SecOps Engineer - Central London (hybrid working) Up to £75,000 PA Well-established and highly profitable construction engineering business is seeking an experienced SecOps Engineer to join them on a permanent basis. This is a critical leadership role within an organisation undergoing significant digital transformation, with ambitious growth and acquisition plans driving demand for scalable, standardised and efficient business applications. This role is ideal for a proactive security professional with strong technical expertise across application, network and infrastructure security. You will play a key part in implementing security controls, mitigating risk and contributing to the continuous improvement of the company's overall security posture. Responsibilities: Monitor security tools including SIEM (QRadar) and respond to threat detection alerts Triage, analyse and prioritise security (via ServiceNow) Investigate root causes of security issues and design effective remediation solutions Oversee Patch Management Conduct vulnerability scans with Qualys, analyse results and prioritise remediation Document SecOps processes and create knowledge base articles in line with best practices Automate security tasks and toolchains using scripting (PowerShell, Batch, etc.) Collaborate with external SOC teams Prepare post-incident reports and root cause analyses Manage end-user device (EUD) security via MS Intune, Sophos and NinjaOne Schedule and assess vulnerability scans on critical infrastructure Maintain patching compliance for OS, Microsoft Office and third-party applications Support infrastructure teams to deploy systems, enhance security policies and manage security-driven changes Produce weekly security operations reports Manage Cisco Umbrella web filtering and SSL inspection policies Requirements: Previous hands-on experience in SecOps or Incident Response Recognised Security certifications such as Security+, CEH, or Microsoft security certifications Strong knowledge of Microsoft Windows OS security and hardening Working PowerShell scripting ability for automation tasks Solid understanding of cloud-native security across M365, Azure and AWS Experience with enterprise IT infrastructure Any experience with the following will be highly favoured: Strong experience with Qualys Exposure to Varonis Network security knowledge or relevant certifications (TCP/IP, VPNs, routing, segmentation) Experience working with ServiceNow Initially 4 days per week onsite, dropping to 3 once passed probation.
Aug 08, 2026
Full time
SecOps Engineer - Central London (hybrid working) Up to £75,000 PA Well-established and highly profitable construction engineering business is seeking an experienced SecOps Engineer to join them on a permanent basis. This is a critical leadership role within an organisation undergoing significant digital transformation, with ambitious growth and acquisition plans driving demand for scalable, standardised and efficient business applications. This role is ideal for a proactive security professional with strong technical expertise across application, network and infrastructure security. You will play a key part in implementing security controls, mitigating risk and contributing to the continuous improvement of the company's overall security posture. Responsibilities: Monitor security tools including SIEM (QRadar) and respond to threat detection alerts Triage, analyse and prioritise security (via ServiceNow) Investigate root causes of security issues and design effective remediation solutions Oversee Patch Management Conduct vulnerability scans with Qualys, analyse results and prioritise remediation Document SecOps processes and create knowledge base articles in line with best practices Automate security tasks and toolchains using scripting (PowerShell, Batch, etc.) Collaborate with external SOC teams Prepare post-incident reports and root cause analyses Manage end-user device (EUD) security via MS Intune, Sophos and NinjaOne Schedule and assess vulnerability scans on critical infrastructure Maintain patching compliance for OS, Microsoft Office and third-party applications Support infrastructure teams to deploy systems, enhance security policies and manage security-driven changes Produce weekly security operations reports Manage Cisco Umbrella web filtering and SSL inspection policies Requirements: Previous hands-on experience in SecOps or Incident Response Recognised Security certifications such as Security+, CEH, or Microsoft security certifications Strong knowledge of Microsoft Windows OS security and hardening Working PowerShell scripting ability for automation tasks Solid understanding of cloud-native security across M365, Azure and AWS Experience with enterprise IT infrastructure Any experience with the following will be highly favoured: Strong experience with Qualys Exposure to Varonis Network security knowledge or relevant certifications (TCP/IP, VPNs, routing, segmentation) Experience working with ServiceNow Initially 4 days per week onsite, dropping to 3 once passed probation.
Position: (phone number removed) - Data Quality Analyst Location: Gaydon Position Type: Rolling contract Inside IR35 Salary: £30.18 per hour umbrella inside IR35 About the company I am currently recruiting on behalf of a Luxury Automotive OEM based in Gaydon who are seeking a Data Quality Analyst to join their team on a rolling contract basis working 40 hours per week Based inside IR35 Job Description As a CAD Quality Analyst, you will be a core part of the delivery of the Virtual Series for our vehicle programmes. You will have the opportunity to ensure we deliver exceptional products to our customers by proactively identifying any potential quality issues in our Engineering Data (CAD), early in the development phase, so the Client can resolve them early. Knowledge, Skills and Experience: Proficiency with PLM and CAD tools, including Dassault Systèmes 3DEXPERIENCE (PLM), CATIA V5 (CAD), and Siemens Teamcenter (PLM). Strong technical understanding of automotive architectures, systems, or commodities, with the ability to apply this knowledge in an engineering or design environment. Strong communication skills, able to simplify complex information and convey it clearly both verbally and through high quality written documentation. Exceptional attention to detail, with a methodical approach to problem solving and issue detection. Comfortable working independently, with the confidence to seek support or clarification when required. Why work through Contechs? Contechs is a leading Automotive, Design, Engineering, Technology and Innovation Recruitment Consultancy. Founded in 1997, with an inhouse Contractor Care Team to support all external employees, acts as an employment agency for permanent and contract recruitment. How to Apply If you're interested in applying for this position, submit your application and one of our recruiters will be in touch. If you know anyone that is suitable for the role, please visit the below page where we offer up to £600 referral fee: (url removed) APPLICABLE (UK AND B2B ROLES) Applicants MUST have proof of immediate, on-going and valid eligibility to work full time in the UK and travel within the EU.
Aug 08, 2026
Contractor
Position: (phone number removed) - Data Quality Analyst Location: Gaydon Position Type: Rolling contract Inside IR35 Salary: £30.18 per hour umbrella inside IR35 About the company I am currently recruiting on behalf of a Luxury Automotive OEM based in Gaydon who are seeking a Data Quality Analyst to join their team on a rolling contract basis working 40 hours per week Based inside IR35 Job Description As a CAD Quality Analyst, you will be a core part of the delivery of the Virtual Series for our vehicle programmes. You will have the opportunity to ensure we deliver exceptional products to our customers by proactively identifying any potential quality issues in our Engineering Data (CAD), early in the development phase, so the Client can resolve them early. Knowledge, Skills and Experience: Proficiency with PLM and CAD tools, including Dassault Systèmes 3DEXPERIENCE (PLM), CATIA V5 (CAD), and Siemens Teamcenter (PLM). Strong technical understanding of automotive architectures, systems, or commodities, with the ability to apply this knowledge in an engineering or design environment. Strong communication skills, able to simplify complex information and convey it clearly both verbally and through high quality written documentation. Exceptional attention to detail, with a methodical approach to problem solving and issue detection. Comfortable working independently, with the confidence to seek support or clarification when required. Why work through Contechs? Contechs is a leading Automotive, Design, Engineering, Technology and Innovation Recruitment Consultancy. Founded in 1997, with an inhouse Contractor Care Team to support all external employees, acts as an employment agency for permanent and contract recruitment. How to Apply If you're interested in applying for this position, submit your application and one of our recruiters will be in touch. If you know anyone that is suitable for the role, please visit the below page where we offer up to £600 referral fee: (url removed) APPLICABLE (UK AND B2B ROLES) Applicants MUST have proof of immediate, on-going and valid eligibility to work full time in the UK and travel within the EU.
Infrastructure Engineer An established financial services organisation is looking to appoint a Senior IT Infrastructure Engineer to play a key role in maintaining and developing its enterprise technology estate. This position combines hands-on technical engineering with infrastructure ownership, supporting business-critical platforms used across the organisation. Working within a highly regulated environment, you'll be responsible for the reliability, security and ongoing enhancement of server infrastructure, virtualisation, networking, endpoint technologies and core business applications. You'll also contribute to infrastructure projects, mentor colleagues and help shape future technology improvements. What You'll Be Doing As a senior member of the infrastructure team, you'll take ownership of day-to-day operations across the organisation's core technology platforms while supporting wider transformation initiatives. Your responsibilities will include: Managing Windows Server and Linux environments to ensure high availability and operational stability. Supporting and optimising VMware virtual infrastructure across production environments. Maintaining enterprise backup, recovery and disaster recovery capabilities using industry-leading technologies. Monitoring infrastructure performance and proactively resolving capacity, availability and resilience issues. Administering Microsoft 365 services and supporting hybrid infrastructure technologies. Managing Active Directory, Group Policy, identity administration and user access management. Supporting desktop operating systems, laptops, mobile devices and collaboration technologies across multiple office locations. Maintaining endpoint security controls, encryption technologies and vulnerability remediation processes. Working closely with cyber security teams to strengthen infrastructure security and reduce operational risk. Supporting enterprise patch management and software deployment across server and desktop environments. Troubleshooting complex infrastructure, networking and systems issues while acting as a senior technical escalation point. Contributing to infrastructure upgrades, technology refresh programmes and strategic improvement projects. Producing technical documentation, operational procedures and infrastructure standards. Working alongside third-party suppliers and internal stakeholders to deliver stable, secure technology services. Enterprise Systems The environment includes a range of specialist financial platforms supporting treasury operations, payments, market data, secure financial messaging, compliance and business operations. Previous experience supporting financial services applications within regulated organisations would be highly advantageous. Networking & Security You'll provide administration and support across the organisation's network and security estate, including: Enterprise switching and routing Firewall administration DNS, DHCP and TCP/IP services Secure remote connectivity Network monitoring and performance optimisation Endpoint protection technologies Vulnerability management Security monitoring platforms Certificate and encryption management Technical Environment You'll have strong experience across most of the following technologies: Infrastructure Windows Server Red Hat Enterprise Linux VMware vSphere / vCenter Microsoft 365 SQL Server Enterprise virtualisation Hybrid infrastructure Backup & Recovery Veeam Backup & Replication Disaster Recovery Infrastructure monitoring Networking Cisco networking Fortinet firewalls LAN/WAN Routing & Switching DNS DHCP Security Endpoint Detection & Response (EDR) Endpoint Encryption Data Loss Prevention SIEM solutions Vulnerability Management SSL Certificate Management Hardware Enterprise Dell server platforms SAN storage technologies About You We're looking for an experienced infrastructure professional who enjoys taking ownership of complex enterprise environments and delivering reliable technology services. You'll ideally have: Five or more years' experience supporting enterprise infrastructure. A background within banking, financial services or another highly regulated sector. Strong troubleshooting and problem-solving skills. Experience working within virtualised server environments. A broad understanding of infrastructure security principles.
Aug 08, 2026
Contractor
Infrastructure Engineer An established financial services organisation is looking to appoint a Senior IT Infrastructure Engineer to play a key role in maintaining and developing its enterprise technology estate. This position combines hands-on technical engineering with infrastructure ownership, supporting business-critical platforms used across the organisation. Working within a highly regulated environment, you'll be responsible for the reliability, security and ongoing enhancement of server infrastructure, virtualisation, networking, endpoint technologies and core business applications. You'll also contribute to infrastructure projects, mentor colleagues and help shape future technology improvements. What You'll Be Doing As a senior member of the infrastructure team, you'll take ownership of day-to-day operations across the organisation's core technology platforms while supporting wider transformation initiatives. Your responsibilities will include: Managing Windows Server and Linux environments to ensure high availability and operational stability. Supporting and optimising VMware virtual infrastructure across production environments. Maintaining enterprise backup, recovery and disaster recovery capabilities using industry-leading technologies. Monitoring infrastructure performance and proactively resolving capacity, availability and resilience issues. Administering Microsoft 365 services and supporting hybrid infrastructure technologies. Managing Active Directory, Group Policy, identity administration and user access management. Supporting desktop operating systems, laptops, mobile devices and collaboration technologies across multiple office locations. Maintaining endpoint security controls, encryption technologies and vulnerability remediation processes. Working closely with cyber security teams to strengthen infrastructure security and reduce operational risk. Supporting enterprise patch management and software deployment across server and desktop environments. Troubleshooting complex infrastructure, networking and systems issues while acting as a senior technical escalation point. Contributing to infrastructure upgrades, technology refresh programmes and strategic improvement projects. Producing technical documentation, operational procedures and infrastructure standards. Working alongside third-party suppliers and internal stakeholders to deliver stable, secure technology services. Enterprise Systems The environment includes a range of specialist financial platforms supporting treasury operations, payments, market data, secure financial messaging, compliance and business operations. Previous experience supporting financial services applications within regulated organisations would be highly advantageous. Networking & Security You'll provide administration and support across the organisation's network and security estate, including: Enterprise switching and routing Firewall administration DNS, DHCP and TCP/IP services Secure remote connectivity Network monitoring and performance optimisation Endpoint protection technologies Vulnerability management Security monitoring platforms Certificate and encryption management Technical Environment You'll have strong experience across most of the following technologies: Infrastructure Windows Server Red Hat Enterprise Linux VMware vSphere / vCenter Microsoft 365 SQL Server Enterprise virtualisation Hybrid infrastructure Backup & Recovery Veeam Backup & Replication Disaster Recovery Infrastructure monitoring Networking Cisco networking Fortinet firewalls LAN/WAN Routing & Switching DNS DHCP Security Endpoint Detection & Response (EDR) Endpoint Encryption Data Loss Prevention SIEM solutions Vulnerability Management SSL Certificate Management Hardware Enterprise Dell server platforms SAN storage technologies About You We're looking for an experienced infrastructure professional who enjoys taking ownership of complex enterprise environments and delivering reliable technology services. You'll ideally have: Five or more years' experience supporting enterprise infrastructure. A background within banking, financial services or another highly regulated sector. Strong troubleshooting and problem-solving skills. Experience working within virtualised server environments. A broad understanding of infrastructure security principles.
