Cyber Security Engineer - Microsoft 365 & Azure 6-Month Contract Outside IR35 (Apply online only) per day Remote (UK) 1-2 Days per Month On-Site (South West London) A leading public sector organisation is looking for a Cyber Security Engineer to support a major cyber security improvement programme. Working alongside the Cyber Security, Infrastructure and Platform teams, you'll help deliver a range of security enhancements across Microsoft 365, Azure and AWS, strengthening the organisation's overall security posture while improving identity, endpoint, cloud and data protection capabilities. This is a fantastic opportunity for someone who enjoys hands-on engineering and wants to be involved in delivering meaningful security improvements across a large enterprise environment. Key Responsibilities Deliver security improvement projects across Microsoft 365, Azure and AWS. Implement and enhance security controls across identity, endpoint, cloud and data protection. Configure and support Microsoft Intune, Microsoft Defender, Microsoft Purview and related Microsoft security technologies. Assist with SIEM configuration, alert tuning and security monitoring. Support Identity & Access Management improvements, including MFA, Conditional Access and Microsoft Entra ID. Work closely with Infrastructure, Platform and Service Desk teams to plan and implement security changes. Assist with vulnerability management and endpoint security improvements. Support cloud security initiatives across Azure and AWS. Produce clear technical documentation and operational handover documentation. Work collaboratively with internal technical teams to ensure successful delivery of security initiatives. Essential Experience We're looking for someone with experience across several of the following areas: Experience working as a Cyber Security Engineer within an enterprise environment. Good knowledge of Microsoft 365 and Azure security. Experience with Microsoft Intune and Microsoft Defender. Understanding of Identity & Access Management, including Microsoft Entra ID, MFA and Conditional Access. Experience supporting or configuring SIEM platforms (Microsoft Sentinel or similar). Knowledge of endpoint security and vulnerability management. Experience working within Azure and/or AWS environments. Basic PowerShell scripting skills. Experience delivering technical projects and working with multiple technology teams. Strong communication skills with the ability to produce clear technical documentation. Desirable Experience Experience in any of the following would be beneficial but is not essential: Microsoft Purview, DLP or Information Protection. Zscaler (ZIA/ZPA). AWS Security. Infrastructure-as-Code (Terraform, Bicep or ARM Templates). Experience within the UK Public Sector or another regulated environment. Knowledge of UK GDPR, PSN or PCI DSS. Contract Details Role: Cyber Security Engineer - Microsoft 365 & Azure Contract: 6 Months Day Rate: (Apply online only) per day IR35 Status: Outside IR35 Location: Remote (UK) Travel: 1-2 days per month on-site in South West London Start Date: ASAP This is an excellent opportunity to join a high-profile cyber security programme, working on modern Microsoft security technologies within a collaborative team while enjoying the flexibility of a predominantly remote contract. GCS is acting as an Employment Business in relation to this vacancy.
Aug 07, 2026
Contractor
Cyber Security Engineer - Microsoft 365 & Azure 6-Month Contract Outside IR35 (Apply online only) per day Remote (UK) 1-2 Days per Month On-Site (South West London) A leading public sector organisation is looking for a Cyber Security Engineer to support a major cyber security improvement programme. Working alongside the Cyber Security, Infrastructure and Platform teams, you'll help deliver a range of security enhancements across Microsoft 365, Azure and AWS, strengthening the organisation's overall security posture while improving identity, endpoint, cloud and data protection capabilities. This is a fantastic opportunity for someone who enjoys hands-on engineering and wants to be involved in delivering meaningful security improvements across a large enterprise environment. Key Responsibilities Deliver security improvement projects across Microsoft 365, Azure and AWS. Implement and enhance security controls across identity, endpoint, cloud and data protection. Configure and support Microsoft Intune, Microsoft Defender, Microsoft Purview and related Microsoft security technologies. Assist with SIEM configuration, alert tuning and security monitoring. Support Identity & Access Management improvements, including MFA, Conditional Access and Microsoft Entra ID. Work closely with Infrastructure, Platform and Service Desk teams to plan and implement security changes. Assist with vulnerability management and endpoint security improvements. Support cloud security initiatives across Azure and AWS. Produce clear technical documentation and operational handover documentation. Work collaboratively with internal technical teams to ensure successful delivery of security initiatives. Essential Experience We're looking for someone with experience across several of the following areas: Experience working as a Cyber Security Engineer within an enterprise environment. Good knowledge of Microsoft 365 and Azure security. Experience with Microsoft Intune and Microsoft Defender. Understanding of Identity & Access Management, including Microsoft Entra ID, MFA and Conditional Access. Experience supporting or configuring SIEM platforms (Microsoft Sentinel or similar). Knowledge of endpoint security and vulnerability management. Experience working within Azure and/or AWS environments. Basic PowerShell scripting skills. Experience delivering technical projects and working with multiple technology teams. Strong communication skills with the ability to produce clear technical documentation. Desirable Experience Experience in any of the following would be beneficial but is not essential: Microsoft Purview, DLP or Information Protection. Zscaler (ZIA/ZPA). AWS Security. Infrastructure-as-Code (Terraform, Bicep or ARM Templates). Experience within the UK Public Sector or another regulated environment. Knowledge of UK GDPR, PSN or PCI DSS. Contract Details Role: Cyber Security Engineer - Microsoft 365 & Azure Contract: 6 Months Day Rate: (Apply online only) per day IR35 Status: Outside IR35 Location: Remote (UK) Travel: 1-2 days per month on-site in South West London Start Date: ASAP This is an excellent opportunity to join a high-profile cyber security programme, working on modern Microsoft security technologies within a collaborative team while enjoying the flexibility of a predominantly remote contract. GCS is acting as an Employment Business in relation to this vacancy.
Senior Cyber Consultant 65,000 + 15k Bonus Hybrid UK A growing cyber security consultancy is seeking a Senior Cyber Consultant to help organisations enhance their Security Operations and threat detection capabilities. This is a client-facing role focused on designing and delivering SIEM, XDR and SOAR solutions, developing detection content, automating security processes, and improving SOC effectiveness. You will lead detection engineering initiatives, create use cases aligned to MITRE ATT&CK, develop response playbooks, and implement Detection-as-Code best practices. Key Requirements Experience with SIEM platforms (Microsoft Sentinel preferred) Strong KQL and detection engineering skills SOAR automation and playbook development experience Python and/or PowerShell scripting XDR/EDR experience Knowledge of MITRE ATT&CK and threat detection methodologies Azure security and cloud telemetry exposure Previous consultancy or customer-facing experience What's on Offer 65,000 base salary Annual Bonus Predominantly remote working No on-call requirement Exposure to enterprise-scale cyber security projects Strong development and progression opportunities Ideal for: Detection Engineers, SIEM Engineers, Senior SOC Analysts, Security Automation Engineers, SOC Consultants, and Cyber Security Engineers seeking a consultancy-focused role.
Aug 07, 2026
Full time
Senior Cyber Consultant 65,000 + 15k Bonus Hybrid UK A growing cyber security consultancy is seeking a Senior Cyber Consultant to help organisations enhance their Security Operations and threat detection capabilities. This is a client-facing role focused on designing and delivering SIEM, XDR and SOAR solutions, developing detection content, automating security processes, and improving SOC effectiveness. You will lead detection engineering initiatives, create use cases aligned to MITRE ATT&CK, develop response playbooks, and implement Detection-as-Code best practices. Key Requirements Experience with SIEM platforms (Microsoft Sentinel preferred) Strong KQL and detection engineering skills SOAR automation and playbook development experience Python and/or PowerShell scripting XDR/EDR experience Knowledge of MITRE ATT&CK and threat detection methodologies Azure security and cloud telemetry exposure Previous consultancy or customer-facing experience What's on Offer 65,000 base salary Annual Bonus Predominantly remote working No on-call requirement Exposure to enterprise-scale cyber security projects Strong development and progression opportunities Ideal for: Detection Engineers, SIEM Engineers, Senior SOC Analysts, Security Automation Engineers, SOC Consultants, and Cyber Security Engineers seeking a consultancy-focused role.
