Cyber Security Operations Specialist

Tank Recruitment

Bath

On-site

GBP 55,000 - 85,000

Full time

15 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Tank Recruitment is seeking an experienced Cyber Security Operations Specialist to join a growing security team protecting a complex IT, cloud and OT environment in Bath.

You will detect, investigate and respond to cyber threats, improving monitoring, incident response capabilities and security controls across IT, cloud and on-premise estates. This role involves hands-on security operations, tooling optimisation and continuous improvement, with opportunities to mentor junior staff.

Qualifications

  • Experience in security operations or SOC/IR.
  • Hands-on with SIEM and EDR platforms.
  • Experience in cloud and on-premise environments.
  • Knowledge of MITRE ATT&CK framework.
  • Familiarity with Windows and Linux/Unix.
  • Understanding of ISO 27001, NIS and GDPR.

Responsibilities

  • Monitor, triage, and investigate security alerts and incidents.
  • Lead or support incident response actions.
  • Develop and optimise SIEM detection rules and EDR policies.
  • Reduce false positives and improve detection coverage.
  • Investigate threats using MITRE ATT&CK.
  • Collaborate with internal IT, engineering and security teams and external security providers.
  • Maintain security playbooks and response processes.
  • Support security reporting, compliance and audits.
  • Provide guidance to junior members of the security team.

Skills

Security Operations
SIEM
EDR
Cloud environments
Windows
Linux/Unix
MITRE ATT&CK
Threat Intelligence
Incident Management
Stakeholder Communication

Job description


We are looking for an experienced Cyber Security Operations Specialist to join a growing security team responsible for protecting a complex IT, cloud and operational technology environment.
You will play a key role in detecting, investigating and responding to cyber threats, while helping to improve the organisation's overall security monitoring and incident response capabilities. The role combines hands-on security operations, tooling optimisation and continuous improvement across a varied technology estate.

Key responsibilities:
  • Monitor, triage and investigate security alerts and incidents across IT, cloud and OT environments.
  • Lead or support incident response, including containment, eradication, recovery and escalation.
  • Develop and optimise SIEM detection rules, EDR policies and security monitoring capabilities.
  • Reduce false positives and improve detection coverage using threat intelligence and incident learnings.
  • Investigate threats using frameworks such as MITRE ATT&CK.
  • Work closely with internal IT, engineering and security teams, alongside external security providers.
  • Maintain and improve security playbooks, procedures, documentation and response processes.
  • Support security reporting, compliance and audit activity.
  • Provide technical guidance and support to junior members of the security team.
Key skills and experience:
  • Strong background in Security Operations, SOC or Incident Response.
  • Hands-on experience with SIEM and EDR platforms, ideally including Microsoft security technologies.
  • Experience investigating security incidents across cloud and on-premise environments.
  • Knowledge of Windows environments, with working knowledge of Linux/Unix.
  • Understanding of threat intelligence, IOCs, TTPs and the MITRE ATT&CK framework.
  • Experience improving detection logic, alert quality and security controls.
  • Strong stakeholder communication and incident management skills.
  • Knowledge of frameworks such as ISO 27001, NIS and GDPR would be beneficial.
Desirable certifications include:

SC-200, SC-300, SC-400, MS-500, Security+ or similar cyber security qualifications.
The role will involve participation in an out-of-hours incident response rota, with occasional travel where required.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Operations Specialist
Cyber Security Operations Specialist

Sanderson • West of England

Hybrid
GBP 120,000 - 150,000
Cyber Security Specialist (Secops / Liverpool)
Cyber Security Specialist (Secops / Liverpool)

Michael Page • Liverpool

Hybrid
GBP 55,000 - 90,000
Private healthcare
Life assurance
Hybrid working
Cyber Security Operations Analyst
Cyber Security Operations Analyst

Caraffi • Reading

On-site
GBP 55,000 - 75,000
Security Operations Manager
Security Operations Manager

InfoSec People Ltd • Bournemouth

On-site
GBP 80,000 - 110,000
Cyber security Operation Manager
Cyber security Operation Manager

Agratas – A Tata Enterprise • Bridgwater

On-site
GBP 55,000 - 75,000
Senior Cloud Security Analyst
Senior Cloud Security Analyst

MCS Group • Belfast City District

On-site
GBP 70,000 - 90,000
Senior Security Analyst
Senior Security Analyst

James Adams • Northampton

Hybrid
GBP 60,000 - 80,000
Clear progression opportunities
Cyber Security Analyst
Cyber Security Analyst

Synapri • Greater London

Hybrid
GBP 50,000 - 70,000
SOC Engineer
SOC Engineer

Spectrum IT Recruitment • Milton Keynes

On-site
GBP 41,000 - 50,000
Security Operations Engineer
Security Operations Engineer

Context Recruitment • Greater London

On-site
GBP 68,000 - 83,000