roles Solid understanding of SIEM, log analytics, data normalization, and detection lifecycle management (rule creation, tuning, suppression, enrichment) Hands-on experience with XSIAM or similar platforms (Splunk, QRadar, Sentinel, etc.) is a strong plus Strong technical writing and communication skills, with the ability to convey complex ideas clearly to both technical and non-technical audiences Skilled in scripting … etc.) for detection development or incident investigation tasks Experience managing multiple projects or programs in dynamic, fast-paced environments with cross-functional visibility Familiarity with cloud infrastructure (AWS, Azure, GCP), especially as it relates to telemetry ingestion, detection engineering, or automated response — a significant advantage Experience with CNAPP solutions (e.g., Prisma Cloud, Wiz, Orca) and integrating cloud posture More ❯
roles Solid understanding of SIEM, log analytics, data normalization, and detection lifecycle management (rule creation, tuning, suppression, enrichment) Hands-on experience with XSIAM or similar platforms (Splunk, QRadar, Sentinel, etc.) is a strong plus Strong technical writing and communication skills, with the ability to convey complex ideas clearly to both technical and non-technical audiences Skilled in scripting … etc.) for detection development or incident investigation tasks Experience managing multiple projects or programs in dynamic, fast-paced environments with cross-functional visibility Familiarity with cloud infrastructure (AWS, Azure, GCP), especially as it relates to telemetry ingestion, detection engineering, or automated response — a significant advantage Experience with CNAPP solutions (e.g., Prisma Cloud, Wiz, Orca) and integrating cloud posture More ❯
DevOps and cloud experience Strong programming skill with experience in API and Webhook development using Python, PowerShell, and Rego. Experience with automating and integrating serverless PaaS solutions in Azure and GCP platforms. Deep knowledge of Container security and orchestration. Experience with compliance and application security tools. Understand Cloud (Azure/GCP) security features (data protection, IAM … controls. Implement the enterprise cloud capability and enhance the cloud orchestration platform for automated provisioning, management and scalability of hosts, containers, applications, and cloud services (AquaSec, Wiz.io, Defender, Sentinel, Google Chronicle, Splunk, etc.) Develop APIs and Webhook for multi-directional integration of cloud orchestration platform with system management systems, DevOps Tools, and cloud platforms. Data transformation and reporting More ❯
Leeds, West Yorkshire, England, United Kingdom Hybrid / WFH Options
Context Recruitment Limited
Security Solution Architect Location: Remote Salary: Paying up to 80k basic + commission (120-130k OTE) A top tier Azure Expert MSP is seeking a Security-Focused Solution Architect to join their high-performing Presales team. This is a strategic opportunity to shape enterprise security solutions using the Microsoft Security Stack, supporting clients across sectors in their … best practices in identity, access, threat protection, and compliance within the Microsoft ecosystem. Key Responsibilities Design and present secure cloud solutions leveraging the Microsoft Security Stack, including Defender, Sentinel, Entra ID, Purview, and Intune. Collaborate with sales and technical teams to translate business needs into scalable, secure architectures. Lead client engagements, workshops, and technical assessments to shape solution … responses, and technical documentation with clarity and precision. Candidate Profile Proven experience in cloud security architecture, ideally within a Microsoft-focused environment. Deep understanding of Microsoft 365 and Azure security capabilities. Strong communication and stakeholder engagement skills, particularly in presales or consultancy settings. Relevant certifications (e.g., SC-100, AZ-500, MS-500) are highly desirable. Ability to work More ❯
Reading, Berkshire, England, United Kingdom Hybrid / WFH Options
Proactive Appointments
and processes Experience of security products, e.g., firewalls, web filtering, anti-virus etc. Some knowledge of specialized security tools would be highly desirable (e.g. Palo Alto, Tenable, Defender, Sentinel tools). would be very beneficial A security professional qualification such as CISSP, CISM, CCSP, CISA, ISO27001 Lead Implementor/Auditor, CEH or equivalent Cloud Computing experience from multiple … vendors (O365, Azure, AWS, Google, etc.) PCI-DSS GRC Cyber Security Analyst Due to the volume of applications received for positions, it will not be possible to respond to all applications and only applicants who are considered suitable for interview will be contacted. Proactive Appointments Limited operates as an employment agency and employment business and is an equal More ❯