Head of Information Security - CISSP, CISM, ISO27001, NIST, PCI DSS, GDPR, DevSecOps, Cloud Security, SIEM, SOC, AI Security. Permanent, West London, Hybrid Working. c.£100k +Benefits Head of Information Security/CISO/Senior InfoSec Consultant required to lead and develop a modern, security-first function within a growing technology business. Reporting to the CTO, you'll combine strategic leadership with a hands-on technical approach, working closely with Engineering, Infrastructure and Operations teams to embed security across the organisation. The role will adopt Information Security strategy, governance, risk and compliance while implementing practical security controls, automation and DevSecOps best practice. This is an excellent opportunity to influence technology strategy, lead security initiatives and help shape a mature, AI-enabled security capability whilst remaining hands-on in the early stages. In time, you will build a small team of InfoSec and Cyber Security Analysts around you. Key Responsibilities: Define and deliver the Information Security strategy, policies and governance framework. Define and develop robust security controls inline with both business practices and compliance requirements inc ISO27001, CE+, SOC2, NIST CSF, GDPR and PCI DSS. Embed Secure by Design and DevSecOps principles across engineering teams. Lead cyber risk management, incident response, threat modelling and vulnerability management using a range of contemporary tools. Drive AI and automation to enhance security operations and threat detection. Oversee third-party security, supplier assurance and client audits. Recruit, mentor, lead and develop the Information Security team. As such, we're looking for candidates with experience leading Information Security or Cyber Security functions within technology-led organisations. You will possess: CISSP, CISM or equivalent security certification. Strong knowledge of ISO27001, NIST, PCI DSS, GDPR and Information Security Governance. Experience developing security strategy, GRC and cyber risk programmes including definition of security controls Strong technical knowledge across cloud, network, endpoint, application and data security. Experience with SIEM, SOC, vulnerability management and incident response. Knowledge of DevSecOps, security automation and modern cloud environments. Excellent communication, stakeholder management and leadership skills. You may have been working as a CISO, Information Security Manager, Cyber Security Consultant or within another senior InfoSec/CyberSec capacity which has granted you experience in both security control definition and hands-on practical management of security threats and incidents including vulnerability scanning and penetration testing. This is an outstanding opportunity to join a forward-thinking organisation where you'll shape the security strategy, influence technology direction and build a modern Information Security function using the latest cloud, automation and AI technologies.
Aug 07, 2026
Full time
Head of Information Security - CISSP, CISM, ISO27001, NIST, PCI DSS, GDPR, DevSecOps, Cloud Security, SIEM, SOC, AI Security. Permanent, West London, Hybrid Working. c.£100k +Benefits Head of Information Security/CISO/Senior InfoSec Consultant required to lead and develop a modern, security-first function within a growing technology business. Reporting to the CTO, you'll combine strategic leadership with a hands-on technical approach, working closely with Engineering, Infrastructure and Operations teams to embed security across the organisation. The role will adopt Information Security strategy, governance, risk and compliance while implementing practical security controls, automation and DevSecOps best practice. This is an excellent opportunity to influence technology strategy, lead security initiatives and help shape a mature, AI-enabled security capability whilst remaining hands-on in the early stages. In time, you will build a small team of InfoSec and Cyber Security Analysts around you. Key Responsibilities: Define and deliver the Information Security strategy, policies and governance framework. Define and develop robust security controls inline with both business practices and compliance requirements inc ISO27001, CE+, SOC2, NIST CSF, GDPR and PCI DSS. Embed Secure by Design and DevSecOps principles across engineering teams. Lead cyber risk management, incident response, threat modelling and vulnerability management using a range of contemporary tools. Drive AI and automation to enhance security operations and threat detection. Oversee third-party security, supplier assurance and client audits. Recruit, mentor, lead and develop the Information Security team. As such, we're looking for candidates with experience leading Information Security or Cyber Security functions within technology-led organisations. You will possess: CISSP, CISM or equivalent security certification. Strong knowledge of ISO27001, NIST, PCI DSS, GDPR and Information Security Governance. Experience developing security strategy, GRC and cyber risk programmes including definition of security controls Strong technical knowledge across cloud, network, endpoint, application and data security. Experience with SIEM, SOC, vulnerability management and incident response. Knowledge of DevSecOps, security automation and modern cloud environments. Excellent communication, stakeholder management and leadership skills. You may have been working as a CISO, Information Security Manager, Cyber Security Consultant or within another senior InfoSec/CyberSec capacity which has granted you experience in both security control definition and hands-on practical management of security threats and incidents including vulnerability scanning and penetration testing. This is an outstanding opportunity to join a forward-thinking organisation where you'll shape the security strategy, influence technology direction and build a modern Information Security function using the latest cloud, automation and AI technologies.
Senior Cyber Consultant 65,000 + 15k Bonus Hybrid UK A growing cyber security consultancy is seeking a Senior Cyber Consultant to help organisations enhance their Security Operations and threat detection capabilities. This is a client-facing role focused on designing and delivering SIEM, XDR and SOAR solutions, developing detection content, automating security processes, and improving SOC effectiveness. You will lead detection engineering initiatives, create use cases aligned to MITRE ATT&CK, develop response playbooks, and implement Detection-as-Code best practices. Key Requirements Experience with SIEM platforms (Microsoft Sentinel preferred) Strong KQL and detection engineering skills SOAR automation and playbook development experience Python and/or PowerShell scripting XDR/EDR experience Knowledge of MITRE ATT&CK and threat detection methodologies Azure security and cloud telemetry exposure Previous consultancy or customer-facing experience What's on Offer 65,000 base salary Annual Bonus Predominantly remote working No on-call requirement Exposure to enterprise-scale cyber security projects Strong development and progression opportunities Ideal for: Detection Engineers, SIEM Engineers, Senior SOC Analysts, Security Automation Engineers, SOC Consultants, and Cyber Security Engineers seeking a consultancy-focused role.
Aug 07, 2026
Full time
Senior Cyber Consultant 65,000 + 15k Bonus Hybrid UK A growing cyber security consultancy is seeking a Senior Cyber Consultant to help organisations enhance their Security Operations and threat detection capabilities. This is a client-facing role focused on designing and delivering SIEM, XDR and SOAR solutions, developing detection content, automating security processes, and improving SOC effectiveness. You will lead detection engineering initiatives, create use cases aligned to MITRE ATT&CK, develop response playbooks, and implement Detection-as-Code best practices. Key Requirements Experience with SIEM platforms (Microsoft Sentinel preferred) Strong KQL and detection engineering skills SOAR automation and playbook development experience Python and/or PowerShell scripting XDR/EDR experience Knowledge of MITRE ATT&CK and threat detection methodologies Azure security and cloud telemetry exposure Previous consultancy or customer-facing experience What's on Offer 65,000 base salary Annual Bonus Predominantly remote working No on-call requirement Exposure to enterprise-scale cyber security projects Strong development and progression opportunities Ideal for: Detection Engineers, SIEM Engineers, Senior SOC Analysts, Security Automation Engineers, SOC Consultants, and Cyber Security Engineers seeking a consultancy-focused role.
Cyber Security Engineer / Leeds or London / 45,000 - 65,000 Shape the Future of Enterprise Cyber Defence This is an opportunity to step into one of the most influential technical security roles within a large-scale organisation undertaking a significant investment in its cyber security capability. Rather than simply responding to incidents, you'll become the internal technical authority for Security Operations tooling, Detection Engineering and security platform optimisation, helping define how the organisation detects, investigates and responds to cyber threats. You'll take ownership of industry-leading technologies including Google SecOps, CrowdStrike and Darktrace, while driving improvements across automation, AI-assisted investigations and next-generation Security Operations. If you're looking for a role where you can genuinely influence cyber strategy, improve enterprise resilience and help shape the future operating model of Security Operations, this is an outstanding opportunity. The Role Working within a collaborative Security Operations function, you'll sit at the centre of Security Operations, Detection Engineering and Security Platform Engineering. You'll become the internal Subject Matter Expert for security tooling, ensuring the organisation's detection capabilities continue to evolve while acting as the technical bridge between Security Operations, Security Engineering, Architecture and an outsourced Security Operations partner. This is far more than a traditional SOC position. Around 70% of your focus will be dedicated to Detection Engineering and platform ownership, with the remaining time spent supporting operational improvements, incident assurance and strengthening the overall security capability. What You'll Be Doing Own and administer Google SecOps, CrowdStrike and Darktrace Design, create and optimise detection rules to improve alert quality and reduce false positives Increase detection coverage through MITRE ATT&CK mapping and continuous engineering improvements Review platform health, telemetry and security tooling integrations Assess investigations completed by the outsourced security provider, providing technical assurance and challenging service quality where required Identify detection gaps through incident reviews and trend analysis Drive improvements across Detection Engineering, telemetry, SIEM and Security Operations processes Develop automation opportunities and support AI-assisted investigations and remediation Collaborate with Security Engineering, Architecture and Cyber Defence teams to continuously enhance the organisation's security posture Essential Experience Google SecOps CrowdStrike Darktrace Detection Engineering, including rule creation, tuning and optimisation Enterprise Security Operations and incident investigation SIEM administration and security platform management Improving detection coverage within complex enterprise environments Desirable Experience Exposure to any of the following would be advantageous: Security automation and SOAR AI-driven Security Operations or Agentic AI Threat Intelligence integration Telemetry Engineering About You You'll likely be an experienced Detection Engineer, Security Platform Engineer or Security Operations Engineer who enjoys working across both engineering and operational security rather than specialising in one area alone. You'll be naturally curious, enjoy solving complex security problems and be motivated by continuously improving detection capability through automation and modern engineering practices. You'll also be comfortable engaging with a variety of technical stakeholders, influencing security decisions and becoming the recognised internal expert for Security Operations tooling. Why Apply? This is a genuinely unique opportunity to influence the future direction of an enterprise Security Operations capability. You'll have the chance to: Become the internal owner of Google SecOps, CrowdStrike and Darktrace Help shape the organisation's long-term Security Operations strategy Drive AI-enabled investigations, automation and next-generation detection capabilities Improve cyber resilience across an enterprise environment processing millions of security events each month Work across Detection Engineering, SIEM, platform administration, MSSP governance and security automation Join a collaborative, technically mature cyber security team investing heavily in innovation Enjoy remote-first working with standard office hours, no shift work and no on-call commitments If you're looking for a position where your technical expertise will have a lasting impact on a large-scale cyber security programme, we'd love to hear from you. Please apply with a copy of your CV by 28th July to Dominic Brown on Cyber Security Engineer / Leeds or London / 45,000 - 65,000
Aug 07, 2026
Full time
Cyber Security Engineer / Leeds or London / 45,000 - 65,000 Shape the Future of Enterprise Cyber Defence This is an opportunity to step into one of the most influential technical security roles within a large-scale organisation undertaking a significant investment in its cyber security capability. Rather than simply responding to incidents, you'll become the internal technical authority for Security Operations tooling, Detection Engineering and security platform optimisation, helping define how the organisation detects, investigates and responds to cyber threats. You'll take ownership of industry-leading technologies including Google SecOps, CrowdStrike and Darktrace, while driving improvements across automation, AI-assisted investigations and next-generation Security Operations. If you're looking for a role where you can genuinely influence cyber strategy, improve enterprise resilience and help shape the future operating model of Security Operations, this is an outstanding opportunity. The Role Working within a collaborative Security Operations function, you'll sit at the centre of Security Operations, Detection Engineering and Security Platform Engineering. You'll become the internal Subject Matter Expert for security tooling, ensuring the organisation's detection capabilities continue to evolve while acting as the technical bridge between Security Operations, Security Engineering, Architecture and an outsourced Security Operations partner. This is far more than a traditional SOC position. Around 70% of your focus will be dedicated to Detection Engineering and platform ownership, with the remaining time spent supporting operational improvements, incident assurance and strengthening the overall security capability. What You'll Be Doing Own and administer Google SecOps, CrowdStrike and Darktrace Design, create and optimise detection rules to improve alert quality and reduce false positives Increase detection coverage through MITRE ATT&CK mapping and continuous engineering improvements Review platform health, telemetry and security tooling integrations Assess investigations completed by the outsourced security provider, providing technical assurance and challenging service quality where required Identify detection gaps through incident reviews and trend analysis Drive improvements across Detection Engineering, telemetry, SIEM and Security Operations processes Develop automation opportunities and support AI-assisted investigations and remediation Collaborate with Security Engineering, Architecture and Cyber Defence teams to continuously enhance the organisation's security posture Essential Experience Google SecOps CrowdStrike Darktrace Detection Engineering, including rule creation, tuning and optimisation Enterprise Security Operations and incident investigation SIEM administration and security platform management Improving detection coverage within complex enterprise environments Desirable Experience Exposure to any of the following would be advantageous: Security automation and SOAR AI-driven Security Operations or Agentic AI Threat Intelligence integration Telemetry Engineering About You You'll likely be an experienced Detection Engineer, Security Platform Engineer or Security Operations Engineer who enjoys working across both engineering and operational security rather than specialising in one area alone. You'll be naturally curious, enjoy solving complex security problems and be motivated by continuously improving detection capability through automation and modern engineering practices. You'll also be comfortable engaging with a variety of technical stakeholders, influencing security decisions and becoming the recognised internal expert for Security Operations tooling. Why Apply? This is a genuinely unique opportunity to influence the future direction of an enterprise Security Operations capability. You'll have the chance to: Become the internal owner of Google SecOps, CrowdStrike and Darktrace Help shape the organisation's long-term Security Operations strategy Drive AI-enabled investigations, automation and next-generation detection capabilities Improve cyber resilience across an enterprise environment processing millions of security events each month Work across Detection Engineering, SIEM, platform administration, MSSP governance and security automation Join a collaborative, technically mature cyber security team investing heavily in innovation Enjoy remote-first working with standard office hours, no shift work and no on-call commitments If you're looking for a position where your technical expertise will have a lasting impact on a large-scale cyber security programme, we'd love to hear from you. Please apply with a copy of your CV by 28th July to Dominic Brown on Cyber Security Engineer / Leeds or London / 45,000 - 65,000
