Quick Overview
Job Description
Cyber Security Operations Specialist We are looking for an experienced Cyber Security Operations Specialist to join a growing security team responsible for protecting a complex IT, cloud and operational technology environment. You will play a key role in detecting, investigating and responding to cyber threats, while helping to improve the organisation's overall security monitoring and incident response capabilities. The role combines hands-on security operations, tooling optimisation and continuous improvement across a varied technology estate.
Key responsibilities:
Monitor, triage and investigate security alerts and incidents across IT, cloud and OT environments.<br />Lead or support incident response, including containment, eradication, recovery and escalation.<br />Develop and optimise SIEM detection rules, EDR policies and security monitoring capabilities.<br />Reduce false positives and improve detection coverage using threat intelligence and incident learnings.<br />Investigate threats using frameworks such as MITRE ATT&CK.<br />Work closely with internal IT, engineering and security teams, alongside external security providers.<br />Maintain and improve security playbooks, procedures, documentation and response processes.<br />Support security reporting, compliance and audit activity.<br />Provide technical guidance and support to junior members of the security team.<br />Key skills and experience: Strong background in Security Operations, SOC or Incident Response.<br />Hands-on experience with SIEM and EDR platforms, ideally including Microsoft security technologies.<br />Experience investigating security incidents across cloud and on-premise environments.<br />Knowledge of Windows environments, with working knowledge of Linux/Unix.<br />Understanding of threat intelligence, IOCs, TTPs and the MITRE ATT&CK framework.<br />Experience improving detection logic, alert quality and security controls.<br />Strong stakeholder communication and incident management skills.<br />Knowledge of frameworks such as ISO 27001, NIS and GDPR would be beneficial.<br />Desirable certifications include: SC-200, SC-300, SC-400, MS-500, Security+ or similar cyber security qualifications. The role will involve participation in an out-of-hours incident response rota, with occasional travel where required
Similar jobs
- PP
Senior IT Security Analyst
Prime Personnel UK
Westminster, South West London🇬🇧Hybrid4 weeks agoAzureZero TrustTechnology - HT
Cyber Resilience Specialist
NewHays Technology
London🇬🇧Remote27 minutes agoStakeholder ManagementTechnology - RT
Fire & Security Engineer
NewRise Technical Recruitment
Newcastle Upon Tyne, Tyne And Wear🇬🇧Remote27 minutes agoTechnology - RT
Fire & Security Engineer
NewRise Technical Recruitment
Stoke-on-trent, Staffordshire🇬🇧Remote27 minutes agoTechnology - VI
Senior Information Security Analyst
NewVIQU IT
Southampton, Hampshire🇬🇧Hybrid27 minutes agoStakeholder ManagementTechnology - HA
Corporate Security Engineering - Engineer Role
NewHackajob Ltd
Manchester🇬🇧Hybrid29 minutes agoAdministrative