Latest Threat Detection Jobs

Pfizer logo

Lead Threat Response Operations Analyst

Leads complex cyber threat investigations and incident response activities across global environments, analyzing telemetry from endpoints, network, cloud, and identity systems to identify and neutralize sophisticated threats. Provides technical leadership in threat response, coordinates cross-functional teams during incidents, and drives improvements in detection, containment, and remediation processes. Focuses on adversary tradecraft analysis, attack lifecycle reconstruction, and strategic recommendations to enhance organizational cyber resilience.

Pfizer Sandwich, Kent, United Kingdom

Director, R&D, Email & Collaboration Threat Protection

Lead a multi-squad engineering organisation responsible for Mimecast’s mission-critical Mail Transfer Agent, processing over 1.7 billion emails daily. Drive technical strategy, engineering excellence, and AI-augmented development across a globally distributed platform. Foster leadership, organisational health, and high-performance culture within Email & Collaboration Security.

Mimecast London, United Kingdom £124,000 – £186,000 pa

SOC Lead

We are seeking an experienced Lead SOC Analyst to oversee Security Operations Centre (SOC) activities, lead incident response efforts, and mentor a team of analysts. The successful candidate will have strong expertise in cyber threat detection, incident investigation, and theSplunk...

NCC Group Remote, United Kingdom
Hybrid

Senior SOC Engineer

The Senior SOC Engineer will deploy, configure, and maintain the QRadar SIEM platform, develop and optimise analytical rules, and create incident response playbooks. They will also monitor security alerts, conduct investigations, and lead threat modelling exercises to enhance detection and response capabilities.

eFinancialCareers Glasgow, Alba / Scotland, G2 1AL, United Kingdom £60,000 pa

Cyber Security Engineer / SOC Analyst

This role involves maintaining and optimising cybersecurity toolsets within a Defence organisation's Security Operations Centre. The engineer will lead on SIEM, threat detection, and network visibility, performing playbook scripting, tool integration, and backend refresh activities. The position requires deep technical expertise in security infrastructure, automation, and incident investigation across hybrid environments.

Tatton Recruitment Stevenage, Hertfordshire, United Kingdom £92 ph
On-site Contract Clearance Required

Cloud Security Engineer

This role involves operating and optimising cloud security across AWS and cloud-native environments using Palo Alto's Cortex and Prisma platforms. You'll develop threat detection rules, support incident response, and enhance Zero Trust and container security controls. The position is fully remote, working within a collaborative security team on a 12-month contract.

Hays Technology London, United Kingdom £450 – £550 pd

Cyber Security & Infrastructure Engineer

This role involves protecting systems, networks, and data by monitoring security alerts, leading incident response, and improving security posture across on-premises and cloud environments. The engineer will implement and maintain Azure, Microsoft 365, and Intune security, conduct vulnerability management, and ensure compliance with standards like ISO 27001 and NCSC. A key focus is threat detection, forensic investigation, and enhancing infrastructure resilience within a small, technical IT team.

Adria Solutions East Howdon, Tyne & Wear, United Kingdom £40,000 – £50,000 pa

SOC Analyst - Active SC required

Monitor and respond to security incidents using IBM QRadar SIEM, conducting threat detection, log analysis, and incident investigation across enterprise systems. Support a defence/aerospace client with robust security controls and detailed post-incident reporting. Engage in proactive threat hunting and handle diverse cyber threats including phishing and malware.

Matchtech Harlow, Essex, United Kingdom
Hybrid Contract Clearance Required

Compliance Enablement Technical Program Manager

This role involves leading the technical compliance automation function for Sophos' Trust and Assurance team, focusing on ensuring controls in the GRC platform are accurate, continuously monitored, and aligned with cybersecurity frameworks. The candidate will work cross-functionally with engineering teams to integrate compliance into development workflows and reduce audit burden through automation. A strong blend of technical depth, program management, and AI-assisted compliance operations is central to the position.

Sophos Canada CA$109,000 – CA$181,000 pa
Remote

Senior Incident Response Consultant, Rapid Response

Leads high-pressure incident response engagements for organizations affected by cyberattacks, directing forensic investigations and coordinating with customer teams. Produces detailed reports mapped to MITRE ATT&CK, focusing on ransomware and business email compromise (BEC) incidents. Operates in a rapid-response environment with a rotating weekend-heavy schedule to support global customers.

Sophos United Kingdom
Remote Permanent

Principal Microsoft Defender XDR, IRM & Deception Engineer

The Principal Microsoft Defender XDR, IRM & Deception Engineer, working within the Global Information and Cyber Security Defence (ICSD) function, is the technical leader for enterprise cyber deception and unified detection and response across the Microsoft security ecosystem. The role...

WTW London, United Kingdom

Elastic SME

As an Elastic SME, you will lead the design, implementation, and evolution of a sophisticated on-premises Elastic Stack environment. Responsibilities include architecting scalable solutions, building high-volume Elasticsearch clusters, delivering SIEM capabilities, and providing expert 3rd/4th line support.

Sopra Steria Hemel Hempstead, HP1 1EW, United Kingdom £85,000 – £90,000 pa

SecOps Engineer

SecOps Engineer - Central London (hyrbid working)Up to £75,000 PAWell-established and highly profitable construction engineering business is seeking an experienced SecOps Engineer to join them on a permanent basis. This is a critical leadership role within an organisation undergoing significant...

Context Recruitment London, United Kingdom

Senior Cyber Security Analyst

The Senior Cyber Security Analyst will work on high-profile client engagements, focusing on threat detection, monitoring, incident response, and security operations. Key responsibilities include developing and maintaining security detection content, triaging alerts, and mentoring junior analysts.

eFinancialCareers London, United Kingdom
Experis logo

Network Security Engineer

This role involves designing, implementing, and securing enterprise network services with a focus on Zero Trust and browser-based security solutions. The engineer will automate security operations, enforce secure access policies, and support cloud and hybrid environments. Key responsibilities include firewall rule optimisation, incident response, and integration with identity and security platforms.

Experis Knutsford, Cheshire, United Kingdom £450 – £490 pd
Hybrid Contract Clearance Required