26 to 50 of 237 MITRE ATT&CK Jobs in the UK

Cyber Security Specialist with Threat Modeling

Hiring Organisation
E-Solutions IT Services UK Ltd
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
Salary negotiable
date stance on the evolving financial service threat landscape. Lead collaborative Threat Modelling workshops using structured frameworks such as STRIDE and MITRE ATT&CK to systematically uncover architectural vulnerabilities before production deployment. Formulate clear risk-mitigation strategies that balance agility with strict data-integrity requirements. … domains (specifically public-key cryptography, TLS configurations, network zoning, and microsegmentation). Framework Mastery: Confident hands-on experience utilizing STRIDE or MITRE ATT&CK concepts in real-world software lifecycles. Professional Certifications Security Management: At least one active certification such as CISSP, CISM, CCSP ...

Senior Detection and Response Engineer

Location
United Kingdom
improve security telemetry, alert enrichment, investigation workflows and response times. Conduct threat hunting using adversary behaviours, TTPs and frameworks such as MITRE ATT&CK, incorporating findings into security controls and detections. Create and continuously improve incident runbooks, playbooks and detection processes based on findings from … ability to write and develop queries for complex investigations. Understanding of adversary tactics, techniques and procedures (TTPs), offensive security concepts and MITRE ATT&CK principles. Practical knowledge of cloud environments and security controls, with the ability to apply detection and incident response practices across hybrid ...

Senior Cyber Security Engineer (EDR) Senior Security Engineer – Monitoring & Detection

Hiring Organisation
Sanderson Recruitment
Location
London, United Kingdom
Salary
£ 70 K
threat detection platforms.Create and optimise detection logic using technologies such as Splunk and endpoint security solutions.Map detections against the MITRE ATT&CK framework to ensure comprehensive threat coverage.Continuously improve detection quality by analysing alert fidelity, false positives, and operational effectiveness.Validate detections through testing, simulation exercises … more of the following:Splunk and SPLYARA rule developmentEDR detection engineeringSIEM content development and tuningExperience mapping detections to the MITRE ATT&CK framework.Strong understanding of modern security principles including Zero Trust, identity-first security, secrets management, and network segmentation.Desirable ExperienceExperience with Cribl and security data ...

Senior Cyber Security Engineer (EDR)

Location
Manchester, Lancashire, United Kingdom
threat detection platforms. Create and optimise detection logic using technologies such as Splunk and endpoint security solutions. Map detections against the MITRE ATT&CK framework to ensure comprehensive threat coverage. Continuously improve detection quality by analysing alert fidelity, false positives, and operational effectiveness. Validate detections … following: Splunk and SPL YARA rule development EDR detection engineering SIEM content development and tuning Experience mapping detections to the MITRE ATT&CK framework. Strong understanding of modern security principles including Zero Trust, identity-first security, secrets management, and network segmentation. Desirable Experience Experience with ...

2nd/3rd Line Security Analyst

Location
Reading, England, United Kingdom
sign-ins, malicious OAuth consent, mailbox access), including session/token revocation Design, build and test SIEM detection rules mapped to MITRE ATT&CK, and tune out false positives without blanket whitelisting Build automation for SOC processes - enrichment, ticketing, containment - using Python, Logic Apps, APIs … security incidents from triage through to closure Hands‐on experience writing and tuning SIEM detection logic, with a solid understanding of MITRE ATT&CK and KQL (or equivalent) Practical scripting/automation experience (Python, Logic Apps, REST APIs) or hands‐on SOAR platform configuration Working ...

Senior Detection & Threat Engineer

Hiring Organisation
Checkout.com
Location
London, UK
Employment Type
Full-time
proactive threat hunting based on attacker behaviour, not vendor alertsTranslating threat intelligence and incident learnings into durable, reusable detectionsMapping detections to MITRE ATT&CK and real-world attack pathsReducing alert fatigue through logic refinement, correlation, and contextual enrichmentAdvising and supporting during high-severity security incidents … plane, SaaS)Familiarity with threat intelligence platforms and frameworks such as PCI DSS, NIST CSF, SOC 2, ISO27001, CIS Benchmarks, and MITRE ATT&CK for Cloud. Additional InformationBring all of you to workWe create the conditions for high performers to thrive, through real ownership, fewer ...