be responsible for implementing and maintaining robust security measures to protect the organisation's technology infrastructure. Client Details The organisation is a public sector. Description Key Responsibilities MicrosoftSentinel Configure and maintain Sentinel analytics rules, workbooks, and connectors Develop and optimise dashboards and reports for threat visibility Manage Sentinel upgrades and ensure platform stability … Defender platforms Collaborate with IT teams to remediate vulnerabilities and improve endpoint security SOAR Automation Design, build, and deploy automated playbooks using Logic Apps Integrate SOAR workflows with Sentinel and Defender alerts Continuously improve automation to reduce response times and manual effort Strategic & Analytic Duties Analyse security datasets to identify trends and emerging threats Produce actionable plans and … reports for senior stakeholders Drive multiple concurrent initiatives, from tactical fixes to strategic improvements Profile A successful Infrastructure Security Engineer should have: Hands-on experience with MicrosoftSentinel including configuration, reporting, and upgrades Strong understanding of SOAR playbook development and automation Ability to manage multiple simultaneous initiatives effectively Proficiency in KQL, Azure Logic Apps, and MicrosoftMore ❯
Analysis; monitoring and responding to incidents whilst also developing new detection rules and enhancing their monitoring infrastructure and tooling. This is a cloud-native SOC capability, based in Azure with a big emphasis on the Microsoft E5 suite of security monitoring and detection tooling. Experience configuring, fine-tuning and managing this tooling will be essential, as well as … years minimum) , dealing with and responding to escalated and most high profile incidents. Comprehensive knowledge and experience utilising/fine-tuning the Microsoft E5 Security stack – Defender, Sentinel, KQL, etc. Experience working in hybrid-cloud SOC environments – Azure preferably. Ability to articulate specific projects that you have built, developed or led on, specific to SecOps Engineering More ❯
Analysis; monitoring and responding to incidents whilst also developing new detection rules and enhancing their monitoring infrastructure and tooling. This is a cloud-native SOC capability, based in Azure with a big emphasis on the Microsoft E5 suite of security monitoring and detection tooling. Experience configuring, fine-tuning and managing this tooling will be essential, as well as … years minimum) , dealing with and responding to escalated and most high profile incidents. Comprehensive knowledge and experience utilising/fine-tuning the Microsoft E5 Security stack – Defender, Sentinel, KQL, etc. Experience working in hybrid-cloud SOC environments – Azure preferably. Ability to articulate specific projects that you have built, developed or led on, specific to SecOps Engineering More ❯
Analysis; monitoring and responding to incidents whilst also developing new detection rules and enhancing their monitoring infrastructure and tooling. This is a cloud-native SOC capability, based in Azure with a big emphasis on the Microsoft E5 suite of security monitoring and detection tooling. Experience configuring, fine-tuning and managing this tooling will be essential, as well as … years minimum) , dealing with and responding to escalated and most high profile incidents. Comprehensive knowledge and experience utilising/fine-tuning the Microsoft E5 Security stack – Defender, Sentinel, KQL, etc. Experience working in hybrid-cloud SOC environments – Azure preferably. Ability to articulate specific projects that you have built, developed or led on, specific to SecOps Engineering More ❯
london (city of london), south east england, united kingdom
Lawrence Harvey
Analysis; monitoring and responding to incidents whilst also developing new detection rules and enhancing their monitoring infrastructure and tooling. This is a cloud-native SOC capability, based in Azure with a big emphasis on the Microsoft E5 suite of security monitoring and detection tooling. Experience configuring, fine-tuning and managing this tooling will be essential, as well as … years minimum) , dealing with and responding to escalated and most high profile incidents. Comprehensive knowledge and experience utilising/fine-tuning the Microsoft E5 Security stack – Defender, Sentinel, KQL, etc. Experience working in hybrid-cloud SOC environments – Azure preferably. Ability to articulate specific projects that you have built, developed or led on, specific to SecOps Engineering More ❯
