SOC Operations Engineer – EDR & NDR Platforms
Listed on 2026-01-02
-
IT/Tech
Cybersecurity, Systems Engineer
Beazley Security is a global cybersecurity firm committed to helping clients enable advanced cyber defenses that reduce risk with quantifiable results. We’re comprised of top talent from private industry, government, intelligence, and law enforcement who are specialists in threat detection, incident response, digital forensics, offensive security, risk management, and cyber resilience. As a subsidiary of specialty insurance giant, Beazley, we’ve been at the forefront of cyber insurance management and breach response activities for business clients in the US, UK, and Europe since 2017.
As Beazley Security, the company will have an expanded scope, leveraging nearly two decades of cyber incident experience, a strong services division, and a business strategy focused on growth, to realise our goals and deliver benefits to clients.
As a company, we are committed to upholding our core values of Belonging, Integrity, Service, Accountability, and Curiosity. We believe these values are essential to creating a strong and inclusive workplace culture, as well as to deliver world-class cybersecurity solutions to our clients worldwide. As Beazley Security, these values will continue to thrive, with an extra emphasis on expansion of our capabilities and capacity in helping solve unique client challenges.
SummaryThe SOC Operations Engineer is responsible for the operational management, optimisation, and lifecycle maintenance of Beazley Group’s core Endpoint Detection and Response (EDR) and Network Detection and Response (NDR) platforms. Working within the IT Security function and in close collaboration with the Beazley Security MDR SOC, this role ensures this detection technologies remain effective, resilient, and optimally tuned to support rapid threat detection and response.
The position bridges engineering with supporting day to day SOC operations. The individual in this role will be responsible for owning the platforms, coordinating upgrades and enhancements, improving alert fidelity, and assisting the SOC teams with advanced investigations, containment support, and continuous improvement.
- Act as the technical owner for SOC systems and operations, ensuring full operational coverage and integration across the enterprise estate.
- Maintain the physical and virtual infrastructure (appliances, sensors, collectors), planning upgrades, hardware refreshes, and configuration changes as required.
- Oversee policy, sensor deployment, and version control across all EDR / NDR agents and connectors.
- Validate data flow and health between endpoints, appliances, and the central XDR platform leveraged by the SOC.
- Coordinate with the SOC, vendors, and IT infrastructure teams to schedule upgrades, patching, and feature enablement.
- Tune detection logic, behavioural models, and response policies to reduce false positives and improve threat visibility.
- Implement target NDR model optimisation, device tagging, and subnet labelling enhancements to support faster investigations.
- Maintain EDR platform configuration baselines and analytics dashboards.
- Support integration and data quality within the Beazley Security XDR platform to ensure reliable event correlation.
- Document all configuration changes, tuning decisions, and engineering work in line with IT Security change management processes.
- Collaborate closely with the Beazley Security SOC, ensuring they have the right visibility, alert quality, and context to perform effective first-line detection and triage.
- Serve as part of the escalation group for security cases from the centralized SOC, assisting with containment and isolation activities during incidents where necessary.
- Provide subject-matter expertise on EDR and NDR telemetry sources during investigations and post-incident reviews.
- Contribute to root-cause analysis and recommend platform-level improvements following any potential incidents.
- Partner with the Threat Intelligence team and MDR organization to proactively hunt for malicious activity and validate emerging TTPs within Beazley’s…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: