26 to 50 of 188 MITRE ATT&CK Jobs in the UK

Senior Security Engineer

Hiring Organisation
Docebo
Location
London, United Kingdom
Salary
£ 70 K
exfiltration, and more). Leverage CloudTrail, GuardDuty, and SIEM integrations to maintain visibility across the AWS estate. Align detection logic with MITRE ATT&CK for Cloud.Vulnerability & Configuration Management: Own vulnerability management for cloud workloads — prioritizing findings from cloud configuration assessments, and runtime protection tools. Drive … multi-cloud exposure is a plus.In-depth knowledge of information security principles and cybersecurity frameworks relevant to cloud environments: MITRE ATT&CK for Cloud, CIS Benchmarks, AWS Well-Architected Security Pillar, NIST CSF, SOC 2, ISO 27001.Willingness and ability to participate in an on-call ...

2nd / 3rd Line Security Analyst

Hiring Organisation
XACT PLACEMENTS LIMITED
Location
Reading, Berkshire, South East, United Kingdom
Employment Type
Permanent
Salary
£60,000
sign-ins, malicious OAuth consent, mailbox access), including session/token revocation Design, build and test SIEM detection rules mapped to MITRE ATT&CK, and tune out false positives without blanket whitelisting Build automation for SOC processes - enrichment, ticketing, containment - using Python, Logic Apps, APIs … security incidents from triage through to closure Hands-on experience writing and tuning SIEM detection logic, with a solid understanding of MITRE ATT&CK and KQL (or equivalent) Practical scripting/automation experience (Python, Logic Apps, REST APIs) or hands-on SOAR platform configuration Working ...

Senior Detection & Threat Engineer

Hiring Organisation
Checkout.com
Location
London, United Kingdom
Salary
£ 80 K
proactive threat hunting based on attacker behaviour, not vendor alertsTranslating threat intelligence and incident learnings into durable, reusable detectionsMapping detections to MITRE ATT&CK and real-world attack pathsReducing alert fatigue through logic refinement, correlation, and contextual enrichmentAdvising and supporting during high-severity security incidents … plane, SaaS)Familiarity with threat intelligence platforms and frameworks such as PCI DSS, NIST CSF, SOC 2, ISO27001, CIS Benchmarks, and MITRE ATT&CK for Cloud.Additional InformationBring all of you to workWe create the conditions for high performers to thrive, through real ownership, fewer blockers ...

Senior Cyber Detection and Response Engineer

Location
Greater London, England, United Kingdom
build and continuously improve detection content, managed as code and version-controlled, mapping coverage to adversary tactics and techniques using the MITRE ATT&CK framework and prioritising the techniques most relevant to a financial services SaaS provider. Telemetry and visibility – maintain a clear view … detections. Working knowledge of cloud security and native cloud telemetry sources (AWS and/or Azure). Practical use of the MITRE ATT&CK framework to structure detection coverage and gap analysis. Hands-on experience building and operating SOAR playbooks and response automation, orchestrating across ...

Security Analyst III - SOC - Welwyn Garden City, United Kingdom of Great Britain and Northern Ireland

Hiring Organisation
Tesco
Location
Welwyn Garden City, Hertfordshire, United Kingdom
Salary
£ 55 K
years’ experience working in an internal SOC or 3 years at an MSSP in a senior role.Deep knowledge of cybersecurity frameworks: MITRE ATT&CK, Cyber Kill Chain, Incident Response Lifecycle, Pyramid of Pain.Expertise in threat hunting and advanced investigative analysis.Deep understanding of attacker tactics, techniques … years’ experience working in an internal SOC or 3 years at an MSSP in a senior role.Deep knowledge of cybersecurity frameworks: MITRE ATT&CK, Cyber Kill Chain, Incident Response Lifecycle, Pyramid of Pain.Expertise in threat hunting and advanced investigative analysis.Deep understanding of attacker tactics, techniques ...

