-prem and cloud security ...

CSOC Lead

Location
Cheltenham, England, United Kingdom
Incident Response Lead for major cyber security events, coordinating technical investigations, containment and remediation activities. Lead advanced threat hunting and digital forensic investigations using SIEM, EDR, network telemetry and threat intelligence sources. Work closely with global CSOC teams to improve cyber defence capabilities, operational processes and detection methodologies. Provide clear … . Proven success leading teams, projects or operational cyber security functions. Strong incident response, cyber threat hunting and digital forensics expertise. Experience using commercial SIEM, EDR and network analysis platforms. Strong understanding of network protocols and traffic analysis across the OSI model. Experience working with cyber threat intelligence methodologies and ...

Senior SOC Engineer (Sentinel One)

Hiring Organisation
Claranet
Location
City, London, United Kingdom
Employment Type
Permanent
Salary
GBP Annual
engineering team. Key Responsibilities Lead the implementation and optimisation of SentinelOne-based SOC solutions for new and existing customers. Design, deploy, and support SIEM, XDR, EDR, SOAR, and telemetry solutions across cloud, hybrid, and on-premises environments. Act as the senior technical escalation point for complex engineering challenges. Drive continuous … experience in Security Engineering, SOC Engineering, or a similar cyber security role. Strong hands-on experience with the SentinelOne Singularity platform, including XDR, AI SIEM, and EDR technologies. Experience integrating and onboarding log sources across cloud, hybrid, and on-premises environments. Knowledge of automation, API integrations, telemetry pipelines, and security ...

Senior SOC Engineer (Sentinel One)

Hiring Organisation
Claranet
Location
WC2E, Covent Garden, Greater London, United Kingdom
Employment Type
Permanent
engineering team. Key Responsibilities Lead the implementation and optimisation of SentinelOne-based SOC solutions for new and existing customers. Design, deploy, and support SIEM, XDR, EDR, SOAR, and telemetry solutions across cloud, hybrid, and on-premises environments. Act as the senior technical escalation point for complex engineering challenges. Drive continuous … experience in Security Engineering, SOC Engineering, or a similar cyber security role. Strong hands-on experience with the SentinelOne Singularity platform, including XDR, AI SIEM, and EDR technologies. Experience integrating and onboarding log sources across cloud, hybrid, and on-premises environments. Knowledge of automation, API integrations, telemetry pipelines, and security ...

Senior Sales Engineer

Location
Greater London, England, United Kingdom
demos, and solution walkthroughs for enterprise security teams across the UK and Europe Run structured technical discovery to understand customer security posture, existing tooling (SIEM, EDR, SOAR, identity), and integration needs Design and validate customer-specific solutions that meet technical, security, compliance, and business requirements Serve as the primary technical … and CISOs in complex enterprise sales cycles Strong understanding of modern security architecture: identity, endpoint, network, and cloud (AWS, Azure, GCP) Strong knowledge of SIEM, EDR/XDR, SOAR, and common log sources (CloudTrail, Okta, endpoint telemetry, etc.) Familiarity with detection frameworks (MITRE ATT&CK) and threat modeling Comfort with ...

Lead Threat Detection Engineer

Location
Greater London, England, United Kingdom
class looks like. What you’ll be doing: Own and improve the threat detection lifecycle across a complex cloud estate Build and enhance SIEM detection rules, use cases and monitoring Automate manual detection and remediation processes Develop threat intelligence and threat-hunting capabilities Improve security monitoring across AWS, GCP and … and help upskill others across the security function What we’re looking for: Experience building detections rather than purely responding to SOC alerts Strong SIEM experience – Microsoft Sentinel, Splunk or similar Cloud security experience across AWS, GCP and/or Azure KQL, SPL or similar querying experience Python scripting/ ...

Platform Engineer – Monitoring, Observability & SIEM (MONSO)

Location
Greater London, England, United Kingdom
Platform Engineer – Monitoring, Observability & SIEM (MONSO) For our SPEAR Technology (Security, Platform Engineering, Automation and Runtime) division in London we are looking to hire a: Platform Engineer – Monitoring, Observability & SIEM (MONSO) Like solving puzzles with an inquisitive mind? Think outside the box and challenge the status quo? Prefer simplicity over … other teams to do more themselves—such as empower-ing our SOC/CyberSec team to develop (including AI-assisted workflows), test, and deploy SIEM use cases independently via CI/CD. The platform spans Splunk Enterprise on-prem (running on Kubernetes), Splunk Observability Cloud, and SolarWinds , with future expansion ...

Platform Engineer - Monitoring, Observability & SIEM (MONSO)

Hiring Organisation
Berenberg
Location
London, UK
Employment Type
Full-time
Platform Engineer – Monitoring, Observability & SIEM (MONSO) Persönliche Daten Land Vereinigtes Königreich Stadt London Art der Anstellung Professional Arbeitszeit Vollzeit Vertragsart Unbefristet Offene Stellen 1 Beschreibung & Anforderungen For our SPEAR Technology (Security, Platform Engineering, Automation and Runtime) division in London we are looking to hire a: Platform Engineer – Monitoring, Observability & SIEM … other teams to do more themselves—such as empower-ing our SOC/CyberSec team to develop (including AI-assisted workflows), test, and deploy SIEM use cases independently via CI/CD.The platform spans Splunk Enterprise on-prem (running on Kubernetes), Splunk Observability Cloud, and SolarWinds, with future expansion into ...

Senior Cyber Security Engineer – SIEM & Threat Detection

Location
Greater London, England, United Kingdom
Proactive Security team, focusing on building security tech stacks to mitigate threats with offensive and preventive measures. You will develop threat models, manage SIEM systems, and implement detection use cases while collaborating with incident response to protect information assets in a hybrid UK workplace. The role demands strong scripting (PowerShell ...