SC Cleared Microsoft Sentinel Detection Engineer - £500/day via Umbrella - Short Term Contract - Remote - Immediate Start - SCC Flex Contract We're looking for an experienced SC Cleared SOC Analyst/Detection Engineer to support the delivery of a prioritised detection engineering backlog across AWS, Azure, Microsoft 365, Defender XDR, Dynatrace, and ServiceNow environments. Key Responsibilities Own assigned Microsoft Sentinel detection engineering use cases from inception through to production deployment. Design, develop and maintain Microsoft Sentinel Analytics Rules, Scheduled Rules, Near Real Time (NRT) Rules and Fusion detection capabilities. Create, optimise and maintain Kusto Query Language (KQL) based detections aligned to relevant MITRE ATT&CK tactics, techniques and procedures (TTPs). Develop and implement detection logic using data from Defender XDR, Microsoft 365, Azure, AWS CloudTrail, Dynatrace, ServiceNow and other integrated Sentinel connectors. Create advanced behavioural detections to identify credential compromise, account takeover, privilege escalation, persistence, lateral movement, defence evasion, command and control activity and data exfiltration. Design and implement correlation logic across multiple telemetry sources to improve detection fidelity and reduce alert fatigue. Develop and maintain Sentinel Watchlists, Entity Mappings, Automation Rules and Logic App integrations where required. Validate detection effectiveness through structured testing, attack simulation, purple team exercises and adversary emulation activities. Perform detection tuning and optimisation activities to minimise false positives and improve operational effectiveness. Support security monitoring maturity initiatives through continuous enhancement of Sentinel content and use cases. Produce high-quality technical documentation including detection logic, implementation details, testing outcomes and operational support procedures. Deliver knowledge transfer sessions and operational handovers to SOC Analysts, Security Engineers and Detection Engineering teams. Work closely with Threat Intelligence, Security Operations, Incident Response and Security Architecture teams to improve detection coverage and threat visibility. Support incident investigations through detection enhancement and rapid development of new Sentinel content to address emerging threats. Participate in technical workshops, backlog grooming, sprint planning and governance activities. Deliver assigned use cases in line with agreed priorities, quality standards and delivery milestones. Technical Requirements Proven hands-on experience with Microsoft Sentinel. Strong Kusto Query Language (KQL) development expertise. Experience creating and managing Sentinel Analytics Rules, Hunting Queries, Fusion Rules and Automation Rules. Strong knowledge of Microsoft Defender XDR, including Defender for Endpoint, Defender for Identity, Defender for Cloud Apps and Defender for Office 365. Experience ingesting and analysing security telemetry from Azure, Microsoft 365, AWS, Syslog, CEF and custom data sources. Knowledge of MITRE ATT&CK framework and detection engineering best practices. Experience tuning SIEM detections and reducing false positives within enterprise environments. Understanding of attack methodologies, adversary behaviours and modern threat actor techniques. Familiarity with Sentinel Content Hub solutions, Data Connectors and SOAR integrations. Experience with Logic Apps and security automation is advantageous. If you are a Microsoft Sentinel Detection Engineer looking to make an impact in a fast-paced environment, apply today - professional references required. NOTE: At SCC, we take the privacy and security of your information very seriously. Any information we hold will be handled in accordance with current data protection legislation. Upon submitting your application, SCC will process your information in line with our privacy policy, which can be found on our website under Legal Privacy Notice Flexible Resourcing.
Aug 07, 2026
Contractor
SC Cleared Microsoft Sentinel Detection Engineer - £500/day via Umbrella - Short Term Contract - Remote - Immediate Start - SCC Flex Contract We're looking for an experienced SC Cleared SOC Analyst/Detection Engineer to support the delivery of a prioritised detection engineering backlog across AWS, Azure, Microsoft 365, Defender XDR, Dynatrace, and ServiceNow environments. Key Responsibilities Own assigned Microsoft Sentinel detection engineering use cases from inception through to production deployment. Design, develop and maintain Microsoft Sentinel Analytics Rules, Scheduled Rules, Near Real Time (NRT) Rules and Fusion detection capabilities. Create, optimise and maintain Kusto Query Language (KQL) based detections aligned to relevant MITRE ATT&CK tactics, techniques and procedures (TTPs). Develop and implement detection logic using data from Defender XDR, Microsoft 365, Azure, AWS CloudTrail, Dynatrace, ServiceNow and other integrated Sentinel connectors. Create advanced behavioural detections to identify credential compromise, account takeover, privilege escalation, persistence, lateral movement, defence evasion, command and control activity and data exfiltration. Design and implement correlation logic across multiple telemetry sources to improve detection fidelity and reduce alert fatigue. Develop and maintain Sentinel Watchlists, Entity Mappings, Automation Rules and Logic App integrations where required. Validate detection effectiveness through structured testing, attack simulation, purple team exercises and adversary emulation activities. Perform detection tuning and optimisation activities to minimise false positives and improve operational effectiveness. Support security monitoring maturity initiatives through continuous enhancement of Sentinel content and use cases. Produce high-quality technical documentation including detection logic, implementation details, testing outcomes and operational support procedures. Deliver knowledge transfer sessions and operational handovers to SOC Analysts, Security Engineers and Detection Engineering teams. Work closely with Threat Intelligence, Security Operations, Incident Response and Security Architecture teams to improve detection coverage and threat visibility. Support incident investigations through detection enhancement and rapid development of new Sentinel content to address emerging threats. Participate in technical workshops, backlog grooming, sprint planning and governance activities. Deliver assigned use cases in line with agreed priorities, quality standards and delivery milestones. Technical Requirements Proven hands-on experience with Microsoft Sentinel. Strong Kusto Query Language (KQL) development expertise. Experience creating and managing Sentinel Analytics Rules, Hunting Queries, Fusion Rules and Automation Rules. Strong knowledge of Microsoft Defender XDR, including Defender for Endpoint, Defender for Identity, Defender for Cloud Apps and Defender for Office 365. Experience ingesting and analysing security telemetry from Azure, Microsoft 365, AWS, Syslog, CEF and custom data sources. Knowledge of MITRE ATT&CK framework and detection engineering best practices. Experience tuning SIEM detections and reducing false positives within enterprise environments. Understanding of attack methodologies, adversary behaviours and modern threat actor techniques. Familiarity with Sentinel Content Hub solutions, Data Connectors and SOAR integrations. Experience with Logic Apps and security automation is advantageous. If you are a Microsoft Sentinel Detection Engineer looking to make an impact in a fast-paced environment, apply today - professional references required. NOTE: At SCC, we take the privacy and security of your information very seriously. Any information we hold will be handled in accordance with current data protection legislation. Upon submitting your application, SCC will process your information in line with our privacy policy, which can be found on our website under Legal Privacy Notice Flexible Resourcing.