SecOps Engineer

Hiring Organisation
OCS Group
Location
London, United Kingdom
Salary
£ 70 K
Detection engineering and tuningBuild, test and maintain high-quality detections across our SIEM, XDR and email security platforms, mapped to the MITRE ATT&CK frameworkContinuously tune existing detections to reduce false positives and improve fidelity, using a data-driven approachIdentify gaps in detection coverage proactively … Python, PowerShell or KQL, with a working understanding of APIs and integration patternsPractical understanding of common attack techniques mapped to MITRE ATT&CK, and how they manifest in telemetryA proactive mindset: the candidate must be able to point to specific examples where they have identified ...

Lead Security Operations Engineer

Location
Greater London, England, United Kingdom
Define and deliver Pleo's SecOps roadmap for detection, response, and investigation capabilities Build a structured roadmap based on MITRE ATT&CK, NIST, and CIS benchmarks Lead security investigations and digital forensics through incident response Design, tune, and scale SIEM and standardized logging pipelines Strengthen … Modeling Compliance Risk Management Soft Skills Mentoring Collaboration Leadership Industry Keywords Fintech Payments Fraud Trust & Safety Regulated Environments Tools & Technologies SIEM MITRE ATT&CK NIST CIS Benchmarks AI Automation #J-18808-Ljbffr ...

Senior Operational Technology (OT) Security Consultant

Hiring Organisation
Amentum
Location
Burghfield Common, Berkshire, United Kingdom
Employment Type
Permanent
Salary
GBP Annual
architectures, key components, and common IT/OT protocols. Certifications - Cybersecurity & Infrastructure Security Agency (CISA) Industrial Control Systems (ICS) Training, AttackIQ - MITRE ATT&CK, SANS Global Industrial Cyber Security Professional (GICSP), Certified Information Systems Security Professional (CISSP). Standards, frameworks, and regulatory experience including … Directive, ISA/IEC 62443 Series/ISO 27000 Series, MITRE ATT&CK, NIST Cyber Security Framework (CSF), NCSC CAF, Office for Nuclear Regulation (ONR) Security Assessment Principles, Technical Assessment Guides, and supplementary guidance. Our Culture: Our values stand on a foundation of safety, integrity ...

Principal Microsoft Defender XDR, IRM & Deception Engineer

Hiring Organisation
Willis Towers Watson
Location
London, United Kingdom
Salary
£ 100 K
hunting at scaleDetection-as-code, CI/CD of detection content, and security content managementStrong knowledge of adversary tradecraft and frameworks:MITRE ATT&CK, MITRE Engage, MITRE D3FEND, and the cyber kill chainExperience leveraging Agentic AI, Microsoft Security Copilot ...

Senior SOC Analyst

Hiring Organisation
Sopra Steria
Location
Farnborough, Hampshire, South East, United Kingdom
Employment Type
Permanent
Salary
£55,000
Lead and support incident response activities, providing expert guidance on containment, eradication and recovery. Enhance detection rules and use cases using MITRE ATT&CK and threat-informed defence techniques. Support threat intelligence activities and contribute to the continuous improvement of SOC operations. What … Bring: Proven experience working within a Security Operations Centre. Hands-on experience with Microsoft Sentinel and Splunk. Strong understanding of MITRE ATT&CK. It would be great if you had: Networking protocols and infrastructure (TCP/IP, LAN/WAN, HTTP, SMTP, FTP, LDAP). Firewalls, VPNs ...

Senior Security Operations Centre Analyst

Hiring Organisation
Sopra Steria
Location
United Kingdom
Employment Type
Permanent
Salary
GBP Annual
Lead and support incident response activities, providing expert guidance on containment, eradication and recovery. Enhance detection rules and use cases using MITRE ATT&CK and threat-informed defence techniques. Support threat intelligence activities and contribute to the continuous improvement of SOC operations. What … Bring: Proven experience working within a Security Operations Centre. Hands-on experience with Microsoft Sentinel and Splunk. Strong understanding of MITRE ATT&CK. It would be great if you had: Networking protocols and infrastructure (TCP/IP, LAN/WAN, HTTP, SMTP, FTP, LDAP). Firewalls, VPNs ...

