bolton, greater manchester, north west england, united kingdom Hybrid / WFH Options
Lawrence Harvey
with and responding to escalated and most high profile incidents. Comprehensive knowledge and experience utilising/fine-tuning the Microsoft Security stack – Defender, Sentinel, KQL, etc. Experience working in hybrid-cloud SOC environments – Azure/AWS preferably. Ability to articulate specific projects that you have built, developed or led on More ❯
Manchester, North West, United Kingdom Hybrid / WFH Options
Queen Square Recruitment Limited
intelligence summaries Required Skills & Experience: 5+ years in cybersecurity, with 2+ years at SOC Level 3 or senior analyst level Expertise in Microsoft Sentinel (KQL, custom rules, automation, dashboards) Strong hands-on experience with Microsoft Defender for Endpoint, Identity, and Office 365 Proficient in handling incidents aligned with MITRE ATT More ❯
liverpool, north west england, united kingdom Hybrid / WFH Options
Net Talent
alerts, and system logs for signs of suspicious activity or security breaches. Requirements Proven experience with Microsoft Sentinel, Defender for Endpoint, Defender for Identity KQL experience In depth understanding of PCAP analysis using Wireshark or equivalent. Network engineering/network admin OT operations/security (optional, but a bonus) What More ❯
manchester, north west england, united kingdom Hybrid / WFH Options
Net Talent
alerts, and system logs for signs of suspicious activity or security breaches. Requirements Proven experience with Microsoft Sentinel, Defender for Endpoint, Defender for Identity KQL experience In depth understanding of PCAP analysis using Wireshark or equivalent. Network engineering/network admin OT operations/security (optional, but a bonus) What More ❯
chester, north west england, united kingdom Hybrid / WFH Options
Net Talent
alerts, and system logs for signs of suspicious activity or security breaches. Requirements Proven experience with Microsoft Sentinel, Defender for Endpoint, Defender for Identity KQL experience In depth understanding of PCAP analysis using Wireshark or equivalent. Network engineering/network admin OT operations/security (optional, but a bonus) What More ❯
stockport, north west england, united kingdom Hybrid / WFH Options
Net Talent
alerts, and system logs for signs of suspicious activity or security breaches. Requirements Proven experience with Microsoft Sentinel, Defender for Endpoint, Defender for Identity KQL experience In depth understanding of PCAP analysis using Wireshark or equivalent. Network engineering/network admin OT operations/security (optional, but a bonus) What More ❯
warrington, cheshire, north west england, united kingdom Hybrid / WFH Options
Net Talent
alerts, and system logs for signs of suspicious activity or security breaches. Requirements Proven experience with Microsoft Sentinel, Defender for Endpoint, Defender for Identity KQL experience In depth understanding of PCAP analysis using Wireshark or equivalent. Network engineering/network admin OT operations/security (optional, but a bonus) What More ❯
preston, lancashire, north west england, united kingdom Hybrid / WFH Options
Net Talent
alerts, and system logs for signs of suspicious activity or security breaches. Requirements Proven experience with Microsoft Sentinel, Defender for Endpoint, Defender for Identity KQL experience In depth understanding of PCAP analysis using Wireshark or equivalent. Network engineering/network admin OT operations/security (optional, but a bonus) What More ❯
bolton, greater manchester, north west england, united kingdom Hybrid / WFH Options
Net Talent
alerts, and system logs for signs of suspicious activity or security breaches. Requirements Proven experience with Microsoft Sentinel, Defender for Endpoint, Defender for Identity KQL experience In depth understanding of PCAP analysis using Wireshark or equivalent. Network engineering/network admin OT operations/security (optional, but a bonus) What More ❯
chester, north west england, united kingdom Hybrid / WFH Options
Cloud Decisions
complex Microsoft Sentinel at SMC and enterprise Understanding of security telemetry across identity, endpoint, cloud, and network layers Experience in SIEM content development, including KQL, analytics rules, and custom data connectors Scripting and engineering skills – Python, PowerShell, APIs, Function Apps A background in cyber threat detection, incident response or DFIR … is a real plus Comfortable working in very fast-moving, customer facing delivery environments The Technical Shizzle: Microsoft Sentinel (KQL, Analytics Rules, Workbooks, Watchlists) Azure Function Apps, Logic Apps, ARM templates PowerShell, Python, REST APIs Log ingestion and parsing across multi platforms (Azure/AWS/GCP, M365, Defender, Entra More ❯
manchester, north west england, united kingdom Hybrid / WFH Options
