176 to 200 of 237 SOAR Jobs in the UK

Senior SOC Analyst

Hiring Organisation
Corpay
Location
Walsall, West Midlands (County), United Kingdom
Salary
£ 70 K
reduce false positives and improve detection quality.Examining and correlating log data across endpoints, databases, applications, identity systems, networks, mobile platforms, and cloud environments.Working with SOAR platforms, SIEM technologies, MCP solutions, threat intelligence sources, endpoints, applications, network devices, and cloud environments.Mentoring junior analysts and supporting the development of the wider … experience in cybersecurity, particularly within SOC, incident response, and information technology environments.Strong technical understanding of emerging cybersecurity threats, including adversary use of AI.Experience with SOAR, SIEM, threat intelligence platforms, identity systems, sandboxes, vulnerability management, and EDR/XDR tools.Broad understanding of endpoints, applications, network devices, databases, cloud environments, and security ...

SOAR Playbook Engineer

Location
Manchester, England, United Kingdom
SOAR Playbook Engineer Department: Cyber Services and Capabilities Employment Type: Full Time Location: GBR Manchester Hardman Boulevard Reporting To: Kai Leenders Description As an MXDR SOAR Engineer, you design, develop, maintain and optimise security automation solutions using Splunk SOAR and similar automation platforms. Your primary focus is playbook engineering, Python … across technical and business functions, and help ensure their environments remain secure, resilient, and operationally effective. You act as the technical authority for Splunk SOAR, supporting customers and internal teams by translating operational requirements into scalable automations. Experience with Splunk SOAR is essential. This role requires a broad combination ...

AI-Driven Cyber Operations Leader for Incident Response

Location
England, United Kingdom
security operations and cyber defence across cloud and on-premises environments. Reporting to the CISO, you will drive detection engineering, SOAR automation, and AI integration, while managing MSSP/vendor governance and delivering executive risk reporting. #J-18808-Ljbffr ...

Senior GCP SecOps Engineer - SIEM/SOAR, Flexible & Remote

Location
Manchester, England, United Kingdom
Bynd Limited is searching for a Senior Security Engineer in Manchester to lead security deployments for regulated clients, primarily in Google Cloud environments. This role involves hands-on technical work, mentoring junior team members, and ...

Senior Security Analyst (L3 SOC Analyst)

Location
City Of London, England, United Kingdom
Conduct proactive threat hunting activities using threat intelligence, behavioural analytics and industry frameworks to identify previously undetected threats. Develop and enhance security automation and SOAR playbooks to improve operational efficiency, response capability and analytical effectiveness. Mentor and support SOC analysts while contributing to the ongoing maturity of detection engineering, incident … senior SOC environment, including working in an L3 analyst, incident response, threat hunting or detection engineering capacity. Deep technical knowledge of SIEM, EDR, SOAR, cloud security, identity security, endpoint security and enterprise monitoring platforms. Proven experience leading the investigation and response to complex cyber security incidents and acting ...

Senior Security Analyst (L3 SOC Analyst)

Location
Greater London, England, United Kingdom
Conduct proactive threat hunting activities using threat intelligence, behavioural analytics and industry frameworks to identify previously undetected threats.* Develop and enhance security automation and SOAR playbooks to improve operational efficiency, response capability and analytical effectiveness.* Mentor and support SOC analysts while contributing to the ongoing maturity of detection engineering, incident … senior SOC environment, including working in an L3 analyst, incident response, threat hunting or detection engineering capacity.* Deep technical knowledge of SIEM, EDR, SOAR, cloud security, identity security, endpoint security and enterprise monitoring platforms.* Proven experience leading the investigation and response to complex cyber security incidents and acting ...

Senior Security Engineer (GCP)

Location
Manchester, England, United Kingdom
Google Cloud Estates. As a Premier Google Cloud Partner, we deliver Google Unified Security (GUS) engagements across the full stack — from greenfield SIEM/SOAR deployments and SOC modernisation programmes to detection engineering, posture management, threat hunting, and incident response uplift. Secure GCP estates with the adoption of CI/… rule packs, playbooks, and points of view that make the next engagement faster than the last. What you'll do Google SecOps (SIEM/SOAR) Lead end‐to‐end SecOps deployments — tenant setup, multi‐tenant architecture, data ingestion, retention design, RBAC, and feed onboarding. Build and maintain parsers, UDM mappings ...