Role: Sentinel Engineer Type: Contract (Inside IR35) Duration: 6 months Location: Remote Overview We are seeking an experienced Microsoft Sentinel Engineer with a strong cyber security background to support the delivery, optimisation, and ongoing development of a large-scale Microsoft security environment. The successful candidate will play a key role in enhancing security monitoring, threat detection, automation, and SIEM capabilities, whilst helping drive security improvements across cloud and hybrid platforms. This role is ideally suited to a hands-on Security Engineer with proven experience implementing and managing Microsoft Sentinel, delivering SIEM migrations, and working across the wider Microsoft Security stack. You will work closely with Security Operations, Infrastructure, and Cloud teams to strengthen the organisation's security posture and improve incident detection and response capabilities. Key Responsibilities Design, implement, configure and support Microsoft Sentinel solutions . Lead and support SIEM migration projects from legacy platforms into Microsoft Sentinel . Develop and maintain analytics rules, alerting capabilities and detection use cases. Create and optimise Kusto Query Language (KQL) queries for threat hunting, incident investigation and reporting. Integrate and onboard new log sources and security tooling into Sentinel. Configure and support Azure Monitor and Log Analytics environments . Develop automation and orchestration playbooks using Azure Logic Apps. Work with Microsoft Defender technologies to improve threat detection and response. Build dashboards, workbooks and reporting capabilities for operational and management teams. Support Security Operations teams with incident response, threat hunting and security investigations. Tune detections and reduce false positives whilst improving overall visibility and coverage. Implement security best practices aligned to industry frameworks and standards. Collaborate with internal and third-party stakeholders across security, infrastructure and cloud teams. Essential Skills & Experience Technical Skills Microsoft Sentinel SIEM Migration Experience Log Analytics Azure Monitor Microsoft Defender XDR Microsoft Defender for Endpoint Microsoft Defender for Cloud Microsoft 365 Security Kusto Query Language (KQL) Azure Logic Apps Azure Lighthouse Experience Minimum 5 years' experience within Cyber Security, Security Engineering, SOC, SIEM Engineering or related disciplines. Strong understanding of SIEM, SOAR, threat detection and incident response. Demonstrable experience designing and implementing Microsoft Sentinel solutions. Experience developing detection rules, use cases and security monitoring capabilities. Strong threat hunting and security investigation experience. Knowledge of MITRE ATT&CK and modern security operations practices. Experience working within enterprise-scale Azure and Microsoft security environments. Desirable Skills QRadar Devo SentinelOne Mimecast Check Point Qualys Azure Networking Terraform PowerShell Python GitHub Azure DevOps ServiceNow Azure RBAC Azure Monitor Agent (AMA) Data Collection Rules (DCR) Syslog CEF Windows Event Logging Linux Logging REST APIs Candidate Profile The ideal candidate will be a proactive and technically strong Security Engineer who combines deep Microsoft Sentinel expertise with a broad understanding of cyber security operations. You will be comfortable working in a fast-paced environment, engaging with stakeholders at all levels, and driving improvements across monitoring, detection, automation and incident response capabilities.
Aug 07, 2026
Contractor
Role: Sentinel Engineer Type: Contract (Inside IR35) Duration: 6 months Location: Remote Overview We are seeking an experienced Microsoft Sentinel Engineer with a strong cyber security background to support the delivery, optimisation, and ongoing development of a large-scale Microsoft security environment. The successful candidate will play a key role in enhancing security monitoring, threat detection, automation, and SIEM capabilities, whilst helping drive security improvements across cloud and hybrid platforms. This role is ideally suited to a hands-on Security Engineer with proven experience implementing and managing Microsoft Sentinel, delivering SIEM migrations, and working across the wider Microsoft Security stack. You will work closely with Security Operations, Infrastructure, and Cloud teams to strengthen the organisation's security posture and improve incident detection and response capabilities. Key Responsibilities Design, implement, configure and support Microsoft Sentinel solutions . Lead and support SIEM migration projects from legacy platforms into Microsoft Sentinel . Develop and maintain analytics rules, alerting capabilities and detection use cases. Create and optimise Kusto Query Language (KQL) queries for threat hunting, incident investigation and reporting. Integrate and onboard new log sources and security tooling into Sentinel. Configure and support Azure Monitor and Log Analytics environments . Develop automation and orchestration playbooks using Azure Logic Apps. Work with Microsoft Defender technologies to improve threat detection and response. Build dashboards, workbooks and reporting capabilities for operational and management teams. Support Security Operations teams with incident response, threat hunting and security investigations. Tune detections and reduce false positives whilst improving overall visibility and coverage. Implement security best practices aligned to industry frameworks and standards. Collaborate with internal and third-party stakeholders across security, infrastructure and cloud teams. Essential Skills & Experience Technical Skills Microsoft Sentinel SIEM Migration Experience Log Analytics Azure Monitor Microsoft Defender XDR Microsoft Defender for Endpoint Microsoft Defender for Cloud Microsoft 365 Security Kusto Query Language (KQL) Azure Logic Apps Azure Lighthouse Experience Minimum 5 years' experience within Cyber Security, Security Engineering, SOC, SIEM Engineering or related disciplines. Strong understanding of SIEM, SOAR, threat detection and incident response. Demonstrable experience designing and implementing Microsoft Sentinel solutions. Experience developing detection rules, use cases and security monitoring capabilities. Strong threat hunting and security investigation experience. Knowledge of MITRE ATT&CK and modern security operations practices. Experience working within enterprise-scale Azure and Microsoft security environments. Desirable Skills QRadar Devo SentinelOne Mimecast Check Point Qualys Azure Networking Terraform PowerShell Python GitHub Azure DevOps ServiceNow Azure RBAC Azure Monitor Agent (AMA) Data Collection Rules (DCR) Syslog CEF Windows Event Logging Linux Logging REST APIs Candidate Profile The ideal candidate will be a proactive and technically strong Security Engineer who combines deep Microsoft Sentinel expertise with a broad understanding of cyber security operations. You will be comfortable working in a fast-paced environment, engaging with stakeholders at all levels, and driving improvements across monitoring, detection, automation and incident response capabilities.
Senior Security Engineering Team Lead Leeds (Home with 1 HQ visit per quarter) Up to 82,500 (NEG) + Excellent Benefits Are you an experienced Security Engineer ready to lead from the front? We're supporting a leading international managed technology organisation in the search for a Senior Security Engineering Team Lead to head a dedicated cyber security engineering function supporting a major enterprise customer operating within a highly regulated environment. This is far more than a traditional management role. You'll remain hands-on, acting as the technical authority for Microsoft security technologies whilst leading a team of experienced Security Analysts and Engineers responsible for protecting a critical customer environment. If you're passionate about Microsoft security, detection engineering, automation and mentoring technical teams, this is an opportunity to influence the direction of an enterprise-scale security operation. The Opportunity As the technical lead for the Security Engineering function, you'll own the security platform estate, providing architectural guidance, driving continuous improvement and acting as the primary escalation point for complex cyber security incidents. You'll combine strategic leadership with hands-on engineering, working closely with Security Analysts, Infrastructure teams and customer stakeholders to ensure security platforms remain resilient, effective and continually evolving. This is an excellent opportunity to join an organisation that invests heavily in technology, professional development and long-term career progression whilst working with some of the latest Microsoft security technologies. Key Responsibilities Lead and develop a team of Security Engineers and Security Analysts Act as the senior technical escalation point for complex cyber security incidents Own the configuration, maintenance and optimisation of the Microsoft security platform Drive detection engineering, rule tuning and continuous platform improvement Lead SIEM and SOAR engineering activities, including automation and Logic Apps Oversee log ingestion, telemetry quality and detection coverage Support vulnerability management and exposure management tooling Work closely with customers and internal technical teams on security architecture and platform improvements Mentor engineers and analysts, helping raise technical capability across the team Contribute to platform roadmaps, governance, documentation and service improvements Technology Environment You'll work across a modern Microsoft-centric cyber security stack including: Microsoft Defender XDR Defender for Endpoint Defender for Identity Microsoft Sentinel Logic Apps SOAR Automation Microsoft Purview Qualys XM Cyber CyberArk Detection Engineering KQL Threat Hunting Platform Engineering About You We're looking for someone who combines deep technical expertise with natural leadership skills. You'll likely have experience in areas such as: Security Engineering Detection Engineering SOC Engineering Microsoft Security Security Platform Management Cyber Security Architecture Security Automation Team Leadership You'll also possess: Expert knowledge of Microsoft Defender technologies Strong Microsoft Sentinel experience Experience building or improving security detections Knowledge of SOAR and security automation Experience within regulated or enterprise environments Excellent stakeholder management and communication skills Previous leadership or mentoring experience Why Apply? This organisation is recognised as one of the world's leading managed technology providers, delivering cloud, cyber security, data and digital workplace solutions to thousands of enterprise customers across multiple countries. It combines the scale of an international business with a culture that genuinely invests in its people through continuous learning, technical certifications, structured development programmes and internal career progression. You'll be joining at an exciting stage of growth, leading a newly established security capability supporting a strategic customer where you'll have genuine influence over both the technology roadmap and the development of your team. Package Salary up to 82,500 (NEG) Home working with one visit to HQ per quarter Excellent benefits package Significant investment in training and certifications Career progression opportunities Opportunity to work with enterprise Microsoft security technologies Technical leadership role with genuine strategic influence
Aug 06, 2026
Full time
Senior Security Engineering Team Lead Leeds (Home with 1 HQ visit per quarter) Up to 82,500 (NEG) + Excellent Benefits Are you an experienced Security Engineer ready to lead from the front? We're supporting a leading international managed technology organisation in the search for a Senior Security Engineering Team Lead to head a dedicated cyber security engineering function supporting a major enterprise customer operating within a highly regulated environment. This is far more than a traditional management role. You'll remain hands-on, acting as the technical authority for Microsoft security technologies whilst leading a team of experienced Security Analysts and Engineers responsible for protecting a critical customer environment. If you're passionate about Microsoft security, detection engineering, automation and mentoring technical teams, this is an opportunity to influence the direction of an enterprise-scale security operation. The Opportunity As the technical lead for the Security Engineering function, you'll own the security platform estate, providing architectural guidance, driving continuous improvement and acting as the primary escalation point for complex cyber security incidents. You'll combine strategic leadership with hands-on engineering, working closely with Security Analysts, Infrastructure teams and customer stakeholders to ensure security platforms remain resilient, effective and continually evolving. This is an excellent opportunity to join an organisation that invests heavily in technology, professional development and long-term career progression whilst working with some of the latest Microsoft security technologies. Key Responsibilities Lead and develop a team of Security Engineers and Security Analysts Act as the senior technical escalation point for complex cyber security incidents Own the configuration, maintenance and optimisation of the Microsoft security platform Drive detection engineering, rule tuning and continuous platform improvement Lead SIEM and SOAR engineering activities, including automation and Logic Apps Oversee log ingestion, telemetry quality and detection coverage Support vulnerability management and exposure management tooling Work closely with customers and internal technical teams on security architecture and platform improvements Mentor engineers and analysts, helping raise technical capability across the team Contribute to platform roadmaps, governance, documentation and service improvements Technology Environment You'll work across a modern Microsoft-centric cyber security stack including: Microsoft Defender XDR Defender for Endpoint Defender for Identity Microsoft Sentinel Logic Apps SOAR Automation Microsoft Purview Qualys XM Cyber CyberArk Detection Engineering KQL Threat Hunting Platform Engineering About You We're looking for someone who combines deep technical expertise with natural leadership skills. You'll likely have experience in areas such as: Security Engineering Detection Engineering SOC Engineering Microsoft Security Security Platform Management Cyber Security Architecture Security Automation Team Leadership You'll also possess: Expert knowledge of Microsoft Defender technologies Strong Microsoft Sentinel experience Experience building or improving security detections Knowledge of SOAR and security automation Experience within regulated or enterprise environments Excellent stakeholder management and communication skills Previous leadership or mentoring experience Why Apply? This organisation is recognised as one of the world's leading managed technology providers, delivering cloud, cyber security, data and digital workplace solutions to thousands of enterprise customers across multiple countries. It combines the scale of an international business with a culture that genuinely invests in its people through continuous learning, technical certifications, structured development programmes and internal career progression. You'll be joining at an exciting stage of growth, leading a newly established security capability supporting a strategic customer where you'll have genuine influence over both the technology roadmap and the development of your team. Package Salary up to 82,500 (NEG) Home working with one visit to HQ per quarter Excellent benefits package Significant investment in training and certifications Career progression opportunities Opportunity to work with enterprise Microsoft security technologies Technical leadership role with genuine strategic influence
Role Title: Splunk SIEM Engineer Duration: contract to run until 30/11/2026 Location: Knutsford. Hybrid, 3 days per week onsite Rate: up to 587.33 p/d Umbrella inside IR35 Role purpose / summary Join us as Splunk SIEM Engineer where you must design, develop and improve software, utilizing various engineering methodologies, that provides business, platform, and technology capabilities for our customers and colleagues. Looking for a successful Splunk SIEM Engineer, where one should have experience with: Minimum Qualification - bachelor's degree Multi-Platform SIEM Expertise: Proven experience with Splunk Enterprise Security, Microsoft Sentinel, and SIEM architecture including data models, correlation rules, and administrative functions. Security Operations: Strong analytical skills in threat detection, incident response, and security event analysis with experience in large enterprise environments (10,000+ endpoints). Data Pipeline Management: Hands-on experience with log ingestion, data routing, and transformation using tools like Cribl, plus understanding of data normalisation and parsing in Splunk Enterprise. SOAR & Automation: Experience with Security Orchestration platforms, playbook development, and automated response workflows for incident management. Network Security Fundamentals: Working knowledge of network architectures, firewalls, proxies, and common attack vectors with troubleshooting expertise. Communication & Documentation: Excellent technical writing and communication skills to create runbooks, procedures, and translate complex security concepts for diverse audiences. Some other highly valued skills may include: Cloud Security & Modern Infrastructure: Proficiency with AWS/Azure cloud security, containerized environments, and SaaS-based security solutions. Programming & Scripting: Advanced skills in Python, PowerShell, KQL, SPL, and SQL for automation, custom integrations, and advanced analytics development. Security Certifications: Professional certifications such as CISSP, GCIH, GCFA, Splunk Certified Architect, or Microsoft Sentinel Ninja. Extended Security Stack: Experience with EDR, UBA, CASB, CSPM, vulnerability assessment tools, and threat intelligence platforms. Infrastructure as Code: Experience with Chef, Ansible, Jenkins, GitLab CI/CD for automated security tool deployment and configuration management. Compliance & Governance: Knowledge of regulatory frameworks (SOX, PCI-DSS, GDPR) and hands-on incident response/forensics experience. All profiles will be reviewed against the required skills and experience. Due to the high number of applications we will only be able to respond to successful applicants in the first instance. We thank you for your interest and the time taken to apply! If you receive suspicious outreach claiming to be from us, please contact us via the ManpowerGroup website.
Aug 06, 2026
Contractor
Role Title: Splunk SIEM Engineer Duration: contract to run until 30/11/2026 Location: Knutsford. Hybrid, 3 days per week onsite Rate: up to 587.33 p/d Umbrella inside IR35 Role purpose / summary Join us as Splunk SIEM Engineer where you must design, develop and improve software, utilizing various engineering methodologies, that provides business, platform, and technology capabilities for our customers and colleagues. Looking for a successful Splunk SIEM Engineer, where one should have experience with: Minimum Qualification - bachelor's degree Multi-Platform SIEM Expertise: Proven experience with Splunk Enterprise Security, Microsoft Sentinel, and SIEM architecture including data models, correlation rules, and administrative functions. Security Operations: Strong analytical skills in threat detection, incident response, and security event analysis with experience in large enterprise environments (10,000+ endpoints). Data Pipeline Management: Hands-on experience with log ingestion, data routing, and transformation using tools like Cribl, plus understanding of data normalisation and parsing in Splunk Enterprise. SOAR & Automation: Experience with Security Orchestration platforms, playbook development, and automated response workflows for incident management. Network Security Fundamentals: Working knowledge of network architectures, firewalls, proxies, and common attack vectors with troubleshooting expertise. Communication & Documentation: Excellent technical writing and communication skills to create runbooks, procedures, and translate complex security concepts for diverse audiences. Some other highly valued skills may include: Cloud Security & Modern Infrastructure: Proficiency with AWS/Azure cloud security, containerized environments, and SaaS-based security solutions. Programming & Scripting: Advanced skills in Python, PowerShell, KQL, SPL, and SQL for automation, custom integrations, and advanced analytics development. Security Certifications: Professional certifications such as CISSP, GCIH, GCFA, Splunk Certified Architect, or Microsoft Sentinel Ninja. Extended Security Stack: Experience with EDR, UBA, CASB, CSPM, vulnerability assessment tools, and threat intelligence platforms. Infrastructure as Code: Experience with Chef, Ansible, Jenkins, GitLab CI/CD for automated security tool deployment and configuration management. Compliance & Governance: Knowledge of regulatory frameworks (SOX, PCI-DSS, GDPR) and hands-on incident response/forensics experience. All profiles will be reviewed against the required skills and experience. Due to the high number of applications we will only be able to respond to successful applicants in the first instance. We thank you for your interest and the time taken to apply! If you receive suspicious outreach claiming to be from us, please contact us via the ManpowerGroup website.
