Overview
Location: UK (remote/hybrid, with up to one day per week in central London)
Stack:
- SIEM: Microsoft Sentinel, or similar
- EDR/XDR: Defender, SentinelOne, CrowdStrike or equivalent
- Cloud/Platform: Azure (strongly preferred)
- Exposure to Microsoft security stack is advantageous but not required
Join a dedicated customer team as part of the wider Cybanetix engineering and security function. This role is open to both early-career security professionals and platform-focused engineers with Azure or equivalent systems experience who want to move into security engineering.
You will support investigations, contribute to detection tuning, and develop hands-on engineering capability across modern SIEM, EDR, and cloud platforms.
- Work with the configuration of modern SIEM, EDR, and cloud-based security platforms.
- Assist with configuration reviews and platform optimisation tasks.
- Support onboarding of new log sources and telemetry improvements.
- Work with detections from design through deployment and maintenance.
- Contribute to documentation and repeatable engineering processes.
Responsibilities
- Assist with incident handling activities, documentation, and follow-up actions.
- Contribute to SIEM and EDR tuning to improve signal quality.
- Help identify detection gaps and suggest improvements.
- Write and refine SIEM queries for investigation and hunting support.
- Support proactive threat hunting initiatives under guidance from senior engineers.
- Work as part of a dedicated customer team supporting day-to-day security operations.
- Communicate clearly with internal teams and senior engineers.
- Participate in structured knowledge sharing and mentoring sessions.
- Support on-call escalation processes where appropriate.
What we’re looking for
Must have:
- Strong understanding of core IT systems and platforms (Windows Server, Azure, networking fundamentals).
- Experience working with cloud or infrastructure platforms, ideally Azure.
- Strong analytical thinking and willingness to learn.
- Clear written and verbal communication skills.
- Ability to understand how systems integrate and how telemetry is generated.
Nice to have:
- Understanding of endpoint and SIEM investigations.
- Familiarity with at least one SIEM and one EDR platform.
- Basic experience writing queries in a SIEM environment.
- Exposure to the Microsoft security ecosystem.
- Experience working in a SOC or security operations environment.
- Basic scripting knowledge (PowerShell or Python).
What this role gives you
- Structured progression into security engineering from either a SOC or platform background.
- Hands-on experience with modern SIEM, EDR, and Azure security tooling.
- Mentorship from senior engineers and architects.
- Exposure to real-world enterprise environments.
#J-18808-Ljbffr…