Cyber Security Engineer

Location
City Of London, England, United Kingdom
cyber security capabilities. You will have a broad remit across Microsoft security technologies, identity and access management, vulnerability management, incident response, SIEM/SOAR, threat hunting and cloud security , while also providing security advice to technology projects and supporting security‐by‐design principles. Key Responsibilities Design, implement and maintain cyber … Online, SharePoint and Teams. Support identity and access management, vulnerability management and security monitoring . Investigate and respond to security incidents, including SIEM/SOAR investigations and advanced threat hunting. Support security reviews, audits and annual penetration testing. Identify vulnerabilities, risks and opportunities to improve the organisation's security posture. ...

Cyber Security Engineer

Location
Greater London, England, United Kingdom
cyber security capabilities. You will have a broad remit across Microsoft security technologies, identity and access management, vulnerability management, incident response, SIEM/SOAR, threat hunting and cloud security, while also providing security advice to technology projects and supporting security-by-design principles. Key Responsibilities Design, implement and maintain cyber … Exchange Online, SharePoint and Teams. Support identity and access management, vulnerability management and security monitoring. Investigate and respond to security incidents, including SIEM/SOAR investigations and advanced threat hunting. Support security reviews, audits and annual penetration testing. Identify vulnerabilities, risks and opportunities to improve the organisation's security posture. ...

SOC Subject Matter Expert (UK)

Location
Horsham, England, United Kingdom
Lead Deep understanding of end‐to‐end SOC operations including alert triage, incident response, threat hunting, and case management Extensive experience with SIEM platforms, security orchestration tools, and the broader SOC technology stack Strong knowledge of threat detection methodologies, alert correlation, and incident prioritisation frameworks Expert‐level understanding of MITRE … Tier 3 SOC roles with incident response and threat hunting responsibilities. Previous involvement in SOC tool evaluation, selection, or implementation projects. Experience with security automation, SOAR platforms, or playbook development. Experience working with or partnering with SOC/SIEM/EDR vendors and MSSP (Managed Security Service Provider) vendors. Familiarity ...

Engineer - Splunk

Location
Greater London, England, United Kingdom
Services and Capabilities Location: GBR Manchester Hardman Boulevard Description We are seeking an experienced Splunk Engineer to help design, build, and manage our Splunk SOAR service, with a strong focus on automation, security response, and service maturity. This role will be responsible for developing, reviewing, testing, and deploying Splunk SOAR … ensuring they are secure, reliable, and aligned with security governance and operational needs. The role requires a technically strong Splunk engineer with experience in SOAR development, Splunk architecture, and security engineering best practices. You will work closely with SOC teams, security engineers, and customers, owning your own workload and providing ...

Engineer - Splunk

Location
Cheltenham, England, United Kingdom
Fixed Term Contract Location: GBR Cheltenham Jessop House Description We are seeking an experienced Splunk Engineer to help design, build, and manage our Splunk SOAR service, with a strong focus on automation, security response, and service maturity. This role will be responsible for developing, reviewing, testing, and deploying Splunk SOAR … ensuring they are secure, reliable, and aligned with security governance and operational needs. The role requires a technically strong Splunk engineer with experience in SOAR development, Splunk architecture, and security engineering best practices. You will work closely with SOC teams, security engineers, and customers, owning your own workload and providing ...

SOC Automation Engineer

Location
Pocklington, England, United Kingdom
with SOC, engineering and service delivery teams to understand operational requirements and deliver automation solutions. Build and maintain integrations with security technologies including SIEM, SOAR, EDR, threat intelligence and cloud platforms. Leverage APIs and external data sources to enhance security workflows and processes. Explore and implement AI-enhanced automation capabilities … and systems integration. Experience working within a Security Operations, Incident Response, Threat Engineering or Security Engineering environment. Understanding of modern security technologies including SIEM, SOAR, EDR, IAM, threat intelligence and vulnerability management solutions. Knowledge of cloud security and cloud-based platforms. Awareness of AI technologies and their practical application within ...

SOAR Engineer

Hiring Organisation
Sanderson Government and Defence
Location
Cheltenham, Gloucestershire, South West, United Kingdom
Employment Type
Permanent
SOAR/SIEM Security Engineer - Critical National Infrastructure (OT) 18-Month FTC | SC Cleared A leading cyber security firm is looking for a SOAR/SIEM Security Engineer to join a critical national infrastructure (CNI) client on an 18-month fixed-term contract, supporting the protection of operational technology … across converged IT/OT infrastructure. You'll be working on live, high-stakes environments. What you'll be doing Designing, building, and maintaining SOAR playbooks to automate detection and response workflows Developing and tuning Splunk use cases, dashboards, and correlation searches across IT and OT data sources Supporting incident ...

