126 to 150 of 193 SIEM Jobs in London

SecOps Engineer

Hiring Organisation
Trainline
Location
London, United Kingdom
Salary
£ 80 K
security telemetry to identify emerging threats, improve detection capabilities and help shape our Security Operations roadmap.Support the administration, configuration and continuous optimisation of our SIEM platform (Splunk), ensuring it remains resilient, up to date, cost effective and aligned with industry best practice.Partner with Engineering and Technology teams to embed security … investigate security events and make informed, risk-based decisions.Experience working with security technologies such as Microsoft Defender, endpoint detection and response (EDR) solutions and SIEM platforms.Experience working with Web Application Firewalls (WAF), including creating, tuning and maintaining WAF rules to protect internet-facing applications, would be highly beneficial.Experience with vulnerability ...

Senior Manager, Security Architect, Cyber, Defence & Security (Government and Public Sector)

Hiring Organisation
Deloitte
Location
London, United Kingdom
Salary
£ 120 K
network security, encryption, authentication, and access control mechanisms.Experience with security technologies such as firewalls, intrusion detection/prevention systems, security information and event management (SIEM) systems, and vulnerability assessment tools, and their configuration options.Familiarity with cloud security principles and best practices, including securing cloud-based infrastructure and services (AWS, Azure ...

IT Infrastructure Operations and Security Lead

Hiring Organisation
Nexus Jobs
Location
London, United Kingdom
Salary
£ 80 K
and Privileged Access Management (PAM). Lead threat monitoring, detection, and response using cloud-native security solutions such as Microsoft Defender, Sentinel, and SIEM platforms. Ensure compliance with cloud security frameworks and regulatory requirements (ISO 27001, NIST, GDPR, SOC2, FCA). Conduct regular security risk assessments, penetration tests, and vulnerability … Single Sign-On (SSO), and Privileged Access Management (PAM). Threat Management & Incident Response: Ability to detect, respond to, and mitigate cyber threats using SIEM, endpoint security, and vulnerability management tools. Networking & Infrastructure Security: Understanding of firewalls, VPNs, SD-WAN, DNS security, endpoint protection, and cloud security controls. IT Service ...

IT Operations and Security Lead

Hiring Organisation
Nexus Jobs
Location
London, United Kingdom
Salary
£ 80 K
and Privileged Access Management (PAM). Lead threat monitoring, detection, and response using cloud-native security solutions such as Microsoft Defender, Sentinel, and SIEM platforms. Ensure compliance with cloud security frameworks and regulatory requirements (ISO 27001, NIST, GDPR, SOC2, FCA). Conduct regular security risk assessments, penetration tests, and vulnerability … Single Sign-On (SSO), and Privileged Access Management (PAM). Threat Management & Incident Response: Ability to detect, respond to, and mitigate cyber threats using SIEM, endpoint security, and vulnerability management tools. Networking & Infrastructure Security: Understanding of firewalls, VPNs, SD-WAN, DNS security, endpoint protection, and cloud security controls. IT Service ...

Infrastructure Security Design

Hiring Organisation
NTT DATA
Location
London, United Kingdom
Salary
£ 60 K
network security configurations and changes accuratelyPerform routine security device maintenance and updates under guidanceSecurity Technology Configuration Support deployment and configuration of security technologies including SIEM, EDR, and endpoint protectionAssist in integrating security tools with existing infrastructure under supervisionConfigure security monitoring rules and alerts based on approved templatesSupport security technology testing … and exceptionsSupport remediation activities for configuration vulnerabilitiesMaintain secure configuration templates and standard operating proceduresSecurity Monitoring and Incident Support Monitor security alerts and events from SIEM and security tools under guidancePerform initial triage of security incidents and escalate appropriatelyAssist in security incident investigations and evidence collectionDocument security incidents and response actions ...