The Role: Salary: Market Leading Base + Bonus + Excellent Benefits Location: London (hybrid working) My client is a rapidly growing international main market listed organisation offering a range of solutions to the global Financial & Professional Services sector. As part of their exciting growth plans a new opportunity now exists for an experienced Cyber Security specialist to join their well established and growing technology team based in the London HQ. You will join the team as a Cyber Security Analyst, providing day-to-day operational security coverage across their extensive toolset. Working closely with their Senior Cyber Security Engineer, you will maintain and administer key security platforms, support client-facing security assurance activities, and help strengthen the company's security posture ahead of ISO 27001 certification. Responsibilities: Implement, manage and actively monitor security controls across email, web, endpoint and cloud environments. Monitor and respond to security incidents using advanced threat detection tools. Day-to-day administration of Netskope web filtering platform including website unblocks and policy updates. Day-to-day administration of Mimecast email filtering system including email review and release. Day-to-day administration of CyberArk identity and privileged access management tooling. Microsoft Purview administration including DLP policy monitoring, sensitivity labels, Discovery Searches and compliance alerts. Maintain and respond to security-related DDQs, keeping the security evidence library current. Assist with compliance activities and audits for ISO 27001, Cyber Essentials & Cyber Essentials Plus certification. Provide technical expertise on security best practices and risk mitigation. Collaborate with IT and business teams to ensure secure configuration and data protection. Participating in the out-of-hours support rota to provide cover for critical cyber incidents. The Person: Previous hands-on experience with Mimecast (or similar email security platform), Crowdstrike (or similar EDR platform) and Microsoft Purview - data governance, DLP and compliance tooling are essential for success in the role. Hands-on experience with Netskope - web filtering, CASB and cloud security and/or CyberArk - identity and privileged access management would be highly desirable skills. Experience with Rapid7, InsightVM or InsightIDR for vulnerability management and SIEM would also be highly desirable. Experience of responding to security DDQs and maintaining security evidence. Experience supporting ISO 27001, Cyber Essentials and Cyber Essentials Plus. Strong understanding of UK cyber security regulations and frameworks. Experience working in an FCA-regulated or similarly governed environment. Experience with Microsoft Entra ID and identity governance, alongside familiarity with Microsoft Azure and M365 E5 security features. This is a fantastic opportunity to join a prominent organisation at an exciting time with genuine opportunities for career development and progression. Alongside their compelling salary and bonus, they also offer a very generous pension contribution, private medical and the ability to 'buy and sell' holidays. The role is based from their London office, offering hybrid working with 3 days in the office, with travel to their other UK locations as and when required. If you feel you have the qualities our client is seeking, please forward your CV and covering letter indicating your current package to Lee Rankin at GEM Partnership or for a discreet conversation call our Peterlee office. GEM Partnership is acting as an employment agency on this vacancy.
Aug 07, 2026
Full time
The Role: Salary: Market Leading Base + Bonus + Excellent Benefits Location: London (hybrid working) My client is a rapidly growing international main market listed organisation offering a range of solutions to the global Financial & Professional Services sector. As part of their exciting growth plans a new opportunity now exists for an experienced Cyber Security specialist to join their well established and growing technology team based in the London HQ. You will join the team as a Cyber Security Analyst, providing day-to-day operational security coverage across their extensive toolset. Working closely with their Senior Cyber Security Engineer, you will maintain and administer key security platforms, support client-facing security assurance activities, and help strengthen the company's security posture ahead of ISO 27001 certification. Responsibilities: Implement, manage and actively monitor security controls across email, web, endpoint and cloud environments. Monitor and respond to security incidents using advanced threat detection tools. Day-to-day administration of Netskope web filtering platform including website unblocks and policy updates. Day-to-day administration of Mimecast email filtering system including email review and release. Day-to-day administration of CyberArk identity and privileged access management tooling. Microsoft Purview administration including DLP policy monitoring, sensitivity labels, Discovery Searches and compliance alerts. Maintain and respond to security-related DDQs, keeping the security evidence library current. Assist with compliance activities and audits for ISO 27001, Cyber Essentials & Cyber Essentials Plus certification. Provide technical expertise on security best practices and risk mitigation. Collaborate with IT and business teams to ensure secure configuration and data protection. Participating in the out-of-hours support rota to provide cover for critical cyber incidents. The Person: Previous hands-on experience with Mimecast (or similar email security platform), Crowdstrike (or similar EDR platform) and Microsoft Purview - data governance, DLP and compliance tooling are essential for success in the role. Hands-on experience with Netskope - web filtering, CASB and cloud security and/or CyberArk - identity and privileged access management would be highly desirable skills. Experience with Rapid7, InsightVM or InsightIDR for vulnerability management and SIEM would also be highly desirable. Experience of responding to security DDQs and maintaining security evidence. Experience supporting ISO 27001, Cyber Essentials and Cyber Essentials Plus. Strong understanding of UK cyber security regulations and frameworks. Experience working in an FCA-regulated or similarly governed environment. Experience with Microsoft Entra ID and identity governance, alongside familiarity with Microsoft Azure and M365 E5 security features. This is a fantastic opportunity to join a prominent organisation at an exciting time with genuine opportunities for career development and progression. Alongside their compelling salary and bonus, they also offer a very generous pension contribution, private medical and the ability to 'buy and sell' holidays. The role is based from their London office, offering hybrid working with 3 days in the office, with travel to their other UK locations as and when required. If you feel you have the qualities our client is seeking, please forward your CV and covering letter indicating your current package to Lee Rankin at GEM Partnership or for a discreet conversation call our Peterlee office. GEM Partnership is acting as an employment agency on this vacancy.
Security Platform Engineer - Cloud and Kubernetes Must have an Active DV Clearance Can be based in London, Farnborough or Corsham You will work closely with platform engineers, security specialists, and cloud teams to deliver resilient, secure, and highly automated cloud infrastructure. The position is ideal for an experienced Security Platform Engineer with strong Kubernetes security expertise and a passion for cloud-native security engineering. Security Platform Engineer Responsibilities Design, deploy, configure, and manage cloud security platforms and tooling. Implement and maintain SIEM, IDS, and IPS technologies. Develop security monitoring, logging, and detection capabilities across Kubernetes environments. Investigate, analyse, and respond to security incidents, performing root cause analysis and remediation. Perform forensic investigations into suspicious activity and security events. Automate security workflows and operational processes using Scripting and Infrastructure as Code. Support Kubernetes platform security, workload isolation, RBAC, and network policies. Participate in an on-call rota to support security incidents and operational resilience. Security Platform Engineer Skills and Experience Active DV Clearance Experience within Cloud Security Engineering, DevSecOps, or Cloud Platform Engineering is essential Extensive experience using Kubernetes Security Strong experience securing Kubernetes environments, including RBAC, workload isolation, and network policies. Experience with Kubernetes threat detection, anomaly detection, Istio, Linkerd, or workload identity would be advantageous. Security certifications such as CISSP, CISM, GSEC, or OSCP would be beneficial. To apply, please send your CV by pressing the apply button. Due to high volume of applications, only shortlisted CVs will be contacted. Due to the nature and urgency of this post, candidates holding or who have held high level security clearance in the past are most welcome to apply. Please note successful applicants will be required to be security cleared prior to appointment which can take a minimum 18 weeks. LA International is an award-winning partner of choice for many of the world's most influential companies and government organisations. Holding Enhanced Government Security Accreditation, we are recognised as the European market leader in the delivery of Security Cleared talent to organisations that demand the very highest levels of security, compliance and assurance. An award-winning organisation, having secured the prestigious Queens Award for Enterprise: International Trade over multiple years. We are committed to fostering an inclusive, equitable and accessible workplace where everyone feels valued and supported. We welcome applications from all individuals, regardless of background or identity, and we encourage candidates who may not meet every listed requirement to still apply. If you require any adjustments or support during the recruitment process, please let us know and we will work with you to ensure a fair and accessible experience. Please Note: If a high volume of applications is received, only candidates shortlisted will be contacted.
Aug 07, 2026
Contractor
Security Platform Engineer - Cloud and Kubernetes Must have an Active DV Clearance Can be based in London, Farnborough or Corsham You will work closely with platform engineers, security specialists, and cloud teams to deliver resilient, secure, and highly automated cloud infrastructure. The position is ideal for an experienced Security Platform Engineer with strong Kubernetes security expertise and a passion for cloud-native security engineering. Security Platform Engineer Responsibilities Design, deploy, configure, and manage cloud security platforms and tooling. Implement and maintain SIEM, IDS, and IPS technologies. Develop security monitoring, logging, and detection capabilities across Kubernetes environments. Investigate, analyse, and respond to security incidents, performing root cause analysis and remediation. Perform forensic investigations into suspicious activity and security events. Automate security workflows and operational processes using Scripting and Infrastructure as Code. Support Kubernetes platform security, workload isolation, RBAC, and network policies. Participate in an on-call rota to support security incidents and operational resilience. Security Platform Engineer Skills and Experience Active DV Clearance Experience within Cloud Security Engineering, DevSecOps, or Cloud Platform Engineering is essential Extensive experience using Kubernetes Security Strong experience securing Kubernetes environments, including RBAC, workload isolation, and network policies. Experience with Kubernetes threat detection, anomaly detection, Istio, Linkerd, or workload identity would be advantageous. Security certifications such as CISSP, CISM, GSEC, or OSCP would be beneficial. To apply, please send your CV by pressing the apply button. Due to high volume of applications, only shortlisted CVs will be contacted. Due to the nature and urgency of this post, candidates holding or who have held high level security clearance in the past are most welcome to apply. Please note successful applicants will be required to be security cleared prior to appointment which can take a minimum 18 weeks. LA International is an award-winning partner of choice for many of the world's most influential companies and government organisations. Holding Enhanced Government Security Accreditation, we are recognised as the European market leader in the delivery of Security Cleared talent to organisations that demand the very highest levels of security, compliance and assurance. An award-winning organisation, having secured the prestigious Queens Award for Enterprise: International Trade over multiple years. We are committed to fostering an inclusive, equitable and accessible workplace where everyone feels valued and supported. We welcome applications from all individuals, regardless of background or identity, and we encourage candidates who may not meet every listed requirement to still apply. If you require any adjustments or support during the recruitment process, please let us know and we will work with you to ensure a fair and accessible experience. Please Note: If a high volume of applications is received, only candidates shortlisted will be contacted.
