> Markdown version of [/jobs/ext/336223-l1-cyber-engineer](https://www.wearedevelopers.com/jobs/ext/336223-l1-cyber-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # L1 - Cyber Engineer - **Company:** VirtualArmour - **Location:** Middlesbrough, UK (Remote available) - **Experience:** Starter - **Salary:** £26,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, CompTIA Security+, Cyber Security, Dynamic Host Configuration Protocol, Event Logging, Issue Tracking Systems, Network Security, Network Monitoring, Network Protocols, Phishing, Security Information and Event Management, File Transfer Protocol (FTP), Mitre Att&ck, Malware, Azure Security Center, Information Technology, SentinelOne Expertise, Cisco - **Published:** June 5, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=77e9be1e05d94f19 ## About the Role Do you have experience in SIEM?, Do you have a Bachelor's degree?, We are seeking an L1 Cyber Engineer to join our MSS team in a Managed Security Service Provider (MSSP) environment. This role is focused on high-volume alert and ticket triage, customer-facing escalations, and first-level security investigations. The ideal candidate has strong foundational knowledge of SIEM, XDR, and EDR concepts, excellent communication skills, and the ability to follow playbooks while thinking critically under pressure., Required * A strong desire to work in either Cyber security or Network security fields * Strong understanding of SIEM, XDR, and EDR fundamentals (telemetry types, detection logic, correlation, and response workflows). * Understanding of attack lifecycle concepts (MITRE ATT&CK basics, NIST, Lockhead Martin etc.). * Ability to analyze endpoint and security logs (Windows Event Logs concepts, process/parent-child relationships, network indicators). * Ability to demonstrate an understanding of IP protocols like DHCP, FTP/SFTP, HTTPS/HTTPS, TCP/UDP, SSH etc. * Strong written communication and ticket hygiene (clear summaries, evidence-based conclusions). * Comfort working in a 24x7 SOC environment and meeting SLA-driven targets. * Team player with strong collaboration skills and a flexible approach to problem solving., * 6 months - 2 years in a SOC, MSSP, or IT security operations role (internship/coop considered). * A bachelor's degree in cyber security or related field, or equivalent level of experience within IT. * Certifications (nice to have): CompTIA Security+, SC-200, CCNA, or vendor-specific endpoint/SIEM training., * Do you currently have the unrestricted right to work in the UK without the need for visa or sponsorship? Education: * Bachelor's (preferred) Licence/Certification: * CompTIA Security+ (preferred) * Cisco CCNA (preferred) ## Description We are seeking a dedicated L1 Cyber Engineer to join our team on a 4-on, 4-off shift rotation, working 6:00 AM - 6:00 PM. This hybrid role offers flexibility, allowing remote work on weekends and office attendance only when shifts fall on Tuesdays, Wednesdays, or Thursdays. The L1 Cyber Engineer is a junior level position. Working as part of a team the SOC Engineer's primary role is to work on helpdesk tickets for our Managed Security Services (MSS) department. The position is dual rolled, combining a Cyber Security Analyst and a Network Security Engineer at a junior level. This role will build a foundation across all aspects of MSS technologies, allowing for the candidate to develop their own career path within VirtualArmour., * Monitor and triage security and network alerts from network monitoring, EDR/XDR, SIEM, and related security tooling; prioritize incidents based on risk and business impact. * Investigate endpoint threats (malware, ransomware, credential theft, persistence, lateral movement) using Microsoft Defender for Endpoint (MDE), CrowdStrike EDR, SentinelOne EDR, and Stellar Cyber XDR. * Identify common attack patterns (phishing, malware execution, credential abuse, lateral movement, persistence indicators) and recommend next steps. * Escalate complex or high-severity incidents to Tier 2/IR with high-quality handoffs (evidence, hypotheses, affected entities, attempted actions). * Support ongoing investigations by collecting additional artifacts/logs, re-checking endpoints, and monitoring for recurrence. * Document findings clearly in the ticketing system, ensuring complete timelines, evidence, and actions taken. * Follow SOC runbooks, playbooks, and standard operating procedures (SOPs) consistently. * Participate in shift handovers and maintain accurate case notes to ensure continuity of operations. * Identify recurring false positives, detection gaps, and tuning opportunities; propose improvements to content/rules and playbooks. * Stay up to date on information technology trends and security standards. * Adhere to company-wide best practices for IT security. ## Related Videos - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [The AI Security Survival Guide: Practical Advice for Stressed-Out Developers](https://www.wearedevelopers.com/videos/1015-the-ai-security-survival-guide-practical-advice-for-stressed-out-developers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Data Engineer Salary UK](https://www.wearedevelopers.com/magazine/253-data-engineer-salary-uk) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs)