Cyber Security Operations Specialist
Summary
Monitor and respond to security incidents using SIEM/EDR tools, investigate threats across cloud and on-prem environments, and improve detection logic in a Windows/Linux environment.
Salary: £? - ? per year
Requirements:- Strong background in Security Operations, SOC, or Incident Response.
- Hands-on experience with SIEM and EDR platforms, ideally including Microsoft security technologies.
- Experience investigating security incidents across cloud and on-premise environments.
- Knowledge of Windows environments, with working knowledge of Linux/Unix.
- Understanding of threat intelligence, IOCs, TTPs, and the MITRE ATT&CK framework.
- Experience improving detection logic, alert quality, and security controls.
- Strong stakeholder communication and incident management skills.
- Knowledge of frameworks such as ISO 27001, NIS, and GDPR would be beneficial.
- Desirable certifications include SC-200, SC-300, SC-400, MS-500, Security+, or similar cyber security qualifications.
- Participation in an out-of-hours incident response rota.
- Occasional travel where required.
- Monitor, triage, and investigate security alerts and incidents across IT, cloud, and OT environments.
- Lead or support incident response, including containment, eradication, recovery, and escalation.
- Develop and optimise SIEM detection rules, EDR policies, and security monitoring capabilities.
- Reduce false positives and improve detection coverage using threat intelligence and incident learnings.
- Investigate threats using frameworks such as MITRE ATT&CK.
- Work closely with internal IT, engineering, and security teams, alongside external security providers.
- Maintain and improve security playbooks, procedures, documentation, and response processes.
- Support security reporting, compliance, and audit activity.
- Provide technical guidance and support to junior members of the security team.
- Cloud
- Incident Management
- Support
- Linux
- Security
- Unix
- Windows
More:
We are a growing security team protecting a complex IT, cloud, and operational technology environment. This role combines hands-on security operations, tooling optimisation, and continuous improvement across a varied technology estate. We offer the opportunity to play a key role in detecting, investigating, and responding to cyber threats while helping strengthen our overall security monitoring and incident response capabilities.
last updated 34 week of 2026