76 to 100 of 247 Azure Sentinel Jobs

SOC Engineer: SIEM & Cloud Logs Specialist

Location
Greater London, England, United Kingdom
Hamilton Barnes Associates Limited is seeking a SOC Engineer to onboard clients to SIEM platforms such as Azure Sentinel and Chronicle, integrating log sources and ensuring reliable security telemetry. You will help shape onboarding standards and troubleshoot system availability while supporting Windows and Unix/Linux ...

Security Detection Engineer

Hiring Organisation
McCabe & Barton
Location
London, United Kingdom
Employment Type
Contract
Initial 6-Month Contract We are looking for an experienced Security Detection Engineer to take ownership of detection engineering, and threat hunting across Azure and GCP environments. This is a hands-on opportunity for a security professional with strong SIEM, cloud security, and automation expertise who can operate … independently in a fast-paced environment. Key Responsibilities Detection Engineering & SIEM Uplift Design and implement detection rules in Datadog (or Sentinel/SIEM equivalent) Support UEBA (User & Entity Behaviour Analytics) to catch compromise early Use Claude Code to develop detection logic and correlation rules Build AI-powered anomaly ...

Cyber Security Engineer (Identity & Cloud)

Location
Warrington, England, United Kingdom
Microsoft-focused technology environment. The role will have a particular focus on Identity & Access Management (IAM), Microsoft Entra ID, Privileged Identity Management (PIM), Azure, Microsoft 365 security and Power Platform governance. You will work closely with Cyber Security, Architecture and Infrastructure teams to strengthen identity governance, improve privileged … Governance. Implement, operate and continuously improve Privileged Identity Management (PIM) controls and privileged access reviews. Support the secure configuration and operation of Microsoft Azure and Microsoft 365. Implement and maintain Microsoft Defender security controls. Support security monitoring, threat investigation and incident response activities. Support vulnerability management, including identifying ...

AMBG - Cloud Security & Exposure Management Architect

Location
Greater London, England, United Kingdom
control improvements, and reporting outputs against agreed engagement milestones. Contribute to solution architecture and pre-sales deal shaping for cloud security, Microsoft Defender, Sentinel, Entra, Defender for Cloud, and exposure management opportunities while building trusted relationships with client security, cloud, and operations stakeholders during delivery and pre-sales … engagements. Design, implement, and integrate cloud security, exposure management, threat detection, and security operations capabilities, including Microsoft Sentinel, Defender for Cloud, Defender XDR, and related Microsoft Security technologies. Understand threat modelling, attack paths, cloud misconfigurations, identity risks, vulnerabilities, and how to prioritise remediation based on exploitability and business ...

Security Team Lead

Location
Greater London, England, United Kingdom
security engineers (currently 3) Act as the senior escalation point for security incidents and decision-making Work across a modern Microsoft/Azure environment , driving improvements in M365 security and identity Influence how security is delivered across our sites, combining internal and client-facing services … governance Translate regulatory obligations (FCA, PRA, ISO 27001, Lloyd’s) into practical, measurable controls Hands-On Security Engineering Implement and optimise controls across Azure, M365, and infrastructure environments Lead hardening initiatives across IAM, PAM, AD, and network security Drive security automation and DevSecOps practices Lead real-time response ...

Security Engineer

Hiring Organisation
LT Harper Recruitment Group
Location
United Kingdom
XSOAR, XDR or XSIAM Palo Alto Prisma Access, Strata Cloud Manager, IoT Security and NGFWs Google SecOps SIEM and SOAR Microsoft Defender and Sentinel Experience deploying and supporting cloud, network and security technologies Python scripting, including writing and debugging code Solid understanding of Windows, Linux and macOS, networking … concepts to technical and non-technical clients Nice to have: MSSP or MDR experience SIEM or SOAR deployment and support experience Google Cloud, Azure or AWS experience Security Operations background ...