SC Cleared Microsoft Sentinel Detection Engineer - £500/day via Umbrella - Short Term Contract - Remote - Immediate Start - SCC Flex Contract We're looking for an experienced SC Cleared SOC Analyst/Detection Engineer to support the delivery of a prioritised detection engineering backlog across AWS, Azure, Microsoft 365, Defender XDR, Dynatrace, and ServiceNow environments. Key Responsibilities Own assigned Microsoft Sentinel detection engineering use cases from inception through to production deployment. Design, develop and maintain Microsoft Sentinel Analytics Rules, Scheduled Rules, Near Real Time (NRT) Rules and Fusion detection capabilities. Create, optimise and maintain Kusto Query Language (KQL) based detections aligned to relevant MITRE ATT&CK tactics, techniques and procedures (TTPs). Develop and implement detection logic using data from Defender XDR, Microsoft 365, Azure, AWS CloudTrail, Dynatrace, ServiceNow and other integrated Sentinel connectors. Create advanced behavioural detections to identify credential compromise, account takeover, privilege escalation, persistence, lateral movement, defence evasion, command and control activity and data exfiltration. Design and implement correlation logic across multiple telemetry sources to improve detection fidelity and reduce alert fatigue. Develop and maintain Sentinel Watchlists, Entity Mappings, Automation Rules and Logic App integrations where required. Validate detection effectiveness through structured testing, attack simulation, purple team exercises and adversary emulation activities. Perform detection tuning and optimisation activities to minimise false positives and improve operational effectiveness. Support security monitoring maturity initiatives through continuous enhancement of Sentinel content and use cases. Produce high-quality technical documentation including detection logic, implementation details, testing outcomes and operational support procedures. Deliver knowledge transfer sessions and operational handovers to SOC Analysts, Security Engineers and Detection Engineering teams. Work closely with Threat Intelligence, Security Operations, Incident Response and Security Architecture teams to improve detection coverage and threat visibility. Support incident investigations through detection enhancement and rapid development of new Sentinel content to address emerging threats. Participate in technical workshops, backlog grooming, sprint planning and governance activities. Deliver assigned use cases in line with agreed priorities, quality standards and delivery milestones. Technical Requirements Proven hands-on experience with Microsoft Sentinel. Strong Kusto Query Language (KQL) development expertise. Experience creating and managing Sentinel Analytics Rules, Hunting Queries, Fusion Rules and Automation Rules. Strong knowledge of Microsoft Defender XDR, including Defender for Endpoint, Defender for Identity, Defender for Cloud Apps and Defender for Office 365. Experience ingesting and analysing security telemetry from Azure, Microsoft 365, AWS, Syslog, CEF and custom data sources. Knowledge of MITRE ATT&CK framework and detection engineering best practices. Experience tuning SIEM detections and reducing false positives within enterprise environments. Understanding of attack methodologies, adversary behaviours and modern threat actor techniques. Familiarity with Sentinel Content Hub solutions, Data Connectors and SOAR integrations. Experience with Logic Apps and security automation is advantageous. If you are a Microsoft Sentinel Detection Engineer looking to make an impact in a fast-paced environment, apply today - professional references required. NOTE: At SCC, we take the privacy and security of your information very seriously. Any information we hold will be handled in accordance with current data protection legislation. Upon submitting your application, SCC will process your information in line with our privacy policy, which can be found on our website under Legal Privacy Notice Flexible Resourcing.
Aug 07, 2026
Contractor
SC Cleared Microsoft Sentinel Detection Engineer - £500/day via Umbrella - Short Term Contract - Remote - Immediate Start - SCC Flex Contract We're looking for an experienced SC Cleared SOC Analyst/Detection Engineer to support the delivery of a prioritised detection engineering backlog across AWS, Azure, Microsoft 365, Defender XDR, Dynatrace, and ServiceNow environments. Key Responsibilities Own assigned Microsoft Sentinel detection engineering use cases from inception through to production deployment. Design, develop and maintain Microsoft Sentinel Analytics Rules, Scheduled Rules, Near Real Time (NRT) Rules and Fusion detection capabilities. Create, optimise and maintain Kusto Query Language (KQL) based detections aligned to relevant MITRE ATT&CK tactics, techniques and procedures (TTPs). Develop and implement detection logic using data from Defender XDR, Microsoft 365, Azure, AWS CloudTrail, Dynatrace, ServiceNow and other integrated Sentinel connectors. Create advanced behavioural detections to identify credential compromise, account takeover, privilege escalation, persistence, lateral movement, defence evasion, command and control activity and data exfiltration. Design and implement correlation logic across multiple telemetry sources to improve detection fidelity and reduce alert fatigue. Develop and maintain Sentinel Watchlists, Entity Mappings, Automation Rules and Logic App integrations where required. Validate detection effectiveness through structured testing, attack simulation, purple team exercises and adversary emulation activities. Perform detection tuning and optimisation activities to minimise false positives and improve operational effectiveness. Support security monitoring maturity initiatives through continuous enhancement of Sentinel content and use cases. Produce high-quality technical documentation including detection logic, implementation details, testing outcomes and operational support procedures. Deliver knowledge transfer sessions and operational handovers to SOC Analysts, Security Engineers and Detection Engineering teams. Work closely with Threat Intelligence, Security Operations, Incident Response and Security Architecture teams to improve detection coverage and threat visibility. Support incident investigations through detection enhancement and rapid development of new Sentinel content to address emerging threats. Participate in technical workshops, backlog grooming, sprint planning and governance activities. Deliver assigned use cases in line with agreed priorities, quality standards and delivery milestones. Technical Requirements Proven hands-on experience with Microsoft Sentinel. Strong Kusto Query Language (KQL) development expertise. Experience creating and managing Sentinel Analytics Rules, Hunting Queries, Fusion Rules and Automation Rules. Strong knowledge of Microsoft Defender XDR, including Defender for Endpoint, Defender for Identity, Defender for Cloud Apps and Defender for Office 365. Experience ingesting and analysing security telemetry from Azure, Microsoft 365, AWS, Syslog, CEF and custom data sources. Knowledge of MITRE ATT&CK framework and detection engineering best practices. Experience tuning SIEM detections and reducing false positives within enterprise environments. Understanding of attack methodologies, adversary behaviours and modern threat actor techniques. Familiarity with Sentinel Content Hub solutions, Data Connectors and SOAR integrations. Experience with Logic Apps and security automation is advantageous. If you are a Microsoft Sentinel Detection Engineer looking to make an impact in a fast-paced environment, apply today - professional references required. NOTE: At SCC, we take the privacy and security of your information very seriously. Any information we hold will be handled in accordance with current data protection legislation. Upon submitting your application, SCC will process your information in line with our privacy policy, which can be found on our website under Legal Privacy Notice Flexible Resourcing.
Role: Sentinel Engineer Type: Contract (Inside IR35) Duration: 6 months Location: Remote Overview We are seeking an experienced Microsoft Sentinel Engineer with a strong cyber security background to support the delivery, optimisation, and ongoing development of a large-scale Microsoft security environment. The successful candidate will play a key role in enhancing security monitoring, threat detection, automation, and SIEM capabilities, whilst helping drive security improvements across cloud and hybrid platforms. This role is ideally suited to a hands-on Security Engineer with proven experience implementing and managing Microsoft Sentinel, delivering SIEM migrations, and working across the wider Microsoft Security stack. You will work closely with Security Operations, Infrastructure, and Cloud teams to strengthen the organisation's security posture and improve incident detection and response capabilities. Key Responsibilities Design, implement, configure and support Microsoft Sentinel solutions . Lead and support SIEM migration projects from legacy platforms into Microsoft Sentinel . Develop and maintain analytics rules, alerting capabilities and detection use cases. Create and optimise Kusto Query Language (KQL) queries for threat hunting, incident investigation and reporting. Integrate and onboard new log sources and security tooling into Sentinel. Configure and support Azure Monitor and Log Analytics environments . Develop automation and orchestration playbooks using Azure Logic Apps. Work with Microsoft Defender technologies to improve threat detection and response. Build dashboards, workbooks and reporting capabilities for operational and management teams. Support Security Operations teams with incident response, threat hunting and security investigations. Tune detections and reduce false positives whilst improving overall visibility and coverage. Implement security best practices aligned to industry frameworks and standards. Collaborate with internal and third-party stakeholders across security, infrastructure and cloud teams. Essential Skills & Experience Technical Skills Microsoft Sentinel SIEM Migration Experience Log Analytics Azure Monitor Microsoft Defender XDR Microsoft Defender for Endpoint Microsoft Defender for Cloud Microsoft 365 Security Kusto Query Language (KQL) Azure Logic Apps Azure Lighthouse Experience Minimum 5 years' experience within Cyber Security, Security Engineering, SOC, SIEM Engineering or related disciplines. Strong understanding of SIEM, SOAR, threat detection and incident response. Demonstrable experience designing and implementing Microsoft Sentinel solutions. Experience developing detection rules, use cases and security monitoring capabilities. Strong threat hunting and security investigation experience. Knowledge of MITRE ATT&CK and modern security operations practices. Experience working within enterprise-scale Azure and Microsoft security environments. Desirable Skills QRadar Devo SentinelOne Mimecast Check Point Qualys Azure Networking Terraform PowerShell Python GitHub Azure DevOps ServiceNow Azure RBAC Azure Monitor Agent (AMA) Data Collection Rules (DCR) Syslog CEF Windows Event Logging Linux Logging REST APIs Candidate Profile The ideal candidate will be a proactive and technically strong Security Engineer who combines deep Microsoft Sentinel expertise with a broad understanding of cyber security operations. You will be comfortable working in a fast-paced environment, engaging with stakeholders at all levels, and driving improvements across monitoring, detection, automation and incident response capabilities.
Aug 07, 2026
Contractor
Role: Sentinel Engineer Type: Contract (Inside IR35) Duration: 6 months Location: Remote Overview We are seeking an experienced Microsoft Sentinel Engineer with a strong cyber security background to support the delivery, optimisation, and ongoing development of a large-scale Microsoft security environment. The successful candidate will play a key role in enhancing security monitoring, threat detection, automation, and SIEM capabilities, whilst helping drive security improvements across cloud and hybrid platforms. This role is ideally suited to a hands-on Security Engineer with proven experience implementing and managing Microsoft Sentinel, delivering SIEM migrations, and working across the wider Microsoft Security stack. You will work closely with Security Operations, Infrastructure, and Cloud teams to strengthen the organisation's security posture and improve incident detection and response capabilities. Key Responsibilities Design, implement, configure and support Microsoft Sentinel solutions . Lead and support SIEM migration projects from legacy platforms into Microsoft Sentinel . Develop and maintain analytics rules, alerting capabilities and detection use cases. Create and optimise Kusto Query Language (KQL) queries for threat hunting, incident investigation and reporting. Integrate and onboard new log sources and security tooling into Sentinel. Configure and support Azure Monitor and Log Analytics environments . Develop automation and orchestration playbooks using Azure Logic Apps. Work with Microsoft Defender technologies to improve threat detection and response. Build dashboards, workbooks and reporting capabilities for operational and management teams. Support Security Operations teams with incident response, threat hunting and security investigations. Tune detections and reduce false positives whilst improving overall visibility and coverage. Implement security best practices aligned to industry frameworks and standards. Collaborate with internal and third-party stakeholders across security, infrastructure and cloud teams. Essential Skills & Experience Technical Skills Microsoft Sentinel SIEM Migration Experience Log Analytics Azure Monitor Microsoft Defender XDR Microsoft Defender for Endpoint Microsoft Defender for Cloud Microsoft 365 Security Kusto Query Language (KQL) Azure Logic Apps Azure Lighthouse Experience Minimum 5 years' experience within Cyber Security, Security Engineering, SOC, SIEM Engineering or related disciplines. Strong understanding of SIEM, SOAR, threat detection and incident response. Demonstrable experience designing and implementing Microsoft Sentinel solutions. Experience developing detection rules, use cases and security monitoring capabilities. Strong threat hunting and security investigation experience. Knowledge of MITRE ATT&CK and modern security operations practices. Experience working within enterprise-scale Azure and Microsoft security environments. Desirable Skills QRadar Devo SentinelOne Mimecast Check Point Qualys Azure Networking Terraform PowerShell Python GitHub Azure DevOps ServiceNow Azure RBAC Azure Monitor Agent (AMA) Data Collection Rules (DCR) Syslog CEF Windows Event Logging Linux Logging REST APIs Candidate Profile The ideal candidate will be a proactive and technically strong Security Engineer who combines deep Microsoft Sentinel expertise with a broad understanding of cyber security operations. You will be comfortable working in a fast-paced environment, engaging with stakeholders at all levels, and driving improvements across monitoring, detection, automation and incident response capabilities.