Senior Security Sales Engineer

Location
City of Edinburgh, Scotland, United Kingdom
across both AI-assisted analysis and the discovery and control of AI use in client environments. Map detections and demos to MITRE ATT&CK, and be straight with partners about what the product does not do. Cover the wider SentinelOne portfolio Build working fluency across … quickly. Strong Windows and macOS fundamentals: process behaviour, persistence mechanisms, and what normal looks like on an endpoint. Working fluency in MITRE ATT&CK, and real experience tuning policy and handling false positives at scale and surrounding in AI security to hold the conversation credibly ...

Senior Developer Experience Security Engineer

Location
Greater London, England, United Kingdom
tools and technologies, such as SIEM, IDS/IPS, WAF and vulnerability scanners. Knowledge of common adversarial Tactics, Techniques and Procedures (Mitre Att&ck TTPs). Knowledge of security standards and frameworks (e.g. ISO27001, NIST CSF, AWS FSBP) is beneficial. Relevant security certifications (e.g. GCLD … tools and technologies, such as SIEM, IDS/IPS, WAF and vulnerability scanners. Knowledge of common adversarial Tactics, Techniques and Procedures (Mitre Att&ck TTPs). Knowledge of security standards and frameworks (e.g. ISO27001, NIST CSF, AWS FSBP) is beneficial. Relevant security certifications (e.g. GCLD ...

SecOps Engineer

Hiring Organisation
OCS Group
Location
United Kingdom
Salary
£ 60 K
Detection engineering and tuningBuild, test and maintain high-quality detections across our SIEM, XDR and email security platforms, mapped to the MITRE ATT&CK frameworkContinuously tune existing detections to reduce false positives and improve fidelity, using a data-driven approachIdentify gaps in detection coverage proactively … Python, PowerShell or KQL, with a working understanding of APIs and integration patternsPractical understanding of common attack techniques mapped to MITRE ATT&CK, and how they manifest in telemetryA proactive mindset: the candidate must be able to point to specific examples where they have identified ...

Principal Cyber Security Consultant

Hiring Organisation
QinetiQ
Location
Bristol, UK
Employment Type
Full-time
effective risk management across a range of environmentsAssessing cyber vulnerabilities and organisational security maturity using recognised frameworks such as NIST, MITRE ATT&CK and UK Government guidance to provide actionable recommendationsContributing innovative cyber security solutions, methodologies and bid responses that deliver value to customers … evaluating cyber security solutions, architectures and emerging approaches, including Zero Trust, while applying frameworks and standards such as NIST, ISO27001 and MITRE ATT&CK within complex environmentsExtensive experience in a range of different areas/activitiesPrevious experience leading customer engagement and business development activities, creating ...

Principal Cyber Security Consultant

Location
West of England, England, United Kingdom
effective risk management across a range of environments Assessing cyber vulnerabilities and organisational security maturity using recognised frameworks such as NIST, MITRE ATT&CK and UK Government guidance to provide actionable recommendations Contributing innovative cyber security solutions, methodologies and bid responses that deliver value … evaluating cyber security solutions, architectures and emerging approaches, including Zero Trust, while applying frameworks and standards such as NIST, ISO27001 and MITRE ATT&CK within complex environments Extensive experience in a range of different areas/activities Previous experience leading customer engagement and business development ...

Senior Principal (Managing) Cyber Security Consultant

Hiring Organisation
QinetiQ
Location
Bristol, UK
Employment Type
Full-time
effective risk management across a range of environmentsAssessing cyber vulnerabilities and organisational security maturity using recognised frameworks such as NIST, MITRE ATT&CK and UK Government guidance to provide actionable recommendationsContributing innovative cyber security solutions, methodologies and bid responses that deliver value to customers … operational performance, including regulatory and compliance requirementsPrevious experience applying and evaluating cyber security frameworks, standards and approaches such as NIST, ISO27001, MITRE ATT&CK and Zero Trust principlesPrevious experience contributing to business development activities, including solution development, bid writing and winning new opportunities within government ...

