Latest Threat Detection Jobs

Senior Security Operations Analyst

This role involves leading threat detection, incident response, and security monitoring at scale within a UK fintech. The analyst will develop and tune SIEM rules, conduct threat hunting, manage EDR systems, and contribute to security policies and controls. Collaboration with infrastructure, network, and DevOps teams is key to investigating and remediating security incidents.

Forward Role Leeds, United Kingdom £54,000 – £65,000 pa
Hybrid Permanent

Cyber Security & Infrastructure Engineer

This role involves hands-on management of cyber security and IT infrastructure across on-premises and cloud environments, with a focus on threat detection, incident response, and security hardening. The engineer will monitor alerts, conduct forensic investigations, secure Azure and Microsoft 365 environments, and ensure compliance with standards like ISO 27001 and NCSC guidance. A key aspect is leading during incidents and improving organisational resilience through proactive security measures.

Adria Solutions Newcastle upon Tyne, United Kingdom £40,000 – £50,000 pa

Cyber Security Engineer

This role involves hands-on security engineering within a mature cyber resilience function, focusing on Microsoft security stack (Defender, Sentinel, Entra ID), Azure cloud security, identity protection, and data controls via Purview. The engineer will enhance threat detection, support incident response, manage vulnerabilities, and ensure alignment with standards like NCSC CAF, ISO 27001, and NIST CSF, while acting as a security SME across technical and business teams.

Yolk Recruitment Cardiff, Cymru / Wales, CF10 2AF, United Kingdom £62,000 – £72,000 pa

Senior Incident Response Consultant, Rapid Response

Leads high-pressure incident response engagements for organizations affected by cyberattacks, directing forensic investigations and coordinating with customer teams. Produces detailed reports mapped to MITRE ATT&CK, focusing on ransomware and business email compromise (BEC) incidents. Operates in a rapid-response environment with a rotating weekend-heavy schedule to support global customers.

Sophos United Kingdom
Remote Permanent

Principal Microsoft Defender XDR, IRM & Deception Engineer

The Principal Microsoft Defender XDR, IRM & Deception Engineer, working within the Global Information and Cyber Security Defence (ICSD) function, is the technical leader for enterprise cyber deception and unified detection and response across the Microsoft security ecosystem. The role...

WTW London, United Kingdom

Cyber Security Lead

Role: Cyber Security Lead Location: NottinghamshireWorking Arrangement: 3 days a week in officeSalary: Up to £70kAre you an experienced SOC professional who's ready to take the next step into leadership without leaving the technical work behind?We're looking for a Cyber...

Rebel Recruitment Nottingham, Nottinghamshire, United Kingdom £65,000 – £70,000 pa
CrowdStrike logo

Manager, Corporate Sales Engineering

Lead and develop a high-performing Corporate Sales Engineering team, driving technical excellence and strategic pre-sales support for enterprise cybersecurity solutions. Guide complex sales cycles, PoV engagements, and technical training while fostering innovation and collaboration. Work closely with sales, marketing, and partners to scale technical sales impact and deliver customer success in a fast-paced AI-native security environment.

CrowdStrike Reading, United Kingdom
CrowdStrike logo

Sr. Manager, Data Science , GBR)

Lead a team of data scientists focused on applying machine learning and large language models to cybersecurity challenges, including malware detection, behavioral threat analysis, and AI-driven security automation. Translate business needs into technical research objectives, guide production ML system development, and collaborate with security researchers and engineers. Work at the intersection of reverse engineering, AI, and large-scale data systems processing trillions of events daily.

CrowdStrike United Kingdom
Remote

Tier 2 SOC Analyst

This role involves investigating and analysing escalated security alerts and complex incidents within a fast-paced Security Operations Centre. The analyst will conduct in-depth incident investigations, perform threat hunting, tune detection rules, and support incident response across diverse client environments. Collaboration with Tier 1 and Tier 3 teams is key, along with maintaining awareness of evolving threats and improving SOC processes.

Oscar Technology London, United Kingdom £40,000 – £50,000 pa
Hybrid Permanent Clearance Required
Darktrace logo

Senior Technical Success Manager - Enterprise Accounts

A Senior Technical Success Manager partners with enterprise customers to drive adoption of Darktrace’s AI-driven cybersecurity platform, embedding it into daily security operations. The role involves identifying technical use cases, reducing risk, accelerating time-to-value, and ensuring long-term customer health. It requires deep technical understanding of cybersecurity, strong stakeholder engagement, and collaboration across internal teams to support renewals and expansion.

Darktrace France
On-site Permanent
Darktrace logo

Technical Success Manager - Enterprise Accounts

The role involves building trusted relationships with enterprise security and IT teams to drive technical adoption of Darktrace’s AI-driven cybersecurity platform. You'll create success plans, identify high-value use cases, and guide customers from deployment to active use, ensuring measurable risk reduction and operational integration. The position acts as a technical advisor, bridging customer needs with internal teams to improve health, retention, and expansion opportunities.

Darktrace London, UB8 1LQ, United Kingdom
Hybrid Permanent

Wiz Security Engineer

This role involves hands-on cloud security engineering with a focus on threat modeling, vulnerability management, and security automation. The engineer will integrate Wiz and Tenable with ServiceNow, harden cloud-native environments (especially Kubernetes), and embed security into CI/CD pipelines. The position supports cloud infrastructure across AWS, Azure, or GCP with regular on-site presence in central London.

VIQU IT South Kensington, London, SW7 4SD, United Kingdom £450 – £550 pd

Senior Security Engineering Consultant

Our client, a leader in the cyber security sector, is currently seeking a Senior Security Engineering Consultant to join their team. This permanent role is a hands-on technical position within the Security Operations domain, focused on helping customers improve and...

Infosec Basingstoke, Hampshire, United Kingdom £70,000 – £80,000 pa

SOC Analyst (Tier 1)

Monitor and triage security alerts using Microsoft Defender and Sentinel in a 24/7 Security Operations Centre. Conduct incident investigation and support response activities within a collaborative team environment. Contribute to improving detection capabilities and SOC processes in a hybrid-working setup with rotating 12-hour shifts.

VIQU IT New Edlington, South Yorkshire, DN12 1DZ, United Kingdom £25,000 – £30,000 pa

Cyber Security Operations Manager

Lead and develop a security operations team while managing the full incident lifecycle from detection to resolution. Design and improve security monitoring strategies using SIEM, EDR, and SOAR tools, and integrate threat intelligence to enhance defensive capabilities. Work closely with MSSPs and internal stakeholders to strengthen the organisation's security posture through continuous improvement and strategic planning.

Tatton Recruitment Pinhoe, Devon, EX4 9EY, United Kingdom £800 pd