Portsmouth, Hampshire, England, United Kingdom Hybrid / WFH Options
Franklin Fitch
client onboarding and configuration alignment. Mentor junior engineers and analysts. You’ll bring: 3–5 years’ experience in SOC or security engineering. Strong knowledge of platforms such as Sentinel, Splunk, Defender, or Elastic. Scripting/automation ability (PowerShell, KQL, Python, etc.). Understanding of Azure/AWS cloud and network fundamentals. Desirable: Experience with SOAR tools More ❯
public areas. Job Purpose: Provide technical support and maintenance to the business and its customers. Implement and maintain server, network, and software configurations for cloud computing infrastructure (MicrosoftAzure) with a focus on DevOps principles. Proactively identify, test, and implement new technologies that enhance business efficiency. Support the communication, assessment, and delivery of changing business requirements. Key Responsibilities … Build and administer PCs and servers; monitor systems, logs, and IT services. Support business continuity, disaster recovery, backups, and restores. Manage Active Directory and M365 (Office 365, OneDrive, Azure, InTune), following best practice. Maintain IT documentation, security systems, and related software including firewalls and endpoint protection. Research and recommend innovative or automated solutions for system administration. Skills, Experience … Behaviours: Strong knowledge of Microsoft 365/Azure and Active Directory administration . Experience with VMware , SAN storage , SQL Server , and ITIL best practices . Proficiency in endpoint security , ideally with SentinelOne or similar tools. Experience managing third-party service providers. Excellent troubleshooting and customer service skills. Experience supporting Momentus (Ungerboeck) or similar event management systems. Knowledge of More ❯
Leeds, England, United Kingdom Hybrid / WFH Options
Harvey Nash
security, and are looking for an Infrastructure Security Engineer to join their growing team. In this role, you will support the organisation’s transition to a cloud-first Azure environment, maintain and improve their hybrid infrastructure, and work on a variety of projects across automation, networking, and security. You’ll also have the opportunity to collaborate with sector … and server hardware. 🔹Support email security platforms and tools, such as MS Defender, and Mimecast. 🔹Maintain security processes, web filters(iBoss), firewalls, scanners, and SIEM tools (AlienVault/Sentinel). 🔹Work on automation and continuous improvement initiatives, maintaining and streamlining processes. 🔹Take ownership of escalated tickets, applying practical solutions under pressure. 🔹Collaborate with stakeholders across technical and non More ❯
bradford, yorkshire and the humber, united kingdom Hybrid / WFH Options
Harvey Nash
security, and are looking for an Infrastructure Security Engineer to join their growing team. In this role, you will support the organisation’s transition to a cloud-first Azure environment, maintain and improve their hybrid infrastructure, and work on a variety of projects across automation, networking, and security. You’ll also have the opportunity to collaborate with sector … and server hardware. 🔹Support email security platforms and tools, such as MS Defender, and Mimecast. 🔹Maintain security processes, web filters(iBoss), firewalls, scanners, and SIEM tools (AlienVault/Sentinel). 🔹Work on automation and continuous improvement initiatives, maintaining and streamlining processes. 🔹Take ownership of escalated tickets, applying practical solutions under pressure. 🔹Collaborate with stakeholders across technical and non More ❯
Brighton, East Sussex, South East, United Kingdom Hybrid / WFH Options
Eligo Recruitment Limited
We are looking to recruit an experienced Microsoft Cloud Infrastructure Engineer who has ideally gained experience in the deployment and support of Cyber Security tools such as Sentinel, Defender and SOAR Automation. What you must have is a wealth of experience deploying, managing and supporting a Cloud based Microsoft infrastructure including Azure, Active Directory and Exchange. … key member of the team responsible for creating and securing our clients digital infrastructure. You will work Closely with the Cyber Security team to deploy and manage the Azure based Cloud Infrastructure and Cyber security estate including the implementation, configuration and optimisation of MicrosoftSentinel, Microsoft Defender and SOAR Playbook automation and deployment. Experience of KQL … will be an advantage. In this role you will be part of the Microsoft Infrastructure and Cyber Security team and will be key to creating a secure Azure based Cloud infrastructure. You will be working as part of a open and friendly Infrastructure and Security team and will be in a role that will add real value to More ❯
