101 to 125 of 149 SOAR Jobs in England

Senior Splunk Security Architect & AI Ops Leader

Location
Greater London, England, United Kingdom
Cisco Systems, Inc. in London seeks a senior Splunk security consultant to lead technical leadership and strategic advisory across SIEM, SOAR, and AI-driven security operations. You will design and deliver tailored Splunk security architectures, mentor teams, and collaborate with CISO and IT leadership to maximize technology investments and risk ...

Senior Splunk Security Architect & Advisory Lead

Location
Greater London, England, United Kingdom
Cisco seeks a senior security consultant within its Professional Services team to provide technical leadership in Splunk SIEM/SOAR, guide multi-functional projects, and deliver tailored security architectures across regional and global customers. You will leverage AI-driven operations, automate incident response, mentor teams on PDIO methodologies, and drive ...

Senior Cyber Incident Response Lead

Location
Greater London, England, United Kingdom
providing strategic direction to maintain a robust security posture for clients. You will own detection rules and playbooks for Microsoft Sentinel, Defender XDR, SIEM, SOAR, EDR and XDR, while mentoring the Cyber Services team. You will collaborate with architects and cross-functional teams to align tooling with client needs, produce ...

Lead Splunk Security Architect & AI Ops Innovator

Location
City Of London, England, United Kingdom
Cisco Systems, Inc. is seeking a senior Splunk security specialist to provide technical leadership and strategic advisory across SIEM, SOAR, and AI-driven security operations. You will guide multi-functional security projects, design tailored Splunk architectures, and partner with CISOs to maximize technology investments. The role emphasizes collaboration with security ...

Cybersecurity Analyst

Location
Greater London, England, United Kingdom
engineer, SOC automation engineer, threat hunter, threat modeler, and security awareness engineer. Our SOC team is involved in engineering (e.g., we built our own SOAR, email content scanning system, the entire alerting stack and much more) and we handle the incident response and remediation when a threat is found. ...

Regional Sales Manager, EMEA

Location
Greater London, England, United Kingdom
mentality who enjoys building new business. Ability to thrive in a fast-growing, high-velocity startup environment. Nice to have Experience selling AI, SecOps, SOAR, SIEM, XDR, or security operations platforms. Experience working with enterprise customers across the UK market. Experience partnering with MSSPs, channel partners, or strategic alliances. ...

SOAR Playbook Engineer

Location
Manchester, England, United Kingdom
SOAR Playbook Engineer Department: Cyber Services and Capabilities Employment Type: Full Time Location: GBR Manchester Hardman Boulevard Reporting To: Kai Leenders Description As an MXDR SOAR Engineer, you design, develop, maintain and optimise security automation solutions using Splunk SOAR and similar automation platforms. Your primary focus is playbook engineering, Python … across technical and business functions, and help ensure their environments remain secure, resilient, and operationally effective. You act as the technical authority for Splunk SOAR, supporting customers and internal teams by translating operational requirements into scalable automations. Experience with Splunk SOAR is essential. This role requires a broad combination ...

Senior Security Analyst (L3 SOC Analyst)

Location
City Of London, England, United Kingdom
Conduct proactive threat hunting activities using threat intelligence, behavioural analytics and industry frameworks to identify previously undetected threats. Develop and enhance security automation and SOAR playbooks to improve operational efficiency, response capability and analytical effectiveness. Mentor and support SOC analysts while contributing to the ongoing maturity of detection engineering, incident … senior SOC environment, including working in an L3 analyst, incident response, threat hunting or detection engineering capacity. Deep technical knowledge of SIEM, EDR, SOAR, cloud security, identity security, endpoint security and enterprise monitoring platforms. Proven experience leading the investigation and response to complex cyber security incidents and acting ...

