SOAR Jobs in the UK

26 to 50 of 80 SOAR Jobs in the UK

Senior Security Engineer

Portsmouth, Hampshire, England, United Kingdom
Computappoint
Up to £78,500 (DOE) + Bonus Working arrangement: Hybrid Office Location: Portsmouth As a Senior Security Engineer, you will: Design, deploy, and maintain core SOC technologies (SIEM, EDR, SOAR, threat intelligence, and logging infrastructure). Develop and optimise detection use cases, correlation rules, and analytics content. Build and maintain automation workflows and integrations using automation platforms or custom scripting. … and cloud security (Azure, AWS, or M365). Solid understanding of network, system, and identity security fundamentals. Excellent problem-solving skills and a passion for continuous improvement. Experience with SOAR platforms (e.g., Microsoft Sentinel Automation, Cortex XSOAR, Splunk SOAR). Knowledge of MITRE ATT&CK mapping and detection engineering frameworks. Infrastructure-as-Code experience (Terraform, Bicep, or ARM templates). More ❯
Employment Type: Full-Time
Salary: £71,250 - £78,500 per annum
Posted:

Senior Director of Cyber Security

London, South East, England, United Kingdom
WTW
strongly preferred). Expertise in IAM technologies (SailPoint, Okta, Azure AD, CyberArk, Ping Identity), DLP platforms (Symantec, Microsoft Purview, Forcepoint, Digital Guardian), and security engineering tools (EDR, CSPM, SIEM, SOAR, vulnerability management). Strong knowledge of Zero Trust, data protection regulations (GDPR, FCA, PRA), cloud-native security, and DevSecOps practices. Exceptional leadership, communication, and stakeholder engagement skills, with the ability More ❯
Employment Type: Full-Time
Salary: Competitive salary
Posted:

Senior Director of Cyber Security

England, United Kingdom
Willis Towers Watson
strongly preferred). Expertise in IAM technologies (SailPoint, Okta, Azure AD, CyberArk, Ping Identity), DLP platforms (Symantec, Microsoft Purview, Forcepoint, Digital Guardian), and security engineering tools (EDR, CSPM, SIEM, SOAR, vulnerability management). Strong knowledge of Zero Trust, data protection regulations (GDPR, FCA, PRA), cloud-native security, and DevSecOps practices. Exceptional leadership, communication, and stakeholder engagement skills, with the ability More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

Security Analyst

Greater Cardiff Area, United Kingdom
CPS Group (UK) Limited
external security assessments and audits Update and maintain incident response plans, playbooks, and procedures Provide 3rd-line support to IT colleagues and the wider business Technical Skills: SIEM and SOAR platforms Log analytics, rule creation, tuning, and threat hunting Familiarity with security frameworks Azure and M365 security configuration and alert investigation Dashboards and visualisation tools Firewalls (CheckPoint, VMware NSX) Windows More ❯
Posted:

Security Analyst (GRC)

City, Cardiff, United Kingdom
CPS Group (UK) Limited
external security assessments and audits - Update and maintain incident response plans, playbooks, and procedures - Provide 3rd-line support to IT colleagues and the wider business Technical Skills: - SIEM and SOAR platforms - Log analytics, rule creation, tuning, and threat hunting - Familiarity with security frameworks - Azure and M365 security configuration and alert investigation - Dashboards and visualisation tools - Firewalls (CheckPoint, VMware NSX) - Windows More ❯
Employment Type: Permanent
Salary: GBP 40,000 - 45,000 Annual
Posted:

Security Analyst GRC

Cardiff, South Glamorgan, Wales, United Kingdom
CPS Group
and external security assessments and audits- Update and maintain incident response plans, playbooks, and procedures- Provide 3rd-line support to IT colleagues and the wider businessTechnical Skills:- SIEM and SOAR platforms- Log analytics, rule creation, tuning, and threat hunting- Familiarity with security frameworks- Azure and M365 security configuration and alert investigation- Dashboards and visualisation tools- Firewalls (CheckPoint, VMware NSX)- Windows More ❯
Employment Type: Full-Time
Salary: £40,000 - £45,000 per annum
Posted:

SentinelOne Architect / SME

England, United Kingdom
Whitehall Resources
on virtualized platform , networking, and storage. • Ability to produce HLDs and LLDs with clarity and precision. • Excellent communication and stakeholder engagement skills. • Involved with integrating SentinelOne with SIEM/SOAR platforms (e.g., Splunk) and deployment to Windows and RHEL endpoints. Preferred Qualifications: • SentinelOne certifications (e.g., SentinelOne Certified Architect or equivalent). • Scripting knowledge (e.g., PowerShell, Python) for automation and integration. More ❯
Posted:

Vice President, Incident Respond Lead

England, United Kingdom
MUFG Bank, Ltd
e.g., NIST, SANS) Experience with both network-based and host-based threat detection and analysis Proficiency in writing detection queries (Splunk preferred) and working with SIEM/EDR/SOAR tools At least 5 years of experience in Information Security within the financial services sector Strong analytical and communication skills, with the ability to present complex issues clearly to stakeholders More ❯
Employment Type: Permanent
Salary: GBP Annual
Posted:

Information Security Architect - Solutions & Enterprise Security Architecture

Manchester, England, United Kingdom
Hybrid/Remote Options
Acumin
level security architectures in hybrid and cloud (AWS/Azure) environments. Strong hands-on expertise with enterprise security platforms – including Endpoint Protection, Cloud Security, Network Security, DevSecOps, SIEM/SOAR, and vulnerability management. Deep understanding of secure design principles, IAM, encryption, API security, and application security. Experience performing threat modelling, security risk assessments, and control design validation. In-depth knowledge More ❯
Posted:

Information Security Architect - Solutions & Enterprise Security Architecture

London Area, United Kingdom
Hybrid/Remote Options
Acumin
level security architectures in hybrid and cloud (AWS/Azure) environments. Strong hands-on expertise with enterprise security platforms – including Endpoint Protection, Cloud Security, Network Security, DevSecOps, SIEM/SOAR, and vulnerability management. Deep understanding of secure design principles, IAM, encryption, API security, and application security. Experience performing threat modelling, security risk assessments, and control design validation. In-depth knowledge More ❯
Posted:

Information Security Architect - Solutions & Enterprise Security Architecture

City of London, London, United Kingdom
Hybrid/Remote Options
Acumin
level security architectures in hybrid and cloud (AWS/Azure) environments. Strong hands-on expertise with enterprise security platforms – including Endpoint Protection, Cloud Security, Network Security, DevSecOps, SIEM/SOAR, and vulnerability management. Deep understanding of secure design principles, IAM, encryption, API security, and application security. Experience performing threat modelling, security risk assessments, and control design validation. In-depth knowledge More ❯
Posted:

Security Information & Event Monitoring (SIEM) Engineer- SC-Must, Readings UK

Reading, Berkshire, England, United Kingdom
KBC Technologies UK LTD
Skills: Proven hands-on experience in SIEM engineering. Strong understanding of security logs across domains (identity, network, system, data, cloud). Proficient in PowerShell and Python. Good knowledge of SOAR platforms. Leadership and stakeholder management skills More ❯
Employment Type: Contractor
Rate: Salary negotiable
Posted:

IT Security Operations Manager

City of London, London, United Kingdom
ARC IT Recruitment
as CISSP, TOGAF, CCSP, GCIH or equivalent Strong experience securing Microsoft cloud environments (Azure) – design, deployment, configuration and management Broad knowledge of infrastructure and security solutions, including SIEM/SOAR Proven track record designing end-to-end solutions with security embedded across network, infrastructure, access, cloud services, controls and SecOps Experience addressing cloud-specific security challenges, patterns and controls Demonstrated More ❯
Posted:

IT Security Operations Manager

London, United Kingdom
ARC IT Recruitment Ltd
as CISSP, TOGAF, CCSP, GCIH or equivalent Strong experience securing Microsoft cloud environments (Azure) design, deployment, configuration and management Broad knowledge of infrastructure and security solutions, including SIEM/SOAR Proven track record designing end-to-end solutions with security embedded across network, infrastructure, access, cloud services, controls and SecOps Experience addressing cloud-specific security challenges, patterns and controls Demonstrated More ❯
Employment Type: Permanent
Posted:

