> Markdown version of [/jobs/ext/2100506-security-operations-engineer](https://www.wearedevelopers.com/jobs/ext/2100506-security-operations-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Operations Engineer - **Company:** Ellison Institute, LLC - **Location:** Oxford, UK - **Salary:** £53,169.0 - **Contract:** Permanent contract - **Skills:** Computing Platforms, Microsoft Azure, Bash Shell, Cloud Computing, CompTIA Security+, Cyber Security, Linux, Intrusion Detection and Prevention, Python (Programming Language), Automation of Marketing, Windows PowerShell, Runbook, Security Information and Event Management, Scripting, Mitre Att&ck, Oracle Cloud Infrastructure, Splunk, SentinelOne Expertise, Vulnerability Analysis - **Published:** August 18, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5846346096 ## About the Role * Experience working in Security Operations, a SOC, or in Incident Response. * Hands-on experience with SIEM platforms such as Azure Sentinel, Splunk, or Sophos Taegis. * Familiarity with EDR tools including SentinelOne or CrowdStrike. * A strong understanding of common attack techniques (MITRE ATT&CK). * Working knowledge of Windows, Linux, identity systems, and networking. * Experience working with cloud platforms (OCI preferred) in a security context. Desirable Skills, Qualifications & Experience: * Scripting or automation skills (Python, PowerShell, Bash). * Experience in research, higher education, healthcare, or similarly open computing environments. * Familiarity with SOAR tooling or automation platforms. * Experience with ISO27001:2022 or similar standards. * Relevant certifications (e.g., ISC2 CC, CompTIA Security+). ## Description At EIT we are seeking a proactive Security Operations Engineer with demonstrable experience to help protect our people, platforms, and world-class research. This is a hands-on, impactful role at the centre of our cyber-security function, combining monitoring, incident response, detection engineering, and continuous improvement of our security posture. You will work closely with IT, research computing, governance, and legal teams to ensure that security enables, not hinders scientific innovation. If you want to be part of a mission-driven environment and play a critical role in safeguarding breakthrough research, we'd love to hear from you. Your Responsibilities: In this role, you will: * Operate and continuously enhance security monitoring across endpoints, servers, cloud platforms, and networks. * Tune and maintain SIEM tools (including Sophos Taegis, SentinelOne EDR, and OCI security tooling) to improve detection accuracy. * Investigate and triage security alerts, escalating and responding appropriately. * Act as a responder for security incidents, supporting containment, eradication, and recovery. * Produce clear incident documentation, including reports and root-cause analysis. * Develop and refine detection rules, automation workflows, and threat-based use cases. * Apply threat intelligence to improve detection coverage in complex research environments. * Support vulnerability scanning, prioritisation, and remediation tracking. * Collaborate closely with stakeholders to embed secure practices into day-to-day operations. * Contribute to runbooks, documentation, audits, compliance activities, and risk assessments. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)