The Role The Senior Security Engineer (Team Leader) is responsible for leading a dedicated security engineering team, combining hands-on platform engineering with technical leadership and people management. You will own security platform architecture, act as the primary escalation point for complex issues, and ensure platforms remain secure, resilient, and compliant within a regulated environment. Key Responsibilities Act as technical lead for security engineering and platform architecture Serve as primary escalation point for complex and major incidents Provide technical leadership and mentoring to engineers and analysts Line manage and develop the security engineering and analyst teams Own platform maintenance, configuration, and lifecycle management Ensure security platforms are integrated across hybrid environments Oversee patching, upgrades, and platform performance Drive platform improvements and engineering enhancements Support detection engineering, tuning, and platform optimisation Lead automation and SOAR initiatives to improve efficiency Collaborate with SOC providers on SIEM governance and data ingestion Ensure platforms meet regulatory and compliance requirements Maintain engineering documentation, standards, and governance Represent engineering in client governance and audit activities Coordinate cross-team resolution of complex technical issues Experience & Knowledge Essential: Significant experience in security engineering and platform management Strong leadership experience managing technical teams Deep knowledge of Microsoft Defender and SIEM platforms (e.g. Sentinel) Experience in hybrid cloud and on-prem environments Strong understanding of security architecture and frameworks Experience in regulated environments (e.g. financial services) Strong stakeholder and client engagement skills Experience with automation and scripting (PowerShell, Python, etc.) Desirable: Experience with vulnerability and exposure management tools Knowledge of security frameworks (NIST, ISO 27001, CIS) Relevant security certifications (e.g. CISSP, AZ-500, SC-100)
Aug 05, 2026
Full time
The Role The Senior Security Engineer (Team Leader) is responsible for leading a dedicated security engineering team, combining hands-on platform engineering with technical leadership and people management. You will own security platform architecture, act as the primary escalation point for complex issues, and ensure platforms remain secure, resilient, and compliant within a regulated environment. Key Responsibilities Act as technical lead for security engineering and platform architecture Serve as primary escalation point for complex and major incidents Provide technical leadership and mentoring to engineers and analysts Line manage and develop the security engineering and analyst teams Own platform maintenance, configuration, and lifecycle management Ensure security platforms are integrated across hybrid environments Oversee patching, upgrades, and platform performance Drive platform improvements and engineering enhancements Support detection engineering, tuning, and platform optimisation Lead automation and SOAR initiatives to improve efficiency Collaborate with SOC providers on SIEM governance and data ingestion Ensure platforms meet regulatory and compliance requirements Maintain engineering documentation, standards, and governance Represent engineering in client governance and audit activities Coordinate cross-team resolution of complex technical issues Experience & Knowledge Essential: Significant experience in security engineering and platform management Strong leadership experience managing technical teams Deep knowledge of Microsoft Defender and SIEM platforms (e.g. Sentinel) Experience in hybrid cloud and on-prem environments Strong understanding of security architecture and frameworks Experience in regulated environments (e.g. financial services) Strong stakeholder and client engagement skills Experience with automation and scripting (PowerShell, Python, etc.) Desirable: Experience with vulnerability and exposure management tools Knowledge of security frameworks (NIST, ISO 27001, CIS) Relevant security certifications (e.g. CISSP, AZ-500, SC-100)
Security Engineer Job Type: Fixed-Term Contract (6 months) Working Arrangement: Hybrid 2 days in the office per week Office Location: City of London Full Job Description This is an exciting opportunity to play a pivotal role in delivering and advancing security engineering initiatives within a globally recognised law firm. You will join a fast-paced and dynamic environment where you'll contribute to a variety of security projects, helping to strengthen the firm's security capabilities while supporting key business objectives. This is not a traditional SOC role. Whilst SIEM engineering and integration experience remain essential, the focus is firmly on security engineering, project delivery, platform improvements, and business engagement. We're looking for someone who can successfully balance multiple priorities, adapt quickly to changing requirements, and drive security initiatives forward with minimal supervision. The Role As a Security Engineer, you will: Lead and contribute to a range of security engineering and improvemeant projects across the business. Enhance, optimise, and integrate security technologies, with a particular focus on SIEM platforms and associated tooling. Identify, onboard, and integrate new log sources across cloud, on-premise, network, endpoint, and identity environments. Design, build, and implement security solutions that improve the organisation's detection, monitoring, and response capabilities. Develop and refine detection use cases, dashboards, workflows, and automation initiatives. Support the design and execution of security-related change and build activities. Work closely with technical teams, security stakeholders, and business users to deliver successful outcomes. Provide subject matter expertise and technical guidance across security platforms and projects. Produce and maintain high-quality technical and operational documentation. What We're Looking For Essential Experience Proven experience working in a Security Engineering role rather than a purely SOC or analyst-focused position. Strong hands-on SIEM engineering and integration experience with platforms such as Microsoft Sentinel, Splunk, Exabeam, QRadar, or Elastic. Experience delivering security-related projects, change initiatives, and platform enhancements. Strong understanding of log ingestion technologies and formats including JSON, Syslog, CEF, and XML. Experience building and tuning detections, correlation rules, dashboards, and security workflows. Scripting and automation experience using tools such as Python, PowerShell, or similar technologies. Ability to manage multiple projects and competing priorities within a fast-paced environment. Excellent communication and stakeholder management skills, with the confidence to engage directly with both technical and non-technical audiences. Strong business English, both written and verbal. Highly Desirable Previous experience working within a law firm, professional services organisation, or consultancy environment. Experience working in client-facing or business-facing security roles. Knowledge of MITRE ATT&CK, threat detection, security operations, and security architecture principles. Familiarity with SOAR platforms and security automation. Relevant certifications such as CISSP, SSCP, Microsoft SC-200/SC-100, or GIAC certifications. A Level 4 qualification or higher in a computing-related discipline, or equivalent commercial experience. Who Will Succeed in This Role? We're looking for a high-energy, proactive individual who thrives in a fast-moving environment. You'll be comfortable operating autonomously, driving initiatives forward, and adapting to changing business priorities. This role will suit someone who enjoys building relationships across the organisation, can communicate effectively with a wide range of stakeholders, and has a track record of delivering successful security engineering outcomes. Services offered by Computappoint Limited are those of an Employment Business and/or Employment Agency in relation to this vacancy. Computappoint do not use AI to filter or assess candidates. We use experienced and dedicated recruiters who focus on matching the best people with the right opportunities.
