626 to 650 of 684 SIEM Jobs in the UK

Lead Security Operations Engineer

Location
Greater London, England, United Kingdom
structured roadmap based on MITRE ATT&CK, NIST, and CIS benchmarks Lead security investigations and digital forensics through incident response Design, tune, and scale SIEM and standardized logging pipelines Strengthen perimeter and authentication security through WAF configuration, authorization tuning, and suspicious-traffic monitoring Implement DLP controls aligned with sensitive-data … risk reduction through monetary impact, incidents contained, or forensics that changed outcomes Strong development and engineering background, including writing automation Hands-on SOC and SIEM management experience Experience in detection engineering and log pipeline design Experience building security capability in scale-up environments Strong understanding of cloud architectures, especially ...

Senior Security Engineer

Hiring Organisation
Spendesk
Location
London, United Kingdom
Salary
£ 80 K
lead on complex or high-severity findings.Lead security incident response: qualification, forensics (including fraud investigations), fix coordination, post-mortem, and resolution tracking.Detection & SIEMOwn our SIEM platform (ElasticSearch, multi-node Linux): architecture, detection rules, and indicators of compromise.Build and evolve detection coverage, focusing on signal quality over manual toil.Build and maintain … owning security outcomes end to end, with hands-on experience across at least three of: code auditing, infrastructure security (AWS/Linux), penetration testing, SIEM operations, incident response.Ability to own a roadmap: identify priorities, build a plan, execute autonomously, and communicate progress to non-specialists.Deep understanding of modern web architectures ...

Senior Detection and Response Engineer

Location
Cambridge, England, United Kingdom
Requirements Hands-on experience investigating security incidents, including developing investigation hypotheses, collecting artefacts and analysing endpoint, network and application data. Strong working knowledge of SIEM and security monitoring tooling, including the ability to write and develop queries for complex investigations. Understanding of adversary tactics, techniques and procedures (TTPs), offensive security … MITRE ATT&CK and enhancing security telemetry through automation and tooling. Highest-signal resume keywords Incident Investigation Detection Logic Development MITRE ATT&CK Framework SIEM Tooling Cloud Security Practices ATS Optimization Keywords Hard Skills Security Incident Investigation Detection Rule Development Threat Hunting Forensic Investigation Scripting (PowerShell, Python) Industry Keywords Adversary ...

IT Security & Compliance Lead

Location
City of Edinburgh, Scotland, United Kingdom
and external partners (e.g. SOCaaS providers), and running post‐incident reviews and tabletop exercises. Operate and tune security monitoring and detection tooling (EDR, DLP, SIEM, or similar) to catch and respond to threats quickly. Compliance & Certification Own SOC 2 Type II and ISO 27001/27017/… post‐incident review. Working knowledge of SOC 2 and the ISO 27000 series. Comfortable evaluating and operating security tooling such as EDR, DLP, or SIEM platforms. A strong cross‐functional operator, comfortable bridging IT, Security, Engineering, and GTM teams. Valued Exposure to privacy regulation (e.g. GDPR) and AI governance frameworks ...

AI Staff Security Engineer

Hiring Organisation
Matchtech
Location
London, United Kingdom
Salary
£ 100 K
protect proprietary models and systems from novel threats like prompt injection, data poisoning, and model inversion/extraction.Automate critical security workflows using Agentic/SIEM integration to achieve high operational velocity and enable rapid response to millisecond attack speeds generated by autonomous adversary AI.Execute regular offensive security operations, including … Teaming/Penetration Testing against agentic frameworks and LLM integrations.Demonstrated ability to engineer or deploy AI Detection and Response (AIDR) workflows utilizing agentic and SIEM technologies, with a strong focus on AI-native threat modeling (e.g., MAESTRO framework).Understanding of Governance, Risk, and Compliance (GRC), specifically managing AI governance policies ...

AI Staff Security Engineer

Hiring Organisation
Matchtech
Location
London, UK
Employment Type
Full-time
proprietary models and systems from novel threats like prompt injection, data poisoning, and model inversion/extraction. Automate critical security workflows using Agentic/SIEM integration to achieve high operational velocity and enable rapid response to millisecond attack speeds generated by autonomous adversary AI.Execute regular offensive security operations, including …/Penetration Testing against agentic frameworks and LLM integrations. Demonstrated ability to engineer or deploy AI Detection and Response (AIDR) workflows utilizing agentic and SIEM technologies, with a strong focus on AI-native threat modeling (e.g., MAESTRO framework).Understanding of Governance, Risk, and Compliance (GRC), specifically managing AI governance policies ...

