SOC Engineer
IBEX RECRUITMENT LTD
London
Location
London, England
We recruiting for an exciting opportunity within a highly regulated environment. We're looking for SOC Engineers (both Junior and Senior levels) to join a growing Cyber Security team, engineering and optimising Microsoft Sentinel, Defender XDR, and SOAR capabilities.
This isn't a pure triage/analyst role
we need engineers who can build, tune, automate, and scale our detection platform. What you'll be doing: Engineering and maintaining Microsoft Sentinel , Defender XDR , and Log Analytics platforms Onboarding and normalising log sources across hybrid/cloud environments Writing and tuning KQL detection rules and analytics logic Building SOAR playbooks (Logic Apps, automation workflows) to reduce manual effort Managing telemetry ingestion, parsers, and data retention for cost optimisation Producing platform health reports and identifying coverage gaps Mentoring junior engineers and contributing to team development Acting as technical SME during incidents
What we're looking for: Deep experience with Microsoft Sentinel , Defender suite , and KQL Strong scripting/automation skills ( PowerShell, Python, Logic Apps ) Solid understanding of MITRE ATT&CK , NCSC CAF , NIST CSF Stakeholder management
able to translate technical complexity to non-technical audiences Degree in Computer Science, Cyber Security, or equivalent Desirable: SC-200 / AZ-500, ServiceNow SecOps, regulated sector experience (nuclear/defence/CNI). What's in it for you: 30 days annual leave (+ bank holidays) Hybrid working - flexible on-site Opportunity to shape SOC engineering strategy in a critical environment Clear progression pathway (Junior ? Senior ? Lead) Certifications and training budget (SC-200, AZ-500, etc.) Work with cutting-edge Microsoft security tech
TPBN1_UKTJ
← Back to job search
This isn't a pure triage/analyst role
we need engineers who can build, tune, automate, and scale our detection platform. What you'll be doing: Engineering and maintaining Microsoft Sentinel , Defender XDR , and Log Analytics platforms Onboarding and normalising log sources across hybrid/cloud environments Writing and tuning KQL detection rules and analytics logic Building SOAR playbooks (Logic Apps, automation workflows) to reduce manual effort Managing telemetry ingestion, parsers, and data retention for cost optimisation Producing platform health reports and identifying coverage gaps Mentoring junior engineers and contributing to team development Acting as technical SME during incidents
What we're looking for: Deep experience with Microsoft Sentinel , Defender suite , and KQL Strong scripting/automation skills ( PowerShell, Python, Logic Apps ) Solid understanding of MITRE ATT&CK , NCSC CAF , NIST CSF Stakeholder management
able to translate technical complexity to non-technical audiences Degree in Computer Science, Cyber Security, or equivalent Desirable: SC-200 / AZ-500, ServiceNow SecOps, regulated sector experience (nuclear/defence/CNI). What's in it for you: 30 days annual leave (+ bank holidays) Hybrid working - flexible on-site Opportunity to shape SOC engineering strategy in a critical environment Clear progression pathway (Junior ? Senior ? Lead) Certifications and training budget (SC-200, AZ-500, etc.) Work with cutting-edge Microsoft security tech
TPBN1_UKTJ