×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

SecOps Engineer

Job in London, Greater London, W1B, England, UK
Listing for: OCS Group
Full Time position
Listed on 2026-09-04
Job specializations:
  • IT/Tech
    Cybersecurity
Job Description & How to Apply Below
About The Role:

The Security Operations Analyst plays a central role in strengthening OCS’s cyber defence capability. The role exists to make our Sec Ops function measurably more effective every quarter, by improving how we detect, investigate and respond to threats, and by removing the friction that holds analysts back.

We are looking for a proactive engineer who does not wait to be told where the problems are. The successful candidate will actively look for weaknesses in our detection coverage, configuration drift in our security platforms, gaps in our automation and inefficiencies in our processes. They will then propose pragmatic fixes, build them, and measure the outcome

Main

Duties & Responsibilities of the Role Detection engineering and tuning

Build, test and maintain high-quality detections across our SIEM, XDR and email security platforms, mapped to the MITRE ATT&CK framework

Continuously tune existing detections to reduce false positives and improve fidelity, using a data-driven approach

Identify gaps in detection coverage proactively and propose engineering work to close them Develop and maintain detection-as-code practices, including version control, peer review and CI/CD where appropriate Automation and tooling

Identify repetitive analyst tasks and engineer automation to remove them, using SOAR, native platform automation, scripting or low-code approaches

Build and maintain integrations between security tools and adjacent platforms such as identity, endpoint management and ticketing

Develop and maintain dashboards that give analysts and leadership a clear view of operational health

Platform health and configuration

Own the configuration and ongoing health of assigned Sec Ops platforms, including SIEM, EDR, email security and identity protection Monitor for configuration drift, agent coverage gaps and ingestion failures, and resolve them at source

Lead technical onboarding of new log sources, telemetry and integrations, ensuring that data is usable, normalised and well documented Threat hunting and proactive defence

Conduct regular threat hunts based on intelligence, recent incidents and known weaknesses, documenting hypotheses, methodology and findings

Translate hunt findings into durable detections, automation or process changes

Contribute to purple team exercises and adversary emulation, working with internal and external partners

Incident response support

Provide deep technical support during significant incidents, including forensic data collection, log analysis and containment engineering Capture lessons learned from incidents and translate them into engineering improvements that prevent recurrence

Continuous improvement

Maintain a backlog of identified weaknesses, ideas and improvements, and work with the Senior Sec Ops Lead to prioritise it Document standards, runbooks and engineering decisions clearly, so that knowledge does not live only in individual heads Stay current with the threat landscape, vendor road maps and the broader security engineering community, and bring relevant ideas back into OCS Professional Qualifications required for the job (particularly for compliance purposes or technical requirements of the role) Extensive Sec Ops experience with a multitude of different tools

Relevant Industry Certifications Experience –previous experience –desirable/essential for technical competence of the role Demonstrable hands-on experience as a security engineer or senior SOC analyst with engineering responsibilities

Strong working knowledge of at least one enterprise SIEM and one EDR or XDR platform, with the ability to write detections, tune content and operate at a deep technical level

Solid scripting ability, for example in Python, Power Shell or KQL, with a working understanding of APIs and integration patterns

Practical understanding of common attack techniques mapped to MITRE ATT&CK, and how they manifest in telemetryA proactive mindset: the candidate must be able to point to specific examples where they have identified a problem, designed a solution and delivered it end to end Strong written communication, including the ability to document detections, runbooks and engineering…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary