> Markdown version of [/jobs/ext/2857071-security-operations-engineer](https://www.wearedevelopers.com/jobs/ext/2857071-security-operations-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Operations Engineer - **Company:** The Ellison Institute Of Technology (eit) - **Location:** Oxford, UK - **Salary:** £60,000.0 - £70,000.0 - **Contract:** Permanent contract - **Skills:** Bash Shell, Big Data, Cloud Computing Security, CompTIA Security+, Cyber Security, Linux, Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), Networking Basics, Windows PowerShell, Security Information and Event Management, Software Vulnerability Management, Scripting, Cloud Platform System, Mitre Att&ck, Cybercrime, SentinelOne Expertise - **Published:** September 12, 2026 - **Apply:** https://jobs.sciencecareers.org/external-redirect-registration?JobId=680087&LinkSource=JobDetails ## About the Role * Experience working within Security Operations, a Security Operations Centre (SOC), Incident Response, or a similar cyber security function. * Hands-on experience using SIEM platforms such as Azure Sentinel, Splunk, Sophos Taegis, or equivalent technologies. * Familiarity with Endpoint Detection and Response (EDR) solutions such as SentinelOne, CrowdStrike or similar tools. * A good understanding of common cyber threats, attack techniques and detection methodologies, including familiarity with the MITRE ATT&CK framework. * Working knowledge of Windows and Linux operating systems, networking fundamentals and identity management technologies. * Experience supporting or securing cloud environments, ideally within a complex or enterprise setting. * Strong analytical and problem-solving skills, with the ability to investigate and respond to security events effectively. * The ability to communicate technical information clearly to both technical and non-technical audiences. * A collaborative approach and a desire to work closely with colleagues across a range of disciplines. * A commitment to continuous learning and professional development., * Experience with scripting or automation using Python, PowerShell, Bash or similar languages. * Experience working in research, higher education, healthcare, scientific or other innovation-focused environments. * Familiarity with SOAR platforms and security automation technologies. * Experience supporting organisations aligned to ISO27001:2022 or other recognised security frameworks. * Relevant certifications such as ISC2 Certified in Cybersecurity (CC), CompTIA Security+, CISSP, SSCP, CySA+, or similar. * Experience supporting large-scale data platforms, research computing environments or high-performance computing (HPC) infrastructure. What Will Help You Succeed The most successful people in this role are likely to be: * Curious and motivated to learn. * Calm and methodical when solving problems. * Collaborative and supportive team players. * Comfortable building relationships across technical and non-technical teams. * Passionate about using technology to enable meaningful scientific and societal impact. ## Description As EIT continues to expand its research programmes, digital platforms and scientific infrastructure, we are looking for an experienced and proactive Security Operations Engineer to help protect our people, platforms and world-class research. This is an opportunity to play a meaningful role within a growing cyber security team, combining security monitoring, incident response, detection engineering and continuous improvement. You'll work closely with colleagues across IT, research computing, governance and legal functions to help create a secure environment that enables scientific discovery and innovation to thrive. We are looking for individuals who enjoy solving complex problems, collaborating with others and continuously developing their skills in an environment where security is viewed as a trusted partner to the organisation. Whether your background comes from a Security Operations Centre, incident response team or another security discipline, you'll have the opportunity to contribute, learn and grow while helping safeguard research that could shape the future. Working as part of a collaborative cyber security team, you'll help strengthen our security capabilities while supporting the scientists, researchers and technology teams delivering work with global impact. You will: * Help operate and continuously improve security monitoring across endpoints, servers, cloud platforms and networks. * Maintain and optimise security tooling, including SIEM, EDR and cloud security platforms, to improve visibility and detection capabilities. * Investigate, triage and respond to security alerts, working with colleagues to identify and address potential threats. * Support incident response activities, helping to coordinate containment, remediation and recovery efforts. * Produce clear and accurate documentation, including incident reports, lessons learned and root cause analyses. * Contribute to the development of detection rules, automation workflows and threat-based use cases. * Use threat intelligence and emerging security trends to strengthen monitoring and detection capabilities. * Support vulnerability management activities, including assessment, prioritisation and remediation tracking. * Partner with colleagues across IT, research computing and governance teams to embed secure ways of working. * Contribute to security documentation, audit preparation, compliance activities and risk assessments. * Share knowledge and support a culture of continuous learning and improvement across the team. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Alibaba Big Data and Machine Learning Technology](https://www.wearedevelopers.com/videos/37-alibaba-big-data-and-machine-learning-technology) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [6 Emerging Technologies We’ll Learn About in 2025](https://www.wearedevelopers.com/magazine/381-6-emerging-technologies-we-ll-learn-about-in-2025)