3rd Line Security Analyst

Hiring Organisation
Xact Placements Limited
Location
Reading, Berkshire, United Kingdom
Employment Type
Full-Time
Salary
£55,000 - £60,000 per annum
optimise detection content across Microsoft Sentinel, Defender XDR, CrowdStrike and associated platforms, developing advanced KQL queries and analytics rules aligned to MITRE ATT&CK. Act as senior technical owner for security platforms including Microsoft Sentinel, Defender XDR, CrowdStrike Falcon, Entra ID, Intune, Darktrace and supporting technologies, managing … understanding of Azure, AWS and hybrid infrastructure security, with strong knowledge of networking, operating systems and attacker techniques. Practical understanding of MITRE ATT&CK, Cyber Kill Chain, NIST and SANS incident response frameworks. Experience working within regulated and audited environments, including ISO 27001 and Cyber ...

Cyber Security Analyst

Hiring Organisation
XACT PLACEMENTS LIMITED
Location
Reading, Berkshire, South East, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£60,000
optimise detection content across Microsoft Sentinel, Defender XDR, CrowdStrike and associated platforms, developing advanced KQL queries and analytics rules aligned to MITRE ATT&CK. Act as senior technical owner for security platforms including Microsoft Sentinel, Defender XDR, CrowdStrike Falcon, Entra ID, Intune, Darktrace and supporting technologies, managing … understanding of Azure, AWS and hybrid infrastructure security, with strong knowledge of networking, operating systems and attacker techniques. Practical understanding of MITRE ATT&CK, Cyber Kill Chain, NIST and SANS incident response frameworks. Experience working within regulated and audited environments, including ISO 27001 and Cyber ...

Cyber Security Operations Specialist

Hiring Organisation
Tank Recruitment
Location
Bath, Somerset, United Kingdom
Employment Type
Contract
Contract Rate
£450 - £550/day
monitoring capabilities. Reduce false positives and improve detection coverage using threat intelligence and incident learnings. Investigate threats using frameworks such as MITRE ATT&CK. Work closely with internal IT, engineering and security teams, alongside external security providers. Maintain and improve security playbooks, procedures, documentation and response processes. … environments . Knowledge of Windows environments, with working knowledge of Linux/Unix. Understanding of threat intelligence, IOCs, TTPs and the MITRE ATT&CK framework . Experience improving detection logic, alert quality and security controls. Strong stakeholder communication and incident management skills. Knowledge of frameworks ...

Senior SOC Analyst

Hiring Organisation
Fynity
Location
Aldershot, Hampshire, United Kingdom
Salary
£ 60 K
logsSupporting live incident response, containment and escalationThreat hunting and identifying suspicious or malicious activityImproving detection rules, use cases and playbooksWorking with MITRE ATT&CK and attacker TTPsProducing clear incident reports and communicating findingsContributing to the continued improvement of SOC capabilityWhat I’m Looking ForYou … within a SOC or Security Operations environmentHands-on SIEM experience – Sentinel, Splunk, Elastic or similarGood incident investigation and response experienceUnderstanding of MITRE ATT&CKExperience analysing endpoint, network and log dataGood networking knowledge including TCP/IP, DNS and HTTPExposure to EDR, firewalls, IDS/IPS and wider ...

Senior SOC Analyst

Hiring Organisation
Fynity
Location
Milton Keynes, Buckinghamshire, United Kingdom
Salary
£ 60 K
logsSupporting live incident response, containment and escalationThreat hunting and identifying suspicious or malicious activityImproving detection rules, use cases and playbooksWorking with MITRE ATT&CK and attacker TTPsProducing clear incident reports and communicating findingsContributing to the continued improvement of SOC capabilityWhat I’m Looking ForYou … within a SOC or Security Operations environmentHands-on SIEM experience – Sentinel, Splunk, Elastic or similarGood incident investigation and response experienceUnderstanding of MITRE ATT&CKExperience analysing endpoint, network and log dataGood networking knowledge including TCP/IP, DNS and HTTPExposure to EDR, firewalls, IDS/IPS and wider ...

Microsoft Security & Purview Consultant

Hiring Organisation
Tenth Revolution Group
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£400.00 - £500.00 per day
capabilities. Key Responsibilities Review and optimise Microsoft Defender alerting, monitoring, and detection coverage. Conduct gap analysis against security best practices and MITRE ATT&CK. Design and implement Microsoft Purview DLP policies across M365 workloads. Develop sensitivity labels, classification frameworks, and information protection controls. Deliver GDPR-aligned retention … Labels, Auto-Labelling, and Data Classification. Retention Labels, Retention Policies, and Data Lifecycle Management. Detection engineering, alert tuning, incident management, and MITRE ATT&CK mapping. Microsoft 365 Security & Compliance architecture. Strong understanding of GDPR and data governance principles. Experience delivering security and compliance projects ...