Senior Security Engineer

Hiring Organisation
Docebo
Location
London, United Kingdom
Salary
£ 70 K
and maintain detection coverage for cloud-native threats (privilege escalation, unusual API activity, lateral movement, data exfiltration, and more). Leverage CloudTrail, GuardDuty, and SIEM integrations to maintain visibility across the AWS estate. Align detection logic with MITRE ATT&CK for Cloud.Vulnerability & Configuration Management: Own vulnerability management for cloud workloads … Terraform, CloudFormation) and integrating security scanning into CI/CD workflows.Good experience with container and image security — scanning, runtime protection, supply chain risk.Experience with SIEM and detection engineering — building and tuning cloud-native detection rules, threat hunting across CloudTrail and application logs.Familiarity with automation platforms and AI-driven security tools ...

Cyber Security Analyst

Hiring Organisation
CCL Global
Location
City of London, Greater London, UK
files, network traffic and cloud environments to understand potential cyber incidents. Supporting the technical response to incidents, including containment, eradication and recovery . Using SIEM and EDR security tools to investigate and respond to threats. Supporting the coordination of cyber security incidents and contributing to post-incident reviews. Identifying opportunities … Cyber Security Analyst or in a similar security operations role. Proven experience investigating and responding to cyber security incidents . Hands-on experience with SIEM tools , ideally Splunk. Experience with Microsoft Sentinel, Microsoft Defender and/or KQL . Strong understanding of threat actor TTPs and common cyber attack techniques. ...

Infrastructure Security Engineer

Hiring Organisation
X
Location
London, United Kingdom
Salary
£ 70 K
/CD pipelines; integrate and maintain code scanning platformsDetection, operations & toolingMonitor and respond to security events and incidents in cloud and hybrid environmentsMaintain SIEM data pipelines needed for reliable alertingBuild, deploy, and maintain security operations infrastructure using Python, Terraform, and configuration management (e.g., Puppet)Develop dashboards and alerts from securityand configuration management (e.g., Puppet)Hands-on experience building GitHub Actions and workflowsExperience with observability and security operations tooling (e.g., Prometheus, Grafana, CloudWatch, Karma; SIEM platforms such as Wazuh)Experience in building custom cloud security tools or integrationsInterest in leveraging AI for cloud security monitoring and automationContributions to open-source ...

Senior Cloud Security Engineer

Hiring Organisation
Checkout.com
Location
London, United Kingdom
Salary
£ 80 K
shaping the future of fintech – and we’re just getting started.The roleYou will evolve Checkout.com's security posture across our multi-cloud environments and SIEM platform. This role sits at the intersection of cloud security engineering and detection capability — responsible for both hardening the infrastructure we operate on and ensuring … security baseline across AWS, Azure, and GCP.You will partner closely with Engineering, GRC, Technology Risk and Security Operations - defining standards, fine tuning the SIEM, and progressively taking on the most complex cloud security and detection engineering challenges across the organisation.What you’ll be responsible forCloud SecuritySecure and continuously improve ...

Head of Cyber Defence & Incident Response

Hiring Organisation
Quadient
Location
London, United Kingdom
Salary
£ 80 K
organisation. This fits within the context of the broader organizational Crisis Management plan owned outside Technology.A key focus is optimising security tooling (e.g., SIEM, SOAR, EDR/XDR, NDR, email security, vulnerability scanning) and driving strong vulnerability and threat management, using threat intelligence to prioritise defensive improvements.Key ResponsibilitiesOwn the incident … definition, SLAs/KPIs, escalation paths, continuous improvement plans, quality assurance, and commercial governance.Optimise security monitoring and response tooling working across technology teams (e.g., SIEM, SOAR, EDR/XDR, NDR, email security) including use‐case coverage, alert quality, automation, logging strategy, and operational runbooks.Own the vulnerability management programme (on‐prem ...

Head of Cyber Defence & Incident Response

Hiring Organisation
Quadient
Location
Greater London, United Kingdom
Employment Type
Full Time
organisation. This fits within the context of the broader organizational Crisis Management plan owned outside Technology. A key focus is optimising security tooling (e.g., SIEM, SOAR, EDR/XDR, NDR, email security, vulnerability scanning) and driving strong vulnerability and threat management, using threat intelligence to prioritise defensive improvements. Key Responsibilities … SLAs/KPIs, escalation paths, continuous improvement plans, quality assurance, and commercial governance. Optimise security monitoring and response tooling working across technology teams (e.g., SIEM, SOAR, EDR/XDR, NDR, email security) including use‐case coverage, alert quality, automation, logging strategy, and operational runbooks. Own the vulnerability management programme ...

Senior SecOps Specialist

Hiring Organisation
Teya Solutions
Location
London, United Kingdom
Salary
£ 80 K
incident reviews and ensure improvements are implemented and follow-upscompleted.• Support incident metrics (MTTD, MTTR, recurrence, etc.)SOC Tooling & Platform Operations• Operate and improve SIEM, EDR, email security, case management, and vulnerabilitytools.• Monitor health, coverage, data quality, and integrations.• Troubleshoot ingestion, parsing, API, and configuration issues.• Build and maintain integrations … 7+ years in SOC, incident response, detection engineering, or security engineering.• Experience leading complex security incidents end-to-end.• Strong hands-on experience with SIEM, EDR, and security tooling.• Experience building and tuning detections and queries.• Experience with log onboarding, telemetry pipelines, and data quality issues.• Strong vulnerability management and ...

SOC Analyst - Tier 1

Hiring Organisation
Methods Consulting
Location
London, United Kingdom
Salary
£ 80 K
start or grow their career in cybersecurity, with opportunities for advancement and skill development.RequirementsKey Responsibilities:Monitor security alerts and events from Microsoft Defender, SIEM and other security tools.Perform initial triage and analysis of security incidents.Escalate verified incidents to Tier 2/3 analysts as needed.Document incidents, investigations, and response actions … Information Technology, or related field (or equivalent experience).Basic understanding of networking concepts (TCP/IP, DNS, firewalls).Familiarity with security tools such as SIEM, antivirus, IDS/IPS, and endpoint protection.Strong analytical and problem-solving skills.Excellent written and verbal communication skills.Ability to work in a fast-paced, team-oriented ...

Crowdstrike Pre-Sales Senior Manager

Hiring Organisation
Accenture
Location
London, United Kingdom
Salary
£ 80 K
state, identify gaps, and map Falcon platform capabilities to business outcomes. You have designed and deliveredcompelling technical demonstrations of the Falcon platform, including NG-SIEM, Exposure Management (CTEM), Identity Protection, Cloud Security, and Charlotte AI, tailored to the client's environment and priorities. You excel at the development and presentation … capacityProven, demonstrated experience leading technical client conversations at the CISO, security architect, or SOC lead levelExtensive experience with at least two of the following: SIEM platforms (Splunk, QRadar, Elastic, Sentinel, Chronicle), endpoint security, identity threat detection, cloud security posture management, or vulnerability/exposure managementProven experience with enterprise security architectures ...

Security Platform Engineer, Google Cloud Public Sector

Hiring Organisation
Hackajob Ltd
Location
South West London, London, United Kingdom
Employment Type
Permanent
Salary
£40,000
custom exploits, adversary emulation scenarios, or security automation frameworks for internal testing. Knowledge of cloud-native logging, monitoring, and Security Information and Event Management (SIEM) integration for detecting sophisticated adversary tactics. Understanding of Kubernetes attack surfaces, including container escapes, privilege escalation, and lateral movement techniques. Current and active UK Developed … Vetting (DV) Security Clearance. Responsibilities: Deploy, configure, and manage cloud security platform tools and technologies, including Security Information and Event Management (SIEM), Intrusion Detection/Prevention Systems (IDS/IPS), and Cloud Workload Protection Platforms (CWPP). Develop and implement security monitoring and logging strategies. Investigate and analyse security incidents ...

Identity and Access Management Architect / Engineer (Consultant/Senior Consultant), Cyber Risk

Hiring Organisation
Deloitte
Location
London, United Kingdom
Salary
£ 80 K
storage requirements.Defining the system specifications to support optimal performance.Integrating workflows with third-party systems and security tools, such as Security Information and Event Management (SIEM) solutions, multi-factor authentication solutions, and cloud platforms like Amazon Web Services (AWS) and Azure.Defining the Responsible, Accountable, Consulted, and Informed (RACI) matrix to operate ...

Head of Information Security

Hiring Organisation
Duco
Location
London, United Kingdom
Salary
£ 100 K
strategy and zero trust adoption– Oversee penetration testing, DLP, and advanced threat detection programmes.– Own the vulnerability management programme– Implement enterprise frameworks including IAM, SIEM, and data classification.– Anticipate emerging threats, leverage AI/ML for predictive security, and set the technology vision– Lead Security Incident Response ProgrammeGovernance, risk, and … leading and developing a small, high-performing team- Familiarity with AI governance and the security implications of agentic AI systemsBeneficial Experience- Experience with DLP, SIEM, or SOC build-outs- Relevant certifications such as CISSP, CISM, or ISO 27001 Lead Implementer- Experience in capital markets, asset management, or securities servicesDepartmentInfosecEmployment TypeFull ...

Cortex Cloud Sales Specialist - Public Sector

Hiring Organisation
Palo Alto Networks
Location
London, United Kingdom
Salary
£ 80 K
focusing on key customer accounts and delivering value to public sector accounts.Extensive platform selling experience in complex sales with multiple buying centers.Experience selling Cybersecurity, SIEM, EDR or CNAPP (DevSecOps, CloudOps) solutions is highly preferred.Established trusted relationships with CIOs and CISOs with the ability to influence and drive strategic conversationsExpertise ...

IT Infrastructure & Systems Manager

Hiring Organisation
Nexus Jobs
Location
London, United Kingdom
Salary
£ 60 K
Recovery Orchestrator (VRO) environments. Administer endpoint security and encryption solutions, including Symantec Endpoint Protection (SEP) and Symantec Endpoint Encryption (SEE). Support endpoint DLP, SIEM, and security monitoring tools (e.g., Splunk, Tenable). Manage patching processes using ManageEngine Patch Manager Plus. Support Microsoft 365 services and related cloud technologies. … Plus SAAS solutionsSQL ServerSecuritySymantec Endpoint Protection (SEP) Symantec Endpoint Encryption (SEE) SentinelOne – EDR/XDREndpoint DLP solutions Firewall administration Vulnerability management tools (e.g., Tenable) SIEM tools (e.g., Splunk) NetworkingCisco Switches and Routers FortiGate Firewalls LAN/WAN networking and routing Hardware & StorageDell PowerEdge Servers Dell PowerVault SAN Storage Technical CompetenciesData ...

Crowdstrike Technical Consultant

Hiring Organisation
Accenture
Location
London, United Kingdom
Salary
£ 80 K
identify gaps, and map Falcon platform capabilities to business outcomes. You have designed and delivered compelling technical demonstrations of the Falcon platform, including NG-SIEM, Exposure Management (CTEM), Identity Protection, Cloud Security, and Charlotte AI, tailored to the client's environment and priorities. You excel at the development and presentation … protection, EDR, or adjacent modules), either in a vendor, partner, or customer capacity Minimum 2 years experience with at least two of the following: SIEM platforms (Splunk, QRadar, Elastic, Sentinel, Chronicle), endpoint security, identity threat detection, cloud security posture management, or vulnerability/exposure management Minimum 2 years experience with ...