Senior Security Analyst (L3 SOC Analyst)

Location
Greater London, England, United Kingdom
Conduct proactive threat hunting activities using threat intelligence, behavioural analytics and industry frameworks to identify previously undetected threats.* Develop and enhance security automation and SOAR playbooks to improve operational efficiency, response capability and analytical effectiveness.* Mentor and support SOC analysts while contributing to the ongoing maturity of detection engineering, incident … senior SOC environment, including working in an L3 analyst, incident response, threat hunting or detection engineering capacity.* Deep technical knowledge of SIEM, EDR, SOAR, cloud security, identity security, endpoint security and enterprise monitoring platforms.* Proven experience leading the investigation and response to complex cyber security incidents and acting ...

SOC Subject Matter Expert (UK)

Location
Horsham, England, United Kingdom
Lead Deep understanding of end‐to‐end SOC operations including alert triage, incident response, threat hunting, and case management Extensive experience with SIEM platforms, security orchestration tools, and the broader SOC technology stack Strong knowledge of threat detection methodologies, alert correlation, and incident prioritisation frameworks Expert‐level understanding of MITRE … Tier 3 SOC roles with incident response and threat hunting responsibilities. Previous involvement in SOC tool evaluation, selection, or implementation projects. Experience with security automation, SOAR platforms, or playbook development. Experience working with or partnering with SOC/SIEM/EDR vendors and MSSP (Managed Security Service Provider) vendors. Familiarity ...

Engineer - Splunk

Location
Greater London, England, United Kingdom
Services and Capabilities Location: GBR Manchester Hardman Boulevard Description We are seeking an experienced Splunk Engineer to help design, build, and manage our Splunk SOAR service, with a strong focus on automation, security response, and service maturity. This role will be responsible for developing, reviewing, testing, and deploying Splunk SOAR … ensuring they are secure, reliable, and aligned with security governance and operational needs. The role requires a technically strong Splunk engineer with experience in SOAR development, Splunk architecture, and security engineering best practices. You will work closely with SOC teams, security engineers, and customers, owning your own workload and providing ...

Engineer - Splunk

Location
Cheltenham, England, United Kingdom
Fixed Term Contract Location: GBR Cheltenham Jessop House Description We are seeking an experienced Splunk Engineer to help design, build, and manage our Splunk SOAR service, with a strong focus on automation, security response, and service maturity. This role will be responsible for developing, reviewing, testing, and deploying Splunk SOAR … ensuring they are secure, reliable, and aligned with security governance and operational needs. The role requires a technically strong Splunk engineer with experience in SOAR development, Splunk architecture, and security engineering best practices. You will work closely with SOC teams, security engineers, and customers, owning your own workload and providing ...

SOC Automation Engineer

Location
Pocklington, England, United Kingdom
with SOC, engineering and service delivery teams to understand operational requirements and deliver automation solutions. Build and maintain integrations with security technologies including SIEM, SOAR, EDR, threat intelligence and cloud platforms. Leverage APIs and external data sources to enhance security workflows and processes. Explore and implement AI-enhanced automation capabilities … and systems integration. Experience working within a Security Operations, Incident Response, Threat Engineering or Security Engineering environment. Understanding of modern security technologies including SIEM, SOAR, EDR, IAM, threat intelligence and vulnerability management solutions. Knowledge of cloud security and cloud-based platforms. Awareness of AI technologies and their practical application within ...

SOAR Engineer

Location
Bradley Stoke, England, United Kingdom
SOAR/SIEM Security Engineer - Critical National Infrastructure (OT) 18-Month FTC | SC Cleared A leading cyber security firm is looking for a SOAR/SIEM Security Engineer to join a critical national infrastructure (CNI) client on an 18-month fixed-term contract, supporting the protection of operational technology … across converged IT/OT infrastructure. You'll be working on live, high-stakes environments. What you'll be doing Designing, building, and maintaining SOAR playbooks to automate detection and response workflows Developing and tuning Splunk use cases, dashboards, and correlation searches across IT and OT data sources Supporting incident ...

