26 to 50 of 242 MITRE ATT&CK Jobs in the UK

Threat Hunting & Detection Engineering Analyst in Cheltenham

Location
Cheltenham, England, United Kingdom
maintain threat detection use cases aligned to real-world attack scenarios Build and tune detection logic using industry frameworks such as MITRE ATT&CK Conduct proactive, hypothesis-led threat hunting across client environments Analyse telemetry, threat intelligence and security data to identify suspicious activity Develop … passionate about identifying sophisticated threats and improving security operations. Threat Hunting Detection Engineering Security Operations Centres (SOC) SIEM technologies MITRE ATT&CK Framework Threat Intelligence Detection rule creation and tuning Security telemetry analysis Incident detection and investigation Writing detection use cases and playbooks Developing ...

Interim Cyber Security Officer

Location
Greater London, England, United Kingdom
implement SOAR workflows to automate detection, response, and security operations processes. Conduct proactive threat hunting using SIEM/EDR data and MITRE ATT&CK‐aligned techniques. Support vulnerability assessment and security scanning activities using relevant tools. Provide input into penetration testing activities and interpret findings … Security (ES). Solid understanding of network protocols, cloud security (AWS/Azure), and threat detection methodologies. Working knowledge of the MITRE ATT&CK framework. Experience building automation or SOAR playbooks for security operations. CrowdStrike certifications (CCFA/CCFR/CCSE – any combination preferred). ...

Senior Cyber Security Engineer (EDR) Senior Security Engineer – Monitoring & Detection

Hiring Organisation
Sanderson Recruitment
Location
London, United Kingdom
Salary
£ 70 K
threat detection platforms.Create and optimise detection logic using technologies such as Splunk and endpoint security solutions.Map detections against the MITRE ATT&CK framework to ensure comprehensive threat coverage.Continuously improve detection quality by analysing alert fidelity, false positives, and operational effectiveness.Validate detections through testing, simulation exercises … more of the following:Splunk and SPLYARA rule developmentEDR detection engineeringSIEM content development and tuningExperience mapping detections to the MITRE ATT&CK framework.Strong understanding of modern security principles including Zero Trust, identity-first security, secrets management, and network segmentation.Desirable ExperienceExperience with Cribl and security data ...

Senior Cyber Security Engineer (EDR)

Hiring Organisation
Sanderson Government and Defence
Location
Manchester, North West, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£85,000
threat detection platforms. Create and optimise detection logic using technologies such as Splunk and endpoint security solutions. Map detections against the MITRE ATT&CK framework to ensure comprehensive threat coverage. Continuously improve detection quality by analysing alert fidelity, false positives, and operational effectiveness. Validate detections … following: Splunk and SPL YARA rule development EDR detection engineering SIEM content development and tuning Experience mapping detections to the MITRE ATT&CK framework. Strong understanding of modern security principles including Zero Trust, identity-first security, secrets management, and network segmentation. Desirable Experience Experience with ...

Senior Detection Engineer (Consultancy)

Hiring Organisation
Fazer Recruitment
Location
Reading, Berkshire, United Kingdom
Employment Type
Full-Time
Salary
£85,000 - £90,000 per annum
without losing coverage Mapping customer log sources against use cases to identify and close coverage gaps Designing use cases aligned to MITRE ATT&CK Building SOAR automations and automated response workflows Writing incident response playbooks for customers Owning the detection-as-code approach — pipelines, version … Azure Logic Apps, Cortex XSOAR or similar Scripting in Python or PowerShell, and comfort working with APIs Use case design against MITRE ATT&CK Working knowledge of XDR/EDR platforms and Azure telemetry sources Some exposure to NDR tooling such as Vectra ...

Senior Detection and Response Engineer

Hiring Organisation
Jagex
Location
Cambridge, Cambridgeshire, United Kingdom
Salary
£ 80 K
improve security telemetry, alert enrichment, investigation workflows and response times.Conduct threat hunting using adversary behaviours, TTPs and frameworks such as MITRE ATT&CK, incorporating findings into security controls and detections.Create and continuously improve incident runbooks, playbooks and detection processes based on findings from real-world … ability to write and develop queries for complex investigations.Understanding of adversary tactics, techniques and procedures (TTPs), offensive security concepts and MITRE ATT&CK principles.Practical knowledge of cloud environments and security controls, with the ability to apply detection and incident response practices across hybrid infrastructure.Background developing ...

Senior Detection and Response Engineer

Location
United Kingdom
improve security telemetry, alert enrichment, investigation workflows and response times. Conduct threat hunting using adversary behaviours, TTPs and frameworks such as MITRE ATT&CK, incorporating findings into security controls and detections. Create and continuously improve incident runbooks, playbooks and detection processes based on findings from … ability to write and develop queries for complex investigations. Understanding of adversary tactics, techniques and procedures (TTPs), offensive security concepts and MITRE ATT&CK principles. Practical knowledge of cloud environments and security controls, with the ability to apply detection and incident response practices across hybrid ...

Associate Consultant, Digital Forensics, Incident Response

Location
Greater London, England, United Kingdom
experience and awareness of recognised international standards Understanding of NPCC, NIST and ISO17025 best-practice procedures and evidence handling Understanding of MITRE ATT&CK, Cyber Kill Chain, network topology and EDR solutions Excellent written and verbal communication skills Educated to BSc in IT or similar … Preservation Soft Skills Excellent Communication Skills Client-Facing Experience Presentation Skills Certifications & Qualifications EnCE ACE GCFE Industry Keywords Cyber Kill Chain MITRE ATT&CK NIST ISO17025 NPCC EDiscovery Crisis Management Data Breaches Digital Investigations Forensic Accreditation Tools & Technologies Logicube Falcon Velociraptor EnCase FTK Nuix ...

Senior Security Engineer

Hiring Organisation
Docebo
Location
London, United Kingdom
Salary
£ 70 K
exfiltration, and more). Leverage CloudTrail, GuardDuty, and SIEM integrations to maintain visibility across the AWS estate. Align detection logic with MITRE ATT&CK for Cloud.Vulnerability & Configuration Management: Own vulnerability management for cloud workloads — prioritizing findings from cloud configuration assessments, and runtime protection tools. Drive … multi-cloud exposure is a plus.In-depth knowledge of information security principles and cybersecurity frameworks relevant to cloud environments: MITRE ATT&CK for Cloud, CIS Benchmarks, AWS Well-Architected Security Pillar, NIST CSF, SOC 2, ISO 27001.Willingness and ability to participate in an on-call ...

2nd / 3rd Line Security Analyst

Hiring Organisation
XACT PLACEMENTS LIMITED
Location
Reading, Berkshire, South East, United Kingdom
Employment Type
Permanent
Salary
£60,000
sign-ins, malicious OAuth consent, mailbox access), including session/token revocation Design, build and test SIEM detection rules mapped to MITRE ATT&CK, and tune out false positives without blanket whitelisting Build automation for SOC processes - enrichment, ticketing, containment - using Python, Logic Apps, APIs … security incidents from triage through to closure Hands-on experience writing and tuning SIEM detection logic, with a solid understanding of MITRE ATT&CK and KQL (or equivalent) Practical scripting/automation experience (Python, Logic Apps, REST APIs) or hands-on SOAR platform configuration Working ...

Senior Detection & Threat Engineer

Hiring Organisation
Checkout.com
Location
London, United Kingdom
Salary
£ 80 K
proactive threat hunting based on attacker behaviour, not vendor alertsTranslating threat intelligence and incident learnings into durable, reusable detectionsMapping detections to MITRE ATT&CK and real-world attack pathsReducing alert fatigue through logic refinement, correlation, and contextual enrichmentAdvising and supporting during high-severity security incidents … plane, SaaS)Familiarity with threat intelligence platforms and frameworks such as PCI DSS, NIST CSF, SOC 2, ISO27001, CIS Benchmarks, and MITRE ATT&CK for Cloud.Additional InformationBring all of you to workWe create the conditions for high performers to thrive, through real ownership, fewer blockers ...

Senior Cyber Detection and Response Engineer

Location
Greater London, England, United Kingdom
build and continuously improve detection content, managed as code and version-controlled, mapping coverage to adversary tactics and techniques using the MITRE ATT&CK framework and prioritising the techniques most relevant to a financial services SaaS provider. Telemetry and visibility – maintain a clear view … detections. Working knowledge of cloud security and native cloud telemetry sources (AWS and/or Azure). Practical use of the MITRE ATT&CK framework to structure detection coverage and gap analysis. Hands-on experience building and operating SOAR playbooks and response automation, orchestrating across ...

