Quick Overview
Job Description
We are looking for an experienced Cyber Security Operations Specialist to join a growing security team responsible for protecting a complex IT, cloud and operational technology environment.
You will play a key role in detecting, investigating and responding to cyber threats, while helping to improve the organisation's overall security monitoring and incident response capabilities. The role combines hands-on security operations, tooling optimisation and continuous improvement across a varied technology estate.
Key responsibilities:
- Monitor, triage and investigate security alerts and incidents across IT, cloud and OT environments.
- Lead or support incident response, including containment, eradication, recovery and escalation.
- Develop and optimise SIEM detection rules, EDR policies and security monitoring capabilities.
- Reduce false positives and improve detection coverage using threat intelligence and incident learnings.
- Investigate threats using frameworks such as MITRE ATT&CK.
- Work closely with internal IT, engineering and security teams, alongside external security providers.
- Maintain and improve security playbooks, procedures, documentation and response processes.
- Support security reporting, compliance and audit activity.
- Provide technical guidance and support to junior members of the security team.
Key skills and experience:
- Strong background in Security Operations, SOC or Incident Response.
- Hands-on experience with SIEM and EDR platforms, ideally including Microsoft security technologies.
- Experience investigating security incidents across cloud and on-premise environments.
- Knowledge of Windows environments, with working knowledge of Linux/Unix.
- Understanding of threat intelligence, IOCs, TTPs and the MITRE ATT&CK framework.
- Experience improving detection logic, alert quality and security controls.
- Strong stakeholder communication and incident management skills.
- Knowledge of frameworks such as ISO 27001, NIS and GDPR would be beneficial.
Desirable certifications include: SC-200, SC-300, SC-400, MS-500, Security+ or similar cyber security qualifications.
The role will involve participation in an out-of-hours incident response rota, with occasional travel where required.
Similar jobs
- GR
Fire & Security Engineer, Hertfordshire
Grassroots Recruitment Limited
Stevenage, Hertfordshire🇬🇧£20 - £24/hrHybrid2 weeks agoTechnology - GR
Multi-Skilled Fire & Security Engineer, Woking
Grassroots Recruitment Limited
Woking, Surrey🇬🇧£21 - £24/hrHybrid2 weeks agoTechnology - EJ
Cyber Security Consultant
Eden James Consulting Limited
London🇬🇧€1k/moHybrid2 weeks agoTechnology - GR
Fire & Security Engineer, Essex
Grassroots Recruitment Limited
Brentwood, Essex🇬🇧£21 - £24/hrHybrid3 weeks agoTechnology - AG
Security Systems Technical Engineer
ADI Group Services Ltd
Olney, Buckinghamshire🇬🇧On-site3 weeks agoGenesysTechnical Support - FA
Electronic Security Project Engineer
Fire and Security Careers
Sheffield, South Yorkshire🇬🇧Hybrid3 months ago