Senior Security Architect - SecOps and Vulnerability Management

Hiring Organisation
Hackajob Ltd
Location
South West London, London, United Kingdom
Employment Type
Permanent
risk-based vulnerability management platform that automatically prioritizes infrastructure and application flaws utilizing real-world exploit intelligence and asset criticality. Build and optimize SOAR playbooks to automate incident response workflows, accelerate threat containment, and streamline vulnerability ticketing. Provide senior technical escalation support during critical security incidents and drive post-incident … specifically utilizing EPSS (Exploit Prediction Scoring System) alongside CVSS to determine patching prioritisation. Ability to design and influence automated response playbooks using SOAR platforms Practical experience creating reference architectures and patterns for engineering teams. Proven ability to design and deploy automated preventive and detective guardrails at scale. Ability to solve ...

Security Engineer - SIEM/XDR - London (Hybrid)

Hiring Organisation
Nova Source Technologies
Location
London, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£70,000
Security Engineer (SIEM/XDR) Microsoft Sentinel, Defender, Endpoint, Detection Engineering, Detection-as-Code, KQL, Security Automation, SOAR, Playbooks, Telemetry, Cloud Security, APIs, CI/CD, Infrastructure-as-Code, Python, PowerShell, Windows, Linux, London (Hybrid) This is an exceptional permanent Security Engineer (SIEM/XDR) opportunity to join a leading … security content and alert logic Security telemetry, logging pipelines, data quality and telemetry coverage improvement Cloud security engineering and scalable security architecture design Automation, SOAR, playbooks, enrichment workflows and response improvement Scripting/programming skills such as Python and PowerShell Infrastructure-as-code, CI/CD pipelines, version control and ...

Interim Cyber Security Officer

Location
Greater London, England, United Kingdom
technical escalation point for high‐severity security incidents, facilitating rapid investigation, containment, and remediation using EDR and SIEM tools. Develop and implement SOAR workflows to automate detection, response, and security operations processes. Conduct proactive threat hunting using SIEM/EDR data and MITRE ATT&CK‐aligned techniques. Support vulnerability assessment … network protocols, cloud security (AWS/Azure), and threat detection methodologies. Working knowledge of the MITRE ATT&CK framework. Experience building automation or SOAR playbooks for security operations. CrowdStrike certifications (CCFA/CCFR/CCSE – any combination preferred). Splunk Certified Cybersecurity Defense Engineer (mandatory preferred requirement). Security certifications ...

Cyber Security Engineer

Location
Greater London, England, United Kingdom
cyber security capabilities. You will have a broad remit across Microsoft security technologies, identity and access management, vulnerability management, incident response, SIEM/SOAR, threat hunting and cloud security, while also providing security advice to technology projects and supporting security-by-design principles. Key Responsibilities Design, implement and maintain cyber … Exchange Online, SharePoint and Teams. Support identity and access management, vulnerability management and security monitoring. Investigate and respond to security incidents, including SIEM/SOAR investigations and advanced threat hunting. Support security reviews, audits and annual penetration testing. Identify vulnerabilities, risks and opportunities to improve the organisation's security posture. ...

Lead SOC Architect

Hiring Organisation
Anson Mccade
Location
Central London, London, United Kingdom
Employment Type
Permanent
concepts, CONOPS and high/low-level architecture designs • Working directly with senior client and government stakeholders • Designing and integrating security technologies including SIEM, SOAR, EDR, Threat Intelligence and Vulnerability Management • Assessing existing SOC capabilities and developing security maturity • Designing scalable, resilient on-prem and cloud security architectures • Supporting accreditation … and operation They're looking for: • Strong experience in SOC architecture and security operations • Hands-on architectural experience across at least two of SIEM, SOAR, EDR, Vulnerability Management or Threat Intelligence • Strong understanding of security operations, threat detection and incident response • Experience designing both on-prem and cloud security architectures ...

Senior Sales Engineer

Location
Greater London, England, United Kingdom
solution walkthroughs for enterprise security teams across the UK and Europe Run structured technical discovery to understand customer security posture, existing tooling (SIEM, EDR, SOAR, identity), and integration needs Design and validate customer-specific solutions that meet technical, security, compliance, and business requirements Serve as the primary technical owner … enterprise sales cycles Strong understanding of modern security architecture: identity, endpoint, network, and cloud (AWS, Azure, GCP) Strong knowledge of SIEM, EDR/XDR, SOAR, and common log sources (CloudTrail, Okta, endpoint telemetry, etc.) Familiarity with detection frameworks (MITRE ATT&CK) and threat modeling Comfort with APIs, scripting (Python, Bash ...

