Security Controls Administration - maintain availability and functionality of all security controls; implement new and advanced features where available; write technical documentation and manage changes. SIEM Maintenance & Content - maintain the availability of the underlying infrastructure, develop new alerts, field parsers, models and automated playbooks, and integrate new log sources where appropriate. … develop and integrate external threat intelligence data into the team's detection capabilities; perform proactive threat hunts based on working hypotheses, and implement subsequent SIEM alerts where required. Purple Team & Scenario Exercises - regularly test the team's detection capabilities, develop scenario-based training, and organise purple team exercises, both in … years of experience within operational IT or security roles, with a minimum of 2 years SOC. Deep familiarity with one or more SIEM tools is. A strong understanding of technical IT concepts is required, including: Windows and Linux operating systems and system administration Networking, including TCP/IP and other More ❯
Ashford, Kent, United Kingdom Hybrid / WFH Options
UNAVAILABLE
a MAF Security Operations Specialist you will play a critical role in protecting our digital infrastructure. You'll lead the implementation andmanagement of SIEM systems, Fortinet security tools, and endpoint detection & response (EDR) while conducting vulnerability assessments and penetration testing to stay ahead of cyber threats. You'll enhance … on infrastructure security Strong experience with Fortinet security products and solutions Advanced knowledge of Microsoft Active Directory and Entra ID administration Demonstrated experience with SIEM implementation andmanagement Strong background in network securityand infrastructure protection Experience with IDS/IPS systems andsecurity monitoring tools Proven incident response andMore ❯
a MAF Security Operations Specialist you will play a critical role in protecting our digital infrastructure. You'll lead the implementation andmanagement of SIEM systems, Fortinet security tools, and endpoint detection & response (EDR) while conducting vulnerability assessments and penetration testing to stay ahead of cyber threats. You'll enhance … on infrastructure security Strong experience with Fortinet security products and solutions Advanced knowledge of Microsoft Active Directory and Entra ID administration Demonstrated experience with SIEM implementation andmanagement Strong background in network securityand infrastructure protection Experience with IDS/IPS systems andsecurity monitoring tools Proven incident response andMore ❯
Gosport, Hampshire, South East, United Kingdom Hybrid / WFH Options
Walsh Employment
analysis, and improvement of cybersecurity postures. Essential Skills and Experience: Proven experience in a Security Operations Centre (SOC) environment Strong hands-on expertise with SIEM tools such as Microsoft Sentinel and Splunk Solid understanding of network protocols and infrastructure (e.g. TCP/IP , VPNs , firewalls ) Skilled in incident response and … at the forefront of digital defenceleading incident response, improving detection mechanisms, and mentoring junior analysts. Your responsibilities will include: Analysing security incidents using advanced SIEM platforms ( Microsoft Sentinel , Splunk ) Leading incident response and driving improvements in detection and containment strategies Tuning and maintaining detection rules, using threat frameworks like Mitre More ❯
Reading, England, United Kingdom Hybrid / WFH Options
Project People
a technology industry (mobile telecommunications desirable but not essential). A background of assuring a wide range of security solutions and services such as SIEM, IDS, SOC, IAM, PAM, TVM. A history of bringing industry best practice into an organisation and using this to drive continuous improvement. Demonstrable experience of More ❯
reading, south east england, united kingdom Hybrid / WFH Options
Mobile Broadband Network Ltd (MBNL)
a technology industry (mobile telecommunications desirable but not essential). A background of assuring a wide range of security solutions and services such as SIEM, IDS, SOC, IAM, PAM, TVM. A history of bringing industry best practice into an organisation and using this to drive continuous improvement. Demonstrable experience of More ❯
Reading, Berkshire, United Kingdom Hybrid / WFH Options
Project People
a technology industry (mobile telecommunications desirable but not essential). A background of assuring a wide range of security solutions and services such as SIEM, IDS, SOC, IAM, PAM, TVM. A history of bringing industry best practice into an organisation and using this to drive continuous improvement. Demonstrable experience of More ❯
