276 to 300 of 363 SIEM Jobs in London

Senior Cyber Security Engineer (EDR) Senior Security Engineer – Monitoring & Detection

Hiring Organisation
Sanderson Recruitment
Location
London, United Kingdom
Salary
£ 70 K
securing large-scale, cloud-based environments supporting critical public sector and government services.This is a hands-on engineering role focused on threat detection, SIEM engineering, security monitoring, log management, and SOC optimisation. You’ll design and enhance detection capabilities, improve security visibility, and ensure organisations can rapidly identify and respond … capabilities that improve resilience while enabling faster, risk-based decision-making.What You’ll Be DoingDetection Engineering & Threat MonitoringDevelop, tune, and maintain detection rules across SIEM, EDR, and threat detection platforms.Create and optimise detection logic using technologies such as Splunk and endpoint security solutions.Map detections against the MITRE ATT&CK framework ...

Interim Cyber Security Officer

Location
Greater London, England, United Kingdom
and security data models. Serve as a technical escalation point for high‐severity security incidents, facilitating rapid investigation, containment, and remediation using EDR and SIEM tools. Develop and implement SOAR workflows to automate detection, response, and security operations processes. Conduct proactive threat hunting using SIEM/EDR data and MITRE … needed. Requirements Minimum of 5+ years’ experience in Cyber Security Engineering or SOC Tier 3 role. Strong hands‐on experience with endpoint security and SIEM platforms in enterprise environments. Experience supporting or working alongside managed SOC providers. At least 2 years’ experience in vulnerability assessment tools (desirable). Exposure ...

Senior Security Analyst (L3 SOC Analyst)

Location
City Of London, England, United Kingdom
coordinating containment, eradication and recovery activities with internal and external stakeholders. Design, develop and optimise detection rules, threat models and advanced monitoring capabilities across SIEM, EDR and cloud security platforms. Conduct proactive threat hunting activities using threat intelligence, behavioural analytics and industry frameworks to identify previously undetected threats. Develop and … operating in a senior SOC environment, including working in an L3 analyst, incident response, threat hunting or detection engineering capacity. Deep technical knowledge of SIEM, EDR, SOAR, cloud security, identity security, endpoint security and enterprise monitoring platforms. Proven experience leading the investigation and response to complex cyber security incidents and ...

Cyber Security Engineer

Location
Greater London, England, United Kingdom
and security maturity improvements. Get exposure to AI security: Work around Copilot, AI agents, Purview, and data security compliance. Broad technical remit: Microsoft security, SIEM, incident response, cloud/SaaS security, identity, and network security. Room to grow: The team is investing in capability, and strong performers may have scope … management, remediation planning, reporting, and automation. Security incident triage, investigation, and response. Microsoft Defender, Entra ID/Active Directory, Conditional Access, and related controls. SIEM query building and KQL. Ransomware resilience, including backup and network segmentation. Cyber Essentials Plus and wider security maturity initiatives. AI, Copilot, Purview, and data security ...

Senior Cyber Security Engineer

Hiring Organisation
Checkout.com
Location
London, UK
Employment Type
Full-time
and progressively taking ownership of the tooling and procedures that keep security operations running. What you'll be responsible forSupporting and enhancing security tooling SIEM, EDR, DLP, vulnerability management, and automation platforms including configuration, tuning, and day-to-day maintenanceBuilding and improving operational procedures, runbooks, and playbooks so the team … looking for5+ years of hands-on experience in a Security Operations, SOC, or equivalent operational security rolePractical experience operating modern security tooling SIEM (e.g. Sentinel), Data Loss Prevention (DLP) tools, EDR, and vulnerability management platformsSolid understanding of security operations workflows: alert triage, incident handling, and vulnerability/finding remediation lifecyclesComfort ...

Security Consultant

Location
Greater London, England, United Kingdom
facing consultancy role where you'll work with a wide range of organisations to design, develop and optimise detection and response capabilities across leading SIEM, XDR and SOAR technologies. You'll combine deep technical expertise with strong consulting skills, helping customers improve their security maturity through practical, scalable solutions. What … doing You'll play a key role in delivering detection engineering engagements, including: Designing and implementing high-quality detection rules across SIEM and XDR platforms. Creating and optimising detection logic using KQL and other query languages. Developing detection use cases aligned with the MITRE ATT&CK framework and current threat ...

Lead SOC Architect

Hiring Organisation
Anson Mccade
Location
Central London, London, United Kingdom
Employment Type
Permanent
concepts, CONOPS and high/low-level architecture designs • Working directly with senior client and government stakeholders • Designing and integrating security technologies including SIEM, SOAR, EDR, Threat Intelligence and Vulnerability Management • Assessing existing SOC capabilities and developing security maturity • Designing scalable, resilient on-prem and cloud security architectures • Supporting accreditation … deployment and operation They're looking for: • Strong experience in SOC architecture and security operations • Hands-on architectural experience across at least two of SIEM, SOAR, EDR, Vulnerability Management or Threat Intelligence • Strong understanding of security operations, threat detection and incident response • Experience designing both on-prem and cloud security ...

Senior SOC Engineer (Sentinel One)

Hiring Organisation
Claranet
Location
City, London, United Kingdom
Employment Type
Permanent
Salary
GBP Annual
engineering team. Key Responsibilities Lead the implementation and optimisation of SentinelOne-based SOC solutions for new and existing customers. Design, deploy, and support SIEM, XDR, EDR, SOAR, and telemetry solutions across cloud, hybrid, and on-premises environments. Act as the senior technical escalation point for complex engineering challenges. Drive continuous … experience in Security Engineering, SOC Engineering, or a similar cyber security role. Strong hands-on experience with the SentinelOne Singularity platform, including XDR, AI SIEM, and EDR technologies. Experience integrating and onboarding log sources across cloud, hybrid, and on-premises environments. Knowledge of automation, API integrations, telemetry pipelines, and security ...

Senior SOC Engineer (Sentinel One)

Hiring Organisation
Claranet
Location
WC2E, Covent Garden, Greater London, United Kingdom
Employment Type
Permanent
engineering team. Key Responsibilities Lead the implementation and optimisation of SentinelOne-based SOC solutions for new and existing customers. Design, deploy, and support SIEM, XDR, EDR, SOAR, and telemetry solutions across cloud, hybrid, and on-premises environments. Act as the senior technical escalation point for complex engineering challenges. Drive continuous … experience in Security Engineering, SOC Engineering, or a similar cyber security role. Strong hands-on experience with the SentinelOne Singularity platform, including XDR, AI SIEM, and EDR technologies. Experience integrating and onboarding log sources across cloud, hybrid, and on-premises environments. Knowledge of automation, API integrations, telemetry pipelines, and security ...

Senior Sales Engineer

Location
Greater London, England, United Kingdom
demos, and solution walkthroughs for enterprise security teams across the UK and Europe Run structured technical discovery to understand customer security posture, existing tooling (SIEM, EDR, SOAR, identity), and integration needs Design and validate customer-specific solutions that meet technical, security, compliance, and business requirements Serve as the primary technical … and CISOs in complex enterprise sales cycles Strong understanding of modern security architecture: identity, endpoint, network, and cloud (AWS, Azure, GCP) Strong knowledge of SIEM, EDR/XDR, SOAR, and common log sources (CloudTrail, Okta, endpoint telemetry, etc.) Familiarity with detection frameworks (MITRE ATT&CK) and threat modeling Comfort with ...

Lead Threat Detection Engineer

Location
Greater London, England, United Kingdom
class looks like. What you’ll be doing: Own and improve the threat detection lifecycle across a complex cloud estate Build and enhance SIEM detection rules, use cases and monitoring Automate manual detection and remediation processes Develop threat intelligence and threat-hunting capabilities Improve security monitoring across AWS, GCP and … and help upskill others across the security function What we’re looking for: Experience building detections rather than purely responding to SOC alerts Strong SIEM experience – Microsoft Sentinel, Splunk or similar Cloud security experience across AWS, GCP and/or Azure KQL, SPL or similar querying experience Python scripting/ ...

Platform Engineer – Monitoring, Observability & SIEM (MONSO)

Location
Greater London, England, United Kingdom
Platform Engineer – Monitoring, Observability & SIEM (MONSO) For our SPEAR Technology (Security, Platform Engineering, Automation and Runtime) division in London we are looking to hire a: Platform Engineer – Monitoring, Observability & SIEM (MONSO) Like solving puzzles with an inquisitive mind? Think outside the box and challenge the status quo? Prefer simplicity over … other teams to do more themselves—such as empower-ing our SOC/CyberSec team to develop (including AI-assisted workflows), test, and deploy SIEM use cases independently via CI/CD. The platform spans Splunk Enterprise on-prem (running on Kubernetes), Splunk Observability Cloud, and SolarWinds , with future expansion ...