SOC Automation Engineer As a SOC Automation Engineer, you will apply hands-on engineering expertise to design, build, and optimise automation workflows that improve the scalability and efficiency of SOC services. Working across SIEM, endpoint, and orchestration platforms (primarily Palo Alto XSOAR), you will reduce analyst workload, accelerate incident response, and enhance decision-making across customer environments. Key Responsibilities Automation Development - Design, build, and maintain scalable automation workflows across detection and response platforms. Integration & Orchestration - Deliver cross-platform automation enabling fast, reliable response actions. Lifecycle Management - Develop, deploy, and continuously optimise automation for performance, resilience, and coverage. Collaboration & Requirements Gathering - Work with SOC and engineering teams to identify automation opportunities. Documentation - Produce clear documentation to support delivery, troubleshooting, and continuous improvement. Automation Planning - Contribute to automation roadmaps, threat modelling, and use case development. Pre-Sales Support - Assist with demos, scoping, and proof-of-value activities where required. Core Duties Automation Design & Development Build and maintain workflows across SIEM, EDR, and SOAR platforms Develop reusable scripts, templates, and components Ensure solutions support secure, multi-tenant environments Integration & Response Automation Orchestrate containment, enrichment, and remediation actions Integrate with threat intelligence, cloud, vulnerability, and reporting tools Partner with analysts to map and automate response processes Lifecycle Management & Optimisation Manage automation from design through to optimisation Troubleshoot failures and refine logic Use post-incident insights to improve workflows Documentation & Standards Maintain clear documentation of workflows, dependencies, and error handling Ensure consistency and usability for wider teams Strategic Contribution Support use cases aligned to threat modelling and MITRE ATT&CK Contribute to automation playbooks and response strategies Stay current with tools, frameworks, and emerging threats Collaboration Embed automation into SOC workflows Share best practices and support team development Pre-Sales Support workshops, onboarding, and solution design where needed Stakeholder Collaboration SOC Analysts - Automate repeatable triage and response activities Platform & Detection Engineers - Integrate automation into tooling and detections Sales & Pre-Sales - Provide technical input for customer solutions Requirements 2+ years' experience in SOC, automation, or cloud security engineering Experience in managed services or multi-tenant environments Strong experience building automations across SIEM, SOAR, or EDR platforms Proficiency in scripting (e.g., Python, PowerShell) Experience working with APIs, webhooks, and authentication methods Knowledge of threat frameworks (e.g., MITRE ATT&CK) Understanding of cloud security, identity, and event-driven automation Strong communication and analytical skills Security clearance (NPPV and/or SC) may be required. Technical Knowledge Security orchestration and automation principles Scripting and integration patterns (APIs, webhooks) SOC detection and response workflows Threat intelligence integration and use case design Cloud and identity security concepts Multi-tenant automation design Certifications Essential: Hands-on experience with Palo Alto XSOAR Desirable: Palo Alto Networks Certified XSOAR Engineer Palo Alto Networks Certified Security Automation Engineer (PCSAE) Palo Alto Networks Security Operations Professional
Aug 07, 2026
Full time
SOC Automation Engineer As a SOC Automation Engineer, you will apply hands-on engineering expertise to design, build, and optimise automation workflows that improve the scalability and efficiency of SOC services. Working across SIEM, endpoint, and orchestration platforms (primarily Palo Alto XSOAR), you will reduce analyst workload, accelerate incident response, and enhance decision-making across customer environments. Key Responsibilities Automation Development - Design, build, and maintain scalable automation workflows across detection and response platforms. Integration & Orchestration - Deliver cross-platform automation enabling fast, reliable response actions. Lifecycle Management - Develop, deploy, and continuously optimise automation for performance, resilience, and coverage. Collaboration & Requirements Gathering - Work with SOC and engineering teams to identify automation opportunities. Documentation - Produce clear documentation to support delivery, troubleshooting, and continuous improvement. Automation Planning - Contribute to automation roadmaps, threat modelling, and use case development. Pre-Sales Support - Assist with demos, scoping, and proof-of-value activities where required. Core Duties Automation Design & Development Build and maintain workflows across SIEM, EDR, and SOAR platforms Develop reusable scripts, templates, and components Ensure solutions support secure, multi-tenant environments Integration & Response Automation Orchestrate containment, enrichment, and remediation actions Integrate with threat intelligence, cloud, vulnerability, and reporting tools Partner with analysts to map and automate response processes Lifecycle Management & Optimisation Manage automation from design through to optimisation Troubleshoot failures and refine logic Use post-incident insights to improve workflows Documentation & Standards Maintain clear documentation of workflows, dependencies, and error handling Ensure consistency and usability for wider teams Strategic Contribution Support use cases aligned to threat modelling and MITRE ATT&CK Contribute to automation playbooks and response strategies Stay current with tools, frameworks, and emerging threats Collaboration Embed automation into SOC workflows Share best practices and support team development Pre-Sales Support workshops, onboarding, and solution design where needed Stakeholder Collaboration SOC Analysts - Automate repeatable triage and response activities Platform & Detection Engineers - Integrate automation into tooling and detections Sales & Pre-Sales - Provide technical input for customer solutions Requirements 2+ years' experience in SOC, automation, or cloud security engineering Experience in managed services or multi-tenant environments Strong experience building automations across SIEM, SOAR, or EDR platforms Proficiency in scripting (e.g., Python, PowerShell) Experience working with APIs, webhooks, and authentication methods Knowledge of threat frameworks (e.g., MITRE ATT&CK) Understanding of cloud security, identity, and event-driven automation Strong communication and analytical skills Security clearance (NPPV and/or SC) may be required. Technical Knowledge Security orchestration and automation principles Scripting and integration patterns (APIs, webhooks) SOC detection and response workflows Threat intelligence integration and use case design Cloud and identity security concepts Multi-tenant automation design Certifications Essential: Hands-on experience with Palo Alto XSOAR Desirable: Palo Alto Networks Certified XSOAR Engineer Palo Alto Networks Certified Security Automation Engineer (PCSAE) Palo Alto Networks Security Operations Professional
Senior Network and Security Engineer - L2/L3 Network Infrastructure - Cyber Security - SIEM tools My client who are leaders in their field are looking for a Senior Cyber Security and Network Analyst to provide effective and timely operational support, development and management of the IT network and security infrastructure to meet business requirements and objectives. Responsibilities: Support the delivery and maintenance of the organisation's cyber security and network infrastructure, ensuring systems remain secure, resilient, and aligned to business needs Manage day-to-day security operations, including monitoring SIEM platforms, Firewalls, endpoint protection, and threat detection tools Investigate security incidents and vulnerabilities, recommending and implementing corrective actions where required Maintain and support network technologies including LAN/WAN, Wi-Fi, Internet connectivity, and Layer 2/3 infrastructure Contribute to cyber security and infrastructure projects, including the implementation of new security controls and technologies Perform patching, upgrades, and ongoing maintenance across security and network environments to minimise risk and downtime Develop and maintain security policies, operational procedures, technical documentation, and compliance standards Support disaster recovery and business continuity planning, testing, and readiness activities Key Experience & Skills: Palo Alto Firewalls and all associated NG services Endpoint detection and remediation Proven track record in Cyber security and understanding of cyber security analysis, tools and software Experience of implementing, supporting and developing L2/3 network infrastructure Qualys Vulnerability Management Aruba Wifi L2/3 switching - Cisco Nexus Network Load balancing Penetration Testing (3rd Party) Incident management Data Security
Aug 06, 2026
Full time
Senior Network and Security Engineer - L2/L3 Network Infrastructure - Cyber Security - SIEM tools My client who are leaders in their field are looking for a Senior Cyber Security and Network Analyst to provide effective and timely operational support, development and management of the IT network and security infrastructure to meet business requirements and objectives. Responsibilities: Support the delivery and maintenance of the organisation's cyber security and network infrastructure, ensuring systems remain secure, resilient, and aligned to business needs Manage day-to-day security operations, including monitoring SIEM platforms, Firewalls, endpoint protection, and threat detection tools Investigate security incidents and vulnerabilities, recommending and implementing corrective actions where required Maintain and support network technologies including LAN/WAN, Wi-Fi, Internet connectivity, and Layer 2/3 infrastructure Contribute to cyber security and infrastructure projects, including the implementation of new security controls and technologies Perform patching, upgrades, and ongoing maintenance across security and network environments to minimise risk and downtime Develop and maintain security policies, operational procedures, technical documentation, and compliance standards Support disaster recovery and business continuity planning, testing, and readiness activities Key Experience & Skills: Palo Alto Firewalls and all associated NG services Endpoint detection and remediation Proven track record in Cyber security and understanding of cyber security analysis, tools and software Experience of implementing, supporting and developing L2/3 network infrastructure Qualys Vulnerability Management Aruba Wifi L2/3 switching - Cisco Nexus Network Load balancing Penetration Testing (3rd Party) Incident management Data Security
hackajob is collaborating with Google to connect them with exceptional professionals for this role. As a part of the UK Security Operations (SecOps) team in Google Public Sector, you will deliver, operate and secure private cloud services. You will aim to provide the flexibility, reliability, and scalability of public cloud for customers with exceptionally high security requirements that can only be met in a private cloud environment. You will deliver and operate these private cloud deployments for the most critical customers, helping scale, secure and maintain the deployment whilst working closely with Google product teams to continually improve our technology. As a Security Platform Engineer, you will play a critical role in designing, building, and managing cloud-native security platforms with a strong emphasis on Kubernetes-based environments. You will be at the intersection of security and engineering, developing scalable tooling, automating security controls, and enabling robust detection and response capabilities across our cloud infrastructure. In this role, you will require deep technical expertise in cloud environments, Kubernetes security, and platform automation. You will work closely with Incident Response Engineers and platform teams to ensure that security is seamlessly integrated into our infrastructure and operational workflows. Your role will require participation in a rotating on-call schedule outside of core business hours and over the weekend to ensure security incidents can be swiftly resolved. Minimum qualifications: Bachelor's degree in Computer Science, Information Security, a related field, or equivalent practical experience. 5 years of experience in security engineering, DevSecOps, or platform engineering roles. Experience with technical troubleshooting and scripting languages such as Python, Go, or Bash. Experience with Kubernetes security, including workload isolation, Role-Based Access Control (RBAC), and network policies, containerisation, orchestration, and Kubernetes observability tools (e.g., Falco, Prometheus, Grafana). Experience with infrastructure-as-code and configuration management tools (e.g., Terraform, Helm, ArgoCD). Active, or the ability to obtain, a Developed Vetting (DV) UK security clearance. Preferred qualifications: Certifications in Security (e.g., GSEC, CISSP, CISM, OSCP). Experience with Kubernetes threat detection and anomaly detection. Experience with service mesh security concepts (e.g., Istio, Linkerd) and workload identity. Experience in detection engineering, logging pipeline development, or SIEM tuning in containerised environments. Experience in contributing to security-focused open-source projects or internal security platform tooling. Responsibilities: Deploy, configure, and manage cloud security platform tools and technologies, including Security Information and Event Management (SIEM), Intrusion Detection/Prevention Systems (IDS/IPS), and Cloud Workload Protection Platforms (CWPP). Develop and implement security monitoring and logging strategies. Investigate and analyse security incidents, including identifying root causes, determining the scope of impact, and taking appropriate containment and remediation actions. Perform forensic analysis to identify and investigate suspicious activity. Automate security tasks and workflows to improve efficiency and effectiveness. Must be a British citizen to meet compliance and security clearance requirements. Office location can either be a satellite site in Wiltshire, or London. This is an on-site position, requiring a standard five day per week schedule in the office
Aug 06, 2026
Full time
hackajob is collaborating with Google to connect them with exceptional professionals for this role. As a part of the UK Security Operations (SecOps) team in Google Public Sector, you will deliver, operate and secure private cloud services. You will aim to provide the flexibility, reliability, and scalability of public cloud for customers with exceptionally high security requirements that can only be met in a private cloud environment. You will deliver and operate these private cloud deployments for the most critical customers, helping scale, secure and maintain the deployment whilst working closely with Google product teams to continually improve our technology. As a Security Platform Engineer, you will play a critical role in designing, building, and managing cloud-native security platforms with a strong emphasis on Kubernetes-based environments. You will be at the intersection of security and engineering, developing scalable tooling, automating security controls, and enabling robust detection and response capabilities across our cloud infrastructure. In this role, you will require deep technical expertise in cloud environments, Kubernetes security, and platform automation. You will work closely with Incident Response Engineers and platform teams to ensure that security is seamlessly integrated into our infrastructure and operational workflows. Your role will require participation in a rotating on-call schedule outside of core business hours and over the weekend to ensure security incidents can be swiftly resolved. Minimum qualifications: Bachelor's degree in Computer Science, Information Security, a related field, or equivalent practical experience. 5 years of experience in security engineering, DevSecOps, or platform engineering roles. Experience with technical troubleshooting and scripting languages such as Python, Go, or Bash. Experience with Kubernetes security, including workload isolation, Role-Based Access Control (RBAC), and network policies, containerisation, orchestration, and Kubernetes observability tools (e.g., Falco, Prometheus, Grafana). Experience with infrastructure-as-code and configuration management tools (e.g., Terraform, Helm, ArgoCD). Active, or the ability to obtain, a Developed Vetting (DV) UK security clearance. Preferred qualifications: Certifications in Security (e.g., GSEC, CISSP, CISM, OSCP). Experience with Kubernetes threat detection and anomaly detection. Experience with service mesh security concepts (e.g., Istio, Linkerd) and workload identity. Experience in detection engineering, logging pipeline development, or SIEM tuning in containerised environments. Experience in contributing to security-focused open-source projects or internal security platform tooling. Responsibilities: Deploy, configure, and manage cloud security platform tools and technologies, including Security Information and Event Management (SIEM), Intrusion Detection/Prevention Systems (IDS/IPS), and Cloud Workload Protection Platforms (CWPP). Develop and implement security monitoring and logging strategies. Investigate and analyse security incidents, including identifying root causes, determining the scope of impact, and taking appropriate containment and remediation actions. Perform forensic analysis to identify and investigate suspicious activity. Automate security tasks and workflows to improve efficiency and effectiveness. Must be a British citizen to meet compliance and security clearance requirements. Office location can either be a satellite site in Wiltshire, or London. This is an on-site position, requiring a standard five day per week schedule in the office
