Security Operations Engineer

Required IT
Br11Aa, United Kingdom
Today
£55,000 – £60,000 pa

Salary

£55,000 – £60,000 pa

Posted
5 Oct 2026 (Today)
Security Operations Engineer

Working pattern: Monday–Friday, 40 hours per week

Working hours: Flexible start between 7:30am and 9:30am

Hybrid working: 2 day per week from home after successful completion of training

We’re looking for aSecurity Operations Engineer to join our cyber security team and play a key role in protecting our organisation from an ever-changing threat landscape.

This is a genuinelyhands-on operational security role, ideal for someone who enjoys investigating incidents, getting to the root cause of security events, working across a range of security technologies, and making a tangible difference to an organisation’s cyber resilience.

You’ll sit at the heart of our cyber defence operations, working with technologies includingMicrosoft Defender, Microsoft Entra ID, Intune, Rapid7 SIEM and Sophos Antivirus. From investigating suspicious activity and responding to security incidents through to improving detection capabilities and strengthening our security controls, you’ll have real responsibility and the opportunity to see the impact of your work.

AtForesters, we’re proud to offer a supportive and collaborative environment where you’ll have ongoing opportunities to develop your technical skills, broaden your experience and grow your career in cyber security.

What you’ll be doingSecurity Monitoring & Incident Response
  • Monitor security alerts and telemetry across endpoints, identities, email and cloud services usingRapid7 SIEM, Microsoft Defender and Sophos.
  • Investigate and respond to suspected cyber attacks, including malware infections, phishing campaigns, identity compromise and unauthorised access attempts.
  • Perform security incident triage, root cause analysis, containment and remediation.
  • Lead or support incident response activities in line with established policies and procedures.
  • Escalate significant incidents appropriately and provide clear, timely updates to relevant stakeholders.
Threat Detection & Prevention
  • Identify emerging threats, vulnerabilities and attack patterns that could impact the organisation.
  • Tune and optimise security tools to improve detection accuracy and reduce false positives.
  • Implement, manage and maintain endpoint protection and security policies.
  • Support vulnerability management activities, including remediation planning, prioritisation and risk tracking.
  • Help identify opportunities to strengthen our preventative and detective security controls.
Security Operations & Continuous Improvement
  • Maintain and enhance security monitoring rules, alerts and dashboards.
  • Develop and maintain security runbooks and incident response playbooks.
  • Support security audits, compliance activities and risk assessments.
  • Identify opportunities to improve security processes, tooling and operational efficiency.
  • Contribute to the continued development of our overall cyber security maturity.
Collaboration & Communication
  • Work closely with IT, infrastructure and service desk teams to investigate and resolve security-related issues.
  • Produce clear and structured technical and non-technical incident reports.
  • Identify trends in phishing and risky user behaviour and support security awareness initiatives.
  • Contribute to security projects and the implementation of new technologies and controls.
  • Communicate complex security issues clearly to both technical and non-technical audiences.
What we’re looking for

We’re looking for someone with practical security operations experience who is comfortable investigating incidents, analysing evidence and taking action.

You’ll ideally have:

  • Experience working as aCyber Security Engineer, SOC Analyst, Security Operations Engineer or in a similar security-focused role.
  • Hands-on experience withMicrosoft Defender, particularly Endpoint and/or Microsoft 365 security.
  • Experience usingRapid7 SIEM or another SIEM platform for security monitoring, alerting and investigations.
  • Experience managing or supportingSophos Antivirus or another endpoint protection platform.
  • A strong understanding of common cyber threats, attack techniques and incident response processes.
  • The ability to analyse logs, alerts and endpoint activity to establish scope, impact and root cause.
  • Good working knowledge ofWindows environments and fundamental networking concepts.
  • Strong documentation, reporting and communication skills.
  • Practical experience with security and vulnerability assessment tools such asIDS/IPS, Metasploit, Nexpose, Nmap, Nessus, Wireshark, L0phtCrack, John the Ripper or similar technologies.
  • Familiarity with recognised security frameworks such asISO 27001 and theNIST Cybersecurity Framework.

Related Jobs

View all jobs

Senior Security Operations Engineer

Risk Ledger London, United Kingdom
£90,000 – £100,000 pa

Cloud Security Operations Engineer

MJA (London) Ltd London, United Kingdom
On-site

3rd Line Security Analyst - Reading Sentinel Defender XDR CrowdStrike

Global Technology Solutions Ltd Rg15Bs, United Kingdom
£50,000 – £60,000 pa Hybrid

Senior Security Engineering Consultant

Infosec Basingstoke, Hampshire, United Kingdom
£70,000 – £80,000 pa

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.