Platform Engineer - Monitoring, Observability & SIEM (MONSO)

Hiring Organisation
Berenberg
Location
London, UK
Employment Type
Full-time
Platform Engineer – Monitoring, Observability & SIEM (MONSO) Persönliche Daten Land Vereinigtes Königreich Stadt London Art der Anstellung Professional Arbeitszeit Vollzeit Vertragsart Unbefristet Offene Stellen 1 Beschreibung & Anforderungen For our SPEAR Technology (Security, Platform Engineering, Automation and Runtime) division in London we are looking to hire a: Platform Engineer – Monitoring, Observability & SIEM … other teams to do more themselves—such as empower-ing our SOC/CyberSec team to develop (including AI-assisted workflows), test, and deploy SIEM use cases independently via CI/CD.The platform spans Splunk Enterprise on-prem (running on Kubernetes), Splunk Observability Cloud, and SolarWinds, with future expansion into ...

Senior Cyber Security Engineer – SIEM & Threat Detection

Location
Greater London, England, United Kingdom
Proactive Security team, focusing on building security tech stacks to mitigate threats with offensive and preventive measures. You will develop threat models, manage SIEM systems, and implement detection use cases while collaborating with incident response to protect information assets in a hybrid UK workplace. The role demands strong scripting (PowerShell ...

Elasticsearch Consultant

Location
Greater London, England, United Kingdom
Elastic SIEM Engineer We are seeking an experienced Elastic SIEM Engineer to design, implement and maintain security monitoring solutions using the Elastic Stack. The successful candidate will be responsible for developing scalable log-management and threat-detection capabilities across complex cloud and containerised environments. Key Responsibilities Design, deploy and support … Elastic SIEM solutions using Elasticsearch, Logstash and Kibana. Build and maintain log‐ingestion pipelines for infrastructure, applications, cloud platforms and security tools. Develop Kibana dashboards, alerts, detection rules and visualisations. Configure data parsing, enrichment, transformation and indexing within Logstash and Elasticsearch. Integrate Kafka to support reliable, high‐volume event streaming ...

Blockchain Security Operations Vice President

Location
Greater London, England, United Kingdom
multiple security domains, including network security, malware analysis, threat hunting, and security architecture and design, with proficiency in using Security Information and Event Management (SIEM) tools and advanced analytics techniques Advanced knowledge of network and infrastructure configuration/security, including experience in designing and implementing security solutions for on-prem ...

Blockchain Security Operations Vice President

Location
Greater London, England, United Kingdom
multiple security domains, including network security, malware analysis, threat hunting, and security architecture and design, with proficiency in using Security Information and Event Management (SIEM) tools and advanced analytics techniques Advanced knowledge of network and infrastructure configuration/security, including experience in designing and implementing security solutions for on-prem ...

Security Architect - Microsoft Security Platform

Hiring Organisation
Colt Telecom
Location
London, UK
Employment Type
Full-time
Microsoft 365 E5 security capabilities, including: Microsoft Defender (Endpoint, Identity, Office 365, Cloud Apps)Microsoft Entra ID (P2), Conditional Access and identity protectionMicrosoft Sentinel (SIEM integration)Microsoft PurviewStrong experience designing and implementing Microsoft Purview capabilities, including DLP, Information Protection, Insider Risk and eDiscovery Strong understanding of Zero Trust architecture principles … particularly identity-driven security models Experience deploying and operating Defender and SIEM capabilities, integrated within a wider security ecosystem Experience conducting security design reviews and translating policy into practical controls Experience performing risk assessments aligned to recognised methodologies Strong understanding of cloud security concepts across IaaS, PaaS and SaaS, particularly ...

Senior Cybersecurity Analyst - Social, Healthcare and Public Entities

Location
City of Westminster, England, United Kingdom
and participation in audit/certification such as: GDPR, NIST SP800-53, ISO 27001, NIST CSF, etc Experience evaluating logging activities for ingestion into SIEM as part of continuous monitoring plan Experience with security technologies and tooling, e.g. vulnerability scanners, firewalls, network monitors, IAM, SIEM, IDS/IPS Knowledge ...

Cyber Security Engineer

Hiring Organisation
Langley James
Location
London, UK
Employment Type
Full-time
reporting to the IT Security Officer, to implement and maintain robust security across their infrastructure. Key responsibilities include managing WAF/DDoS, security gateways, SIEM/SOAR/EDR, firewalls, MFA/SSO, MDM/MAM, vulnerability scans, and incident response. Key Responsibilities: Manage WAF/DDoS, web/email … security gateways, SIEM/SOAR/EDR (alert response), firewalls, MFA/SSO, MDM/MAM, vulnerability scans/remediation, security certificates, IDS/IPS, PAM, and deliver security awareness training. Remediate penetration test findings and contribute to ad-hoc projects. Essential Experience: Strong knowledge of CrowdStrike EDR, Mimecast ...

Infrastructure Security Engineer

Hiring Organisation
Blockchain
Location
London, UK
Employment Type
Full-time
ownership, and a drive to continuously improve the security posture of complex systems. Familiarity with some of the following: Cloudflare (DDoS protection, WAF), OSS SIEM tools (Splunk, Elastic, etc), Incident management platforms (e.g. Incident.io, PagerDuty)Familiarity with at least one of the following CI/CD systems (Github Actions, Concourse … governance frameworks (e.g., CIS Benchmarks, NIST, SOC2, ISO 27001, PCI DSS) and how to operationalize them. Hands-on experience with building and maintaining a SIEM comprised of open-source and hosted componentsExperience securing consumer-facing web and iOS/Android applicationsExperience designing policies and administering Vault & other Hashicorp products. Experience ...

Senior Attack Monitoring Analyst, GSOC

Hiring Organisation
London Stock Exchange Group
Location
London, UK
Employment Type
Full-time
candidate availability. RESPONSIBILITIES: Triage security events and employ a methodical and coherent response to security incidents adopting playbooks where necessary. Competently operate a chosen SIEM (e.g., Splunk/QRadar/LogRhythm) for incident investigations, or for the development of monitoring dashboards. Utilise playbooks, existing knowledge and accurate online resources … with current vulnerabilities, attacks, and countermeasures. Identify, respond and remediate cyber events generated through monitoring technologies. EXPERIENCE: Preferred experience with operating or administrating a SIEM (e.g., Splunk/QRadar/LogRhythm). Solid understanding of networks including the TCP/IP stack, typical organisation architectures, and common protocols abused ...

Senior CSIRT Analyst

Hiring Organisation
G Research
Location
London, UK
Employment Type
Full-time
technology landscape, including high-performance compute clusters, Kubernetes and containerised infrastructures, and corporate Windows environments. You will use cloud-native security tooling and multi-SIEM operations, such as Elastic, Azure, AWS, to strengthen detection and response capabilities. You will also participate in purple team and red team exercises, continuously validating … role include: Investigating and responding to complex security incidents across cloud, hybrid, and on-premise environmentsProactively hunting for threats and developing detection logic across SIEM and cloud security systemsParticipating in red and purple team exercises to test, validate and enhance detection and response capabilitiesDeveloping and maintaining automation workflows using tools ...

Senior CSIRT Analyst

Location
Greater London, England, United Kingdom
technology landscape, including high-performance compute clusters, Kubernetes and containerised infrastructures, and corporate Windows environments. You will use cloud-native security tooling and multi-SIEM operations, such as Elastic, Azure, AWS, to strengthen detection and response capabilities. You will also participate in purple team and red team exercises, continuously validating … include: Investigating and responding to complex security incidents across cloud, hybrid, and on-premise environments Proactively hunting for threats and developing detection logic across SIEM and cloud security systems Participating in red and purple team exercises to test, validate and enhance detection and response capabilities Developing and maintaining automation workflows ...

Senior Systems Engineer

Location
Greater London, England, United Kingdom
VLAN, 802.1X, SSL, and related protocols. OT Security: Strong Knowledge with securing operational technology environments, addressing unique threats and vulnerabilities inICS/SCADA systems. SIEM : Strong Understanding of SIEM technologies for log management, log analysis, and event correlation. Authentication & Access Control: Proficient in 802.1x, RADIUS, LDAP, AD, smart cards, and ...