Senior Security Engineering Team Lead Leeds (Home with 1 HQ visit per quarter) Up to 82,500 (NEG) + Excellent Benefits Are you an experienced Security Engineer ready to lead from the front? We're supporting a leading international managed technology organisation in the search for a Senior Security Engineering Team Lead to head a dedicated cyber security engineering function supporting a major enterprise customer operating within a highly regulated environment. This is far more than a traditional management role. You'll remain hands-on, acting as the technical authority for Microsoft security technologies whilst leading a team of experienced Security Analysts and Engineers responsible for protecting a critical customer environment. If you're passionate about Microsoft security, detection engineering, automation and mentoring technical teams, this is an opportunity to influence the direction of an enterprise-scale security operation. The Opportunity As the technical lead for the Security Engineering function, you'll own the security platform estate, providing architectural guidance, driving continuous improvement and acting as the primary escalation point for complex cyber security incidents. You'll combine strategic leadership with hands-on engineering, working closely with Security Analysts, Infrastructure teams and customer stakeholders to ensure security platforms remain resilient, effective and continually evolving. This is an excellent opportunity to join an organisation that invests heavily in technology, professional development and long-term career progression whilst working with some of the latest Microsoft security technologies. Key Responsibilities Lead and develop a team of Security Engineers and Security Analysts Act as the senior technical escalation point for complex cyber security incidents Own the configuration, maintenance and optimisation of the Microsoft security platform Drive detection engineering, rule tuning and continuous platform improvement Lead SIEM and SOAR engineering activities, including automation and Logic Apps Oversee log ingestion, telemetry quality and detection coverage Support vulnerability management and exposure management tooling Work closely with customers and internal technical teams on security architecture and platform improvements Mentor engineers and analysts, helping raise technical capability across the team Contribute to platform roadmaps, governance, documentation and service improvements Technology Environment You'll work across a modern Microsoft-centric cyber security stack including: Microsoft Defender XDR Defender for Endpoint Defender for Identity Microsoft Sentinel Logic Apps SOAR Automation Microsoft Purview Qualys XM Cyber CyberArk Detection Engineering KQL Threat Hunting Platform Engineering About You We're looking for someone who combines deep technical expertise with natural leadership skills. You'll likely have experience in areas such as: Security Engineering Detection Engineering SOC Engineering Microsoft Security Security Platform Management Cyber Security Architecture Security Automation Team Leadership You'll also possess: Expert knowledge of Microsoft Defender technologies Strong Microsoft Sentinel experience Experience building or improving security detections Knowledge of SOAR and security automation Experience within regulated or enterprise environments Excellent stakeholder management and communication skills Previous leadership or mentoring experience Why Apply? This organisation is recognised as one of the world's leading managed technology providers, delivering cloud, cyber security, data and digital workplace solutions to thousands of enterprise customers across multiple countries. It combines the scale of an international business with a culture that genuinely invests in its people through continuous learning, technical certifications, structured development programmes and internal career progression. You'll be joining at an exciting stage of growth, leading a newly established security capability supporting a strategic customer where you'll have genuine influence over both the technology roadmap and the development of your team. Package Salary up to 82,500 (NEG) Home working with one visit to HQ per quarter Excellent benefits package Significant investment in training and certifications Career progression opportunities Opportunity to work with enterprise Microsoft security technologies Technical leadership role with genuine strategic influence
Aug 06, 2026
Full time
Senior Security Engineering Team Lead Leeds (Home with 1 HQ visit per quarter) Up to 82,500 (NEG) + Excellent Benefits Are you an experienced Security Engineer ready to lead from the front? We're supporting a leading international managed technology organisation in the search for a Senior Security Engineering Team Lead to head a dedicated cyber security engineering function supporting a major enterprise customer operating within a highly regulated environment. This is far more than a traditional management role. You'll remain hands-on, acting as the technical authority for Microsoft security technologies whilst leading a team of experienced Security Analysts and Engineers responsible for protecting a critical customer environment. If you're passionate about Microsoft security, detection engineering, automation and mentoring technical teams, this is an opportunity to influence the direction of an enterprise-scale security operation. The Opportunity As the technical lead for the Security Engineering function, you'll own the security platform estate, providing architectural guidance, driving continuous improvement and acting as the primary escalation point for complex cyber security incidents. You'll combine strategic leadership with hands-on engineering, working closely with Security Analysts, Infrastructure teams and customer stakeholders to ensure security platforms remain resilient, effective and continually evolving. This is an excellent opportunity to join an organisation that invests heavily in technology, professional development and long-term career progression whilst working with some of the latest Microsoft security technologies. Key Responsibilities Lead and develop a team of Security Engineers and Security Analysts Act as the senior technical escalation point for complex cyber security incidents Own the configuration, maintenance and optimisation of the Microsoft security platform Drive detection engineering, rule tuning and continuous platform improvement Lead SIEM and SOAR engineering activities, including automation and Logic Apps Oversee log ingestion, telemetry quality and detection coverage Support vulnerability management and exposure management tooling Work closely with customers and internal technical teams on security architecture and platform improvements Mentor engineers and analysts, helping raise technical capability across the team Contribute to platform roadmaps, governance, documentation and service improvements Technology Environment You'll work across a modern Microsoft-centric cyber security stack including: Microsoft Defender XDR Defender for Endpoint Defender for Identity Microsoft Sentinel Logic Apps SOAR Automation Microsoft Purview Qualys XM Cyber CyberArk Detection Engineering KQL Threat Hunting Platform Engineering About You We're looking for someone who combines deep technical expertise with natural leadership skills. You'll likely have experience in areas such as: Security Engineering Detection Engineering SOC Engineering Microsoft Security Security Platform Management Cyber Security Architecture Security Automation Team Leadership You'll also possess: Expert knowledge of Microsoft Defender technologies Strong Microsoft Sentinel experience Experience building or improving security detections Knowledge of SOAR and security automation Experience within regulated or enterprise environments Excellent stakeholder management and communication skills Previous leadership or mentoring experience Why Apply? This organisation is recognised as one of the world's leading managed technology providers, delivering cloud, cyber security, data and digital workplace solutions to thousands of enterprise customers across multiple countries. It combines the scale of an international business with a culture that genuinely invests in its people through continuous learning, technical certifications, structured development programmes and internal career progression. You'll be joining at an exciting stage of growth, leading a newly established security capability supporting a strategic customer where you'll have genuine influence over both the technology roadmap and the development of your team. Package Salary up to 82,500 (NEG) Home working with one visit to HQ per quarter Excellent benefits package Significant investment in training and certifications Career progression opportunities Opportunity to work with enterprise Microsoft security technologies Technical leadership role with genuine strategic influence
Role Title: Splunk SIEM Engineer Duration: contract to run until 30/11/2026 Location: Knutsford. Hybrid, 3 days per week onsite Rate: up to 587.33 p/d Umbrella inside IR35 Role purpose / summary Join us as Splunk SIEM Engineer where you must design, develop and improve software, utilizing various engineering methodologies, that provides business, platform, and technology capabilities for our customers and colleagues. Looking for a successful Splunk SIEM Engineer, where one should have experience with: Minimum Qualification - bachelor's degree Multi-Platform SIEM Expertise: Proven experience with Splunk Enterprise Security, Microsoft Sentinel, and SIEM architecture including data models, correlation rules, and administrative functions. Security Operations: Strong analytical skills in threat detection, incident response, and security event analysis with experience in large enterprise environments (10,000+ endpoints). Data Pipeline Management: Hands-on experience with log ingestion, data routing, and transformation using tools like Cribl, plus understanding of data normalisation and parsing in Splunk Enterprise. SOAR & Automation: Experience with Security Orchestration platforms, playbook development, and automated response workflows for incident management. Network Security Fundamentals: Working knowledge of network architectures, firewalls, proxies, and common attack vectors with troubleshooting expertise. Communication & Documentation: Excellent technical writing and communication skills to create runbooks, procedures, and translate complex security concepts for diverse audiences. Some other highly valued skills may include: Cloud Security & Modern Infrastructure: Proficiency with AWS/Azure cloud security, containerized environments, and SaaS-based security solutions. Programming & Scripting: Advanced skills in Python, PowerShell, KQL, SPL, and SQL for automation, custom integrations, and advanced analytics development. Security Certifications: Professional certifications such as CISSP, GCIH, GCFA, Splunk Certified Architect, or Microsoft Sentinel Ninja. Extended Security Stack: Experience with EDR, UBA, CASB, CSPM, vulnerability assessment tools, and threat intelligence platforms. Infrastructure as Code: Experience with Chef, Ansible, Jenkins, GitLab CI/CD for automated security tool deployment and configuration management. Compliance & Governance: Knowledge of regulatory frameworks (SOX, PCI-DSS, GDPR) and hands-on incident response/forensics experience. All profiles will be reviewed against the required skills and experience. Due to the high number of applications we will only be able to respond to successful applicants in the first instance. We thank you for your interest and the time taken to apply! If you receive suspicious outreach claiming to be from us, please contact us via the ManpowerGroup website.
Aug 06, 2026
Contractor
Role Title: Splunk SIEM Engineer Duration: contract to run until 30/11/2026 Location: Knutsford. Hybrid, 3 days per week onsite Rate: up to 587.33 p/d Umbrella inside IR35 Role purpose / summary Join us as Splunk SIEM Engineer where you must design, develop and improve software, utilizing various engineering methodologies, that provides business, platform, and technology capabilities for our customers and colleagues. Looking for a successful Splunk SIEM Engineer, where one should have experience with: Minimum Qualification - bachelor's degree Multi-Platform SIEM Expertise: Proven experience with Splunk Enterprise Security, Microsoft Sentinel, and SIEM architecture including data models, correlation rules, and administrative functions. Security Operations: Strong analytical skills in threat detection, incident response, and security event analysis with experience in large enterprise environments (10,000+ endpoints). Data Pipeline Management: Hands-on experience with log ingestion, data routing, and transformation using tools like Cribl, plus understanding of data normalisation and parsing in Splunk Enterprise. SOAR & Automation: Experience with Security Orchestration platforms, playbook development, and automated response workflows for incident management. Network Security Fundamentals: Working knowledge of network architectures, firewalls, proxies, and common attack vectors with troubleshooting expertise. Communication & Documentation: Excellent technical writing and communication skills to create runbooks, procedures, and translate complex security concepts for diverse audiences. Some other highly valued skills may include: Cloud Security & Modern Infrastructure: Proficiency with AWS/Azure cloud security, containerized environments, and SaaS-based security solutions. Programming & Scripting: Advanced skills in Python, PowerShell, KQL, SPL, and SQL for automation, custom integrations, and advanced analytics development. Security Certifications: Professional certifications such as CISSP, GCIH, GCFA, Splunk Certified Architect, or Microsoft Sentinel Ninja. Extended Security Stack: Experience with EDR, UBA, CASB, CSPM, vulnerability assessment tools, and threat intelligence platforms. Infrastructure as Code: Experience with Chef, Ansible, Jenkins, GitLab CI/CD for automated security tool deployment and configuration management. Compliance & Governance: Knowledge of regulatory frameworks (SOX, PCI-DSS, GDPR) and hands-on incident response/forensics experience. All profiles will be reviewed against the required skills and experience. Due to the high number of applications we will only be able to respond to successful applicants in the first instance. We thank you for your interest and the time taken to apply! If you receive suspicious outreach claiming to be from us, please contact us via the ManpowerGroup website.
IT & Network Security Engineer Job Title: IT Security Engineer Location: Oxfordshire - Hybrid (2 days per week on-site) Industry: Enterprise SaaS / Technology Solutions About the Role We are partnering with a rapidly scaling, globally active software and data platform enterprise looking to appoint a dedicated IT Security Engineer to join their growing security operations team. In this role, you will be instrumental in defending core infrastructure, enterprise networks, and critical data against modern cyber threats. Working closely with the Head of IT Security, you will oversee threat detection, manage security appliances, enforce compliance frameworks, and ensure that robust defensive postures are embedded across the technology stack. Key Responsibilities Security Operations: Oversee network telemetry for suspicious activities, execute rapid threat detection and response, tune perimeter defenses (firewalls and virtual private networks), and direct proactive patch management cycles. Compliance & Audits: Drive internal control testing and maintain alignment with structured information security standards such as ISO 27001, supporting both internal evaluations and external auditor walkthroughs. Incident Handling: Manage the end-to-end lifecycle of security alerts or breaches, lead formal root-cause analysis, and embed corrective actions into future preventive safeguards. Third-Party Risk: Evaluate external vendors and technology partners to ensure compliance with internal security policies and benchmark security standards. Cross-Functional Collaboration: Partner directly with IT infrastructure, application support, software engineering, and legal teams to bake security-by-design principles into technical architectures. Key Requirements Experience: A minimum of 3 to 5 years of dedicated professional experience within an IT or information security function. Technical Proficiency: Deep working knowledge of core network protocols (TCP/IP, DNS, routing, switching) and architecture design. Hands-on proficiency with network analysis utilities, packet sniffers, port scanners, and SIEM monitoring suites. Working familiarity with cryptographic methods, identity controls, endpoint hardening, and multi-cloud security management (AWS, Azure, or GCP). Framework Knowledge: Solid comprehension of ISO 27001 principles, threat modelling frameworks, vulnerability scanning, risk treatment life-cycles, and secondary compliance standards (e.g., SOC 2 or PCI DSS). Qualifications: Relevant technical diploma or equivalent practical background, reinforced by desirable professional credentials (such as CISSP, CEH, CCNA Security, or ISO 27001 Lead Auditor certifications). Personal Attributes: Strong analytical problem-solving skills, clear communication capabilities, and the adaptability to thrive in a fast-moving, collaborative environment. What is on Offer Competitive base salary package. Sustainable hybrid working model (2 days on-site in Oxfordshire). Continuous professional development and training opportunities within an expanding tech organisation. If you are a proactive security professional looking to make a meaningful impact, please submit your CV to begin a confidential discussion.