Aug 05, 2026
Full time
Security Engineer Job Type: Fixed-Term Contract (6 months) Working Arrangement: Hybrid 2 days in the office per week Office Location: City of London Full Job Description This is an exciting opportunity to play a pivotal role in delivering and advancing security engineering initiatives within a globally recognised law firm. You will join a fast-paced and dynamic environment where you'll contribute to a variety of security projects, helping to strengthen the firm's security capabilities while supporting key business objectives. This is not a traditional SOC role. Whilst SIEM engineering and integration experience remain essential, the focus is firmly on security engineering, project delivery, platform improvements, and business engagement. We're looking for someone who can successfully balance multiple priorities, adapt quickly to changing requirements, and drive security initiatives forward with minimal supervision. The Role As a Security Engineer, you will: Lead and contribute to a range of security engineering and improvemeant projects across the business. Enhance, optimise, and integrate security technologies, with a particular focus on SIEM platforms and associated tooling. Identify, onboard, and integrate new log sources across cloud, on-premise, network, endpoint, and identity environments. Design, build, and implement security solutions that improve the organisation's detection, monitoring, and response capabilities. Develop and refine detection use cases, dashboards, workflows, and automation initiatives. Support the design and execution of security-related change and build activities. Work closely with technical teams, security stakeholders, and business users to deliver successful outcomes. Provide subject matter expertise and technical guidance across security platforms and projects. Produce and maintain high-quality technical and operational documentation. What We're Looking For Essential Experience Proven experience working in a Security Engineering role rather than a purely SOC or analyst-focused position. Strong hands-on SIEM engineering and integration experience with platforms such as Microsoft Sentinel, Splunk, Exabeam, QRadar, or Elastic. Experience delivering security-related projects, change initiatives, and platform enhancements. Strong understanding of log ingestion technologies and formats including JSON, Syslog, CEF, and XML. Experience building and tuning detections, correlation rules, dashboards, and security workflows. Scripting and automation experience using tools such as Python, PowerShell, or similar technologies. Ability to manage multiple projects and competing priorities within a fast-paced environment. Excellent communication and stakeholder management skills, with the confidence to engage directly with both technical and non-technical audiences. Strong business English, both written and verbal. Highly Desirable Previous experience working within a law firm, professional services organisation, or consultancy environment. Experience working in client-facing or business-facing security roles. Knowledge of MITRE ATT&CK, threat detection, security operations, and security architecture principles. Familiarity with SOAR platforms and security automation. Relevant certifications such as CISSP, SSCP, Microsoft SC-200/SC-100, or GIAC certifications. A Level 4 qualification or higher in a computing-related discipline, or equivalent commercial experience. Who Will Succeed in This Role? We're looking for a high-energy, proactive individual who thrives in a fast-moving environment. You'll be comfortable operating autonomously, driving initiatives forward, and adapting to changing business priorities. This role will suit someone who enjoys building relationships across the organisation, can communicate effectively with a wide range of stakeholders, and has a track record of delivering successful security engineering outcomes. Services offered by Computappoint Limited are those of an Employment Business and/or Employment Agency in relation to this vacancy. Computappoint do not use AI to filter or assess candidates. We use experienced and dedicated recruiters who focus on matching the best people with the right opportunities.
Join a well-established biotech company using large-scale genetic data and AI to predict disease risk and advance precision healthcare. We re looking for a Threat Detection Engineer who thrives on innovation and technical ownership. This role is not a traditional SOC position, you ll focus on building high-impact detection capabilities, shaping how security protects sensitive genomic and AI-driven data at scale. This role offers hybrid / remote working options, a salary range of £60,000 - £80,000 and benefits. Why This Role is Exciting High autonomy: Lead projects from idea to deployment Innovation-driven: Develop cutting-edge detections beyond standard SIEM rules Collaborative: Work closely with internal teams and an outsourced SOC partner Mission-focused: Protect critical healthcare data that supports precision medicine Key Responsibilities Design and develop threat-led detections using threat intelligence and threat-hunting outputs Create novel analytic techniques for incident detection Collaborate with an MSP SOC to maintain and tune the detection catalogue Build automated reporting dashboards using Microsoft Sentinel workbooks Support security initiatives including ISO 27001 activities and KQL-based tasks Ensure monitoring coverage across cloud platforms, SaaS apps, and internal systems Contribute to documentation of processes, tools, and detection logic What You ll Bring Must-Have Skills & Experience: Previously worked as a Threat Detection Engineer or in a similar role. Strong proficiency in KQL and hands-on experience with Microsoft Sentinel Familiarity with Microsoft Defender tools (Endpoint & O365) Exposure to Azure cloud logging and Kubernetes environments Knowledge of attacker TTPs and MITRE ATT&CK frameworks Proactive, collaborative, and innovative mindset Desirable / Nice-to-Have: Experience with Python, Terraform, or CI/CD pipelines Familiarity with Microsoft Purview, Entra ID, DLP, or Insider Risk tools Understanding of ISO 27001, Agile ways of working Knowledge of statistics, data science, or AI/ML applied to cybersecurity Relevant certifications (MS-500, AZ-500, SC-series, Security+, GSOC, CCSK) Perks & Benefits Hybrid / remote working options Flexible benefits package Opportunity to innovate and make a real impact in threat detection Work in a small, fast-paced, highly collaborative team Contribute to advancing precision healthcare using genomic data and AI Ready to build next-generation threat detection and protect life-changing data Apply today! Important Information: We endeavour to process your personal data in a fair and transparent manner. In applying for this role, Additional Resources will be acting in your best interest and may contact you in relation to the role, either by email, phone, or text message. For more information see our Privacy Policy on our website. It is important you are aware of your individual rights and the provisions the company has put in place to protect your data. If you would like further information on the policy or GDPR please contact us. Additional Resources Ltd is an Employment Business and an Employment Agency as defined within The Conduct of Employment Agencies & Employment Businesses Regulations 2003.
Aug 04, 2026
Full time
Join a well-established biotech company using large-scale genetic data and AI to predict disease risk and advance precision healthcare. We re looking for a Threat Detection Engineer who thrives on innovation and technical ownership. This role is not a traditional SOC position, you ll focus on building high-impact detection capabilities, shaping how security protects sensitive genomic and AI-driven data at scale. This role offers hybrid / remote working options, a salary range of £60,000 - £80,000 and benefits. Why This Role is Exciting High autonomy: Lead projects from idea to deployment Innovation-driven: Develop cutting-edge detections beyond standard SIEM rules Collaborative: Work closely with internal teams and an outsourced SOC partner Mission-focused: Protect critical healthcare data that supports precision medicine Key Responsibilities Design and develop threat-led detections using threat intelligence and threat-hunting outputs Create novel analytic techniques for incident detection Collaborate with an MSP SOC to maintain and tune the detection catalogue Build automated reporting dashboards using Microsoft Sentinel workbooks Support security initiatives including ISO 27001 activities and KQL-based tasks Ensure monitoring coverage across cloud platforms, SaaS apps, and internal systems Contribute to documentation of processes, tools, and detection logic What You ll Bring Must-Have Skills & Experience: Previously worked as a Threat Detection Engineer or in a similar role. Strong proficiency in KQL and hands-on experience with Microsoft Sentinel Familiarity with Microsoft Defender tools (Endpoint & O365) Exposure to Azure cloud logging and Kubernetes environments Knowledge of attacker TTPs and MITRE ATT&CK frameworks Proactive, collaborative, and innovative mindset Desirable / Nice-to-Have: Experience with Python, Terraform, or CI/CD pipelines Familiarity with Microsoft Purview, Entra ID, DLP, or Insider Risk tools Understanding of ISO 27001, Agile ways of working Knowledge of statistics, data science, or AI/ML applied to cybersecurity Relevant certifications (MS-500, AZ-500, SC-series, Security+, GSOC, CCSK) Perks & Benefits Hybrid / remote working options Flexible benefits package Opportunity to innovate and make a real impact in threat detection Work in a small, fast-paced, highly collaborative team Contribute to advancing precision healthcare using genomic data and AI Ready to build next-generation threat detection and protect life-changing data Apply today! Important Information: We endeavour to process your personal data in a fair and transparent manner. In applying for this role, Additional Resources will be acting in your best interest and may contact you in relation to the role, either by email, phone, or text message. For more information see our Privacy Policy on our website. It is important you are aware of your individual rights and the provisions the company has put in place to protect your data. If you would like further information on the policy or GDPR please contact us. Additional Resources Ltd is an Employment Business and an Employment Agency as defined within The Conduct of Employment Agencies & Employment Businesses Regulations 2003.
