26 to 50 of 80 SOAR Jobs in London

SOC Manager

Hiring Organisation
CyPro
Location
London Area, United Kingdom
experience: You must have strong practical knowledge of SIEM, EDR/XDR, incident investigation and response, detection engineering, alert triage, threat intelligence, threat hunting, SOAR, automation and SOC reporting. Experience with Microsoft Sentinel, Microsoft Defender XDR and the wider Microsoft security ecosystem is strongly desirable. 3. Fluent business English: This ...

Professional Services Staff Consultant

Hiring Organisation
Palo Alto Networks
Location
London, United Kingdom
Salary
£ 80 K
security analytics solutions within large enterprise environments6+ years of experience with Security Operations Center (SOC) tooling, processes, and workflowsHands-on technical mastery across SIEM, SOAR, EDR, cloud security, and threat intelligenceAbility to conceive, architect, and develop effective correlation and detection rulesFamiliarity with a range of SIEM technologies, such as Splunk ...

Cyber Analyst in CYBER DEFENCE CENTRE

Hiring Organisation
Bank of England
Location
London, United Kingdom
Salary
£ 80 K
UK. Understanding of common cyber threats and attacker tactics, techniques and procedures and an ability to identify appropriate mitigation strategies Experience using automation or SOAR platforms Knowledge of incident response principles Experience using MITRE ATT&CK Experience using Splunk Experience using an intelligence platform Software development, scripting or programming skills ...

Senior Cyber Analyst

Location
Greater London, England, United Kingdom
technical effectiveness and continual improvement of Microsoft Sentinel, Microsoft Defender, SIEM, SOAR, EDR, and XDR capabilities. Develop and maintain detection rules, use cases, automation, and response playbooks to improve operational efficiency. Work with the Technical Architect to align security tooling, controls, and services with customer and organisational requirements. Technical Leadership … security technologies including Sentinel, Defender XDR, Defender for Endpoint, Defender for Cloud, Microsoft 365 Security, and Entra ID. Experience designing, tuning, and optimising SIEM, SOAR, EDR, and XDR solutions. Strong understanding of threat hunting, attack techniques, threat intelligence, and vulnerability management. Ability to translate technical findings and cyber risk into ...

Technical Cyber Security Advisory, Vice President

Hiring Organisation
State Street Bank
Location
London, United Kingdom
Salary
£ 80 K
and demonstrable knowledge of MITRE ATT&CK, NIST CSF, ISO 27001, CIS Controls, threat-led penetration testing, vulnerability management, cloud security, IAM, SIEM/SOAR, EDR, application security, network security, and secure architecture design.Additional language requirements: N/A.Role Experience: Experience in senior roles at Financial Services or Critical National ...

Senior Security Architect Consultant

Hiring Organisation
NTT
Location
London, United Kingdom
Salary
£ 80 K
and good knowledge covering several of the following examples (this list is not exhaustive): AD, Cryptography, End User Computing, IAM, PKI, Server hardening, SIEM, SOAR, virtualization (VMware)Strong teamwork skills and attention to detailAbility to work independently as needed yet always thinking as part of a teamSelf-motivation and able ...

Zero Trust Security Architect - London

Hiring Organisation
Accenture
Location
London, United Kingdom
Salary
£ 100 K
FWaaS).Managing App segmentation and connector deployment.Zero Trust Client Connector configuration and rollout.Integrating Zero Trust solutions with identity providers (Entra AD, Okta), SIEM/SOAR systems, and endpoint platforms such as CrowdStrike etc.Collaborating with infrastructure teams to migrate legacy VPN, proxy, and firewall solutions to cloud native Zero Trust models.Conducting ...

Director, Cyber Defense

Hiring Organisation
Kyndryl
Location
London, United Kingdom
Salary
£ 120 K
detection-as-code discipline across the detection lifecycle: version-controlled content, release rigor, automated testing, and telemetry quality standards, executed jointly with the SIEM, SOAR, & Agent Development team that owns the underlying pipeline and platform.Drive operational measurement toward compressing the defender's detect-decide-act cycle against AI-accelerated adversaries ...

Information Security Analyst

Hiring Organisation
Fuse Energy Supply
Location
London, United Kingdom
Salary
£ 80 K
with little guidanceBonus: deep familiarity with an EDR platform (CrowdStrike, SentinelOne, Defender); detection-as-code (Sigma, detections in Git, CI-tested); SOAR or custom response automation; defending data centre or colocation environments (OOB networks, BMC/IPMI, physical access telemetry); handling ISO 27001 or SOC 2 audits; FortiGate logging and ...