AI & Automation Engineering, Global Security (Vice President)

Location
Greater London, England, United Kingdom
configuration drift detection, data classification and DLP event triage, and vulnerability prioritisation and contextualisation. Develop LLM and agent-based workflows integrated with SIEM, EDR, SOAR, IGA, PAM, CSPM, DLP, ticketing and threat intelligence platforms via supported APIs. Set the global AI Security and automation roadmap in partnership with the Head … tool and function calling, orchestration, and evaluation or regression testing of non-deterministic outputs. Working knowledge of security operations tooling and workflow - SIEM, EDR, SOAR, case management, threat intelligence. Practical familiarity with at least two additional security domains from identity and access management, privileged access, network or cloud security ...

Presales Executive (Cyber Security)

Location
Leeds, England, United Kingdom
strategy and technical execution across SEP2’s core portfolio, including the Wingman Managed Services Suite (mXDR, MDR, EDR, Managed Firewalls, vCISO), Google SecOps (SIEM, SOAR, Mandiant Threat Intelligence), and vendor partner technologies (e.g., Check Point, Wiz, SentinelOne, CrowdStrike) and services for our clients. This is a Hybrid position with … solutions are scalable, operationally deliverable, and compliant with customer RACI expectations. Demonstrations & Proof of Concepts (POC) Deliver compelling, outcome-based product demonstrations covering SIEM, SOAR, EDR, Cloud Security, and Threat Intelligence platforms. Manage and execute end-to-end technical Proof of Concepts (POCs) for client opportunities, establishing clear success criteria ...

2nd/3rd Line Security Analyst - Reading

Hiring Organisation
Xact Placements Limited
Location
Reading, Berkshire, United Kingdom
Employment Type
Full-Time
Salary
£50,000 - £60,000 per annum
and tune out false positives without blanket whitelisting Build automation for SOC processes - enrichment, ticketing, containment - using Python, Logic Apps, APIs or a SOAR platform Correlate evidence across SIEM, endpoint, identity and cloud platforms (Sentinel, Defender XDR, CrowdStrike, Entra ID, Microsoft 365, AWS) to scope the full blast radius … solid understanding of MITRE ATT&CK and KQL (or equivalent) Practical scripting/automation experience (Python, Logic Apps, REST APIs) or hands-on SOAR platform configuration Working knowledge of several of: Microsoft Sentinel, Defender XDR, CrowdStrike, Microsoft Entra ID/Azure AD, Microsoft 365, AWS security tooling Experience investigating identity ...

SIEM Engineer

Location
Reading, England, United Kingdom
Sentinel; build custom parsers and data transformations Design and optimise KQL queries; build and tune analytic rules and detection logic Develop Logic Apps/SOAR workflows to automate response Implement CI/CD pipelines (Azure DevOps/Git) for SIEM content deployment Automate deployment/config across environments; tune detections … source onboarding, custom parsers and data normalisation Advanced KQL development and optimisation Analytic rule/detection logic design and tuning Logic Apps, Playbooks and SOAR automation Azure DevOps/Git CI/CD pipeline implementation Strong grounding in security monitoring, incident response and threat hunting Strong troubleshooting and root cause ...

Senior Security Engineer

Location
Greater London, England, United Kingdom
researchers; Security Engineering & Orchestration: Design, implement, and optimize core security infrastructure (e.g. EDR,, Zero Trust, IAM, and DLP). Focus on automation and orchestration (SOAR) to reduce manual overhead and ensure security controls are consistently enforced across a global, multi-cloud environment; Incident Response Leadership: Lead the technical responsesecurity tooling, automate repetitive SecOps tasks, and develop sophisticated detection logic; Detection & Response Architecture: Proven experience designing and optimising enterprise security stacks, including SIEM, SOAR, and EDR. You don't just use tools; you tune them to eliminate noise and build high-fidelity alerting pipelines; DevSecOps Leadership: Experience leading ...