design, delivery, and optimisation of customer security solutions. The consultant will work closely with customers to assess, architect, and deploy modern security technologies including Microsoft Defender XDR, MicrosoftSentinel, and Tenable One, ensuring these platforms are aligned with security best practices and operational readiness standards. The Role: The role requires strong technical expertise across SIEM, EDR, and Vulnerability … post-implementation operations, ensuring customers realise full value from their security investments. Key responsibilities: Solution Design & Architecture Implementation & Configuration Health Checks & Optimisation Consultancy & Customer Engagement Technical Expertise: MS Sentinel Architecture MS Defender XDR Suite Tenable/Azure For full details please apply. More ❯
stakeholders. This role blends hands on engineering with ownership of standards and audit readiness. What you will do Own business continuity and disaster recovery for Microsoft 365 and Azure services, with defined RTO and RPO Run backup strategy and restorations, including immutable copies, off site retention and routine recovery tests Support infrastructure and architecture delivery across servers, storage … options to senior stakeholders with clear impact statements and cost benefit Partner with Security, Service Desk and Vendors to resolve incidents and close problems What you will bring Azure and Microsoft 365 certifications or equivalent experience Proven delivery of disaster recovery, backup and restoration in enterprise or public sector settings Strong grasp of infrastructure and architecture fundamentals and … track record of testing plans, learning and improving based on measurable results Nice to have Experience with ISO 22301 or operational resilience frameworks Familiarity with Microsoft Graph, Intune, Sentinel or Defender suite Knowledge of business impact analysis and risk registers Experience with backup platforms such as Veeam and cloud resilience patterns Success in your first year Documented and More ❯
sunderland, tyne and wear, north east england, united kingdom
Careers Plus
stakeholders. This role blends hands on engineering with ownership of standards and audit readiness. What you will do Own business continuity and disaster recovery for Microsoft 365 and Azure services, with defined RTO and RPO Run backup strategy and restorations, including immutable copies, off site retention and routine recovery tests Support infrastructure and architecture delivery across servers, storage … options to senior stakeholders with clear impact statements and cost benefit Partner with Security, Service Desk and Vendors to resolve incidents and close problems What you will bring Azure and Microsoft 365 certifications or equivalent experience Proven delivery of disaster recovery, backup and restoration in enterprise or public sector settings Strong grasp of infrastructure and architecture fundamentals and … track record of testing plans, learning and improving based on measurable results Nice to have Experience with ISO 22301 or operational resilience frameworks Familiarity with Microsoft Graph, Intune, Sentinel or Defender suite Knowledge of business impact analysis and risk registers Experience with backup platforms such as Veeam and cloud resilience patterns Success in your first year Documented and More ❯
We are looking to recruit an experienced Microsoft Cyber Security Analyst who has a wealth of practical experience Sentinel, Defender and SOAR Automation with a good understanding of applying Cyber Security tools in a Microsoft based Cloud infrastructure. On this contract you will be a key member of the team responsible for securing our clients digital infrastructure. As … the Microsoft Cyber Security Analyst you will responsible for the implementation, configuration and optimisation of MicrosoftSentinel, Microsoft Defender and SOAR Playbook automation and deployment. You will also need to be proficient in the use of KQL. In this role you will be the Microsoft Cyber Security SME and will be key to creating a secure AzureMore ❯