Crowdstrike Technical Consulting Manager

Hiring Organisation
Accenture
Location
London, United Kingdom
Salary
£ 80 K
either in a vendor, partner, or customer capacity Extensive technical experience with at least two of the following: SIEM platforms (Splunk, QRadar, Elastic, Sentinel, Chronicle), endpoint security, identity threat detection, cloud security posture management, or vulnerability/exposure management Experience with enterprise security architectures, including identity infrastructure, cloud … environments (AWS, Azure, GCP), OT/ICS environments, or hybrid data center Bachelor's degree or equivalent work experience.Bonus points if you haveStrong written and verbal communication skills; able to translate complex technical concepts into business outcomes for executive audiences Active CrowdStrike certification(s): CCFA, CCSE, or CrowdStrike ...

Crowdstrike Technical Consulting Manager

Hiring Organisation
Accenture
Location
Manchester, Greater Manchester, United Kingdom
Salary
£ 60 K
either in a vendor, partner, or customer capacity Extensive technical experience with at least two of the following: SIEM platforms (Splunk, QRadar, Elastic, Sentinel, Chronicle), endpoint security, identity threat detection, cloud security posture management, or vulnerability/exposure management Experience with enterprise security architectures, including identity infrastructure, cloud … environments (AWS, Azure, GCP), OT/ICS environments, or hybrid data center Bachelor's degree or equivalent work experience.Bonus points if you haveStrong written and verbal communication skills; able to translate complex technical concepts into business outcomes for executive audiences Active CrowdStrike certification(s): CCFA, CCSE, or CrowdStrike ...

Crowdstrike Technical Consulting Manager

Hiring Organisation
Accenture
Location
Holywood, Down, United Kingdom
Salary
£ 60 K
either in a vendor, partner, or customer capacity Extensive technical experience with at least two of the following: SIEM platforms (Splunk, QRadar, Elastic, Sentinel, Chronicle), endpoint security, identity threat detection, cloud security posture management, or vulnerability/exposure management Experience with enterprise security architectures, including identity infrastructure, cloud … environments (AWS, Azure, GCP), OT/ICS environments, or hybrid data center Bachelor's degree or equivalent work experience.Bonus points if you haveStrong written and verbal communication skills; able to translate complex technical concepts into business outcomes for executive audiences Active CrowdStrike certification(s): CCFA, CCSE, or CrowdStrike ...

Threat Response Technology and Capabilities Product Owner

Hiring Organisation
MasterCard
Location
Ringwood, Hampshire, United Kingdom
Salary
£ 60 K
Respond/Recover), NIST SP 800-61r3, MITRE ATT&CK, and D3FEND.• Set roadmap and strategy for SOAR platforms (Splunk SOAR, Microsoft Sentinel SOAR/Logic Apps), case management, evidence collection, and response orchestration.• Define and oversee SOAR playbook automation builds, documentation, and execution• Define … across the full IR lifecycle: triage, scoping, containment, eradication, recovery, evidence handling, post-incident review.• Strong DFIR background covering endpoint, network, cloud (AWS, Azure, GCP), identity, and SaaS forensics.• Working proficiency in Python and PowerShell. Comfort reviewing and directing code without being the primary developer.• Experience with ...

Information Security Analyst - Secops Detection

Location
Southampton, England, United Kingdom
SIEM and other security platforms. Proactive Threat Hunting - Formulate hypotheses and hunt for undetected attacker TTPs across our cloud (AWS, GCP, Azure), SaaS, and endpoint environments. Purple Team - Collaborate with our Adversarial Simulation team in Purple Team exercises to test, validate, and improve detection logic and response. Incident … like MITRE ATT&CK to prioritize and enhance detective controls. SIEM Expertise: Hands‐on experience with SIEM platforms (e.g., Splunk, Google SecOps, Elastic, Sentinel) for rule/query creation and analytics. Threat Hunting: Experience conducting proactive threat hunts, defining hypotheses, and developing hunting methodologies. Cloud Security: Solid knowledge ...