Aug 05, 2026
Full time
IT & Network Security Engineer Job Title: IT Security Engineer Location: Oxfordshire - Hybrid (2 days per week on-site) Industry: Enterprise SaaS / Technology Solutions About the Role We are partnering with a rapidly scaling, globally active software and data platform enterprise looking to appoint a dedicated IT Security Engineer to join their growing security operations team. In this role, you will be instrumental in defending core infrastructure, enterprise networks, and critical data against modern cyber threats. Working closely with the Head of IT Security, you will oversee threat detection, manage security appliances, enforce compliance frameworks, and ensure that robust defensive postures are embedded across the technology stack. Key Responsibilities Security Operations: Oversee network telemetry for suspicious activities, execute rapid threat detection and response, tune perimeter defenses (firewalls and virtual private networks), and direct proactive patch management cycles. Compliance & Audits: Drive internal control testing and maintain alignment with structured information security standards such as ISO 27001, supporting both internal evaluations and external auditor walkthroughs. Incident Handling: Manage the end-to-end lifecycle of security alerts or breaches, lead formal root-cause analysis, and embed corrective actions into future preventive safeguards. Third-Party Risk: Evaluate external vendors and technology partners to ensure compliance with internal security policies and benchmark security standards. Cross-Functional Collaboration: Partner directly with IT infrastructure, application support, software engineering, and legal teams to bake security-by-design principles into technical architectures. Key Requirements Experience: A minimum of 3 to 5 years of dedicated professional experience within an IT or information security function. Technical Proficiency: Deep working knowledge of core network protocols (TCP/IP, DNS, routing, switching) and architecture design. Hands-on proficiency with network analysis utilities, packet sniffers, port scanners, and SIEM monitoring suites. Working familiarity with cryptographic methods, identity controls, endpoint hardening, and multi-cloud security management (AWS, Azure, or GCP). Framework Knowledge: Solid comprehension of ISO 27001 principles, threat modelling frameworks, vulnerability scanning, risk treatment life-cycles, and secondary compliance standards (e.g., SOC 2 or PCI DSS). Qualifications: Relevant technical diploma or equivalent practical background, reinforced by desirable professional credentials (such as CISSP, CEH, CCNA Security, or ISO 27001 Lead Auditor certifications). Personal Attributes: Strong analytical problem-solving skills, clear communication capabilities, and the adaptability to thrive in a fast-moving, collaborative environment. What is on Offer Competitive base salary package. Sustainable hybrid working model (2 days on-site in Oxfordshire). Continuous professional development and training opportunities within an expanding tech organisation. If you are a proactive security professional looking to make a meaningful impact, please submit your CV to begin a confidential discussion.
hackajob is collaborating with Leonardo to connect them with exceptional professionals for this role. Job Description: Salary Range: £44,171 - £61,950 Leonardo UK operates a grade-based salary framework with broad bands. The salary range shown reflects the approved grade band for this role, or a narrower hiring range published within that band, and is benchmarked against the external market. Exceptions above the standard range are managed through governance controls to protect internal equity. Your Impact Are you ready to support and enhance enterprise applications that underpin national security and critical services? At Leonardo UK, our Senior Application Engineers play a key role in maintaining and improving business-critical platforms - ensuring they are secure, scalable, and aligned with operational needs. You'll work collaboratively across engineering and service teams, contributing to technical delivery and continuous improvement. Your work at Leonardo UK will see you take the lead in solving customer problems in an agile, innovative and team-centric manner. The role may involve a blended hybrid working model, with a mixture of working from home and working on site at one of our Leonardo offices to ensure close collaboration with the wider team and with our customers. Leonardo UK is seeking a Senior Application Engineer to join the Cyber & Security Solutions Division team. This role is focused on delivering, maintaining, and improving platform and systems engineering solutions that underpin critical defence, government and public sector services. What you will do as a Senior Application Engineer Support, configure, and enhance security tooling platforms (e.g. SIEM, EDR) that underpin threat detection and response Deliver engineering tasks within defined work packages, ensuring alignment with user needs, security requirements, and service-level objectives. Contribute to application architecture, integration, and lifecycle activities under the guidance of senior engineers. Collaborate with stakeholders across engineering, service management, and business teams to resolve technical issues. Mentor junior engineers and specialists, supporting their development and promoting best practices. Participate in continuous improvement initiatives, including automation, documentation, and knowledge sharing. Ensure compliance with engineering governance, ITSM processes, and cyber security policies. What you'll bring Solid experience in supporting, configuring, and enhancing security tooling platforms (e.g. SIEM, EDR, or similar) Ability to solve moderately complex application-related issues and contribute to secure, scalable solutions. Understanding of application lifecycle management, integration patterns, and secure-by-design principles. Strong communication and collaboration skills across engineering and business teams. A proactive mindset with a passion for continuous improvement and knowledge sharing. Core areas (must have): Support, configuration, and enhancement of security tooling platforms (SIEM, EDR, vulnerability management) Log and event management including ingestion, parsing, and correlation of system and security logs Integration of security tooling with platform, network, and identity services Operational support and tuning of security tooling in live environments Application lifecycle management (deployment, maintenance, upgrades, decommissioning) Integration patterns and identity management (e.g. SSO, RBAC, API integration) Secure-by-design principles and application security practices Technical problem solving and resolution of application-related issues Collaboration with engineering, SOC, and service management teams Experience working within security and ITIL-aligned environments Delivery within secure / enterprise / defence environments Desirable: Experience with SIEM / EDR / vulnerability management tools (e.g. Splunk, Trellix, Tenable, or similar) SOAR platforms and automation of security response workflows Integration with monitoring, alerting, and incident response systems Threat detection, analytics, and use case development Experience integrating with enterprise services (Active Directory, identity platforms) Exposure to DevOps / CI-CD practices Experience working in secure or regulated environments Security Clearance This role is subject to pre-employment screening in line with the UK Government's Baseline Personnel Security Standard (BPSS). An additional range of Personnel Security Controls referred to as National Security Vetting (NSV) will apply. This role requires Developed Vetting (DV) clearance prior to starting. For more information and guidance please visit: Location This role will be based at one of our UK sites - Yeovil. Why join us At Leonardo, our people are at the heart of everything we do. We offer a comprehensive, company-funded benefits package that supports your wellbeing, career development, and work-life balance. Time to Recharge: Generous leave with the opportunity to accrue up to 12 additional flexi-days each year. Secure your Future: Award-winning pension scheme with up to 15% employer contribution. Your Wellbeing Matters: Free access to mental health support, financial advice, and employee-led networks. Never Stop Learning: Free access to 4,000+ online courses via Coursera and LinkedIn Learning. Tailored Perks: Spend up to £500 annually on flexible benefits such as private healthcare, lifestyle discounts, and gym memberships. Flexible Working: Flexible hours with hybrid working options. For a full list of our company benefits please visit our website. Leonardo is a global leader in Aerospace, Defence, and Security. Headquartered in Italy, we employ over 53,000 people worldwide including 8,500 across 9 sites in the UK. Our employees are not just part of a team-they are key contributors to shaping innovation, advancing technology, and enhancing global safety. At Leonardo we are committed to building an inclusive, accessible, and welcoming workplace. We believe that a diverse workforce sparks creativity, drives innovation, and leads to better outcomes for our people and our customers. If you have any accessibility requirements to support you during the recruitment process, just let us know. Be part of something bigger - apply now! Primary Location: GB - Yeovil - Lysander Rd Contract Type: Permanent Hybrid Working: Onsite
Aug 05, 2026
Full time
hackajob is collaborating with Leonardo to connect them with exceptional professionals for this role. Job Description: Salary Range: £44,171 - £61,950 Leonardo UK operates a grade-based salary framework with broad bands. The salary range shown reflects the approved grade band for this role, or a narrower hiring range published within that band, and is benchmarked against the external market. Exceptions above the standard range are managed through governance controls to protect internal equity. Your Impact Are you ready to support and enhance enterprise applications that underpin national security and critical services? At Leonardo UK, our Senior Application Engineers play a key role in maintaining and improving business-critical platforms - ensuring they are secure, scalable, and aligned with operational needs. You'll work collaboratively across engineering and service teams, contributing to technical delivery and continuous improvement. Your work at Leonardo UK will see you take the lead in solving customer problems in an agile, innovative and team-centric manner. The role may involve a blended hybrid working model, with a mixture of working from home and working on site at one of our Leonardo offices to ensure close collaboration with the wider team and with our customers. Leonardo UK is seeking a Senior Application Engineer to join the Cyber & Security Solutions Division team. This role is focused on delivering, maintaining, and improving platform and systems engineering solutions that underpin critical defence, government and public sector services. What you will do as a Senior Application Engineer Support, configure, and enhance security tooling platforms (e.g. SIEM, EDR) that underpin threat detection and response Deliver engineering tasks within defined work packages, ensuring alignment with user needs, security requirements, and service-level objectives. Contribute to application architecture, integration, and lifecycle activities under the guidance of senior engineers. Collaborate with stakeholders across engineering, service management, and business teams to resolve technical issues. Mentor junior engineers and specialists, supporting their development and promoting best practices. Participate in continuous improvement initiatives, including automation, documentation, and knowledge sharing. Ensure compliance with engineering governance, ITSM processes, and cyber security policies. What you'll bring Solid experience in supporting, configuring, and enhancing security tooling platforms (e.g. SIEM, EDR, or similar) Ability to solve moderately complex application-related issues and contribute to secure, scalable solutions. Understanding of application lifecycle management, integration patterns, and secure-by-design principles. Strong communication and collaboration skills across engineering and business teams. A proactive mindset with a passion for continuous improvement and knowledge sharing. Core areas (must have): Support, configuration, and enhancement of security tooling platforms (SIEM, EDR, vulnerability management) Log and event management including ingestion, parsing, and correlation of system and security logs Integration of security tooling with platform, network, and identity services Operational support and tuning of security tooling in live environments Application lifecycle management (deployment, maintenance, upgrades, decommissioning) Integration patterns and identity management (e.g. SSO, RBAC, API integration) Secure-by-design principles and application security practices Technical problem solving and resolution of application-related issues Collaboration with engineering, SOC, and service management teams Experience working within security and ITIL-aligned environments Delivery within secure / enterprise / defence environments Desirable: Experience with SIEM / EDR / vulnerability management tools (e.g. Splunk, Trellix, Tenable, or similar) SOAR platforms and automation of security response workflows Integration with monitoring, alerting, and incident response systems Threat detection, analytics, and use case development Experience integrating with enterprise services (Active Directory, identity platforms) Exposure to DevOps / CI-CD practices Experience working in secure or regulated environments Security Clearance This role is subject to pre-employment screening in line with the UK Government's Baseline Personnel Security Standard (BPSS). An additional range of Personnel Security Controls referred to as National Security Vetting (NSV) will apply. This role requires Developed Vetting (DV) clearance prior to starting. For more information and guidance please visit: Location This role will be based at one of our UK sites - Yeovil. Why join us At Leonardo, our people are at the heart of everything we do. We offer a comprehensive, company-funded benefits package that supports your wellbeing, career development, and work-life balance. Time to Recharge: Generous leave with the opportunity to accrue up to 12 additional flexi-days each year. Secure your Future: Award-winning pension scheme with up to 15% employer contribution. Your Wellbeing Matters: Free access to mental health support, financial advice, and employee-led networks. Never Stop Learning: Free access to 4,000+ online courses via Coursera and LinkedIn Learning. Tailored Perks: Spend up to £500 annually on flexible benefits such as private healthcare, lifestyle discounts, and gym memberships. Flexible Working: Flexible hours with hybrid working options. For a full list of our company benefits please visit our website. Leonardo is a global leader in Aerospace, Defence, and Security. Headquartered in Italy, we employ over 53,000 people worldwide including 8,500 across 9 sites in the UK. Our employees are not just part of a team-they are key contributors to shaping innovation, advancing technology, and enhancing global safety. At Leonardo we are committed to building an inclusive, accessible, and welcoming workplace. We believe that a diverse workforce sparks creativity, drives innovation, and leads to better outcomes for our people and our customers. If you have any accessibility requirements to support you during the recruitment process, just let us know. Be part of something bigger - apply now! Primary Location: GB - Yeovil - Lysander Rd Contract Type: Permanent Hybrid Working: Onsite