Reading, Oxfordshire, United Kingdom Hybrid / WFH Options
Mobile Broadband Network Limited
a technology industry (mobile telecommunications desirable but not essential). • A background of assuring a wide range of security solutions and services such as SIEM, IDS, SOC, IAM, PAM, TVM. • A history of bringing industry best practice into an organisation and using this to drive continuous improvement. • Demonstrable experience of More ❯
Edinburgh, Midlothian, United Kingdom Hybrid / WFH Options
Tesco Bank
Proxy and WAF. Previous experience within financially regulated environment. And if you have any of these, even better Threat hunting experience Blue Team experience SIEM Detection writing experience We don't expect you to tick every box, and if you feel you hit most of the brief, it's worth More ❯
Oxford, Oxfordshire, United Kingdom Hybrid / WFH Options
Sophos Group
defend through the Sophos Central platform. Secureworks provides the innovative, market-leading Taegis XDR/MDR, identity threat detection and response (ITDR), next-gen SIEM capabilities, managed risk, and a comprehensive set of advisory services. Sophos sells all these solutions through reseller partners, Managed Service Providers (MSPs) and Managed SecurityMore ❯
reading, south east england, united kingdom Hybrid / WFH Options
Mobile Broadband Network Ltd (MBNL)
a technology industry (mobile telecommunications desirable but not essential). A background of assuring a wide range of security solutions and services such as SIEM, IDS, SOC, IAM, PAM, TVM. A history of bringing industry best practice into an organisation and using this to drive continuous improvement. Demonstrable experience of More ❯
Harrogate, North Yorkshire, Yorkshire, United Kingdom Hybrid / WFH Options
Redcentric
in a 3rd line or senior engineer role. CCNP or equivalent. ITILv3 qualified or experience within an ITIL environment. Experience in a SOC/SIEM environments, specifically Elastic. Experience with scripting, specifically Python. Experience with UNIX. Experience with cellular technologies - 3G, 4G, etc. Experience with public service networks - N3, HSCN More ❯
Kubernetes, and Helm. Hands-on experience with security practices like vulnerability scanning, encryption, authentication, and secrets management (Vault, Key Management Service). Experience with SIEM platforms (Splunk, Datadog, or equivalent) for monitoring and threat detection. You thrive when working as part of a team, are comfortable in a fast-paced More ❯
Manchester, Lancashire, United Kingdom Hybrid / WFH Options
YourCode Recruitment
Sync. Familiarity with single sign-on technologies such as SAML 2.0 protocol and ADFS 2.0 . Nice-to-Have Skills: Hands-on experience with SIEM, Google Cloud, and advanced endpoint security solutions. Proficiency in PowerShell scripting, patch management, and penetration testing. Experience with Azure conditional access policies. Understanding of PKI More ❯
Greater London, England, United Kingdom Hybrid / WFH Options
CLS Group
a variety of tools, techniques, and data sources Research, document, and develop Use Cases and Hypotheses for proactive hunting in cyber security tools including SIEM, EDR, and IDS/IPS (extract TTPs and behaviours from research to apply to logging and tool queries/hunts and detections) Research, document and … threat intelligence and SOC/CIRT interaction Splunk experience is highly preferred Scripting or automation knowledge, especially Python experience is highly preferred Experience with SIEM, EDR solutions, network monitoring tools, and other cyber security tools Experience with threat intelligence vendors Ability to work on-site at least twice a week More ❯
Gosport, Hampshire, South East, United Kingdom Hybrid / WFH Options
Walsh Employment
analysis, and improvement of cybersecurity postures. Essential Skills and Experience: Proven experience in a Security Operations Centre (SOC) environment Strong hands-on expertise with SIEM tools such as Microsoft Sentinel and Splunk Solid understanding of network protocols and infrastructure (e.g. TCP/IP , VPNs , firewalls ) Skilled in incident response and … at the forefront of digital defenceleading incident response, improving detection mechanisms, and mentoring junior analysts. Your responsibilities will include: Analysing security incidents using advanced SIEM platforms ( Microsoft Sentinel , Splunk ) Leading incident response and driving improvements in detection and containment strategies Tuning and maintaining detection rules, using threat frameworks like Mitre More ❯
Hemel Hempstead, Hertfordshire, South East, United Kingdom Hybrid / WFH Options
Sopra Steria Limited
