> Markdown version of [/jobs/ext/348628-security-operations-engineer-engine-by-starling](https://www.wearedevelopers.com/jobs/ext/348628-security-operations-engineer-engine-by-starling). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Operations Engineer - Engine by Starling - **Company:** The Engine - **Location:** London, UK - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Cloud Computing Security, CompTIA Security+, Cyber Security, Intrusion Detection and Prevention, Mitre Att&ck, Cyber Threat Analysis, Cybercrime, Vulnerability Analysis - **Published:** June 19, 2026 - **Apply:** https://www.free-work.com/en-gb/tech-it/job-mission/data-engineer-1/security-operations-engineer-engine-by-starling ## About the Role * 3+ years of hands-on experience in a Security Operations Center (SOC) or similar cybersecurity role. * Demonstrable experience with cloud security monitoring and incident response. * Familiarity with various attack vectors, threat intelligence frameworks (e.g., MITRE ATT&CK). * A cyber/information security related degree and/or relevant cybersecurity qualifications would be beneficial e.g. CompTIA Security+, (ISC)² SSCP or CySA+ Interviewing is a two way process and we want you to have the time and opportunity to get to know us, as much as we are getting to know you! Our interviews are conversational and we want to get the best from you, so come with questions and be curious. In general you can expect the below, following a chat with one of our Talent Team: * Stage 1 - 45 mins with BISO * Stage 2 - 60 min with Team Members * Stage 3 - Final with CTO ## Description To support our growth, we are looking for talented and motivated SOC engineers to join our foundational in-house SOC team. In this pivotal role, you will be instrumental in supporting the development, implementation, and operating of our security monitoring, detection, and response capabilities, with a particular focus on our cloud environments. You'll be at the forefront of responding to incidents and alerts, and helping shape the future of our security operations capabilities. What you'll get to do: Security Monitoring & Alert Triage: * Monitor security alerts and events generated by various security tools * Perform triage and analysis of security incidents and anomalies, distinguishing between true positives and false positives. * Prioritise alerts based on severity, potential impact, and business criticality. Incident Detection & Response: * Investigate security incidents thoroughly, leveraging logs from platforms, endpoints, applications, and other security tools. * Create and follow incident response playbooks and contribute to their continuous improvement. * Collaborate with Technology, Product and Engineering Teams to contain, eradicate, and recover from security incidents. * Document incident details, findings, and remediation steps accurately and comprehensively. Additionally * Stay informed about the latest cyber threats, attack techniques, and vulnerabilities, especially those targeting cloud environments. * Participate in proactive threat hunting activities using available tools and data sources. * Contribute to the optimisation, tuning, and maintenance of SOC tools * Identify opportunities for automation to streamline security operations and enhance detection capabilities. * Maintain detailed records of security incidents, investigations, and remediation actions. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How to Answer the Interview Question: “Why Do You Want to Be a Software Engineer?”](https://www.wearedevelopers.com/magazine/392-how-to-answer-the-interview-question-why-do-you-want-to-be-a-software-engineer) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london)