1 to 25 of 50 MITRE ATT&CK Jobs in the UK

Threat Intelligence Lead

Hiring Organisation
Everywhen, part of the Ardonagh Group
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
Competitive salary
organisation in key external intelligence-sharing forums, including FS-ISAC, the NCSC’s CiSP and relevant industry partnerships. Use the MITRE ATT&CK framework to identify and analyse attacker tactics, techniques and procedures and strengthen our detection capabilities. Develop the Proactive Threat Hunting Initiative, using … their strong technical expertise with the ability to develop our CTI capability and turn complex intelligence into clear, actionable business insights. MITRE ATT&CK training/certification is essential . Experience developing Priority Intelligence Requirements (PIRs). Strong experience working closely with SOC, Incident Response ...

Senior Cloud Security Engineer

Hiring Organisation
Checkout.com
Location
London, UK
Employment Type
Full-time
modern SIEM platform (e.g. Sentinel) including KQL detection rules, workbooks, logging pipelines, and AI-assisted alert triage. Map detection coverage against MITRE ATT&CK tactics and techniques. Identify and close visibility gaps across the cloud estate. Maintain alignment to PCI DSS, SOC2, ISO27001 NIST … Python, PowerShell, or Bash for security automation. Strong grasp of PCI DSS, NIST CSF, SOC 2, ISO27001, CIS Benchmarks, and MITRE ATT&CK for Cloud. Nice to haveAZ-500, AWS Certified Security – Specialty, or equivalent cloud security certification. Experience integrating ATT&CK ...

Senior SOC Engineer

Hiring Organisation
Anson Mccade
Location
Glasgow, Lanarkshire, Scotland, United Kingdom
Employment Type
Permanent
with threat intelligence teams to enhance detection logic. Threat Modelling & Use Case Development Lead threat modelling exercises using frameworks such as MITRE ATT&CK, STRIDE, and Cyber Kill Chain. Translate threat models into actionable detection use cases and SIEM rules. Prioritise detection engineering based … Python or PowerShell for automation. Deep understanding of threat detection, incident response, and the cyber kill chain. Familiarity with frameworks including MITRE ATT&CK, NIST, and CIS. Strong communication, analytical, and presentation skills. Solid understanding of network traffic flows, vulnerability management, and penetration testing principles. ...

SOC Automation Engineer

Hiring Organisation
Claranet Limited
Location
Leeds, West Yorkshire, United Kingdom
Employment Type
Full-Time
Salary
Salary negotiable
dependencies, and error handling Ensure consistency and usability for wider teams Strategic Contribution Support use cases aligned to threat modelling and MITRE ATT&CK Contribute to automation playbooks and response strategies Stay current with tools, frameworks, and emerging threats Collaboration Embed automation into SOC workflows … platforms Proficiency in scripting (e.g., Python, PowerShell) Experience working with APIs, webhooks, and authentication methods Knowledge of threat frameworks (e.g., MITRE ATT&CK) Understanding of cloud security, identity, and event-driven automation Strong communication and analytical skills Security clearance (NPPV and/ ...

SOC Engineer Detection

Hiring Organisation
Sopra Steria
Location
Farnborough, Hampshire, South East, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£65,000
rules using KQL. Translate threat intelligence, attacker behaviours and operational requirements into measurable detection use cases. Map detection content to the MITRE ATT&CK framework and help identify gaps in detection coverage. Validate required log sources, schemas and field mappings before developing detection logic. Test … detection engineering principles, false-positive reduction and the detection content lifecycle. Experience developing threat-informed use cases and mapping detections to MITRE ATT&CK tactics and techniques. Ability to assess log source suitability, data quality, parsing and field availability for detection requirements. Experience with ...

Threat Hunting & Detection Engineering Analyst

Hiring Organisation
Anson Mccade
Location
Cheltenham, Gloucestershire, South West, United Kingdom
Employment Type
Permanent
Salary
£60,000
maintain threat detection use cases aligned to real-world attack scenarios Build and tune detection logic using industry frameworks such as MITRE ATT&CK Conduct proactive, hypothesis-led threat hunting across client environments Analyse telemetry, threat intelligence and security data to identify suspicious activity Develop … threats and improving security operations. You'll ideally have experience with: Threat Hunting Detection Engineering Security Operations Centres (SOC) SIEM technologies MITRE ATT&CK Framework Threat Intelligence Detection rule creation and tuning Security telemetry analysis Incident detection and investigation Writing detection use cases and playbooks ...

Senior Detection Engineer (Consultancy)

Hiring Organisation
Fazer Recruitment
Location
Reading, Berkshire, United Kingdom
Employment Type
Full-Time
Salary
£85,000 - £90,000 per annum
without losing coverage Mapping customer log sources against use cases to identify and close coverage gaps Designing use cases aligned to MITRE ATT&CK Building SOAR automations and automated response workflows Writing incident response playbooks for customers Owning the detection-as-code approach — pipelines, version … Azure Logic Apps, Cortex XSOAR or similar Scripting in Python or PowerShell, and comfort working with APIs Use case design against MITRE ATT&CK Working knowledge of XDR/EDR platforms and Azure telemetry sources Some exposure to NDR tooling such as Vectra ...

2nd / 3rd Line Security Analyst

Hiring Organisation
XACT PLACEMENTS LIMITED
Location
Reading, Berkshire, South East, United Kingdom
Employment Type
Permanent
Salary
£60,000
sign-ins, malicious OAuth consent, mailbox access), including session/token revocation Design, build and test SIEM detection rules mapped to MITRE ATT&CK, and tune out false positives without blanket whitelisting Build automation for SOC processes - enrichment, ticketing, containment - using Python, Logic Apps, APIs … security incidents from triage through to closure Hands-on experience writing and tuning SIEM detection logic, with a solid understanding of MITRE ATT&CK and KQL (or equivalent) Practical scripting/automation experience (Python, Logic Apps, REST APIs) or hands-on SOAR platform configuration Working ...

Senior Detection and Response Engineer

Hiring Organisation
Jagex
Location
Cambridge, Cambridgeshire, UK
Employment Type
Full-time
improve security telemetry, alert enrichment, investigation workflows and response times. Conduct threat hunting using adversary behaviours, TTPs and frameworks such as MITRE ATT&CK, incorporating findings into security controls and detections. Create and continuously improve incident runbooks, playbooks and detection processes based on findings from … ability to write and develop queries for complex investigations. Understanding of adversary tactics, techniques and procedures (TTPs), offensive security concepts and MITRE ATT&CK principles. Practical knowledge of cloud environments and security controls, with the ability to apply detection and incident response practices across hybrid ...

Senior Detection & Threat Engineer

Hiring Organisation
Checkout.com
Location
London, UK
Employment Type
Full-time
proactive threat hunting based on attacker behaviour, not vendor alertsTranslating threat intelligence and incident learnings into durable, reusable detectionsMapping detections to MITRE ATT&CK and real-world attack pathsReducing alert fatigue through logic refinement, correlation, and contextual enrichmentAdvising and supporting during high-severity security incidents … plane, SaaS)Familiarity with threat intelligence platforms and frameworks such as PCI DSS, NIST CSF, SOC 2, ISO27001, CIS Benchmarks, and MITRE ATT&CK for Cloud. Additional InformationBring all of you to workWe create the conditions for high performers to thrive, through real ownership, fewer ...

Senior SOC Analyst

Hiring Organisation
Sopra Steria
Location
Farnborough, Hampshire, South East, United Kingdom
Employment Type
Permanent
Salary
£55,000
Lead and support incident response activities, providing expert guidance on containment, eradication and recovery. Enhance detection rules and use cases using MITRE ATT&CK and threat-informed defence techniques. Support threat intelligence activities and contribute to the continuous improvement of SOC operations. What … Bring: Proven experience working within a Security Operations Centre. Hands-on experience with Microsoft Sentinel and Splunk. Strong understanding of MITRE ATT&CK. It would be great if you had: Networking protocols and infrastructure (TCP/IP, LAN/WAN, HTTP, SMTP, FTP, LDAP). Firewalls, VPNs ...