Cyber Engineer

Location
West of England, England, United Kingdom
colleagues within the cyber security team. Technology Environment You'll be working within a predominantly Microsoft-focused environment, including: Microsoft Defender Suite Microsoft Sentinel Microsoft Purview Microsoft Entra ID Azure Microsoft Fabric Vulnerability management platforms such as Tenable and Intruder Operational Technology (OT) environments and industrial … experience in a Security Engineer, Cyber Security Engineer or similar role. Strong experience securing Microsoft cloud and enterprise environments. Expertise across Microsoft Defender, Sentinel, Entra ID and Azure security technologies. Experience implementing vulnerability management and security monitoring solutions. Strong understanding of security frameworks such as NCSC ...

Senior Security Operations Engineer

Location
Belfast City District, Northern Ireland, United Kingdom
tools such as vulnerability management, PAM, IDS/IPS, or DLP Networking fundamentals (firewalls, switches, wireless access points) Experience with Microsoft Defender, Microsoft Sentinel, or Azure security tooling Experience working in a cloud or SaaS environment Relevant certifications (e.g. ...

Vulnerability Management Engineer

Hiring Organisation
McCabe & Barton
Location
London, United Kingdom
Employment Type
Contract
Contract Rate
Up to £800 per day
IR35 6-month contract Role Overview We are seeking an experienced Vulnerability Management Engineer to own vulnerability discovery, prioritisation, and remediation tracking across Azure and GCP environments during a critical integration programme. This role requires strong Azure expertise, with GCP experience desirable. You will work closely … identify, prioritise, and remediate security vulnerabilities while leveraging Infrastructure-as-Code and automation to improve security outcomes. Responsibilities Vulnerability Discovery & Triage Scan Azure and GCP infrastructure for known vulnerabilities using Datadog, Sentinel, or equivalent tooling. Integrate with SCA/SBOM tools such as Snyk for dependency ...

3rd Line Engineer

Location
Greater London, England, United Kingdom
scalability, and performance to meet the growth needs of ME+EM. Investigate and diagnose advanced software, hardware, and network problems, utilising expert knowledge of Azure, Google Cloud and Hyper‐V infrastructure to troubleshoot and identify root causes and implement effective solutions. Collaborate with second‐line engineers, vendors, and other … evaluating their potential impact and recommending innovative solutions to address business needs. Skills IT-related degree or equivalent professional experience CCNA or Microsoft Azure Administrator (AZ-104) certified — essential Experience in a third‐line, cloud, or network infrastructure role Proven experience designing and implementing backup & disaster recovery strategies ...

Senior Security Engineer - Contract

Hiring Organisation
Flagstone
Location
London, United Kingdom
Salary
£ 80 K
talk about you.About the teamSecurity Engineering is a team of five covering cloud security, detection, and security operations. They work directly in the Azure estate and are close to the infrastructure, not abstracted behind a policy layer. The team runs Microsoft Sentinel, Defender XDR, and Defender … cloud security, detection tooling, and incident response, without being narrowly specialised. You own meaningful parts of the security stack, contribute hands-on to Azure cloud hardening, and show up reliably when incidents need investigating or pen test cycles need coordinating. You're energised by visible impact, your work ...

Head of Cloud Engineering

Location
Greater London, England, United Kingdom
complex cloud transformation, security modernisation, and AI adoption programmes. Support pre-sales activities, workshops, proof of concepts, and executive presentations. Technology & Innovation Microsoft Azure Microsoft 365 Security Microsoft Defender Suite Microsoft Sentinel Microsoft Entra Microsoft Copilot for Security Microsoft Purview AWS Security Google Cloud Security … Access) Microsoft 365 Defender (Defender for Endpoint, Defender for Office 365, Defender for Identity, Defender for Cloud Apps) Microsoft Defender for Cloud Microsoft Sentinel Microsoft Copilot for Security Microsoft Intune AWS Security Services Google Cloud Platform Security Zero Trust Architectures DevSecOps CNAP platforms (like Wiz and Palo Alto ...

Senior Security Engineer - Contract

Location
Greater London, England, United Kingdom
about you. About the teamSecurity Engineering is a team of five covering cloud security, detection, and security operations. They work directly in the Azure estate and are close to the infrastructure, not abstracted behind a policy layer. The team runs Microsoft Sentinel, Defender XDR, and Defender … cloud security, detection tooling, and incident response, without being narrowly specialised. You own meaningful parts of the security stack, contribute hands‐on to Azure cloud hardening, and show up reliably when incidents need investigating or pen test cycles need coordinating. You're energised by visible impact, your work ...