Bench Fitter required Undertake strip, clean and repair of fan/filter based units forming a section of a trains Fire Detection System Must be: Mechanically adept Electrically aware / competent Hands on Should be able to competently interpret basic wiring diagrams and unit schematics Time flexible Fit & Healthy Should be able to successfully complete and pass a basic medical plus drugs & alcohol test Start date 14/09/26 Description Rolling Stock, Maintenance Technician (Training Provided) Excellent Opportunity to Build a Career in Rolling Stock Maintenance Location: Crawley Pay Rate: T2A: 17.15 per hour (PAYE) days only Hours: 40 hours per week plus overtime opportunities Contract Duration: Ongoing assignment with a guaranteed minimum of 6 months. Expected duration is 18 to 24 months, with the opportunity to secure a permanent position, subject to performance. Start Date: 14 September 2026 About the Opportunity Looking to take your mechanical / dual skilled career to the next level? Shorterm Group, in partnership with Siemens Mobility, is offering an excellent opportunity for experienced mechanical / electrical professionals to transition into the rail industry through a structured training programme. Working on the Class 700 fleet, you'll receive comprehensive training to become a skilled Rolling Stock Maintenance Technician, joining one of the world's leading transportation companies in an exciting and growing industry. This role is ideal for candidates from backgrounds including: Light Vehicle Mechanics HGV/Heavy Vehicle Technicians Plant Maintenance Industrial or Manufacturing Maintenance Aviation Engineering Armed Forces (REME or other technical trades) Motor Mechanics The Role As a Maintenance Technician, you will be responsible for carrying out planned and corrective maintenance on passenger rolling stock plus components removed from the train to ensure the fleet remains safe, reliable and available for service. Working as part of a skilled engineering team, your responsibilities will include: Carrying out routine servicing and preventative maintenance Diagnosing and rectifying mechanical and electrical faults Completing repairs on carriage components and other mechanical assemblies Rectifying in-service defects efficiently and safely Recording all maintenance activities accurately using electronic maintenance systems Completing job cards, service sheets and maintenance documentation Liaising with the Parts Department to source replacement components Operating lifting equipment, powered plant and mechanical handling equipment safely Producing detailed fault-finding reports where required Identifying engineering improvements and feeding these back to the Engineering team Supporting continuous improvement initiatives across the depot Maintaining excellent housekeeping standards within the workshop Reporting process, tooling, or documentation issues to the Shift Manager Promoting a strong health and safety culture and complying with all company procedures and legislation What We're Looking For We're looking for mechanically minded individuals with a positive attitude, strong fault-finding skills and a willingness to learn. Desirable Experience Vehicle mechanical maintenance Industrial or manufacturing maintenance Heavy vehicle or plant maintenance Aviation engineering Armed Forces technical experience (particularly REME) Mechanical fault finding and repair Understanding of mechanical maintenance principles Experience using electronic maintenance or reporting systems Good awareness of Health & Safety practices Qualifications Essential/Mandatory NVQ Level 2 in a Technical discipline (or equivalent practical experience) Desirable At least 12 months' relevant mechanical or electrical maintenance experience Why Apply? Full Rolling Stock training provided Work for Siemens Mobility, a global leader in rail technology Excellent long-term contract with potential permanent opportunities Competitive PAYE rates Regular overtime available Career progression into the rail industry Gain specialist experience on the Class 700 fleet Recruitment Process Interviews and practical assessments will take place 13/08/26, with sessions commencing from 8:00am. Early applications are encouraged as assessment slots are limited. Apply Now For more information or to apply, please contact: Mark Smith Shorterm Group Email: (url removed) Phone: (phone number removed)
Aug 05, 2026
Contractor
Bench Fitter required Undertake strip, clean and repair of fan/filter based units forming a section of a trains Fire Detection System Must be: Mechanically adept Electrically aware / competent Hands on Should be able to competently interpret basic wiring diagrams and unit schematics Time flexible Fit & Healthy Should be able to successfully complete and pass a basic medical plus drugs & alcohol test Start date 14/09/26 Description Rolling Stock, Maintenance Technician (Training Provided) Excellent Opportunity to Build a Career in Rolling Stock Maintenance Location: Crawley Pay Rate: T2A: 17.15 per hour (PAYE) days only Hours: 40 hours per week plus overtime opportunities Contract Duration: Ongoing assignment with a guaranteed minimum of 6 months. Expected duration is 18 to 24 months, with the opportunity to secure a permanent position, subject to performance. Start Date: 14 September 2026 About the Opportunity Looking to take your mechanical / dual skilled career to the next level? Shorterm Group, in partnership with Siemens Mobility, is offering an excellent opportunity for experienced mechanical / electrical professionals to transition into the rail industry through a structured training programme. Working on the Class 700 fleet, you'll receive comprehensive training to become a skilled Rolling Stock Maintenance Technician, joining one of the world's leading transportation companies in an exciting and growing industry. This role is ideal for candidates from backgrounds including: Light Vehicle Mechanics HGV/Heavy Vehicle Technicians Plant Maintenance Industrial or Manufacturing Maintenance Aviation Engineering Armed Forces (REME or other technical trades) Motor Mechanics The Role As a Maintenance Technician, you will be responsible for carrying out planned and corrective maintenance on passenger rolling stock plus components removed from the train to ensure the fleet remains safe, reliable and available for service. Working as part of a skilled engineering team, your responsibilities will include: Carrying out routine servicing and preventative maintenance Diagnosing and rectifying mechanical and electrical faults Completing repairs on carriage components and other mechanical assemblies Rectifying in-service defects efficiently and safely Recording all maintenance activities accurately using electronic maintenance systems Completing job cards, service sheets and maintenance documentation Liaising with the Parts Department to source replacement components Operating lifting equipment, powered plant and mechanical handling equipment safely Producing detailed fault-finding reports where required Identifying engineering improvements and feeding these back to the Engineering team Supporting continuous improvement initiatives across the depot Maintaining excellent housekeeping standards within the workshop Reporting process, tooling, or documentation issues to the Shift Manager Promoting a strong health and safety culture and complying with all company procedures and legislation What We're Looking For We're looking for mechanically minded individuals with a positive attitude, strong fault-finding skills and a willingness to learn. Desirable Experience Vehicle mechanical maintenance Industrial or manufacturing maintenance Heavy vehicle or plant maintenance Aviation engineering Armed Forces technical experience (particularly REME) Mechanical fault finding and repair Understanding of mechanical maintenance principles Experience using electronic maintenance or reporting systems Good awareness of Health & Safety practices Qualifications Essential/Mandatory NVQ Level 2 in a Technical discipline (or equivalent practical experience) Desirable At least 12 months' relevant mechanical or electrical maintenance experience Why Apply? Full Rolling Stock training provided Work for Siemens Mobility, a global leader in rail technology Excellent long-term contract with potential permanent opportunities Competitive PAYE rates Regular overtime available Career progression into the rail industry Gain specialist experience on the Class 700 fleet Recruitment Process Interviews and practical assessments will take place 13/08/26, with sessions commencing from 8:00am. Early applications are encouraged as assessment slots are limited. Apply Now For more information or to apply, please contact: Mark Smith Shorterm Group Email: (url removed) Phone: (phone number removed)
Senior SOC Engineer - Hybrid Join a leading cyber security services organisation as a Senior SOC Engineer , taking ownership of the technology, automation, and engineering capabilities that support a modern Security Operations Centre (SOC). The Role You'll design, deploy, and enhance core SOC platforms including SIEM, XDR, SOAR, automation, and security tooling , driving improvements in threat detection, response, and operational efficiency. Working closely with operational teams, you'll support customer onboarding, develop automated workflows, and help shape the future direction of SOC engineering. Key Responsibilities Design, deploy and optimise SIEM, XDR and SOAR platforms. Build security automation, integrations, and response workflows. Develop log parsing, data normalisation and telemetry solutions. Lead technical onboarding and implementation projects. Act as an escalation point for complex security engineering issues. Mentor SOC analysts and engineers. Improve detection, response and operational processes through automation. Maintain engineering documentation, standards and best practices. Skills & Experience 3-5+ years' experience within a SOC or cyber security engineering environment. Strong experience with SIEM, SOAR and EDR/XDR technologies. Scripting and automation expertise (Python, Go, APIs). Experience with cloud platforms such as Azure, AWS or GCP. Knowledge of vulnerability management and threat intelligence integrations. Strong communication, analytical and problem-solving skills. Eligibility for UK security clearance desirable. What's on Offer 2 Days in the Office Per Month Exposure to a wide range of security environments and technologies. Opportunity to influence SOC strategy and engineering direction. Dedicated training, development, and lab environments. Competitive salary and comprehensive benefits package. Ideal for an experienced SOC Engineer looking to step into a senior, technically focused role with significant ownership, automation responsibilities, and career progression opportunities.
Aug 05, 2026
Full time
Senior SOC Engineer - Hybrid Join a leading cyber security services organisation as a Senior SOC Engineer , taking ownership of the technology, automation, and engineering capabilities that support a modern Security Operations Centre (SOC). The Role You'll design, deploy, and enhance core SOC platforms including SIEM, XDR, SOAR, automation, and security tooling , driving improvements in threat detection, response, and operational efficiency. Working closely with operational teams, you'll support customer onboarding, develop automated workflows, and help shape the future direction of SOC engineering. Key Responsibilities Design, deploy and optimise SIEM, XDR and SOAR platforms. Build security automation, integrations, and response workflows. Develop log parsing, data normalisation and telemetry solutions. Lead technical onboarding and implementation projects. Act as an escalation point for complex security engineering issues. Mentor SOC analysts and engineers. Improve detection, response and operational processes through automation. Maintain engineering documentation, standards and best practices. Skills & Experience 3-5+ years' experience within a SOC or cyber security engineering environment. Strong experience with SIEM, SOAR and EDR/XDR technologies. Scripting and automation expertise (Python, Go, APIs). Experience with cloud platforms such as Azure, AWS or GCP. Knowledge of vulnerability management and threat intelligence integrations. Strong communication, analytical and problem-solving skills. Eligibility for UK security clearance desirable. What's on Offer 2 Days in the Office Per Month Exposure to a wide range of security environments and technologies. Opportunity to influence SOC strategy and engineering direction. Dedicated training, development, and lab environments. Competitive salary and comprehensive benefits package. Ideal for an experienced SOC Engineer looking to step into a senior, technically focused role with significant ownership, automation responsibilities, and career progression opportunities.
The Role The Senior Security Engineer (Team Leader) is responsible for leading a dedicated security engineering team, combining hands-on platform engineering with technical leadership and people management. You will own security platform architecture, act as the primary escalation point for complex issues, and ensure platforms remain secure, resilient, and compliant within a regulated environment. Key Responsibilities Act as technical lead for security engineering and platform architecture Serve as primary escalation point for complex and major incidents Provide technical leadership and mentoring to engineers and analysts Line manage and develop the security engineering and analyst teams Own platform maintenance, configuration, and lifecycle management Ensure security platforms are integrated across hybrid environments Oversee patching, upgrades, and platform performance Drive platform improvements and engineering enhancements Support detection engineering, tuning, and platform optimisation Lead automation and SOAR initiatives to improve efficiency Collaborate with SOC providers on SIEM governance and data ingestion Ensure platforms meet regulatory and compliance requirements Maintain engineering documentation, standards, and governance Represent engineering in client governance and audit activities Coordinate cross-team resolution of complex technical issues Experience & Knowledge Essential: Significant experience in security engineering and platform management Strong leadership experience managing technical teams Deep knowledge of Microsoft Defender and SIEM platforms (e.g. Sentinel) Experience in hybrid cloud and on-prem environments Strong understanding of security architecture and frameworks Experience in regulated environments (e.g. financial services) Strong stakeholder and client engagement skills Experience with automation and scripting (PowerShell, Python, etc.) Desirable: Experience with vulnerability and exposure management tools Knowledge of security frameworks (NIST, ISO 27001, CIS) Relevant security certifications (e.g. CISSP, AZ-500, SC-100)
Aug 05, 2026
Full time
The Role The Senior Security Engineer (Team Leader) is responsible for leading a dedicated security engineering team, combining hands-on platform engineering with technical leadership and people management. You will own security platform architecture, act as the primary escalation point for complex issues, and ensure platforms remain secure, resilient, and compliant within a regulated environment. Key Responsibilities Act as technical lead for security engineering and platform architecture Serve as primary escalation point for complex and major incidents Provide technical leadership and mentoring to engineers and analysts Line manage and develop the security engineering and analyst teams Own platform maintenance, configuration, and lifecycle management Ensure security platforms are integrated across hybrid environments Oversee patching, upgrades, and platform performance Drive platform improvements and engineering enhancements Support detection engineering, tuning, and platform optimisation Lead automation and SOAR initiatives to improve efficiency Collaborate with SOC providers on SIEM governance and data ingestion Ensure platforms meet regulatory and compliance requirements Maintain engineering documentation, standards, and governance Represent engineering in client governance and audit activities Coordinate cross-team resolution of complex technical issues Experience & Knowledge Essential: Significant experience in security engineering and platform management Strong leadership experience managing technical teams Deep knowledge of Microsoft Defender and SIEM platforms (e.g. Sentinel) Experience in hybrid cloud and on-prem environments Strong understanding of security architecture and frameworks Experience in regulated environments (e.g. financial services) Strong stakeholder and client engagement skills Experience with automation and scripting (PowerShell, Python, etc.) Desirable: Experience with vulnerability and exposure management tools Knowledge of security frameworks (NIST, ISO 27001, CIS) Relevant security certifications (e.g. CISSP, AZ-500, SC-100)