Security Analyst III - SOC - Welwyn Garden City, United Kingdom of Great Britain and Northern Ireland

Hiring Organisation
Tesco
Location
Welwyn Garden City, Hertfordshire, United Kingdom
Salary
£ 55 K
years’ experience working in an internal SOC or 3 years at an MSSP in a senior role.Deep knowledge of cybersecurity frameworks: MITRE ATT&CK, Cyber Kill Chain, Incident Response Lifecycle, Pyramid of Pain.Expertise in threat hunting and advanced investigative analysis.Deep understanding of attacker tactics, techniques … years’ experience working in an internal SOC or 3 years at an MSSP in a senior role.Deep knowledge of cybersecurity frameworks: MITRE ATT&CK, Cyber Kill Chain, Incident Response Lifecycle, Pyramid of Pain.Expertise in threat hunting and advanced investigative analysis.Deep understanding of attacker tactics, techniques ...

Cyber Threat Management Analyst, Specialist

Location
Greater London, England, United Kingdom
feed integrations, and security/process orchestration and automation Knowledge of threat modelling and adversary tactics and techniques frameworks, such as MITRE ATT&CK matrices, Cyber Kill Chain, ACH Knowledge of Common Vulnerability Scoring System (CVSS), CVE analysis, adversary exploitation techniques, and attack surface management … contextualize threats effectively. Highest-signal resume keywords Cyber Threat Intelligence Collection Tactics, Techniques, And Procedures (TTPs) Cyber Threat Intelligence Platform MITRE ATT&CK Framework Common Vulnerability Scoring System (CVSS) ATS Optimization Keywords Hard Skills Threat Analysis Vulnerability Exploitation Incident Identification Attack Surface Management CVE Analysis ...

SecOps Engineer

Hiring Organisation
Appcast
Location
Remote, UK
Detection engineering and tuningBuild, test and maintain high-quality detections across our SIEM, XDR and email security platforms, mapped to the MITRE ATT&CK frameworkContinuously tune existing detections to reduce false positives and improve fidelity, using a data-driven approachIdentify gaps in detection coverage proactively … Python, PowerShell or KQL, with a working understanding of APIs and integration patternsPractical understanding of common attack techniques mapped to MITRE ATT&CK, and how they manifest in telemetryA proactive mindset: the candidate must be able to point to specific examples where they have identified ...

SecOps Engineer

Hiring Organisation
OCS Group
Location
United Kingdom
Salary
£ 60 K
Detection engineering and tuningBuild, test and maintain high-quality detections across our SIEM, XDR and email security platforms, mapped to the MITRE ATT&CK frameworkContinuously tune existing detections to reduce false positives and improve fidelity, using a data-driven approachIdentify gaps in detection coverage proactively … Python, PowerShell or KQL, with a working understanding of APIs and integration patternsPractical understanding of common attack techniques mapped to MITRE ATT&CK, and how they manifest in telemetryA proactive mindset: the candidate must be able to point to specific examples where they have identified ...

Lead Security Operations Engineer

Location
Greater London, England, United Kingdom
Define and deliver Pleo's SecOps roadmap for detection, response, and investigation capabilities Build a structured roadmap based on MITRE ATT&CK, NIST, and CIS benchmarks Lead security investigations and digital forensics through incident response Design, tune, and scale SIEM and standardized logging pipelines Strengthen … Modeling Compliance Risk Management Soft Skills Mentoring Collaboration Leadership Industry Keywords Fintech Payments Fraud Trust & Safety Regulated Environments Tools & Technologies SIEM MITRE ATT&CK NIST CIS Benchmarks AI Automation #J-18808-Ljbffr ...

Principal Cyber Security Consultant

Hiring Organisation
QinetiQ
Location
Bristol, Gloucestershire, United Kingdom
Salary
£ 80 K
effective risk management across a range of environmentsAssessing cyber vulnerabilities and organisational security maturity using recognised frameworks such as NIST, MITRE ATT&CK and UK Government guidance to provide actionable recommendationsContributing innovative cyber security solutions, methodologies and bid responses that deliver value to customers … evaluating cyber security solutions, architectures and emerging approaches, including Zero Trust, while applying frameworks and standards such as NIST, ISO27001 and MITRE ATT&CK within complex environmentsExtensive experience in a range of different areas/activitiesPrevious experience leading customer engagement and business development activities, creating ...

Principal Cyber Security Consultant

Location
West of England, England, United Kingdom
effective risk management across a range of environments Assessing cyber vulnerabilities and organisational security maturity using recognised frameworks such as NIST, MITRE ATT&CK and UK Government guidance to provide actionable recommendations Contributing innovative cyber security solutions, methodologies and bid responses that deliver value … evaluating cyber security solutions, architectures and emerging approaches, including Zero Trust, while applying frameworks and standards such as NIST, ISO27001 and MITRE ATT&CK within complex environments Extensive experience in a range of different areas/activities Previous experience leading customer engagement and business development ...