Lead Security Operations Engineer at location: Remote - United Kingdom, Denmark, Portugal, Spain

Location
United Kingdom
from suspicious traffic through to full incident response, and bring the findings back into how we detect and prevent. Design, tune, and scale our SIEM and logging pipeline through standardized log ingestion across services so signal isn't lost in the noise. Strengthen our perimeter and authentication posture, including … forensics that changed outcomes. A strong development and engineering background. You are comfortable writing the automation, not just specifying it. Hands-on SOC and SIEM management experience, including detection engineering and log pipeline design. Experience in scale-up environments, where you've built capability rather than inherited a mature one. ...

Security Engineer, Institutional Trading

Hiring Organisation
Blockchain
Location
London, United Kingdom
Salary
£ 80 K
and maintain monitoring for FinOps-specific security signals such as abnormal order patterns, signature misuse, unusual settlements. You will integrate these signals into our SIEM/SOAR for real-time response.Support secrets and key-management hygiene. You will ensure app/service keys are stored in KMS/Vault, scoped … experience.Proven expertise in Threat Modeling. Ability to perform structured reviews (e.g., STRIDE) of complex data flows and operational processes.Experience with observability and detection tooling (SIEM, logs, metrics) and ability to write basic detection rules.Practical experience with KMS/HSM, secrets management platforms (Vault, 1Password, AWS/GCP KMS), IAM patterns ...

Senior Cyber Security Analyst

Hiring Organisation
Roc Search Limited
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
Salary negotiable
security technologies including Mimecast, Netskope and CyberArk . Investigating and responding to security alerts and incidents. Working alongside the firm's external SOC/SIEM provider. Maintaining security documentation and evidence. Supporting the organisation's ISO 27001 certification programme. Assisting the Lead Cyber Engineer with security projects and improvements. Helping … particularly interested in candidates who have: Good knowledge of cybersecurity and security operations. Experience investigating security alerts, incidents or vulnerabilities. Exposure to SIEM and security monitoring . Experience with technologies such as Mimecast, Netskope, CyberArk, PAM or similar . Strong analytical and problem-solving skills. A collaborative approach and willingness ...

Security Architect

Hiring Organisation
Develop
Location
South West London, London, United Kingdom
Employment Type
Permanent, Work From Home
and customer-facing teams to develop modern security capabilities and influence long-term technology strategy. Key responsibilities include: Designing enterprise security architectures across SIEM, SOAR, EDR and Cloud Security platforms. Defining architecture standards and technical governance. Designing secure integrations between security platforms and cloud services. Improving detection engineering, security automation … experienced Security Architect or a Senior Security Engineer ready to step into an architecture role. You'll ideally have experience with: Enterprise Security Architecture SIEM SOAR EDR Microsoft Security Microsoft Sentinel Microsoft Defender SentinelOne Cloud Security Azure Detection Engineering Security Automation Security Governance API integrations Security Platform Design Experience with ...

Software Engineer II, Security

Hiring Organisation
EverQuote
Location
Belfast, Down, United Kingdom
Salary
£ 60 K
Software Engineer II, SecurityLocation: Belfast, NI/Hybrid(This role requires working in-office 3 days per week.)About us:EverQuote is a leading AI-powered growth solutions partner for regulated property and casualty insurance ...

Software Engineer II, Security

Hiring Organisation
EverQuote
Location
Belfast, UK
Employment Type
Full-time
Software Engineer II, SecurityLocation: Belfast, NI/Hybrid(This role requires working in-office 3 days per week.)About us: EverQuote is a leading AI-powered growth solutions partner for regulated property and casualty insurance ...

SOAR Engineer

Hiring Organisation
Sanderson Government and Defence
Location
Cheltenham, Gloucestershire, South West, United Kingdom
Employment Type
Permanent
SOAR/SIEM Security Engineer - Critical National Infrastructure (OT) 18-Month FTC | SC Cleared A leading cyber security firm is looking for a SOAR/SIEM Security Engineer to join a critical national infrastructure (CNI) client on an 18-month fixed-term contract, supporting the protection of operational technology ...

SecOps Engineer

Hiring Organisation
OCS Group
Location
London, United Kingdom
Salary
£ 70 K
fixes, build them, and measure the outcomeMain Duties & Responsibilities of the Role Detection engineering and tuningBuild, test and maintain high-quality detections across our SIEM, XDR and email security platforms, mapped to the MITRE ATT&CK frameworkContinuously tune existing detections to reduce false positives and improve fidelity, using a data … that give analysts and leadership a clear view of operational healthPlatform health and configurationOwn the configuration and ongoing health of assigned SecOps platforms, including SIEM, EDR, email security and identity protection Monitor for configuration drift, agent coverage gaps and ingestion failures, and resolve them at sourceLead technical onboarding ...

SOC Level 3 Technical Lead

Hiring Organisation
Oscar Associates (UK) Limited
Location
Buckinghamshire, South East, United Kingdom
Employment Type
Permanent
Salary
£70,000
pressure and brief client leadership, up to board level, in language they can act on Run proactive threat hunts and build detection content across SIEM, EDR and cloud platforms, tuning out noise as you go Develop SOAR playbooks and automation, and help shape the SOC's tooling roadmap and architecture … breach cases you can walk through in depth Advanced hands-on malware analysis capability, spanning behavioural analysis and reverse engineering Deep expertise across enterprise SIEM platforms and EDR tooling (CrowdStrike knowledge a strong advantage) A well-developed threat hunting toolkit: YARA rules, IOC development, timeline analysis and adversary profiling Cloud ...

Security Engineer - MOD/Defence - DV Cleared

Hiring Organisation
Talent Locker
Location
Farnborough, Hampshire, South East, United Kingdom
Employment Type
Permanent
Salary
£80,000
and improve security platforms controlling privileged access, credentials and administrative activity across critical infrastructure. There is also a requirement within the team for Elastic SIEM capability, so if you have strong Elastic experience alongside your security engineering background, that would also be relevant. The role You'll work across identity … group access. Monitoring privileged sessions and investigating failed authentication activity. Maintaining, patching and upgrading security platforms. Reviewing audit logs and integrating security events with SIEM tooling. Troubleshooting firewalls, load balancers and connectivity issues. Key experience Hands-on Security Engineering within complex environments. Privileged Access Management (PAM) or identity security solutions. ...

Cyber Security Engineer - SIEM & Automation (Onsite)

Location
Stevenage, England, United Kingdom
Stevenage on a 24-month contract, onsite. The role focuses on implementing, maintaining, and optimising security technologies across complex environments. Key tasks include SIEM administration, log ingestion, automation via PowerShell/Python, and API integrations. This is a hands-on engineering position within the Defence sector, with strong emphasis ...

Security Engineer, Detection and Response

Location
Greater London, England, United Kingdom
infrastructure, high-performance computing environments, or other distributed systems at scale Strong programming skills in Python, KQL, SPL, or similar languages Experience with SIEM platforms, detection technologies, and forensic investigation techniques Ability to build detection for novel attack techniques and conduct forensics in complex distributed environments Track record of securing … and collaborating across security and AI research teams. Highest-signal resume keywords AI Security Threat Detection Incident Response Coordination Forensic Investigation Techniques Python Programming SIEM Platform Experience Hard Skills Detection Engineering Threat Hunting Data Poisoning Prevention Model Extraction Security Adversarial Example Mitigation Automated Response Playbooks Detection-as-Code Frameworks ...

Cyber Security Analyst

Hiring Organisation
VIQU IT Recruitment
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£350.00 - £450.00 per day
IR35 My Client is looking for a Cyber Security Analyst to support day-to-day BAU security operations, with a primary focus on Rapid7, SIEM monitoring, vulnerability management and security investigations . They have quite a few backlog of alerts, so they are looking for someone with strong SIEM, vulnerability … and investigation skills. Key Skills & Experience from the Cyber Security Analyst: Strong hands-on experience with Rapid7 and SIEM platforms . (Monitoring alerts and investigation) Proven experience in alert triage, security investigations and vulnerability management . Strong Mimecast administration experience (Email review, releasing, whitelisting, sandboxing) Good working knowledge of Microsoft ...

