> Markdown version of [/jobs/ext/1303961-security-operations-engineer](https://www.wearedevelopers.com/jobs/ext/1303961-security-operations-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Operations Engineer - **Company:** Giacom - **Location:** Hessle, UK (Remote available) - **Salary:** £46,326.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, User Authentication, Software as a Service, Cyber Security, Identity and Access Management, Information Technology Operations, Intrusion Detection and Prevention, Performance Tuning, Security Information and Event Management, EndPointSecurity, QRadar, Falcon Platform, Cybercrime, Splunk, SentinelOne Expertise - **Published:** July 17, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5803718799 ## About the Role * Previous hands-on experience in cybersecurity operations or security engineering roles. * Experience of security monitoring, threat detection, incident response, and threat hunting methodologies. * Strong working knowledge of endpoint security, identity and access management, authentication controls, privileged access management, and security hardening standards incl. Privileged Access Management (PAM/PIM) principles and enterprise Endpoint Detection & Response (EDR/XDR) tooling. * Experience managing security tooling such as Microsoft Defender XDR, Sentinel, CrowdStrike, Splunk, QRadar, SentinelOne or similar enterprise-grade SIEM/XDR platforms. * Direct experience securing Microsoft 365 tenants and standard corporate SaaS environments. * Proven experience interfacing with, tuning, or triaging escalations from a third-party managed SOC or SIEM platform would also be desirable. ## Description The Security Operations (SecOps) Engineer will play a key role in maintaining and improving the organisation's overall security posture and operational security capability, acting as the bridge between internal stakeholders, technology teams and outsourced security service providers. This role is primarily a Security Operations and Engineering position, with responsibility for coordinating outsourced SOC services and driving security posture improvement. What you'll be doing * Act as the primary technical conduit and liaison between the organisation and our outsourced third-party SOC vendor. * Triage, analyse and prioritise alerts, incidents, escalations, and investigations - validating severity, business impact, and regulatory implications of incidents * Co-ordinate incident management and response activities aligned with defined policies, standards, and framework requirements by being the internal response facilitator and co-ordinator for containment, eradication, and recovery actions for security incidents escalated by the SOC * Actively assist and work closely with the outsourced SOC provider to: + Investigate root causes of security issues and design effective remediation solutions + Monitor and configure security tools - global EDR/XDR policies, blocklists, and automated containment rules including SIEM, EDR and respond to threat detection alerts. + Maintain and enhance security monitoring capabilities through effective integrations and optimisation of security tooling, ensure effective data collection and eliminate visibility blind spots. * Work closely with outsourced SOC vendor and internal engineering teams to implement automation workflows for routine SOC tasks such as alert enrichments, notifications, and data gathering, providing technical support and testing. * Design, configure, and implement security improvement initiatives and projects to enhance the organisation's overall security posture. * Collaborate with Corporate IT Service Desk to maintain governance over IT operations, ensuring technical controls across endpoints, enterprise solutions, and identity services are hardened, continuously monitored, and managed in accordance with Secure by Default principles to enable resilient and secure day-to-day operations. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)