IT Security Operations Manager

London, South East, England, United Kingdom
Arc IT Recruitment
as CISSP, TOGAF, CCSP, GCIH or equivalent Strong experience securing Microsoft cloud environments (Azure) - design, deployment, configuration and management Broad knowledge of infrastructure and security solutions, including SIEM/SOAR Proven track record designing end-to-end solutions with security Embedded across network, infrastructure, access, cloud services, controls and SecOps Experience addressing cloud-specific security challenges, patterns and controls Demonstrated More ❯
Employment Type: Full-Time
Salary: Salary negotiable
Posted:

Elastic Platform Engineer

london, south east england, united kingdom
G-Research
the following skills and experience: Significant experience administering and scaling Elastic SIEM - Elastic Security, Elastic Stack) -in enterprise environments Expertise with automation and orchestration tools, such as Tines and SOAR platforms Familiarity with Bash, Python or equivalent languages Strong knowledge of Linux systems, networking and cloud logging architectures Proven ability to manage upgrades, migrations and high-availability deployments Experience in More ❯
Posted:

Security Engineer

London Area, United Kingdom
Oliver Bernard
Security Orchestration, Automation & Response (SOAR) Engineer | Palo Alto Cortex XSOAR, Python, Rest API's, Linux & Windows | Up to £1000 Inside | 2 Days p/week in London We are seeking an experienced Security Orchestration, Automation & Response (SOAR) Engineer to strengthen cyber threat detection and automation capabilities within a leading financial organisation. This role combines hands-on technical expertise with strategic … to design, build, and optimise security workflows — enabling faster, more effective incident response and reducing manual effort through automation. Key Responsibilities: Develop and enhance security detections and automations across SOAR platforms (ideally Palo Alto Cortex XSOAR) Create and maintain playbooks and integrations to improve incident response and operational efficiency Collaborate across teams to improve detection coverage and response workflows Monitor … query languages (KQL or similar) Understanding of REST APIs and ability to develop and consume them Experience working in Azure environments Strong background in Windows, Linux, and macOS administration Security Orchestration, Automation & Response (SOAR) Engineer | Palo Alto Cortex XSOAR, Python, Rest API's, Linux & Windows | Up to £1000 Inside | 2 Days p/week in London More ❯
Posted:

Security Engineer

City of London, London, United Kingdom
Oliver Bernard
Security Orchestration, Automation & Response (SOAR) Engineer | Palo Alto Cortex XSOAR, Python, Rest API's, Linux & Windows | Up to £1000 Inside | 2 Days p/week in London We are seeking an experienced Security Orchestration, Automation & Response (SOAR) Engineer to strengthen cyber threat detection and automation capabilities within a leading financial organisation. This role combines hands-on technical expertise with strategic … to design, build, and optimise security workflows — enabling faster, more effective incident response and reducing manual effort through automation. Key Responsibilities: Develop and enhance security detections and automations across SOAR platforms (ideally Palo Alto Cortex XSOAR) Create and maintain playbooks and integrations to improve incident response and operational efficiency Collaborate across teams to improve detection coverage and response workflows Monitor … query languages (KQL or similar) Understanding of REST APIs and ability to develop and consume them Experience working in Azure environments Strong background in Windows, Linux, and macOS administration Security Orchestration, Automation & Response (SOAR) Engineer | Palo Alto Cortex XSOAR, Python, Rest API's, Linux & Windows | Up to £1000 Inside | 2 Days p/week in London More ❯
Posted:

Security Analyst

Buckinghamshire, United Kingdom
VIQU IT
Microsoft Sentinel (SIEM) and Microsoft Defender suite (Defender for Endpoint, Identity, Cloud, etc.). Proven track record in security monitoring, incident response, and alert troubleshooting . Working knowledge of SOAR platforms (preferably within Sentinel or similar). Understanding of threat detection, log analysis, and automation within Microsoft s security ecosystem. Experience with Tenable is beneficial Knowledge of Microsoft Purview would … security alerts and incidents in Microsoft Sentinel and Microsoft Defender . Perform detailed security event analysis and correlation, escalating incidents where necessary. Develop and optimise SOAR (Security Orchestration, Automation and Response) playbooks to enhance incident response and efficiency. Collaborate with wider IT and security teams to improve threat detection, incident handling, and response processes. Apply now to speak with VIQU More ❯
Employment Type: Contract
Rate: GBP 400 - 500 Daily
Posted:

