Haystack
← Back to Jobs
Full time
Engineering
IR

SOC Engineer

IBEX RECRUITMENT LTDNorth West England, UK🇬🇧United KingdomPosted 14 Aug 2026

Why This Role Stands Out

This hybrid SOC Engineer role offers significant growth and development by focusing on building, tuning, and automating advanced security platforms like Microsoft Sentinel and Defender XDR. You'll thrive here if you possess strong engineering and scripting skills, enjoy problem-solving in a regulated environment, and are eager to contribute to a growing cybersecurity team. Apply today to engineer the future of cyber defense and gain invaluable experience.

Quick Overview

Work Type
Hybrid
Schedule
Full Time
Level
Mid Senior

Job Description

We recruiting for an exciting opportunity within a highly regulated environment. We're looking forSOC Engineers(both Junior and Senior levels) to join a growing Cyber Security team, engineering and optimising Microsoft Sentinel, Defender XDR, and SOAR capabilities.


This isn't a pure triage/analyst role we needengineerswho can build, tune, automate, and scale our detection platform.

What you'll be doing:

  • Engineering and maintainingMicrosoft Sentinel,Defender XDR, andLog Analyticsplatforms
  • Onboarding and normalising log sources across hybrid/cloud environments
  • Writing and tuningKQL detection rulesand analytics logic
  • BuildingSOAR playbooks(Logic Apps, automation workflows) to reduce manual effort
  • Managing telemetry ingestion, parsers, and data retention for cost optimisation
  • Producing platform health reports and identifying coverage gaps
  • Mentoring junior engineers and contributing to team development
  • Acting as technical SME during incidents


What we're looking for:

Deep experience withMicrosoft Sentinel,Defender suite, andKQL

Strong scripting/automation skills (PowerShell, Python, Logic Apps)

Solid understanding ofMITRE ATT&CK,NCSC CAF,NIST CSF

Stakeholder management able to translate technical complexity to non-technical audiences

Degree in Computer Science, Cyber Security, or equivalent

Desirable:SC-200 / AZ-500, ServiceNow SecOps, regulated sector experience (nuclear/defence/CNI).

What's in it for you:

  • 30 days annual leave (+ bank holidays)
  • Hybrid working - flexible on-site
  • Opportunity to shape SOC engineering strategy in a critical environment
  • Clear progression pathway (Junior ? Senior ? Lead)
  • Certifications and training budget (SC-200, AZ-500, etc.)
  • Work with cutting-edge Microsoft security tech

Skills

Stakeholder Management

Similar jobs