SOAR Engineer

Location
Bradley Stoke, England, United Kingdom
SOAR/SIEM Security Engineer - Critical National Infrastructure (OT) 18-Month FTC | SC Cleared A leading cyber security firm is looking for a SOAR/SIEM Security Engineer to join a critical national infrastructure (CNI) client on an 18-month fixed-term contract, supporting the protection of operational technology … across converged IT/OT infrastructure. You'll be working on live, high-stakes environments. What you'll be doing Designing, building, and maintaining SOAR playbooks to automate detection and response workflows Developing and tuning Splunk use cases, dashboards, and correlation searches across IT and OT data sources Supporting incident ...

Presales Executive (Cyber Security)

Location
Leeds, England, United Kingdom
strategy and technical execution across SEP2’s core portfolio, including the Wingman Managed Services Suite (mXDR, MDR, EDR, Managed Firewalls, vCISO), Google SecOps (SIEM, SOAR, Mandiant Threat Intelligence), and vendor partner technologies (e.g., Check Point, Wiz, SentinelOne, CrowdStrike) and services for our clients. This is a Hybrid position with … solutions are scalable, operationally deliverable, and compliant with customer RACI expectations. Demonstrations & Proof of Concepts (POC) Deliver compelling, outcome-based product demonstrations covering SIEM, SOAR, EDR, Cloud Security, and Threat Intelligence platforms. Manage and execute end-to-end technical Proof of Concepts (POCs) for client opportunities, establishing clear success criteria ...

Interim Cyber Security Officer

Location
Greater London, England, United Kingdom
technical escalation point for high‐severity security incidents, facilitating rapid investigation, containment, and remediation using EDR and SIEM tools. Develop and implement SOAR workflows to automate detection, response, and security operations processes. Conduct proactive threat hunting using SIEM/EDR data and MITRE ATT&CK‐aligned techniques. Support vulnerability assessment … network protocols, cloud security (AWS/Azure), and threat detection methodologies. Working knowledge of the MITRE ATT&CK framework. Experience building automation or SOAR playbooks for security operations. CrowdStrike certifications (CCFA/CCFR/CCSE – any combination preferred). Splunk Certified Cybersecurity Defense Engineer (mandatory preferred requirement). Security certifications ...

Senior Corporate Security Engineer

Hiring Organisation
Deliveroo
Location
London, United Kingdom
Salary
£ 80 K
OAuth 2.0, OpenID Connect).Practical experience securing macOS, Windows and Linux endpoints using MDM and EDR/XDR tooling.Experience operating SIEM and/or SOAR platforms and tuning detection logic.Experience with vulnerability management and patch governance.Ability to write production-quality automation scripts.Demonstrated experience leading cross-functional technical initiatives.Desirable SkillsExperience with … Zero Trust Network Access platforms.Hands on experience deploying applications into K8 and Docker environmentsData Loss Prevention (DLP) and SaaS security governance.Advanced detection engineering or SOAR playbook development.Experience supporting ISO 27001 or SOC 2 audits.Relevant certifications (e.g. CISSP, CISM, GIAC).Workplace & BenefitsAt Deliveroo we know that people are the heart ...

Lead SOC Architect

Hiring Organisation
Anson Mccade
Location
Central London, London, United Kingdom
Employment Type
Permanent
concepts, CONOPS and high/low-level architecture designs • Working directly with senior client and government stakeholders • Designing and integrating security technologies including SIEM, SOAR, EDR, Threat Intelligence and Vulnerability Management • Assessing existing SOC capabilities and developing security maturity • Designing scalable, resilient on-prem and cloud security architectures • Supporting accreditation … and operation They're looking for: • Strong experience in SOC architecture and security operations • Hands-on architectural experience across at least two of SIEM, SOAR, EDR, Vulnerability Management or Threat Intelligence • Strong understanding of security operations, threat detection and incident response • Experience designing both on-prem and cloud security architectures ...