Security Operations Engineer, EMEA

Location
Greater London, England, United Kingdom
streamlining authentication/authorization to ensure unified access control across the board Deploy and operationalize some of the security services and tools (eg: SIEM, SOAR, domain monitoring, endpoint tooling, cloud security tooling) Respond to security incidents and harden environments post-incidents. Support control monitoring and remediation for compliance initiatives Gather ...

Principal Security Architect

Location
Greater London, England, United Kingdom
senior stakeholders. Implementation & Delivery Oversee the implementation and optimisation of Zero Trust technologies. Lead integration with identity providers, endpoint security, and SIEM/SOAR platforms. Manage proof-of-concept activities, technical evaluations, and vendor engagement. Leadership & Business Development Define Zero Trust strategy and provide architectural governance. Mentor security architects and ...

Senior SOC Analyst

Location
Greater London, England, United Kingdom
data, threat intelligence inputs and decision‐making criteria. Ensure procedures are practical, repeatable and aligned with global security operations. Develop analyst playbooks and support SOAR and automation initiatives using technologies such as Microsoft Sentinel Automation, Cortex XSOAR, Splunk SOAR, Tines, and Swimlane . Threat Analysis & Detection Validation Validate the effectiveness … Defender XDR, Microsoft Defender for Endpoint, CrowdStrike Falcon, Cortex XDR, SentinelOne, Carbon Black , or similar EDR/XDR technologies. Proven experience creating SOPs, playbooks, SOAR workflows, or response procedures for SOC teams. Strong understanding of attacker tactics, techniques and procedures (TTPs). Experience mapping detections to recognised threat frameworks such ...

Security Operations Engineer

Hiring Organisation
CloudBees
Location
London, United Kingdom
Salary
£ 80 K
improve detection coverage using the MITRE ATT&CK framework. Continuously reduce false positives while improving visibility into emerging attacker techniques.SOAR & Automation EngineeringDesign and maintain SOAR playbooks that automate alert triage, enrichment, containment and response. Identify repetitive analyst workflows and automate them using APIs, scripting and orchestration platforms. Build integrations across … Hands-on experience with enterprise SIEM platforms such as Splunk, Microsoft Sentinel, Elastic, Chronicle or QRadar. Experience building and tuning detection rules. Experience developing SOAR playbooks or security automation. Strong scripting skills using Python, PowerShell or similar languages. Experience working within cloud environments (AWS preferred; Azure or GCP experience also ...

Head of Cyber Defence & Incident Response

Hiring Organisation
Quadient
Location
London, United Kingdom
Salary
£ 80 K
organisation. This fits within the context of the broader organizational Crisis Management plan owned outside Technology.A key focus is optimising security tooling (e.g., SIEM, SOAR, EDR/XDR, NDR, email security, vulnerability scanning) and driving strong vulnerability and threat management, using threat intelligence to prioritise defensive improvements.Key ResponsibilitiesOwn the incident … SLAs/KPIs, escalation paths, continuous improvement plans, quality assurance, and commercial governance.Optimise security monitoring and response tooling working across technology teams (e.g., SIEM, SOAR, EDR/XDR, NDR, email security) including use‐case coverage, alert quality, automation, logging strategy, and operational runbooks.Own the vulnerability management programme (on‐prem and ...

Head of Cyber Defence & Incident Response London - United Kingdom - Full Time

Location
Greater London, England, United Kingdom
This fits within the context of the broader organizational Crisis Management plan owned outside Technology. A key focus is optimising security tooling (e.g., SIEM, SOAR, EDR/XDR, NDR, email security, vulnerability scanning) and driving strong vulnerability and threat management, using threat intelligence to prioritise defensive improvements. Key Responsibilities …/KPIs, escalation paths, continuous improvement plans, quality assurance, and commercial governance. Optimise security monitoring and response tooling working across technology teams (e.g., SIEM, SOAR, EDR/XDR, NDR, email security) including use‐case coverage, alert quality, automation, logging strategy, and operational runbooks. Own the vulnerability management programme (on‐prem ...

