Security Operations Engineer
Core
Operate and improve security monitoring, incident response, and detection engineering to protect research platforms and infrastructure.
Role type
Security Operations Engineer (SOC/Incident Response)
Builds
Secure research computing environments and digital platforms for scientific discovery
Domain
Cybersecurity in research, higher education, and scientific innovation
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Security Operations Centre (SOC) experience, SIEM platforms (Azure Sentinel, Splunk, Sophos Taegis), Endpoint Detection and Response (EDR) solutions, MITRE ATT&CK framework, Windows and Linux operating systems, networking fundamentals, identity management, cloud environment security, vulnerability management, threat intelligence analysis, incident triage and response, root cause analysis, automation workflow development
Preferred skills
Python, PowerShell, Bash scripting, SOAR platforms, ISO27001:2022 framework experience, large-scale data platform support, high-performance computing (HPC) infrastructure experience
Technologies
Azure Sentinel, Splunk, Sophos Taegis, SentinelOne, CrowdStrike, MITRE ATT&CK, SOAR platforms
Responsibilities
Operate and optimize security monitoring across endpoints, servers, cloud platforms, and networks; investigate, triage, and respond to security alerts; support incident response activities including containment and remediation; produce incident reports and root cause analyses; develop detection rules and automation workflows; support vulnerability management and compliance activities; partner with IT and research teams to embed secure ways of working
Seniority
Mid-Senior, hands-on IC