176 to 193 of 193 SIEM Jobs in London

SOC Shift Lead

Hiring Organisation
Anson Mccade
Location
City of London, London, United Kingdom
Employment Type
Permanent
and threat activity. Conduct root cause analysis and produce detailed incident reports. Coordinate containment, eradication and recovery activities with technical teams. Correlate data across SIEM, EDR and other security platforms to build comprehensive incident assessments. Support detection engineering by identifying gaps in monitoring, alerting and response processes. Provide technical leadership … point when required. What We're Looking For 7+ years' commercial experience within a SOC, Incident Response or Threat Detection environment. Strong knowledge of SIEM, EDR, threat hunting and incident response methodologies. Experience leading investigations and coordinating security responses across multiple teams. Excellent analytical and problem-solving skills. Ability ...

Associate Security Engineer

Hiring Organisation
Spendesk
Location
London, United Kingdom
Salary
£ 80 K
program, scanners, and dependency checks.Support incident response: develop fixes, track resolution, update tickets, and contribute to post-mortems.Monitor and process security alerts from our SIEM and other monitoring tools.Identity & access managementImplement and maintain SSO/MFA configurations for product and infrastructure systems, leveraging Okta and Google Workspace to manage downstream … adoption of AI coding tools across engineering teams: flag insecure usage patterns, identify data leakage risks, and help maintain internal AI usage guidelines.Monitoring & detectionMonitor SIEM alerts, investigate suspicious activity, and escalate when needed.Maintain and tune detection rules under guidance from the Senior Security Engineer.Help operate and maintain SIEM infrastructure (ElasticSearch ...

Senior Security Engineer

Hiring Organisation
Spendesk
Location
London, United Kingdom
Salary
£ 80 K
lead on complex or high-severity findings.Lead security incident response: qualification, forensics (including fraud investigations), fix coordination, post-mortem, and resolution tracking.Detection & SIEMOwn our SIEM platform (ElasticSearch, multi-node Linux): architecture, detection rules, and indicators of compromise.Build and evolve detection coverage, focusing on signal quality over manual toil.Build and maintain … owning security outcomes end to end, with hands-on experience across at least three of: code auditing, infrastructure security (AWS/Linux), penetration testing, SIEM operations, incident response.Ability to own a roadmap: identify priorities, build a plan, execute autonomously, and communicate progress to non-specialists.Deep understanding of modern web architectures ...

Lead Security Operations Engineer

Hiring Organisation
Pleo
Location
London, United Kingdom
Salary
£ 80 K
forensics, from suspicious traffic through to full incident response, and bring the findings back into how we detect and prevent.Design, tune, and scale our SIEM and logging pipeline through standardized log ingestion across services so signal isn't lost in the noise.Strengthen our perimeter and authentication posture, including WAF configuration … incidents contained, forensics that changed outcomes.A strong development and engineering background. You are comfortable writing the automation, not just specifying it.Hands-on SOC and SIEM management experience, including detection engineering and log pipeline design.Experience in scale-up environments, where you've built capability rather than inherited a mature one.A strong ...

AI Staff Security Engineer

Hiring Organisation
Matchtech
Location
London, United Kingdom
Salary
£ 100 K
protect proprietary models and systems from novel threats like prompt injection, data poisoning, and model inversion/extraction.Automate critical security workflows using Agentic/SIEM integration to achieve high operational velocity and enable rapid response to millisecond attack speeds generated by autonomous adversary AI.Execute regular offensive security operations, including … Teaming/Penetration Testing against agentic frameworks and LLM integrations.Demonstrated ability to engineer or deploy AI Detection and Response (AIDR) workflows utilizing agentic and SIEM technologies, with a strong focus on AI-native threat modeling (e.g., MAESTRO framework).Understanding of Governance, Risk, and Compliance (GRC), specifically managing AI governance policies ...

Security Engineer, Institutional Trading

Hiring Organisation
Blockchain
Location
London, United Kingdom
Salary
£ 80 K
and maintain monitoring for FinOps-specific security signals such as abnormal order patterns, signature misuse, unusual settlements. You will integrate these signals into our SIEM/SOAR for real-time response.Support secrets and key-management hygiene. You will ensure app/service keys are stored in KMS/Vault, scoped … experience.Proven expertise in Threat Modeling. Ability to perform structured reviews (e.g., STRIDE) of complex data flows and operational processes.Experience with observability and detection tooling (SIEM, logs, metrics) and ability to write basic detection rules.Practical experience with KMS/HSM, secrets management platforms (Vault, 1Password, AWS/GCP KMS), IAM patterns ...

Security Architect Microsoft, SIEM, SOAR Hybrid LDN 3d/w -then less

Hiring Organisation
Nova Source Technologies
Location
South West London, London, United Kingdom
Employment Type
Permanent, Work From Home
Security Architect Microsoft, SIEM, SOAR, EDR, Cloud Security, Azure, Detection Engineering, Threat Hunting, Security Automation, SOC, APIs, Data Models, Integrations, Microsoft, CrowdStrike, SentinelOne, Palo Alto, Azure, Hybrid (London 3d/w then less) This is an exceptional permanent Security Architect opportunity to join a leading tech company. The Security Architect … travel. Therefore, you must be based at a commutable distance from London. As Security Architect, you will take ownership of key security architecture across SIEM, SOAR, EDR, cloud security, detection engineering, threat hunting and automation. The Security Architect will work closely with internal and 3 rd party engineering and ...

Security Operations Analyst

Hiring Organisation
GoCardless
Location
London, United Kingdom
Salary
£ 70 K
security use cases through to incident response. Your background will ideally be in security operations. In any case, you will be experienced using SIEM tools to develop security monitoring cases and writing scripts to automate tasks and will have previous experience in incident response and threat management.We want people … your Security Operations manager and team members, to ensure we take a data driven approach to presenting our security postureAnalysing logs from multiple sources (SIEM, EDR, DLP, email) to identify and investigate security events and anomaliesRunning day-to-day security operations activitiesProviding technical support for first responder during normal business ...

SecOps Engineer

Hiring Organisation
OCS Group
Location
London, United Kingdom
Salary
£ 70 K
fixes, build them, and measure the outcomeMain Duties & Responsibilities of the Role Detection engineering and tuningBuild, test and maintain high-quality detections across our SIEM, XDR and email security platforms, mapped to the MITRE ATT&CK frameworkContinuously tune existing detections to reduce false positives and improve fidelity, using a data … that give analysts and leadership a clear view of operational healthPlatform health and configurationOwn the configuration and ongoing health of assigned SecOps platforms, including SIEM, EDR, email security and identity protection Monitor for configuration drift, agent coverage gaps and ingestion failures, and resolve them at sourceLead technical onboarding ...

Security and compliance Architect

Hiring Organisation
Oscar Associates (UK) Limited
Location
London, United Kingdom
Employment Type
Contract
Contract Rate
£600 - £680 per day
tenancy, virtualisation, containers, encryption, key and secrets management, AI runtime and threat modelling. Design IAM solutions, including identity providers, SSO, RBAC and MFA. Define SIEM/SOAR architecture and detailed designs for logging, correlation, playbooks and incident response. Review and validate Bills of Materials for security, IAM and SIEM/… SOAR Key Experience: Strong Security Architecture experience within complex enterprise environments Experience across network security, IAM, SIEM/SOAR and threat modelling Strong understanding of EPP, DLP, encryption, containers and cloud or infrastructure security Ability to produce high-level and detailed technical designs If this sounds like a good ...

Cyber Security Manager

Hiring Organisation
Nexus Jobs
Location
London, United Kingdom
Salary
£ 70 K
compliant to industry standards.This role covers information protection, including data loss protection and data classification, and threat protection, including security information and event management (SIEM), user and entity behaviour analytics (UEBA), point products like anti-virus (AV) and intrusion detection system/intrusion prevention system (IDS/IPS) and penetration … ISO27001, PCI and GDPR. Possibly a certified ethical hackerKnowledge of Security technologies is essential, such as network appliances, firewall administration, AD, IAM, PAM, SIEM, UEBA, AV, IDS/IPS and MDM solutions Understanding of common frameworks, such as ITIL or LEAN is preferredGood exposure of user environment management, including desktops ...

AD - Global Detection Engineering

Hiring Organisation
NCC Group
Location
London, United Kingdom
Salary
£ 100 K
coverage for advanced cyber attacks • Manage senior detection engineers who each manage a number of detection engineers on a specific technology set (EDR, NDR, SIEM) • Work pro-actively with wider NCC teams to ensure all relevant inputs are available (TI, DFIR, RTO etc) to build top-notch detection logic andand improvements that provide improved coverage to clients and improved efficiency to our SOC.Skills, Knowledge & ExpertiseExperience in detection engineering on a range of technologies (SIEM and EDR, ideally NDR as well) Experience in working in a global firm in a multi-cultural context Experience in working in a complex international ...

SOC Shift Lead

Hiring Organisation
Anson McCade
Location
City of London, London, United Kingdom
Investigate attack vectors, scope and potential impact across multiple data sources Perform root cause analysis and coordinate containment, eradication and recovery Correlate events across SIEM, EDR and other security tooling to build a clear incident narrative Identify detection gaps and support improvements to rules, thresholds and playbooks Mentor and provide … Analysis , with proven experience leading a SOC team or acting as a senior escalation point . You should have strong hands-on knowledge of: SIEM and EDR technologies Incident response and investigation Threat analysis and malware behaviour Detection engineering/tuning Incident containment and remediation Leading or mentoring SOC Analysts ...

Senior Security and Cyber Operations Manager

Hiring Organisation
McCabe & Barton
Location
City of London, London, United Kingdom
Employment Type
Permanent
attacks, and ensure the organisation is prepared to respond Improve detection coverage, security tooling, telemetry, automation and operational processes Manage key security platforms including SIEM, SOAR, EDR and NDR Provide risk based decision making around cyber incidents, containment, recovery and remediation Manage external security partners and ensure effective delivery and … incident response within a complex enterprise environment Hands-on experience across security monitoring, incident response, threat intelligence and detection engineering Strong understanding of SIEM, SOAR, EDR, NDR, logging, telemetry and security tooling Proven experience managing major cyber incidents, including containment, recovery and executive communication Strong understanding of emerging cyber threats ...

SOC Shift Lead

Hiring Organisation
Anson Mccade
Location
South West London, London, United Kingdom
Employment Type
Permanent
Salary
£85,000
/developing junior analysts Strong security incident investigation and response experience Experience across areas such as threat hunting and incident response Good knowledge of SIEM/EDR tooling no specific SIEM platform is required Ability to confidently take ownership of escalations in a critical 24/7 environment The role ...

Consultant - Senior Consultant, Enterprise Security

Hiring Organisation
Deloitte
Location
London, United Kingdom
Salary
£ 80 K
Basic informationLocationLondonBusiness LineTechnology & TransformationJob TypePermanent/FTCDate published13-Aug-2026Req #22959Job descriptionConnect to your IndustryCyber security is critical to every organisation. We are designing and building solutions to help secure some of the largest global ...

CyberArk SME - 6 Month Contract - Hybrid in London - Inside IR35

Hiring Organisation
Hamilton Barnes
Location
London, United Kingdom
Employment Type
Contract
Contract Rate
GBP Daily
and PSM connectors, performing advanced troubleshooting across PSM, CPM, Vault, and integrations to ensure platform stability. Integrate CyberArk with AD/LDAP, IGA tools, SIEM, and ServiceNow, including REST API-based automation, while supporting audits, compliance, and regulatory reporting. Drive account discovery and onboarding, identify and remediate privileged access risks … define and implement PAM strategy and frameworks, support audits, and meet regulatory and internal governance requirements. Third-party integrations - Experience integrating CyberArk with SIEM, IAM tools, AD/LDAP, ServiceNow, and cloud platforms, including REST API-based automation and Credential Provider (CP, CCP, AIM) experience. Account discovery & onboarding - Hands ...

Service Delivery Manager – Cybersecurity / SOC

Hiring Organisation
Franklin Fitch
Location
City of London, London, United Kingdom
experience is the priority. You won’t need to be a deeply technical security specialist, but you should understand concepts such as SIEM, EDR and XDR and be comfortable working alongside SOC analysts and technical teams. The role Own the service transition and onboarding of new customers and services Manage … Experience in Service Delivery Management within a cybersecurity, SOC or managed services environment A practical understanding of cybersecurity terminology and services, ideally including SIEM, EDR or XDR Strong customer, stakeholder and relationship-management skills Confidence presenting in both informal customer meetings and formal boardroom environments Experience managing service reviews, SLAs ...