AI & Automation Engineering, Global Security (Vice President)

Location
Greater London, England, United Kingdom
configuration drift detection, data classification and DLP event triage, and vulnerability prioritisation and contextualisation. Develop LLM and agent-based workflows integrated with SIEM, EDR, SOAR, IGA, PAM, CSPM, DLP, ticketing and threat intelligence platforms via supported APIs. Set the global AI Security and automation roadmap in partnership with the Head … tool and function calling, orchestration, and evaluation or regression testing of non-deterministic outputs. Working knowledge of security operations tooling and workflow - SIEM, EDR, SOAR, case management, threat intelligence. Practical familiarity with at least two additional security domains from identity and access management, privileged access, network or cloud security ...

Senior Security Architect - SecOps and Vulnerability Management

Hiring Organisation
JP Morgan Chase
Location
London, United Kingdom
Salary
£ 100 K
risks.Design a risk-based vulnerability management platform that automatically prioritizes infrastructure and application flaws utilizing real-world exploit intelligence and asset criticality.Build and optimize SOAR playbooks to automate incident response workflows, accelerate threat containment, and streamline vulnerability ticketing.Provide senior technical escalation support during critical security incidents and drive post-incident … Qualys, or Wiz, specifically utilizing EPSS (Exploit Prediction Scoring System) alongside CVSS to determine patching prioritisation.Ability to design and influence automated response playbooks using SOAR platformsPractical experience creating reference architectures and patterns for engineering teams.Proven ability to design and deploy automated preventive and detective guardrails at scale.Ability to solve design ...

Senior Security Architect - SecOps and Vulnerability Management

Hiring Organisation
JP Morgan Chase
Location
London, UK
Employment Type
Full-time
risk-based vulnerability management platform that automatically prioritizes infrastructure and application flaws utilizing real-world exploit intelligence and asset criticality. Build and optimize SOAR playbooks to automate incident response workflows, accelerate threat containment, and streamline vulnerability ticketing. Provide senior technical escalation support during critical security incidents and drive post-incident … specifically utilizing EPSS (Exploit Prediction Scoring System) alongside CVSS to determine patching prioritisation. Ability to design and influence automated response playbooks using SOAR platformsPractical experience creating reference architectures and patterns for engineering teams. Proven ability to design and deploy automated preventive and detective guardrails at scale. Ability to solve design ...

Automation Engineer II, Falcon Complete (Remote)

Hiring Organisation
CrowdStrike
Location
United Kingdom
Salary
£ 45 K
moderate scope which often call for detailed analysis of situations or data, requiring review of a variety of factors. You will focus on building SOAR playbooks, AI-powered workflows, and scripted solutions while exercising judgment within defined procedures and practices, with general instructions on new assignments.What You'll Do:Automation … DevelopmentAssist in building and maintaining security automation workflows and playbooks in SOAR platforms to streamline investigation, triage, and response actionsDevelop PowerShell and Python scripts for security enrichment, remediation, and basic forensic functionsAssist with SIEM query integration into automated workflows to provide context for security investigationsApply data parsing techniques using JSON ...

Security Engineer - SIEM/XDR - London (Hybrid)

Hiring Organisation
Nova Source Technologies
Location
London, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£70,000
Security Engineer (SIEM/XDR) Microsoft Sentinel, Defender, Endpoint, Detection Engineering, Detection-as-Code, KQL, Security Automation, SOAR, Playbooks, Telemetry, Cloud Security, APIs, CI/CD, Infrastructure-as-Code, Python, PowerShell, Windows, Linux, London (Hybrid) This is an exceptional permanent Security Engineer (SIEM/XDR) opportunity to join a leading … security content and alert logic Security telemetry, logging pipelines, data quality and telemetry coverage improvement Cloud security engineering and scalable security architecture design Automation, SOAR, playbooks, enrichment workflows and response improvement Scripting/programming skills such as Python and PowerShell Infrastructure-as-code, CI/CD pipelines, version control and ...

Senior Security Engineer

Hiring Organisation
FACEIT
Location
United Kingdom
Salary
£ 70 K
researchers;Security Engineering & Orchestration: Design, implement, and optimize core security infrastructure (e.g. EDR,, Zero Trust, IAM, and DLP). Focus on automation and orchestration (SOAR) to reduce manual overhead and ensure security controls are consistently enforced across a global, multi-cloud environment;Incident Response Leadership: Lead the technical responsesecurity tooling, automate repetitive SecOps tasks, and develop sophisticated detection logic;Detection & Response Architecture: Proven experience designing and optimising enterprise security stacks, including SIEM, SOAR, and EDR. You don't just use tools; you tune them to eliminate noise and build high-fidelity alerting pipelines;DevSecOps Leadership: Experience leading ...