Senior Principal (Managing) Cyber Security Consultant

Location
West of England, England, United Kingdom
effective risk management across a range of environments Assessing cyber vulnerabilities and organisational security maturity using recognised frameworks such as NIST, MITRE ATT&CK and UK Government guidance to provide actionable recommendations Contributing innovative cyber security solutions, methodologies and bid responses that deliver value … performance, including regulatory and compliance requirements Previous experience applying and evaluating cyber security frameworks, standards and approaches such as NIST, ISO27001, MITRE ATT&CK and Zero Trust principles Previous experience contributing to business development activities, including solution development, bid writing and winning new opportunities within ...

Director - Security Architecture

Location
Greater London, England, United Kingdom
risks into practical engineering requirements. Drive a threat-led approach to security , using threat modelling, attacker behaviour and frameworks such as MITRE ATT&CK to inform architecture decisions and prioritise controls. Shape security across the complete software delivery lifecycle, including secure SDLC, application security, vulnerability … security . Fluent English and comfortable collaborating across international teams and time zones. Experience with product security, SaaS/software environments, MITRE ATT&CK, infrastructure or network engineering would be valuable, but isn’t essential. Relevant security certifications such as CISSP, CCSP, CSSLP, GIAC ...

Senior Offensive Security Engineer

Location
Greater London, England, United Kingdom
against trading systems, corporate IT, and cloud environments, modeling realistic attacker tactics, techniques, and procedures (TTPs) mapped to frameworks such as MITRE ATT&CK Conduct penetration tests across networks, web and internal applications, APIs, and cloud infrastructure, and report findings with clear, actionable remediation guidance … Burp Suite, Nmap) and a track record of building your own when the situation calls for it Working knowledge of the MITRE ATT&CK framework, adversary emulation, and detection evasion techniques, along with enough understanding of defensive controls and tooling to help defenders improve ...

Principal Security Design Consultant

Location
Greater London, England, United Kingdom
management and data-residency requirements across cloud, on-premises and third-party services. Develop detection and response architectures covering analytics rules, MITRE ATT&CK-aligned use cases, threat hunting, workbooks, watchlists, automation and SOAR playbooks. Design secure integrations with ITSM, CMDB, threat intelligence, vulnerability management … QRadar, Rapid7 or Elastic. Experience with KQL, Sigma, Logic Apps, PowerShell or other automation and detection‐as‐code approaches. Knowledge of MITRE ATT&CK, NIST SP 800-61, NCSC CAF and recognised security operations maturity models. Experience of ITIL‐aligned service design, service transition ...

Senior Microsoft Security Engineer (XDR, IRM, Deception Engineering)

Location
Greater London, England, United Kingdom
scale Detection‐as‐code, CI/CD of detection content, and security content management Strong knowledge of adversary tradecraft and frameworks: MITRE ATT&CK, MITRE Engage, MITRE D3FEND, and the cyber kill chain Experience leveraging Agentic AI, Microsoft Security Copilot ...

Principal Microsoft Defender XDR, IRM & Deception Engineer

Hiring Organisation
Willis Towers Watson
Location
London, UK
Employment Type
Full-time
hunting at scaleDetection-as-code, CI/CD of detection content, and security content managementStrong knowledge of adversary tradecraft and frameworks: MITRE ATT&CK, MITRE Engage, MITRE D3FEND, and the cyber kill chainExperience leveraging Agentic AI, Microsoft Security Copilot ...

Senior Cyber Security Analyst

Hiring Organisation
Context
Location
London, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£80,000
drive proactive security activity. Support Security Risk Management activities, including third-party security assessments. Help improve detection capability, including opportunities around MITRE ATT&CK-aligned detection engineering Identify opportunities to automate repetitive SOC processes using SOAR, orchestration and AI-assisted tooling Requirements: Strong previous experience … working with technologies such as Defender XDR, SIEM, EDR, Vulnerability Management and SOAR platforms Familiarity with security and vulnerability frameworks (e.g. MITRE ATT&CK, CVSS, CISA KEV and NIST) Ability to query and analyse structured security and log data A broader technical IT background, ideally ...