We are working with a client who is a global leader in consulting, technology services, and digital transformation, committed to delivering positive change through technology and human collaboration. They are looking for a Splunk SIEM Engineer with active SC Clearance in place to design, develop and improve software, utilising various engineering methodologies, that provides business, platform, and technology capabilities for our customers and colleagues. You will need to demonstrate your Multi-Platform SIEM Expertise: you need proven experience with Splunk Enterprise Security, Microsoft Sentinel, and SIEM architecture including data models, correlation rules, and administrative functions. Security Operations: Strong analytical skills in threat detection, incident response, and security event analysis with experience in large enterprise environments (10,000+ endpoints). Data Pipeline Management: Hands-on experience with log ingestion, data routing, and transformation using tools like Cribl, plus understanding of data normalisation and parsing in Splunk Enterprise. SOAR & Automation: Experience with Security Orchestration platforms, playbook development, and automated response workflows for incident management. Network Security Fundamentals: Working knowledge of network architectures, firewalls, proxies, and common attack vectors with troubleshooting expertise. Communication & Documentation: Excellent technical writing and communication skills to create runbooks, procedures, and translate complex security concepts for diverse audiences. In order to apply, you must have active SC Level Clearance in place. You must be able to evidence skills in Splunk Enterprise Admin and development. You will be proficient in Splunk Enterprise Security (SIEM) - administering, managing, and maintaining SIEM. Experienced in developing use cases/correlation searches. You will be proficient in data models. Have hands-on knowledge and understanding of Splunk Cloud. Hands-on experience of Microsoft Sentinel. Hands-on CI/CD tools like Gitlab, Jenkins etc. Proficiency in Cribl Stream is expected. Awareness/experience of the following is an advantage - Cloud Security & Modern Infrastructure: Proficiency with AWS/Azure cloud security, containerised environments, and SaaS-based security solutions. Programming & Scripting: Advanced skills in Python, PowerShell, KQL, SPL, and SQL for automation, custom integrations, and advanced analytics development. Security Certifications: Professional certifications such as CISSP, GCIH, GCFA, Splunk Certified Architect, or Microsoft Sentinel Ninja. Extended Security Stack: Experience with EDR, UBA, CASB, CSPM, vulnerability assessment tools, and threat intelligence platforms. Infrastructure as Code: Experience with Chef, Ansible, Jenkins, GitLab CI/CD for automated security tool deployment and configuration management. Compliance & Governance: Knowledge of regulatory frameworks (SOX, PCI-DSS, GDPR) and hands-on incident response/forensics experience. Please be clear that only candidates that meet the above criteria with the right to work and that are resident in the UK with active SC Level Clearance will be considered. No sponsorship is available. This role will involve hybrid working here in the UK at a site based in Cheshire - expected on site 3 days per week and 2 from home. More flexibility may be offered once in situ in the contract. Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at (url removed)
Aug 04, 2026
Contractor
We are working with a client who is a global leader in consulting, technology services, and digital transformation, committed to delivering positive change through technology and human collaboration. They are looking for a Splunk SIEM Engineer with active SC Clearance in place to design, develop and improve software, utilising various engineering methodologies, that provides business, platform, and technology capabilities for our customers and colleagues. You will need to demonstrate your Multi-Platform SIEM Expertise: you need proven experience with Splunk Enterprise Security, Microsoft Sentinel, and SIEM architecture including data models, correlation rules, and administrative functions. Security Operations: Strong analytical skills in threat detection, incident response, and security event analysis with experience in large enterprise environments (10,000+ endpoints). Data Pipeline Management: Hands-on experience with log ingestion, data routing, and transformation using tools like Cribl, plus understanding of data normalisation and parsing in Splunk Enterprise. SOAR & Automation: Experience with Security Orchestration platforms, playbook development, and automated response workflows for incident management. Network Security Fundamentals: Working knowledge of network architectures, firewalls, proxies, and common attack vectors with troubleshooting expertise. Communication & Documentation: Excellent technical writing and communication skills to create runbooks, procedures, and translate complex security concepts for diverse audiences. In order to apply, you must have active SC Level Clearance in place. You must be able to evidence skills in Splunk Enterprise Admin and development. You will be proficient in Splunk Enterprise Security (SIEM) - administering, managing, and maintaining SIEM. Experienced in developing use cases/correlation searches. You will be proficient in data models. Have hands-on knowledge and understanding of Splunk Cloud. Hands-on experience of Microsoft Sentinel. Hands-on CI/CD tools like Gitlab, Jenkins etc. Proficiency in Cribl Stream is expected. Awareness/experience of the following is an advantage - Cloud Security & Modern Infrastructure: Proficiency with AWS/Azure cloud security, containerised environments, and SaaS-based security solutions. Programming & Scripting: Advanced skills in Python, PowerShell, KQL, SPL, and SQL for automation, custom integrations, and advanced analytics development. Security Certifications: Professional certifications such as CISSP, GCIH, GCFA, Splunk Certified Architect, or Microsoft Sentinel Ninja. Extended Security Stack: Experience with EDR, UBA, CASB, CSPM, vulnerability assessment tools, and threat intelligence platforms. Infrastructure as Code: Experience with Chef, Ansible, Jenkins, GitLab CI/CD for automated security tool deployment and configuration management. Compliance & Governance: Knowledge of regulatory frameworks (SOX, PCI-DSS, GDPR) and hands-on incident response/forensics experience. Please be clear that only candidates that meet the above criteria with the right to work and that are resident in the UK with active SC Level Clearance will be considered. No sponsorship is available. This role will involve hybrid working here in the UK at a site based in Cheshire - expected on site 3 days per week and 2 from home. More flexibility may be offered once in situ in the contract. Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at (url removed)
I am currently looking for 2 experienced Cyber Security Engineers (DV Cleared) for a client, based in Milton Keynes with occasional travel to London. DV Clearance is essential - applicants without current clearance unfortunately cannot be considered. About the Role: These roles sit within a client's Cybersecurity Operations function. You will play a key part in designing, implementing, and maintaining the platforms that support enterprise-scale security operations. From SIEM and log collection to endpoint detection, automation, and integration, you'll help ensure the SOC team has the reliable and scalable infrastructure it needs to detect, investigate, and respond to threats. Responsibilities: Manage and optimise SIEM platforms (Splunk, Microsoft Sentinel, open-source alternatives) across hybrid-cloud environments Configure and maintain log/data pipelines from endpoints, cloud services, and network devices Ensure high availability, reliability, and performance of core security platforms Integrate new security tools into the ecosystem, including automation via APIs, Scripting, and AI Maintain clear documentation, diagrams, and procedures to support knowledge sharing and consistency Skills & Experience: Strong hands-on experience with SIEM technologies (Splunk, Sentinel, etc.) Knowledge of cloud platforms (Azure, AWS, GCP) and hybrid environments Scripting skills (Python, PowerShell) for automation and integration Experience with SOAR and SecDevOps practices (Git, GitHub, Azure DevOps, CI/CD) Good understanding of frameworks such as NIST, MITRE ATT&CK, CAF Background in Incident Response or SOC analysis is highly valued Soft Skills: Strong analytical and problem-solving mindset Effective communication and collaboration skills Ability to thrive in a fast-paced, dynamic environment Certifications (Splunk, Microsoft, SANS, etc.) are desirable but not required. Location: Milton Keynes (with some travel to London) Positions: 2 available If you're DV cleared and want to take on a challenging and rewarding role with a leading organisation, I'd love to hear from you.