dashboards, and reports for our SecurityInformationandEventManagement (SIEM) systems. This role requires a strong understanding of security best practices and experience working with SIEM platforms and within an MSSP environments where you may be working across multiple operational customers and projects. Hybrid Variable: Working in Hemel Hampstead … What you'll be doing: Create, implement, and maintain security content (such as rules, dashboards, and reports) for our SIEM system. Continuously monitor and analyze SIEM data to identify and respond to potential security threats. Collaborate with others, such as the SOC Analysts, Architects, Project Managers & Engineers, to improve the … accuracy and efficiency of the SIEM content. Stay up-to-date on the latest security threats, vulnerabilities, and attack techniques and incorporate that knowledge into the SIEM content. Work with the security team to establish and maintain security standards and procedures. What youll bring: Experience working with SIEM systems, such More ❯
hemel hempstead, east anglia, united kingdom Hybrid / WFH Options
Sopra Steria Limited
dashboards, and reports for our SecurityInformationandEventManagement (SIEM) systems. This role requires a strong understanding of security best practices and experience working with SIEM platforms and within an MSSP environments where you may be working across multiple operational customers and projects. Hybrid Variable: Working in Hemel Hampstead … What you'll be doing: Create, implement, and maintain security content (such as rules, dashboards, and reports) for our SIEM system. Continuously monitor and analyze SIEM data to identify and respond to potential security threats. Collaborate with others, such as the SOC Analysts, Architects, Project Managers & Engineers, to improve the … accuracy and efficiency of the SIEM content. Stay up-to-date on the latest security threats, vulnerabilities, and attack techniques and incorporate that knowledge into the SIEM content. Work with the security team to establish and maintain security standards and procedures. What youll bring: Experience working with SIEM systems, such More ❯
watford, hertfordshire, east anglia, united kingdom Hybrid / WFH Options
Sopra Steria Limited
dashboards, and reports for our SecurityInformationandEventManagement (SIEM) systems. This role requires a strong understanding of security best practices and experience working with SIEM platforms and within an MSSP environments where you may be working across multiple operational customers and projects. Hybrid Variable: Working in Hemel Hampstead … What you'll be doing: Create, implement, and maintain security content (such as rules, dashboards, and reports) for our SIEM system. Continuously monitor and analyze SIEM data to identify and respond to potential security threats. Collaborate with others, such as the SOC Analysts, Architects, Project Managers & Engineers, to improve the … accuracy and efficiency of the SIEM content. Stay up-to-date on the latest security threats, vulnerabilities, and attack techniques and incorporate that knowledge into the SIEM content. Work with the security team to establish and maintain security standards and procedures. What youll bring: Experience working with SIEM systems, such More ❯
Capitole keeps growing, and we want to do it with you! We are currently looking for a Senior SIEM Architect to join an international cybersecurity team . This role is crucial to design, optimize, and expand SIEM solutions, mainly based on Splunk , and to lead strategic security projects across cloud … and on-premises environments Key Responsibilities SIEM Architecture & Expansion Design, develop, and expand SIEM solution s, with a focus on Splunk. Define, manage, and support the integration of new log sources. Lead and support SIEM migration projects, both technically and organizationally. Extend SIEM capabilities to commercial cloud environments (Azure, AWS … . Security Monitoring & Innovation Continuously evaluate new SIEM tools and architectures. Support Event Stream Processing development and optimization. Conduct Proof of Concept (PoC) initiatives for emerging security technologies. Cross-Functional Collaboration Collaborate closely with internal cybersecurity, infrastructure, and application teams. Interact with both technical and non-technical stakeholders to ensure More ❯
Manchester, Lancashire, United Kingdom Hybrid / WFH Options
Nomios UK&I Limited
of the following vendors: Fortinet, Palo Alto, Juniper, Cisco, Netskope, Zscaler, CrowdStrike. We would also love to receive applications from people with skills solutioning SIEM, SOAR, or Managed Security Services (experience in DDoS, WAF, IDAM, EDR, MDM or Vulnerability Management is a plus). We are also interested to hear More ❯