SOC Analyst - Tier 2 and Tier 3 (SC and DV)

Hiring Organisation
Pigment Consulting
Location
Manchester Area, United Kingdom
Responsibilities: Tier 2 SOC Analyst You will be responsible for investigating and responding to security incidents escalated from Tier 1, including: Detailed investigation of SIEM, EDR, network and authentication alerts. Threat hunting and identification of indicators of compromise. Investigation of phishing, malware, credential compromise and suspicious activity. Supporting containment, eradication … and mentoring to Tier 1 and Tier 2 SOC analysts. Required experience: Proven experience within a SOC, security monitoring or incident response environment. Strong SIEM and security event investigation experience. Experience with EDR/XDR technologies. Good understanding of cyber attack techniques and MITRE ATT&CK. Experience investigating common security ...

SOC Analysts - L2 and L3 (SC and DV-Cleared)

Hiring Organisation
Pigment Consulting
Location
Manchester, North West, United Kingdom
Employment Type
Contract
Responsibilities: Tier 2 SOC Analyst You will be responsible for investigating and responding to security incidents escalated from Tier 1, including: Detailed investigation of SIEM, EDR, network and authentication alerts. Threat hunting and identification of indicators of compromise. Investigation of phishing, malware, credential compromise and suspicious activity. Supporting containment, eradication … and mentoring to Tier 1 and Tier 2 SOC analysts. Required experience: Proven experience within a SOC, security monitoring or incident response environment. Strong SIEM and security event investigation experience. Experience with EDR/XDR technologies. Good understanding of cyber attack techniques and MITRE ATT&CK. Experience investigating common security ...

Cyber Security Analyst

Hiring Organisation
Seymour John Ltd
Location
Nationwide, United Kingdom
Employment Type
Contract
Contract Rate
£400/day
enterprise environment. Key responsibilities include: Monitoring and responding to security incidents Investigating cyber security alerts Microsoft Defender for Endpoint (MDE) analysis and remediation Managing SIEM, EDR and NDR alert activity Supporting cyber incident response processes Assisting with security investigations and reporting Supporting information security and compliance activities Working closely with … resilience Experience Required We're particularly interested in candidates with experience of: NHS experience Microsoft Defender for Endpoint (MDE) Security Operations or SOC environments SIEM monitoring and incident response Endpoint Detection and Response (EDR) Network Detection and Response (NDR) Microsoft 365 Security Threat investigation and remediation Cyber security frameworks and ...

Staff Security Engineer London, UK

Location
Greater London, England, United Kingdom
cause and remediation. Build and maintain security automation workflows (e.g., in Tines) that reduce manual toil in detection, triage, and response. Own and improve SIEM/data pipeline health, including log source coverage, parsing/normalization, and alert quality. Develop cross-functional relationships to influence security initiatives and drive adoption … advanced proficiency in at least one scripting language for tasks like response automation and using REST APIs to automate security operations work. Experience with SIEM platforms and security data pipelines (e.g., Google SecOps) — you understand log source onboarding, parsing, and alert tuning, not just querying. Hands‐on experience with ...

Programme Manager

Hiring Organisation
Circle Group
Location
London, United Kingdom
Employment Type
Contract, Work From Home
Contract Rate
£500 - £550 per day
delivery across Cyber Security, SOC, Infrastructure, Cloud, IAM, Network and Service Management teams. Drive the implementation and enhancement of Security Operations capabilities, including SOC, SIEM, detection and response, vulnerability management and incident response. Manage the transition of new security capabilities into live operational services. Work closely with security architects and … programmes within enterprise environments. Strong understanding of Security Operations and the delivery of operational cyber capabilities. Experience delivering programmes involving areas such as SOC, SIEM, incident response, threat detection, vulnerability management, security tooling or security service transformation. Proven experience transitioning security capabilities from project delivery into BAU operations. Strong programme ...

Programme Manager

Hiring Organisation
Circle Recruitment
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£500.00 - £550.00 per day
delivery across Cyber Security, SOC, Infrastructure, Cloud, IAM, Network and Service Management teams. Drive the implementation and enhancement of Security Operations capabilities, including SOC, SIEM, detection and response, vulnerability management and incident response. Manage the transition of new security capabilities into live operational services. Work closely with security architects and … programmes within enterprise environments. Strong understanding of Security Operations and the delivery of operational cyber capabilities. Experience delivering programmes involving areas such as SOC, SIEM, incident response, threat detection, vulnerability management, security tooling or security service transformation. Proven experience transitioning security capabilities from project delivery into BAU operations. Strong programme ...