Security Operations Engineer

Company: Hamilton Barnes ?
Apply for the Security Operations Engineer
Location: Doncaster
Job Description:

We are looking for a Security Operations Engineer to join a high-performing Security Operations Centre (SOC) delivering protective monitoring and incident response services to organisations across multiple industries. Working as part of an experienced SOC and Incident Response team, you will help detect, investigate, and respond to cyber threats using industry-leading security technologies while supporting clients during active security incidents.

This role offers the opportunity to work across a wide range of security technologies, develop detection and response capabilities, and play a key role in protecting organisations from evolving cyber threats while progressing your career in a collaborative SOC environment.

Responsibilities:

Monitor and investigate security alerts using industry-leading SOC technologies

Provide guidance and support to clients during cyber security incidents

Produce detailed incident reports and ensure accurate, timely communication

Support threat hunting and threat mining activities

Assist with onboarding new clients including deployment of SIEM, EDR, and vulnerability management tools

Act as a technical escalation point and mentor junior SOC analysts

Engineer and deploy security tooling and detection capabilities

Investigate incidents, analyse attack methods, and research new defence techniques

Develop detection rules, automation, and security procedures

Conduct malware and attack analysis to identify indicators of compromise

Correlate security event data across multiple platforms

Support pre-sales activity including demos and scoping engagements

Skills/Must have:

Experience working in a Security Operations Centre (SOC) environment

Strong incident investigation and threat detection experience

Experience with security monitoring and detection tooling

Ability to work under pressure during active incidents

Ability to work in a hybrid model with some office presence

Industry certifications such as Microsoft SC-200, AZ-500, or SC-100

Experience with tools such as Microsoft Sentinel, Microsoft Defender, USM Anywhere, SentinelOne, or Tenable.io

Experience with detection engineering, threat hunting, or malware analysis

Opportunity to work in an established SOC protecting organisations across multiple industries

Exposure to a wide range of security tools and technologies

Career development within a collaborative security team

#J-18808-Ljbffr…

Posted: March 20th, 2026