Oct 06, 2025
Contractor
I am currently looking for 2 experienced Cyber Security Engineers (DV Cleared) for a client, based in Milton Keynes with occasional travel to London. DV Clearance is essential - applicants without current clearance unfortunately cannot be considered. About the Role: These roles sit within a client's Cybersecurity Operations function. You will play a key part in designing, implementing, and maintaining the platforms that support enterprise-scale security operations. From SIEM and log collection to endpoint detection, automation, and integration, you'll help ensure the SOC team has the reliable and scalable infrastructure it needs to detect, investigate, and respond to threats. Responsibilities: Manage and optimise SIEM platforms (Splunk, Microsoft Sentinel, open-source alternatives) across hybrid-cloud environments Configure and maintain log/data pipelines from endpoints, cloud services, and network devices Ensure high availability, reliability, and performance of core security platforms Integrate new security tools into the ecosystem, including automation via APIs, Scripting, and AI Maintain clear documentation, diagrams, and procedures to support knowledge sharing and consistency Skills & Experience: Strong hands-on experience with SIEM technologies (Splunk, Sentinel, etc.) Knowledge of cloud platforms (Azure, AWS, GCP) and hybrid environments Scripting skills (Python, PowerShell) for automation and integration Experience with SOAR and SecDevOps practices (Git, GitHub, Azure DevOps, CI/CD) Good understanding of frameworks such as NIST, MITRE ATT&CK, CAF Background in Incident Response or SOC analysis is highly valued Soft Skills: Strong analytical and problem-solving mindset Effective communication and collaboration skills Ability to thrive in a fast-paced, dynamic environment Certifications (Splunk, Microsoft, SANS, etc.) are desirable but not required. Location: Milton Keynes (with some travel to London) Positions: 2 available If you're DV cleared and want to take on a challenging and rewarding role with a leading organisation, I'd love to hear from you.
Infrastructure & Security Engineer - Retail Sector London (Hybrid) 30% BAU/70% Project Work Permanent | Immediate Interviews Available We're partnering with a London-based retail brand currently undergoing infrastructure transformation. This is a fantastic opportunity for an experienced Infrastructure & Security Engineer to join a fast-moving organisation investing heavily in technology and digital maturity. You'll play a key role in both business-as-usual operations (30%) and a wide range of modernisation and transformation projects (70%), helping to reshape the future of the company's IT infrastructure. This opportunity is perfect for an experienced Infrastructure or Network Engineer who enjoys being hands-on with both Legacy systems and modern cloud-first environments. If you're looking to work on meaningful projects within a dynamic retail business, this could be the next step in your career. Key Responsibilities Work as a hands-on infrastructure and security engineer, delivering technical improvements and helping to secure enterprise systems. Support and maintain a range of technologies including VMware, Windows Server, Azure, Microsoft 365, and SQL Server. Help manage and enhance the company's Cisco Meraki network infrastructure across head office and retail sites. Contribute to vulnerability management, compliance (PCIDSS), and alignment with NIST/ISO27001 standards. Assist in the deployment of secure, scalable device imaging using Intune & Autopilot for POS, hospitality, and corporate users. Configure and manage SIEM, endpoint protection, IAM, MFA, and RBAC to strengthen infrastructure security. Create and maintain infrastructure documentation, diagrams, and operational runbooks. Support disaster recovery processes and participate in testing and readiness planning. Collaboration & Communication Work closely with internal IT teams and third-party vendors to deliver secure, high-performing infrastructure solutions. Share expertise and promote best practices in infrastructure, networking, and security across the organisation. Contribute to a security-first culture, providing guidance and support across teams. Key Experience & Skills We're looking for candidates with strong experience in: Microsoft Infrastructure: Windows Server, Azure, Microsoft 365, Entra ID, Active Directory, Group Policy Networking: Cisco networking (LAN/WAN/Wi-Fi, TCP/IP, Firewalls, Switching/Routing) Virtualisation: VMware vSphere, ESXi, vCenter Scripting: PowerShell Security & Compliance: Microsoft Defender, Sentinel, IAM, PCIDSS, MFA, RBAC Hardware: Dell server/storage platforms Monitoring & DR: Familiarity with SolarWinds, PRTG, Zabbix, backup tools, and DR best practices If this role is of interest please share your CV and we will be in touch!
Oct 01, 2025
Full time
Infrastructure & Security Engineer - Retail Sector London (Hybrid) 30% BAU/70% Project Work Permanent | Immediate Interviews Available We're partnering with a London-based retail brand currently undergoing infrastructure transformation. This is a fantastic opportunity for an experienced Infrastructure & Security Engineer to join a fast-moving organisation investing heavily in technology and digital maturity. You'll play a key role in both business-as-usual operations (30%) and a wide range of modernisation and transformation projects (70%), helping to reshape the future of the company's IT infrastructure. This opportunity is perfect for an experienced Infrastructure or Network Engineer who enjoys being hands-on with both Legacy systems and modern cloud-first environments. If you're looking to work on meaningful projects within a dynamic retail business, this could be the next step in your career. Key Responsibilities Work as a hands-on infrastructure and security engineer, delivering technical improvements and helping to secure enterprise systems. Support and maintain a range of technologies including VMware, Windows Server, Azure, Microsoft 365, and SQL Server. Help manage and enhance the company's Cisco Meraki network infrastructure across head office and retail sites. Contribute to vulnerability management, compliance (PCIDSS), and alignment with NIST/ISO27001 standards. Assist in the deployment of secure, scalable device imaging using Intune & Autopilot for POS, hospitality, and corporate users. Configure and manage SIEM, endpoint protection, IAM, MFA, and RBAC to strengthen infrastructure security. Create and maintain infrastructure documentation, diagrams, and operational runbooks. Support disaster recovery processes and participate in testing and readiness planning. Collaboration & Communication Work closely with internal IT teams and third-party vendors to deliver secure, high-performing infrastructure solutions. Share expertise and promote best practices in infrastructure, networking, and security across the organisation. Contribute to a security-first culture, providing guidance and support across teams. Key Experience & Skills We're looking for candidates with strong experience in: Microsoft Infrastructure: Windows Server, Azure, Microsoft 365, Entra ID, Active Directory, Group Policy Networking: Cisco networking (LAN/WAN/Wi-Fi, TCP/IP, Firewalls, Switching/Routing) Virtualisation: VMware vSphere, ESXi, vCenter Scripting: PowerShell Security & Compliance: Microsoft Defender, Sentinel, IAM, PCIDSS, MFA, RBAC Hardware: Dell server/storage platforms Monitoring & DR: Familiarity with SolarWinds, PRTG, Zabbix, backup tools, and DR best practices If this role is of interest please share your CV and we will be in touch!
SOC Analyst - £45k This is a fantastic opportunity to join a well-established MSP as part of their SOC function. You will be joining a fast paced fast growing arm of the business which has gone from strength to strength since its addition to the business. The role comes with pretty much 100% remote home working with once a month visits to their office in Manchester. They are a full Microsoft Gold Partner / Family Run and also voted one of the top employers in the UK. The current SOC function has a small close knit team of engineers - they deploy a flat SOC structure so you will be involved in all elements of a SOC function. They are big on certifications and open to candidates with them or happy to put you through relevant courses. Key skills / responsibilities: • Proven experience up to 12 months working as a SOC Analyst• Experience in deep diving into security issues and analysis rather than just ticket management.• Experience with SIEM solutions (Azure Sentinel as but Splunk etc also useful to have.• Scripting experience with - KQL / PowerShell Scripting• Threat Hunting / Analysis Investigation• Opportunity to run and be involved in webinars.• Opportunity to train and mentor new team members in the future.• Core infrastructure / networking background would be desired. The role comes with a base up to £45k They are interviewing ASAP so apply today for consideration!
Sep 25, 2025
Full time
SOC Analyst - £45k This is a fantastic opportunity to join a well-established MSP as part of their SOC function. You will be joining a fast paced fast growing arm of the business which has gone from strength to strength since its addition to the business. The role comes with pretty much 100% remote home working with once a month visits to their office in Manchester. They are a full Microsoft Gold Partner / Family Run and also voted one of the top employers in the UK. The current SOC function has a small close knit team of engineers - they deploy a flat SOC structure so you will be involved in all elements of a SOC function. They are big on certifications and open to candidates with them or happy to put you through relevant courses. Key skills / responsibilities: • Proven experience up to 12 months working as a SOC Analyst• Experience in deep diving into security issues and analysis rather than just ticket management.• Experience with SIEM solutions (Azure Sentinel as but Splunk etc also useful to have.• Scripting experience with - KQL / PowerShell Scripting• Threat Hunting / Analysis Investigation• Opportunity to run and be involved in webinars.• Opportunity to train and mentor new team members in the future.• Core infrastructure / networking background would be desired. The role comes with a base up to £45k They are interviewing ASAP so apply today for consideration!