3rd Line Security Analyst

Hiring Organisation
Xact Placements Limited
Location
Reading, Berkshire, United Kingdom
Employment Type
Full-Time
Salary
£55,000 - £60,000 per annum
optimise detection content across Microsoft Sentinel, Defender XDR, CrowdStrike and associated platforms, developing advanced KQL queries and analytics rules aligned to MITRE ATT&CK. Act as senior technical owner for security platforms including Microsoft Sentinel, Defender XDR, CrowdStrike Falcon, Entra ID, Intune, Darktrace and supporting technologies, managing … understanding of Azure, AWS and hybrid infrastructure security, with strong knowledge of networking, operating systems and attacker techniques. Practical understanding of MITRE ATT&CK, Cyber Kill Chain, NIST and SANS incident response frameworks. Experience working within regulated and audited environments, including ISO 27001 and Cyber ...

Cyber Security Analyst

Hiring Organisation
XACT PLACEMENTS LIMITED
Location
Reading, Berkshire, South East, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£60,000
optimise detection content across Microsoft Sentinel, Defender XDR, CrowdStrike and associated platforms, developing advanced KQL queries and analytics rules aligned to MITRE ATT&CK. Act as senior technical owner for security platforms including Microsoft Sentinel, Defender XDR, CrowdStrike Falcon, Entra ID, Intune, Darktrace and supporting technologies, managing … understanding of Azure, AWS and hybrid infrastructure security, with strong knowledge of networking, operating systems and attacker techniques. Practical understanding of MITRE ATT&CK, Cyber Kill Chain, NIST and SANS incident response frameworks. Experience working within regulated and audited environments, including ISO 27001 and Cyber ...

Cyber Security Operations Specialist

Hiring Organisation
Tank Recruitment
Location
Bath, Somerset, United Kingdom
Employment Type
Contract
Contract Rate
£450 - £550/day
monitoring capabilities. Reduce false positives and improve detection coverage using threat intelligence and incident learnings. Investigate threats using frameworks such as MITRE ATT&CK. Work closely with internal IT, engineering and security teams, alongside external security providers. Maintain and improve security playbooks, procedures, documentation and response processes. … environments . Knowledge of Windows environments, with working knowledge of Linux/Unix. Understanding of threat intelligence, IOCs, TTPs and the MITRE ATT&CK framework . Experience improving detection logic, alert quality and security controls. Strong stakeholder communication and incident management skills. Knowledge of frameworks ...

Microsoft Security & Purview Consultant

Hiring Organisation
Tenth Revolution Group
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£400.00 - £500.00 per day
capabilities. Key Responsibilities Review and optimise Microsoft Defender alerting, monitoring, and detection coverage. Conduct gap analysis against security best practices and MITRE ATT&CK. Design and implement Microsoft Purview DLP policies across M365 workloads. Develop sensitivity labels, classification frameworks, and information protection controls. Deliver GDPR-aligned retention … Labels, Auto-Labelling, and Data Classification. Retention Labels, Retention Policies, and Data Lifecycle Management. Detection engineering, alert tuning, incident management, and MITRE ATT&CK mapping. Microsoft 365 Security & Compliance architecture. Strong understanding of GDPR and data governance principles. Experience delivering security and compliance projects ...

Security Operations Analyst

Hiring Organisation
Matchtech Mobility
Location
London, United Kingdom
Employment Type
Contract
Contract Rate
Up to £594 per day
exercises and risk assessments. Knowledge of threat actor tactics, techniques, and procedures (TTPs). Understanding of common attack frameworks such as MITRE ATT&CK and Cyber Kill Chain. Experience investigating security events and supporting incident response activities. Strong analytical, investigative, and problem-solving skills. Ability ...