Director, Cyber Defense

Hiring Organisation
Kyndryl
Location
London, United Kingdom
Salary
£ 120 K
program and own the intelligence-to-defense loop: convert prioritized adversary intelligence into detection requirements, control coverage decisions, and changes to the defensive architecture.Govern ATT&CK-aligned detection coverage on measured efficacy, and stand up continuous validation through adversary emulation and detection testing to prove that intelligence … decision quality to perform under pressure.Strong command of threat-informed defense: translating intelligence into detection coverage and architecture decisions, anchored in MITRE ATT&CK, with kill chain analysis as a supporting lens for mapping attacker progression.Working command of detection engineering practice: detection-as-code, content ...

Information Security Analyst - SecOps Detection

Hiring Organisation
Starling Bank
Location
London, United Kingdom
Salary
£ 80 K
response, or threat intelligence.Attacker Knowledge: Practical experience analysing attacker behavior, with a strong understanding and application of threat analysis models like MITRE ATT&CK to prioritize and enhance detective controls.SIEM Expertise: Hands-on experience with SIEM platforms (e.g., Splunk, Google SecOps, Elastic, Sentinel) for rule ...

Security Operations Analyst

Hiring Organisation
Matchtech Mobility
Location
London, United Kingdom
Employment Type
Contract
Contract Rate
Up to £594 per day
exercises and risk assessments. Knowledge of threat actor tactics, techniques, and procedures (TTPs). Understanding of common attack frameworks such as MITRE ATT&CK and Cyber Kill Chain. Experience investigating security events and supporting incident response activities. Strong analytical, investigative, and problem-solving skills. Ability ...

Security Operations Analyst

Hiring Organisation
Matchtech
Location
London, United Kingdom
Salary
£ 80 K
Threat Modelling exercises and risk assessments.Knowledge of threat actor tactics, techniques, and procedures (TTPs).Understanding of common attack frameworks such as MITRE ATT&CK and Cyber Kill Chain.Experience investigating security events and supporting incident response activities.Strong analytical, investigative, and problem-solving skills.Ability to assess cyber ...

Cyber Security Analyst

Hiring Organisation
Digital Waffle
Location
London, UK
Employment Type
Full-time
security monitoring and investigations Good understanding of SIEM technologies, log analysis and threat detections Knowledge of security frameworks such as MITRE ATT&CK and the Cyber Kill Chain Experience investigating phishing, malware, endpoint, identity and network security incidents Familiarity with Windows, Linux, Active Directory ...

Senior Cloud Security Analyst

Location
Belfast City District, Northern Ireland, United Kingdom
Cloud Security Microsoft Defender Suite Kubernetes security concepts Identity and Access Management (IAM) Privileged Access Management Microsoft Entra ID (Azure AD) MITRE ATT&CK Framework Threat Intelligence Incident Response Threat Hunting SIEM Technologies Security Monitoring Security Operations (SOC) Cloud Networking Fundamentals What You'll Bring ...

Cyber Security Analyst

Hiring Organisation
Digital Waffle
Location
City of London, London, United Kingdom
security monitoring and investigations Good understanding of SIEM technologies, log analysis and threat detections Knowledge of security frameworks such as MITRE ATT&CK and the Cyber Kill Chain Experience investigating phishing, malware, endpoint, identity and network security incidents Familiarity with Windows, Linux, Active Directory ...

Head of Cyber Defence & Incident Response

Hiring Organisation
Quadient
Location
London, United Kingdom
Salary
£ 80 K
GCIH, GCIA, GNFA, CISSP, CISM, or equivalent experience in incident response and security operations.Experience with threat hunting, purple teaming, and using MITRE ATT&CK to structure detections, gaps analysis, and defensive improvements.Experience with security operations in cloud platforms and common tools (e.g., Microsoft Defender, Sentinel ...