Senior Principal (Managing) Cyber Security Consultant

Hiring Organisation
QinetiQ
Location
Bristol, Gloucestershire, United Kingdom
Salary
£ 80 K
effective risk management across a range of environmentsAssessing cyber vulnerabilities and organisational security maturity using recognised frameworks such as NIST, MITRE ATT&CK and UK Government guidance to provide actionable recommendationsContributing innovative cyber security solutions, methodologies and bid responses that deliver value to customers … operational performance, including regulatory and compliance requirementsPrevious experience applying and evaluating cyber security frameworks, standards and approaches such as NIST, ISO27001, MITRE ATT&CK and Zero Trust principlesPrevious experience contributing to business development activities, including solution development, bid writing and winning new opportunities within government ...

Senior Operational Technology (OT) Security Consultant

Location
Reading, England, United Kingdom
/IPS, Firewalls, etc.) for IT and OT environments. Certifications – Cybersecurity & Infrastructure Security Agency (CISA) Industrial Control Systems (ICS) Training, AttackIQ – MITRE ATT&CK, SANS Global Industrial Cyber Security Professional (GICSP), Certified Information Systems Security Professional (CISSP). Standards, frameworks, and regulatory experience including … Directive, ISA/IEC 62443 Series/ISO 27000 Series, MITRE ATT&CK, NIST Cyber Security Framework (CSF), NCSC CAF, Office for Nuclear Regulation (ONR) Security Assessment Principles, Technical Assessment Guides, and supplementary guidance. Our Culture: Our values stand on a foundation of safety, integrity ...

Senior Security Operations Centre Analyst

Hiring Organisation
Sopra Steria
Location
United Kingdom
Employment Type
Permanent
Salary
GBP Annual
Lead and support incident response activities, providing expert guidance on containment, eradication and recovery. Enhance detection rules and use cases using MITRE ATT&CK and threat-informed defence techniques. Support threat intelligence activities and contribute to the continuous improvement of SOC operations. What … Bring: Proven experience working within a Security Operations Centre. Hands-on experience with Microsoft Sentinel and Splunk. Strong understanding of MITRE ATT&CK. It would be great if you had: Networking protocols and infrastructure (TCP/IP, LAN/WAN, HTTP, SMTP, FTP, LDAP). Firewalls, VPNs ...

3rd Line Security Analyst

Hiring Organisation
Xact Placements Limited
Location
Reading, Berkshire, United Kingdom
Employment Type
Full-Time
Salary
£55,000 - £60,000 per annum
optimise detection content across Microsoft Sentinel, Defender XDR, CrowdStrike and associated platforms, developing advanced KQL queries and analytics rules aligned to MITRE ATT&CK. Act as senior technical owner for security platforms including Microsoft Sentinel, Defender XDR, CrowdStrike Falcon, Entra ID, Intune, Darktrace and supporting technologies, managing … understanding of Azure, AWS and hybrid infrastructure security, with strong knowledge of networking, operating systems and attacker techniques. Practical understanding of MITRE ATT&CK, Cyber Kill Chain, NIST and SANS incident response frameworks. Experience working within regulated and audited environments, including ISO 27001 and Cyber ...

Cyber Security Operations Specialist

Hiring Organisation
Tank Recruitment
Location
Bath, Somerset, United Kingdom
Employment Type
Contract
Contract Rate
£450 - £550/day
monitoring capabilities. Reduce false positives and improve detection coverage using threat intelligence and incident learnings. Investigate threats using frameworks such as MITRE ATT&CK. Work closely with internal IT, engineering and security teams, alongside external security providers. Maintain and improve security playbooks, procedures, documentation and response processes. … environments . Knowledge of Windows environments, with working knowledge of Linux/Unix. Understanding of threat intelligence, IOCs, TTPs and the MITRE ATT&CK framework . Experience improving detection logic, alert quality and security controls. Strong stakeholder communication and incident management skills. Knowledge of frameworks ...

Lead Security Analyst

Location
United Kingdom
standard — author, tune, and peer‐review detections in KQL, SPL, EQL, or Sigma; manage the false‐positive backlog; map coverage to MITRE ATT&CK; and train L1/L2 analysts to write and tune detections themselves. Own the threat‐landscape narrative for your engagement — turn intelligence from … similar environment— including writing and tuning detections in KQL, SPL, EQL, or Sigma, and managing coverage against MITRE ATT&CK Experience designing or improving a log and telemetry pipeline, including application‐level telemetry from cloud‐hosted services (AWS is a strong preference at this grade ...