Brighton, East Sussex, South East, United Kingdom Hybrid / WFH Options
Eligo Recruitment Limited
We are looking to recruit an experienced Microsoft Cyber Security Analyst who has a wealth of practical experience Sentinel, Defender and SOAR Automation with a good understanding of applying Cyber Security tools in a Microsoft based Cloud infrastructure. On this contract you will be a key member of the team responsible for securing our clients digital infrastructure. As … the Microsoft Cyber Security Analyst you will responsible for the implementation, configuration and optimisation of MicrosoftSentinel, Microsoft Defender and SOAR Playbook automation and deployment. You will also need to be proficient in the use of KQL. In this role you will be the Microsoft Cyber Security SME and will be key to creating a secure AzureMore ❯
Warwick, Warwickshire, West Midlands, United Kingdom Hybrid / WFH Options
Data Careers
Location: Home/Warwick Salary: £49,000 - £55,000 (+ on call worth approx. £4k - £6k, excellent benefits) Skills: Cisco, Networking projects, SD-WAN, VLAN, Static & Dynamic Routing, Azure vWAN We are looking to recruit a Network Engineer for a leading public sector organisation based in Warwick. This is an excellent opportunity for a Network Engineer with strong … service providers . Skills & Experience Required: Proven experience in network project delivery , not just day-to-day support. Strong knowledge of Cisco, SD-WAN, VLAN, Static & Dynamic Routing, Azure vWAN . Experience with Avaya telephony (desirable but not essential). Familiarity with AWS, Zscaler, SolarWinds, Sentinel . Ability to write and maintain technical documentation . Experience More ❯
IaC tools (Terraform, Ansible, CloudFormation), scripting (Python, Bash), and AI-enhanced automation. Build and maintain CI/CD (Jenkins, GitLab CI, GitHub Actions, ArgoCD). Cloud infrastructure (AWS, Azure, GCP), container orchestration (Kubernetes, Docker). Logging, monitoring, and observability (Prometheus, Grafana, ELK/EFK), including AI-driven log analysis and incident prediction. Experience supporting MLOps: deploying ML workflows … ensuring model traceability and compliance. Use of AI assistants and workflow tools to script, manage incidents, and enforce security policies (OPA, Sentinel). Soft Skills: Influential in driving DevOps culture change. Strong communicator across development, security, and business teams. Mentorship and process rigor, open-minded to AI-driven productivity improvements. High accountability, initiative, and a proactive approach to More ❯
business which will relate directly to your potential bonus. You'll be given a platform to learn and progress. Most issues you're working on will relate to Azure, with everything on MS here, including the physical stack. You'll need to have strong experience with Azure and this must be current knowledge and experience, along … with Sentinel and Defender. You're going to be joining a well respected PE firm, with over $60bn in assets under management you'll be at a key player in the markets. Starting salary will be up to £95,000 and there are a range of benefits on top of this including discretionary bonus, health and wellness benefits More ❯
City of London, London, United Kingdom Hybrid / WFH Options
Saragossa
business which will relate directly to your potential bonus. You'll be given a platform to learn and progress. Most issues you're working on will relate to Azure, with everything on MS here, including the physical stack. You'll need to have strong experience with Azure and this must be current knowledge and experience, along … with Sentinel and Defender. You're going to be joining a well respected PE firm, with over $60bn in assets under management you'll be at a key player in the markets. Starting salary will be up to £95,000 and there are a range of benefits on top of this including discretionary bonus, health and wellness benefits More ❯
london, south east england, united kingdom Hybrid / WFH Options
Saragossa
business which will relate directly to your potential bonus. You'll be given a platform to learn and progress. Most issues you're working on will relate to Azure, with everything on MS here, including the physical stack. You'll need to have strong experience with Azure and this must be current knowledge and experience, along … with Sentinel and Defender. You're going to be joining a well respected PE firm, with over $60bn in assets under management you'll be at a key player in the markets. Starting salary will be up to £95,000 and there are a range of benefits on top of this including discretionary bonus, health and wellness benefits More ❯