Senior SOC Analyst

Hiring Organisation
Sopra Steria
Location
Farnborough, Hampshire, South East, United Kingdom
Employment Type
Permanent
Salary
£55,000
Lead and support incident response activities, providing expert guidance on containment, eradication and recovery. Enhance detection rules and use cases using MITRE ATT&CK and threat-informed defence techniques. Support threat intelligence activities and contribute to the continuous improvement of SOC operations. What … Bring: Proven experience working within a Security Operations Centre. Hands-on experience with Microsoft Sentinel and Splunk. Strong understanding of MITRE ATT&CK. It would be great if you had: Networking protocols and infrastructure (TCP/IP, LAN/WAN, HTTP, SMTP, FTP, LDAP). Firewalls, VPNs ...

Threat Hunting & Detection Analyst

Hiring Organisation
Accenture
Location
London, UK
Employment Type
Full-time
potential. Key Responsibilities: Threat Detection Use Case DevelopmentDesign and implement detection logic aligned to specific threat scenarios using frameworks such as MITRE ATT&CK. Develop, test, deploy, and tune detection content throughout its lifecycle. Work closely with Client Lead Analysts to ensure detection content remains relevant … Hunting, Detection Engineering, or Cyber Security Operations environment. Experience developing, testing, and tuning threat detection use cases. Good understanding of the MITRE ATT&CK framework and common threat actor tactics, techniques, and procedures (TTPs). Experience conducting proactive threat hunting and analysing security telemetry. Strong ...

3rd Line Security Analyst

Location
Reading, England, United Kingdom
optimise detection content across Microsoft Sentinel, Defender XDR, CrowdStrike and associated platforms, developing advanced KQL queries and analytics rules aligned to MITRE ATT&CK. Act as senior technical owner for security platforms including Microsoft Sentinel, Defender XDR, CrowdStrike Falcon, Entra ID, Intune, Darktrace and supporting technologies, managing … understanding of Azure, AWS and hybrid infrastructure security, with strong knowledge of networking, operating systems and attacker techniques. Practical understanding of MITRE ATT&CK, Cyber Kill Chain, NIST and SANS incident response frameworks. Experience working within regulated and audited environments, including ISO 27001 and Cyber ...

Senior Security Operations Centre Analyst

Hiring Organisation
Sopra Steria
Location
Aldershot, Hampshire, United Kingdom
Salary
£ 70 K
Lead and support incident response activities, providing expert guidance on containment, eradication and recovery. Enhance detection rules and use cases using MITRE ATT&CK and threat-informed defence techniques. Support threat intelligence activities and contribute to the continuous improvement of SOC operations. What … Bring: Proven experience working within a Security Operations Centre. Hands-on experience with Microsoft Sentinel and Splunk. Strong understanding of MITRE ATT&CK. If you are interested in this role but not sure if your skills and experience are exactly what we’re looking for, please ...

Security Detection & Response II

Hiring Organisation
Bank of America
Location
Chester, Cheshire, United Kingdom
Salary
£ 70 K
will build, validate, tune, and optimize detection logic and coverage, leveraging attacker tactics, techniques, and procedures (TTPs) and frameworks such as MITRE ATT&CK to improve accuracy and reduce false positivesExecute and coordinate security event response activities, including containment, isolation, escalation, and remediation, applying sound … attack paths, including credential theft, privilege escalation, and session/token abuseConsiderable understanding of attacker tactics, techniques, and procedures (TTPs), including MITRE ATT&CKRecord of improving operational effectiveness, including reducing alert noise, improving detection coverage, and decreasing mean time to detect and respondGreat analytical, decision-making ...

Lead Security Analyst

Location
United Kingdom
standard — author, tune, and peer‐review detections in KQL, SPL, EQL, or Sigma; manage the false‐positive backlog; map coverage to MITRE ATT&CK; and train L1/L2 analysts to write and tune detections themselves. Own the threat‐landscape narrative for your engagement — turn intelligence from … similar environment— including writing and tuning detections in KQL, SPL, EQL, or Sigma, and managing coverage against MITRE ATT&CK Experience designing or improving a log and telemetry pipeline, including application‐level telemetry from cloud‐hosted services (AWS is a strong preference at this grade ...