Elasticsearch Consultant

Location
Greater London, England, United Kingdom
Elastic SIEM Engineer We are seeking an experienced Elastic SIEM Engineer to design, implement and maintain security monitoring solutions using the Elastic Stack. The successful candidate will be responsible for developing scalable log-management and threat-detection capabilities across complex cloud and containerised environments. Key Responsibilities Design, deploy and support … Elastic SIEM solutions using Elasticsearch, Logstash and Kibana. Build and maintain log‐ingestion pipelines for infrastructure, applications, cloud platforms and security tools. Develop Kibana dashboards, alerts, detection rules and visualisations. Configure data parsing, enrichment, transformation and indexing within Logstash and Elasticsearch. Integrate Kafka to support reliable, high‐volume event streaming ...

Security Operations Specialist ( L3 )

Hiring Organisation
Michael Page
Location
Liverpool, Merseyside, United Kingdom
Employment Type
Contract
Contract Rate
£60000 - £65000/annum healthcare
attack techniques, threat actor methodologies, and appropriate mitigation strategies. Experience investigating security incidents and coordinating response activities. Knowledge of Security Information and Event Management (SIEM), Identity and Access Management (IAM), and Data Loss Prevention (DLP) technologies. Good understanding of modern security frameworks, detection engineering concepts, and operational security best practices. ...

Blockchain Security Operations Vice President

Location
City Of London, England, United Kingdom
multiple security domains, including network security, malware analysis, threat hunting, and security architecture and design, with proficiency in using Security Information and Event Management (SIEM) tools and advanced analytics techniques Advanced knowledge of network and infrastructure configuration/security, including experience in designing and implementing security solutions for on-prem ...

Blockchain Security Operations Vice President

Location
Greater London, England, United Kingdom
multiple security domains, including network security, malware analysis, threat hunting, and security architecture and design, with proficiency in using Security Information and Event Management (SIEM) tools and advanced analytics techniques Advanced knowledge of network and infrastructure configuration/security, including experience in designing and implementing security solutions for on-prem ...

Security Architect - Microsoft Security Platform

Hiring Organisation
Colt Telecom
Location
London, UK
Employment Type
Full-time
Microsoft 365 E5 security capabilities, including: Microsoft Defender (Endpoint, Identity, Office 365, Cloud Apps)Microsoft Entra ID (P2), Conditional Access and identity protectionMicrosoft Sentinel (SIEM integration)Microsoft PurviewStrong experience designing and implementing Microsoft Purview capabilities, including DLP, Information Protection, Insider Risk and eDiscovery Strong understanding of Zero Trust architecture principles … particularly identity-driven security models Experience deploying and operating Defender and SIEM capabilities, integrated within a wider security ecosystem Experience conducting security design reviews and translating policy into practical controls Experience performing risk assessments aligned to recognised methodologies Strong understanding of cloud security concepts across IaaS, PaaS and SaaS, particularly ...

Senior Cybersecurity Analyst - Social, Healthcare and Public Entities

Location
City of Westminster, England, United Kingdom
and participation in audit/certification such as: GDPR, NIST SP800-53, ISO 27001, NIST CSF, etc Experience evaluating logging activities for ingestion into SIEM as part of continuous monitoring plan Experience with security technologies and tooling, e.g. vulnerability scanners, firewalls, network monitors, IAM, SIEM, IDS/IPS Knowledge ...

Cyber Security Engineer

Hiring Organisation
Oscar Associates (UK) Limited
Location
Surrey, South East, United Kingdom
Employment Type
Permanent
Salary
£50,000
implement information security policies, controls and solutions. Monitor security events, risks and vulnerabilities and investigate incidents. Design, build, test and troubleshoot security solutions including SIEM and IDS/IPS. Manage vulnerability testing and recommend improvements. Provide cybersecurity expertise across network design and management. Maintain security policies, procedures and technical documentation. … teams through knowledge sharing and training. Requirements 5+ years' multi-network experience with hands-on secure network design and management. Experience with Cisco, Juniper, SIEM, IDS/IPS, penetration testing and forensic tools. Knowledge of ISO27001, GDPR, ITIL and vulnerability management. Strong communication and customer-facing skills. SC Clearance ...

Security Operations Engineer

Location
Hessle, England, United Kingdom
security issues and design effective remediation solutions Monitor and configure security tools - global EDR/XDR policies, blocklists, and automated containment rules including SIEM, EDR and respond to threat detection alerts. Maintain and enhance security monitoring capabilities through effective integrations and optimisation of security tooling, ensure effective data collection and … Detection & Response (EDR/XDR) tooling. Experience managing security tooling such as Microsoft Defender XDR, Sentinel, CrowdStrike, Splunk, QRadar, SentinelOne or similar enterprise-grade SIEM/XDR platforms. Direct experience securing Microsoft 365 tenants and standard corporate SaaS environments. Proven experience interfacing with, tuning, or triaging escalations from a third ...

Infrastructure Security Engineer

Hiring Organisation
Blockchain
Location
London, UK
Employment Type
Full-time
ownership, and a drive to continuously improve the security posture of complex systems. Familiarity with some of the following: Cloudflare (DDoS protection, WAF), OSS SIEM tools (Splunk, Elastic, etc), Incident management platforms (e.g. Incident.io, PagerDuty)Familiarity with at least one of the following CI/CD systems (Github Actions, Concourse … governance frameworks (e.g., CIS Benchmarks, NIST, SOC2, ISO 27001, PCI DSS) and how to operationalize them. Hands-on experience with building and maintaining a SIEM comprised of open-source and hosted componentsExperience securing consumer-facing web and iOS/Android applicationsExperience designing policies and administering Vault & other Hashicorp products. Experience ...