We are looking for an experienced Cyber Security Operations Specialist to join a growing security team responsible for protecting a complex IT, cloud and operational technology environment. You will play a key role in detecting, investigating and responding to cyber threats, while helping to improve the organisation's overall security monitoring and incident response capabilities. The role combines hands-on security operations, tooling optimisation and continuous improvement across a varied technology estate. Key responsibilities:
Monitor, triage and investigate security alerts and incidents across IT, cloud and OT environments. Lead or support incident response, including containment, eradication, recovery and escalation. Develop and optimise SIEM detection rules, EDR policies and security monitoring capabilities. Reduce false positives and improve detection coverage using threat intelligence and incident learnings. Investigate threats using frameworks such as MITRE ATT&CK. Work closely with internal IT, engineering and security teams, alongside external security providers. Maintain and improve security playbooks, procedures, documentation and response processes. Support security reporting, compliance and audit activity. Provide technical guidance and support to junior members of the security team. Key skills and experience:
Strong background in Security Operations, SOC or Incident Response. Hands-on experience with SIEM and EDR platforms, ideally including Microsoft security technologies. Experience investigating security incidents across cloud and on-premise environments. Knowledge of Windows environments, with working knowledge of Linux/Unix. Understanding of threat intelligence, IOCs, TTPs and the MITRE ATT&CK framework. Experience improving detection logic, alert quality and security controls. Strong stakeholder communication and incident management skills. Knowledge of frameworks such as ISO 27001, NIS and GDPR would be beneficial. Desirable certifications include: SC-200, SC-300, SC-400, MS-500, Security+ or similar cyber security qualifications. The role will involve participation in an out-of-hours incident response rota, with occasional travel where required Only candidates based in UK and eligible to work in UK are allowed
All Job Ads are subject to GrabJobs’s Terms of Service. We allow users to flag postings that may be in violation of those terms. Job Ads may also be flagged by GrabJobs moderation team. However, no moderation system is perfect, and flagging a posting does not ensure that it will be removed.
Be the first to receive the latest Others Full-Time Jobs in the UK.
Setup your job alert:
By activating job alerts, I agree to GrabJobs Terms & Privacy Policy. I can unsubscribe to job alerts anytime.
Skip
GrabJobs is the no1 job portal in the UK, connecting you to thousands of jobs fast!
Find the best jobs in the UK, apply in 1 click and get a job today!