SOC Engineer

Hiring Organisation
Proactive Appointments
Location
Milton Keynes, Buckinghamshire, United Kingdom
Employment Type
Full-Time
Salary
£50,000 - £55,000 per annum
including TCP/IP, DNS, firewalls, and proxies. Experience within a SOC, NOC, or 24/7 operational environment. Familiarity with MITRE ATT&CK, CVEs, and vulnerability management. Exposure to cloud security monitoring across Azure, AWS, or Microsoft 365. Desirable Certifications Microsoft SC-200 CompTIA ...

Cyber Security Analyst

Hiring Organisation
Digital Waffle
Location
London, UK
Employment Type
Full-time
security monitoring and investigations Good understanding of SIEM technologies, log analysis and threat detections Knowledge of security frameworks such as MITRE ATT&CK and the Cyber Kill Chain Experience investigating phishing, malware, endpoint, identity and network security incidents Familiarity with Windows, Linux, Active Directory ...

Head of Cyber Defence & Incident Response

Hiring Organisation
Quadient
Location
Greater London, United Kingdom
Employment Type
Full Time
GCIA, GNFA, CISSP, CISM, or equivalent experience in incident response and security operations. Experience with threat hunting, purple teaming, and using MITRE ATT&CK to structure detections, gaps analysis, and defensive improvements. Experience with security operations in cloud platforms and common tools (e.g., Microsoft Defender ...

Senior SOC Analyst - DV Clearance

Hiring Organisation
Salt
Location
London, United Kingdom
Employment Type
Permanent
Understanding of network protocols, attack techniques, and cyber threat methodologies Experience investigating security incidents across Windows and Linux environments Knowledge of MITRE ATT&CK framework Familiarity with endpoint detection and response platforms We're hiring across multiple Cyber Security disciplines, if you are a specialist ...

Senior Infrastructure Engineer

Hiring Organisation
Inspire People
Location
Plymouth, Devon, South West, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£55,000
similar security certifications. Experience with Red Team tooling such as Burp Suite, Metasploit, Wireshark, Nessus, Nmap or Hashcat. Knowledge of MITRE ATT&CK and adversary emulation frameworks. Experience securing Windows, Linux or Mainframe environments. AWS or Azure security experience. Why Join HMLR: This ...

SOC Analyst

Hiring Organisation
Reed
Location
London, United Kingdom
Employment Type
Full-Time
Salary
£50,000 - £60,000 per annum, Inc benefits
investigating security alerts using SIEM, EDR and security monitoring tools A strong understanding of Modern cyber threats, attacker techniques and the MITRE ATT&CK framework Experience analysing security events across endpoint, network, identity and cloud platforms Knowledge of incident response and risk-based incident prioritisation ...

Threat Intelligence Analyst

Hiring Organisation
Matchtech Mobility
Location
London, United Kingdom
Employment Type
Contract, Work From Home
Contract Rate
Up to £594 per day
Security initiatives within complex environments. Understanding of Security Architecture Design and secure-by-design principles. Familiarity with cyber frameworks such as MITRE ATT&CK, NIST, or Cyber Kill Chain. Experience producing intelligence reports and presenting findings to stakeholders. Strong analytical and problem-solving abilities. Excellent ...

Interim Cyber Security Officer

Hiring Organisation
Alois Technologies Limited
Location
London, United Kingdom
Employment Type
Contract
Contract Rate
GBP 400 - 500 Daily
response, security monitoring, and threat hunting activities. Excellent understanding of network protocols, cyber attack methodologies, security monitoring techniques, and the MITRE ATT&CK Framework . Good knowledge of cloud security principles across Microsoft Azure and/or AWS environments. Strong analytical, troubleshooting, communication, and stakeholder ...

Interim Cyber Security Officer

Hiring Organisation
Alois Technologies Limited
Location
London, United Kingdom
Employment Type
Contract, Temporary
Salary
£400 - £500/day
response, security monitoring, and threat hunting activities. Excellent understanding of network protocols, cyber attack methodologies, security monitoring techniques, and the MITRE ATT&CK Framework . Good knowledge of cloud security principles across Microsoft Azure and/or AWS environments. Strong analytical, troubleshooting, communication, and stakeholder ...