Head of Cyber Defence & Incident Response

Hiring Organisation
Quadient
Location
Greater London, United Kingdom
Employment Type
Full Time
This fits within the context of the broader organizational Crisis Management plan owned outside Technology. A key focus is optimising security tooling (e.g., SIEM, SOAR, EDR/XDR, NDR, email security, vulnerability scanning) and driving strong vulnerability and threat management, using threat intelligence to prioritise defensive improvements. Key Responsibilities …/KPIs, escalation paths, continuous improvement plans, quality assurance, and commercial governance. Optimise security monitoring and response tooling working across technology teams (e.g., SIEM, SOAR, EDR/XDR, NDR, email security) including use‐case coverage, alert quality, automation, logging strategy, and operational runbooks. Own the vulnerability management programme (on‐prem ...

Security Consultant

Hiring Organisation
Anson Mccade
Location
East London, London, United Kingdom
Employment Type
Permanent
Salary
£65,000
Deploy and optimise technologies including DLP, CASB, FWaaS, Cloud Firewall and App Connectors . Integrate Zero Trust platforms with Entra ID, Okta, SIEM/SOAR and endpoint security platforms . Support migration from legacy VPN, proxy and firewall technologies to modern Zero Trust models. Conduct POCs, technical validation, threat modelling ...

Principal Microsoft Defender XDR, IRM & Deception Engineer

Hiring Organisation
WTW
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
Competitive salary
hybrid and multi-cloud environments. Automation, Agentic AI & Continuous Improvement Contribute towards automation of deception deployment, detection, investigation, and response workflows using Microsoft Sentinel SOAR, Logic Apps, and Microsoft Security Copilot. Define KPIs and metrics covering deception engagement, detection coverage, and response maturity. Continuously improve detection, hunting, and deception capabilities ...

SecOps Engineer

Hiring Organisation
OCS Group
Location
London, United Kingdom
Salary
£ 70 K
including version control, peer review and CI/CD where appropriate Automation and toolingIdentify repetitive analyst tasks and engineer automation to remove them, using SOAR, native platform automation, scripting or low-code approachesBuild and maintain integrations between security tools and adjacent platforms such as identity, endpoint management and ticketingDevelop and ...

Customer Success Manager

Hiring Organisation
Mimecast
Location
London, United Kingdom
Salary
£ 45 K
identity and access management concepts such as Okta, Azure AD, SSO, and SAML, along with how email security integrates into SOC and SIEM/SOAR workflows.Experience engaging technical administrators, CISOs, C-level executives, and legal and compliance teams, with the ability to translate complex security architecture into clear, value-focused ...

AI Security Engineer

Location
Greater London, England, United Kingdom
with common attack vectors and defence techniques. Proven ability to build and deploy automation using code, APIs, and orchestration tools (e.g., Python, workflow engines, SOAR platforms). Practical experience with AI/LLM systems and automation, including prompt engineering, retrieval augmented generation (RAG), function‐calling, or agent‐based tools. Skilled ...

Senior Cyber Security Engineer & AVP — Threat Lead

Location
Greater London, England, United Kingdom
team in London. The role emphasizes building and refining security tooling, SIEM/EDR configurations, and SOC collaboration. You will develop threat models, implement SOAR capabilities, manage SIEM/EDR and cloud/infrastructure logs across Azure, AWS, and on-prem environments. #J-18808-Ljbffr ...

Director of Cyber Security

Hiring Organisation
Anson Mccade
Location
South West London, London, United Kingdom
Employment Type
Permanent
Experience with Defender for Endpoint, Defender for Identity, Defender for Office 365 and/or Defender for Cloud Apps. Strong understanding of SIEM, XDR, SOAR, detection engineering and threat hunting. Experience designing solutions across hybrid and multi-cloud environments. Proven ability to lead complex client engagements and solutioning opportunities. Strong ...

Director of Cyber Security

Location
South Ruislip, West London, United Kingdom
Experience with Defender for Endpoint, Defender for Identity, Defender for Office 365 and/or Defender for Cloud Apps. Strong understanding of SIEM, XDR, SOAR, detection engineering and threat hunting. Experience designing solutions across hybrid and multi-cloud environments. Proven ability to lead complex client engagements and solutioning opportunities. Strong ...

Security Engineer, Institutional Trading

Hiring Organisation
Blockchain
Location
London, United Kingdom
Salary
£ 80 K
monitoring for FinOps-specific security signals such as abnormal order patterns, signature misuse, unusual settlements. You will integrate these signals into our SIEM/SOAR for real-time response.Support secrets and key-management hygiene. You will ensure app/service keys are stored in KMS/Vault, scoped to least ...