SOC Engineer – Cyber Security Operations Centre
Proactive Appointments · Milton Keynes
Job description
About the role
We are looking for a hands‑on SOC Engineer to join our growing Cyber Security Operations Centre, supporting a diverse portfolio of customers across multiple sectors. The role focuses on building, maintaining and optimising the tools, telemetry, detections and automation that enable SOC analysts to identify and respond to threats effectively.
Key responsibilities
- Administer and optimise Microsoft Sentinel (or equivalent SIEM), including log ingestion, parsing, normalisation, and retention.
- Develop and maintain SOAR workflows and automation using Azure Logic Apps, Python, PowerShell, Bash, and KQL.
- Onboard and manage security telemetry from a range of data sources.
- Design, implement, and tune detection rules to improve alert quality and reduce false positives.
- Conduct proactive threat hunting using SIEM, EDR, and threat intelligence sources.
- Support incident investigations, containment, and response activities.
- Monitor and maintain the health of SOC tooling, sensors, agents, and log pipelines.
- Produce documentation, runbooks, and operational procedures.
Required profile
- Experience engineering and supporting SIEM platforms, ideally Microsoft Sentinel.
- Strong scripting and automation skills (Python, PowerShell, Bash, KQL).
- Experience with SOAR technologies and security automation.
- Knowledge of detection engineering and threat hunting.
- Strong understanding of Windows and Linux logging.
- Good networking knowledge including TCP/IP, DNS, firewalls, and proxies.
- Experience within a SOC, NOC, or 24/7 operational environment.
- Familiarity with MITRE ATT&CK, CVEs, and vulnerability management.
- Exposure to cloud security monitoring across Azure, AWS, or Microsoft 365.
- Desirable certifications: Microsoft SC‑200, CompTIA Security+ / CySA+, ISC2 CC or CISSP, GIAC GCIA, CEH, Cisco CyberOps or Fortinet certifications.
Required skills
- Microsoft Sentinel
- SIEM
- Azure Logic Apps
- Python
- PowerShell
- Bash
- KQL
- SOAR
- EDR
- Threat intelligence
- Windows logging
- Linux logging
- TCP/IP
- DNS
- Firewalls
- Proxies
- MITRE ATT&CK
- CVE analysis
- Vulnerability management
- Azure
- AWS
- Microsoft 365
What we offer
- Opportunity to work within a mature and growing SOC environment.
- Exposure to a wide range of customer environments and technologies.
- Security clearance sponsorship available for eligible candidates.
- Clear opportunities to contribute to automation, detection engineering, and SOC improvement initiatives.
- Hybrid working model.
- Competitive salary £55,000 plus bonus.
- Shift rota including evenings, weekends, bank holidays with on‑call support.
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in the United Kingdom.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 1 month ago
Expires 1 day from now
17 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
Proactive Appointments
Milton Keynes
Related job offers
-
Incident and Crisis Support – S2 (Milton Keynes)
Santander Milton Keynes -
Senior AWS Cloud Engineer – Data & AI Platform
Santander Milton Keynes -
Contract Data Platform Engineer
Connells Group HQ Milton Keynes -
Software Test Engineer
philips Cambridge (US) -
Co-op Software Engineering (APM) – Cambridge, MA (Jan‑Aug 2027)
philips Cambridge (US)