SOC Engineer
Job Description
We recruiting for an exciting opportunity within a highly regulated environment. We're looking forSOC Engineers(both Junior and Senior levels) to join a growing Cyber Security team, engineering and optimising Microsoft Sentinel, Defender XDR, and SOAR capabilities.
\nThis isn't a pure triage/analyst role we needengineerswho can build, tune, automate, and scale our detection platform.
\nWhat you'll be doing:
\n- \n
- Engineering and maintainingMicrosoft Sentinel,Defender XDR, andLog Analyticsplatforms \n
- Onboarding and normalising log sources across hybrid/cloud environments \n
- Writing and tuningKQL detection rulesand analytics logic \n
- BuildingSOAR playbooks(Logic Apps, automation workflows) to reduce manual effort \n
- Managing telemetry ingestion, parsers, and data retention for cost optimisation \n
- Producing platform health reports and identifying coverage gaps \n
- Mentoring junior engineers and contributing to team development \n
- Acting as technical SME during incidents \n
What we're looking for:
\nDeep experience withMicrosoft Sentinel,Defender suite, andKQL
\nStrong scripting/automation skills (PowerShell, Python, Logic Apps)
\nSolid understanding ofMITRE ATT&CK,NCSC CAF,NIST CSF
\nStakeholder management able to translate technical complexity to non-technical audiences
\nDegree in Computer Science, Cyber Security, or equivalent
\nDesirable:SC-200 / AZ-500, ServiceNow SecOps, regulated sector experience (nuclear/defence/CNI).
\nWhat's in it for you:
\n- \n
- 30 days annual leave (+ bank holidays) \n
- Hybrid working - flexible on-site \n
- Opportunity to shape SOC engineering strategy in a critical environment \n
- Clear progression pathway (Junior ? Senior ? Lead) \n
- Certifications and training budget (SC-200, AZ-500, etc.) \n
- Work with cutting-edge Microsoft security tech \n
\n
JBRP1_UKTJ