Director, ProdSecOps

Hiring Organisation
Genius Sports
Location
London, United Kingdom
Salary
£ 120 K
posture across the estate — CSPM, container and Kubernetes security, IaC review.Security OperationsOwn threat detection and telemetry fidelity end-to-end — high-fidelity signals into SIEM, log source coverage across endpoint, SaaS, cloud, and network.Own incident management — ensure the incident response plan is defined, tested, and executable, with clear escalation paths … including distributed, multi-region teams.Expert-level knowledge of secure SDL frameworks (OWASP SAMM, NIST SSDF), threat modelling, and security architecture.Deep experience with detection engineering, SIEM/XDR platforms, incident response, and MSSP management.Strong cloud security expertise — AWS required; container and Kubernetes security experience.Track record of translating technical risk into business ...

Senior Security Architect - SecOps and Vulnerability Management

Hiring Organisation
JP Morgan Chase
Location
London, United Kingdom
Salary
£ 100 K
collaborate globally, supporting audit, regulatory, and risk initiatives, with a focus on cloud computing and emerging technologies.Job Responsibilities:Design, scale, and manage the enterprise SIEM architecture to provide centralized visibility and high-fidelity threat detection across all corporate and cloud infrastructure.Develop and influence advanced SIEM correlation rules, custom data parsers … control testing, remediation quality, and traceability/auditability in line with resiliency expectations.Required Qualifications, Capabilities, and Skills:Hands-on experience advising and influencing enterprise SIEM platforms (e.g., Microsoft Sentinel, Splunk, Chronicle/SecOps). Must be proficient in writing/reviewing advanced detection logic (KQL, SPL, or YARA rules).Deep ...

Senior Security Architect - SecOps and Vulnerability Management

Hiring Organisation
Hackajob Ltd
Location
South West London, London, United Kingdom
Employment Type
Permanent
globally, supporting audit, regulatory, and risk initiatives, with a focus on cloud computing and emerging technologies. Job Responsibilities: Design, scale, and manage the enterprise SIEM architecture to provide centralized visibility and high-fidelity threat detection across all corporate and cloud infrastructure. Develop and influence advanced SIEM correlation rules, custom data … testing, remediation quality, and traceability/auditability in line with resiliency expectations. Required Qualifications, Capabilities, and Skills: Hands-on experience advising and influencing enterprise SIEM platforms (e.g., Microsoft Sentinel, Splunk, Chronicle/SecOps). Must be proficient in writing/reviewing advanced detection logic (KQL, SPL, or YARA rules). ...

Security Platform Engineer, UK Security Operations

Hiring Organisation
Hackajob Ltd
Location
South West London, London, United Kingdom
Employment Type
Permanent
detection and anomaly detection. Experience with service mesh security concepts (e.g., Istio, Linkerd) and workload identity. Experience in detection engineering, logging pipeline development, or SIEM tuning in containerised environments. Experience in contributing to security-focused open-source projects or internal security platform tooling. Responsibilities: Deploy, configure, and manage cloud security … platform tools and technologies, including Security Information and Event Management (SIEM), Intrusion Detection/Prevention Systems (IDS/IPS), and Cloud Workload Protection Platforms (CWPP). Develop and implement security monitoring and logging strategies. Investigate and analyse security incidents, including identifying root causes, determining the scope of impact, and taking ...

Security Consultant

Hiring Organisation
Hackajob Ltd
Location
South West London, London, United Kingdom
Employment Type
Permanent, Work From Home
authorization models, secrets management and secure SDLC practices. Ability to work with development teams to improve application security posture and shift security left. 3. SIEM Experience Hands-on experience with SIEM platforms for log onboarding, correlation rule creation, alert triage, dashboarding and use-case tuning. Ability to improve visibility, reduce … noise, and align SIEM content to relevant threats and business risks. 4. Organisation/General Security Broad understanding of enterprise security domains including policy, governance, risk, compliance, awareness, third-party risk and operational security. Experience translating business and regulatory requirements into practical security controls and improvement plans. 5. Identity & Access ...