Security Analyst

Milton Keynes, Loughton, Buckinghamshire, United Kingdom
VIQU IT
Microsoft Sentinel (SIEM) and Microsoft Defender suite (Defender for Endpoint, Identity, Cloud, etc.). Proven track record in security monitoring, incident response, and alert troubleshooting . Working knowledge of SOAR platforms (preferably within Sentinel or similar). Understanding of threat detection, log analysis, and automation within Microsoft’s security ecosystem. Experience with Tenable is beneficial Knowledge of Microsoft Purview would … security alerts and incidents in Microsoft Sentinel and Microsoft Defender . Perform detailed security event analysis and correlation, escalating incidents where necessary. Develop and optimise SOAR (Security Orchestration, Automation and Response) playbooks to enhance incident response and efficiency. Collaborate with wider IT and security teams to improve threat detection, incident handling, and response processes. Apply now to speak with VIQU More ❯
Employment Type: Contract
Rate: £400 - £500/day
Posted:

Security Analyst

Milton Keynes, Buckinghamshire, South East, United Kingdom
VIQU IT Recruitment
Microsoft Sentinel (SIEM) and Microsoft Defender suite (Defender for Endpoint, Identity, Cloud, etc.). Proven track record in security monitoring, incident response, and alert troubleshooting . Working knowledge of SOAR platforms (preferably within Sentinel or similar). Understanding of threat detection, log analysis, and automation within Microsoft's security ecosystem. Experience with Tenable is beneficial Knowledge of Microsoft Purview would … security alerts and incidents in Microsoft Sentinel and Microsoft Defender . Perform detailed security event analysis and correlation, escalating incidents where necessary. Develop and optimise SOAR (Security Orchestration, Automation and Response) playbooks to enhance incident response and efficiency. Collaborate with wider IT and security teams to improve threat detection, incident handling, and response processes. Apply now to speak with VIQU More ❯
Employment Type: Contract
Rate: £400 - 500 per day
Posted:

Security Operations Lead (Contract) – Financial Services

City of London, London, United Kingdom
Alexander Ash Consulting
this role if you are/have: 10+ years hands-on experience in cyber security operations and/or engineering Experience setting up security operations centres including SIEM and SOAR Strong understanding of end-to-end security incident management and response Threat intelligence digital forensics and SOC automation experience Degree educated or higher from a leading academic institution More ❯
Posted:

Security Operations Lead (Contract) – Financial Services

London Area, United Kingdom
Alexander Ash Consulting
this role if you are/have: 10+ years hands-on experience in cyber security operations and/or engineering Experience setting up security operations centres including SIEM and SOAR Strong understanding of end-to-end security incident management and response Threat intelligence digital forensics and SOC automation experience Degree educated or higher from a leading academic institution More ❯
Posted:

Cyber Security Technology Product Owner

London, United Kingdom
Salt
etc. a plus. ? Nice to Have Cloud certifications (Azure, AWS, GCP) Experience working in regulated environments (e.g., finance, government) SAFe Agile or Scrum certifications Prior experience with SIEM/SOAR integration, API security, or Identity Governance ?? Why Join Us Play a key role in shaping enterprise-wide secure access architecture Work with a forward-thinking, cross-functional security team Be More ❯
Employment Type: Temporary
Salary: £600 - £800 per day
Posted:

Cyber Security Technology Product Owner

London, South East, England, United Kingdom
Salt Search
etc. a plus. Nice to Have Cloud certifications (Azure, AWS, GCP) Experience working in regulated environments (e.g., finance, government) SAFe Agile or Scrum certifications Prior experience with SIEM/SOAR integration, API security, or Identity Governance Why Join Us Play a key role in shaping enterprise-wide secure access architecture Work with a forward-thinking, cross-functional security team Be More ❯
Employment Type: Temporary
Salary: £600 - £800 per day
Posted:
SOAR
10th Percentile
£51,095
25th Percentile
£61,250
Median
£78,500
75th Percentile
£89,688
90th Percentile
£96,750