Head of Cyber Defence & Incident Response

Hiring Organisation
Quadient
Location
London, United Kingdom
Salary
£ 80 K
MITRE ATT&CK to structure detections, gaps analysis, and defensive improvements.Experience with security operations in cloud platforms and common tools (e.g., Microsoft Defender, Sentinel, Splunk, CrowdStrike, Palo Alto, AWS/Azure security services) and integrating telemetry across environments.Calm under pressure, able to lead effectively during incidents ...

Head of Cyber Defence & Incident Response London - United Kingdom - Full Time

Location
Greater London, England, United Kingdom
structure detections, gaps analysis, and defensive improvements. Experience with security operations in cloud platforms and common tools (e.g., Microsoft Defender, Sentinel, Splunk, CrowdStrike, Palo Alto, AWS/Azure security services) and integrating telemetry across environments. Calm under pressure, able to lead effectively during incidents and make ...

Head of Cyber Defence & Incident Response

Hiring Organisation
Quadient
Location
Greater London, United Kingdom
Employment Type
Full Time
structure detections, gaps analysis, and defensive improvements. Experience with security operations in cloud platforms and common tools (e.g., Microsoft Defender, Sentinel, Splunk, CrowdStrike, Palo Alto, AWS/Azure security services) and integrating telemetry across environments. Calm under pressure , able to lead effectively during incidents and make ...

Senior Security Engineer

Location
Greater London, England, United Kingdom
vulnerability triage workflows that score real risk by exploitability, reachability, and compensating controls rather than raw CVSS. Harden and secure our cloud environment (Azure), partnering with platform engineering on secure configuration, reviewing and remediating vulnerabilities, identity and network controls, posture management, and logging and detection. Strengthen endpoint … control landscape: cloud security, supply‐chain and vulnerability management, endpoint and identity, and detection and response. Are genuinely technical: comfortable in cloud environments (Azure preferred), CI/CD, and at least one scripting language (e.g. Python, Bash, PowerShell), so your controls hold up in engineering reality. Lead with ...

Lead Threat Detection Engineer

Location
Greater London, England, United Kingdom
cases and monitoring Automate manual detection and remediation processes Develop threat intelligence and threat-hunting capabilities Improve security monitoring across AWS, GCP and Azure Work closely with engineering teams to turn security findings into scalable technical improvements Review existing tooling and influence future technology decisions Provide technical leadership … across the security function What we’re looking for: Experience building detections rather than purely responding to SOC alerts Strong SIEM experience – Microsoft Sentinel, Splunk or similar Cloud security experience across AWS, GCP and/or Azure KQL, SPL or similar querying experience Python scripting/ ...

Manager, Cybersecurity, Engineering , TC, UKI

Hiring Organisation
EY (Ernst & Young)
Location
London, United Kingdom
Salary
£ 100 K
CK. Experience designing remote and local access models including PAM and ZTNA with identity integration. Familiarity with Microsoft cloud security stack including Microsoft Sentinel, Microsoft Entra ID, Microsoft Defender for Cloud and secure connectivity on Azure Advanced certifications such as CISSP, TOGAF or SABSA, Cloud Security ...

Security Automation Software Engineer

Hiring Organisation
G Research
Location
London, United Kingdom
Salary
£ 80 K
designs and implements automated detection and response capabilities that protect G-Research’s diverse and complex estate, spanning high-performance compute (HPC) environments, Azure and Windows corporate infrastructure, and public cloud platforms such as AWS.As part of SAE, you’ll play a hands-on role building secure, scalable … computing environments.Key responsibilities of the role include:Design, build and maintain automated detection and response systems across G-Research’s hybrid environments (HPC, Azure, AWS).Develop high-quality, well-tested code primarily in Python, following secure engineering best practices.Implement and maintain infrastructure-as-code and CI/ ...