Cloud Decisions
complex Microsoft Sentinel at SMC and enterprise Understanding of security telemetry across identity, endpoint, cloud, and network layers Experience in SIEM content development, including KQL, analytics rules, and custom data connectors Scripting and engineering skills – Python, PowerShell, APIs, Function Apps A background in cyber threat detection, incident response or DFIR … is a real plus Comfortable working in very fast-moving, customer facing delivery environments The Technical Shizzle: Microsoft Sentinel (KQL, Analytics Rules, Workbooks, Watchlists) Azure Function Apps, Logic Apps, ARM templates PowerShell, Python, REST APIs Log ingestion and parsing across multi platforms (Azure/AWS/GCP, M365, Defender, Entra More ❯
liverpool, north west england, united kingdom Hybrid / WFH Options
Cloud Decisions
complex Microsoft Sentinel at SMC and enterprise Understanding of security telemetry across identity, endpoint, cloud, and network layers Experience in SIEM content development, including KQL, analytics rules, and custom data connectors Scripting and engineering skills – Python, PowerShell, APIs, Function Apps A background in cyber threat detection, incident response or DFIR … is a real plus Comfortable working in very fast-moving, customer facing delivery environments The Technical Shizzle: Microsoft Sentinel (KQL, Analytics Rules, Workbooks, Watchlists) Azure Function Apps, Logic Apps, ARM templates PowerShell, Python, REST APIs Log ingestion and parsing across multi platforms (Azure/AWS/GCP, M365, Defender, Entra More ❯
stockport, north west england, united kingdom Hybrid / WFH Options
Cloud Decisions
complex Microsoft Sentinel at SMC and enterprise Understanding of security telemetry across identity, endpoint, cloud, and network layers Experience in SIEM content development, including KQL, analytics rules, and custom data connectors Scripting and engineering skills – Python, PowerShell, APIs, Function Apps A background in cyber threat detection, incident response or DFIR … is a real plus Comfortable working in very fast-moving, customer facing delivery environments The Technical Shizzle: Microsoft Sentinel (KQL, Analytics Rules, Workbooks, Watchlists) Azure Function Apps, Logic Apps, ARM templates PowerShell, Python, REST APIs Log ingestion and parsing across multi platforms (Azure/AWS/GCP, M365, Defender, Entra More ❯
warrington, cheshire, north west england, united kingdom Hybrid / WFH Options
Cloud Decisions
complex Microsoft Sentinel at SMC and enterprise Understanding of security telemetry across identity, endpoint, cloud, and network layers Experience in SIEM content development, including KQL, analytics rules, and custom data connectors Scripting and engineering skills – Python, PowerShell, APIs, Function Apps A background in cyber threat detection, incident response or DFIR … is a real plus Comfortable working in very fast-moving, customer facing delivery environments The Technical Shizzle: Microsoft Sentinel (KQL, Analytics Rules, Workbooks, Watchlists) Azure Function Apps, Logic Apps, ARM templates PowerShell, Python, REST APIs Log ingestion and parsing across multi platforms (Azure/AWS/GCP, M365, Defender, Entra More ❯
preston, lancashire, north west england, united kingdom Hybrid / WFH Options
Cloud Decisions
complex Microsoft Sentinel at SMC and enterprise Understanding of security telemetry across identity, endpoint, cloud, and network layers Experience in SIEM content development, including KQL, analytics rules, and custom data connectors Scripting and engineering skills – Python, PowerShell, APIs, Function Apps A background in cyber threat detection, incident response or DFIR … is a real plus Comfortable working in very fast-moving, customer facing delivery environments The Technical Shizzle: Microsoft Sentinel (KQL, Analytics Rules, Workbooks, Watchlists) Azure Function Apps, Logic Apps, ARM templates PowerShell, Python, REST APIs Log ingestion and parsing across multi platforms (Azure/AWS/GCP, M365, Defender, Entra More ❯
bolton, greater manchester, north west england, united kingdom Hybrid / WFH Options
Cloud Decisions
complex Microsoft Sentinel at SMC and enterprise Understanding of security telemetry across identity, endpoint, cloud, and network layers Experience in SIEM content development, including KQL, analytics rules, and custom data connectors Scripting and engineering skills – Python, PowerShell, APIs, Function Apps A background in cyber threat detection, incident response or DFIR … is a real plus Comfortable working in very fast-moving, customer facing delivery environments The Technical Shizzle: Microsoft Sentinel (KQL, Analytics Rules, Workbooks, Watchlists) Azure Function Apps, Logic Apps, ARM templates PowerShell, Python, REST APIs Log ingestion and parsing across multi platforms (Azure/AWS/GCP, M365, Defender, Entra More ❯