SecOps Engineer

Manchester Arndale

City Of London

On-site

GBP 55,000 - 85,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Award-winning employer
Digital learning
Retail perks with Hapi app
Professional growth opportunities
Flexible pay with Wagestream

Job summary

OCS UK & Ireland is seeking a Security Operations Analyst to strengthen its cyber defence capability. The role focuses on improving detection, investigation, and response while reducing friction for analysts.

You will build detections across SIEM, XDR, and email security, tune detections to reduce false positives, and lead threat hunts and incident response support. The role requires proactive, technically capable individuals with strong communication.

Qualifications

  • Extensive SecOps experience with a multitude of different tools.
  • Strong working knowledge of at least one enterprise SIEM and one EDR or XDR platform; ability to write detections and tune content.
  • Solid scripting ability, for example in Python, PowerShell or KQL; working understanding of APIs and integration patterns.
  • Practical understanding of MITRE ATT&CK techniques and how they appear in telemetry.
  • A proactive mindset with examples of identifying problems, designing solutions and delivering end-to-end.

Responsibilities

  • Detection engineering and tuning across SIEM, XDR, and email security platforms; mapped to MITRE ATT&CK.
  • Develop and maintain detection-as-code practices, including version control and CI/CD.
  • Automation and tooling: build automation to remove repetitive tasks and integrate security tools with other platforms.
  • Threat hunting and proactive defence; translate findings into durable detections and processes.
  • Incident response support with forensic data collection, log analysis and containment engineering.
  • Continuous improvement: backlog maintenance and documentation of standards and runbooks.

Skills

SecOps experience
MITRE ATT&CK
Scripting
APIs & integration patterns

Tools

SIEM
EDR/XDR
Python
PowerShell
KQL

Job description

About The Role:

The Security Operations Analyst plays a central role in strengthening OCS’s cyber defence capability.

The role exists to make our SecOps function measurably more effective every quarter, by improving how we detect, investigate and respond to threats, and by removing the friction that holds analysts back.

We are looking for a proactive engineer who does not wait to be told where the problems are. The successful candidate will actively look for weaknesses in our detection coverage, configuration drift in our security platforms, gaps in our automation and inefficiencies in our processes. They will then propose pragmatic fixes, build them, and measure the outcome

Main Duties & Responsibilities of the Role

Detection engineering and tuning

Build, test and maintain high-quality detections across our SIEM, XDR and email security platforms, mapped to the MITRE ATT&CK framework

Continuously tune existing detections to reduce false positives and improve fidelity, using a data-driven approach

Identify gaps in detection coverage proactively and propose engineering work to close them

Develop and maintain detection-as-code practices, including version control, peer review and CI/CD where appropriate

Automation and tooling

Identify repetitive analyst tasks and engineer automation to remove them, using SOAR, native platform automation, scripting or low-code approaches

Build and maintain integrations between security tools and adjacent platforms such as identity, endpoint management and ticketing

Develop and maintain dashboards that give analysts and leadership a clear view of operational health

Platform health and configuration

Own the configuration and ongoing health of assigned SecOps platforms, including SIEM, EDR, email security and identity protection

Monitor for configuration drift, agent coverage gaps and ingestion failures, and resolve them at source

Lead technical onboarding of new log sources, telemetry and integrations, ensuring that data is usable, normalised and well documented

Threat hunting and proactive defence

Conduct regular threat hunts based on intelligence, recent incidents and known weaknesses, documenting hypotheses, methodology and findings

Translate hunt findings into durable detections, automation or process changes

Contribute to purple team exercises and adversary emulation, working with internal and external partners

Incident response support

Provide deep technical support during significant incidents, including forensic data collection, log analysis and containment engineering

Capture lessons learned from incidents and translate them into engineering improvements that prevent recurrence

Continuous improvement

Maintain a backlog of identified weaknesses, ideas and improvements, and work with the Senior SecOps Lead to prioritise it

Document standards, runbooks and engineering decisions clearly, so that knowledge does not live only in individual heads

Stay current with the threat landscape, vendor road maps and the broader security engineering community, and bring relevant ideas back into OCS

Professional Qualifications required for the job (particularly for compliance purposes or technical requirements of the role)

Extensive SecOps experience with a multitude of different tools

Relevant Industry Certifications

Experience –previous experience –desirable/essential for technical competence of the role

Demonstrable hands‑on experience as a security engineer or senior SOC analyst with engineering responsibilities

Strong working knowledge of at least one enterprise SIEM and one EDR or XDR platform, with the ability to write detections, tune content and operate at a deep technical level

Solid scripting ability, for example in Python, PowerShell or KQL, with a working understanding of APIs and integration patterns

Practical understanding of common attack techniques mapped to MITRE ATT&CK, and how they manifest in telemetry

A proactive mindset: the candidate must be able to point to specific examples where they have identified a problem, designed a solution and delivered it end to end

Strong written communication, including the ability to document detections, runbooks and engineering decisions to a high standard

Personal Characteristics/Attributes

Organisational and time management skills

Strong interpersonal skills

Exceptional written and verbal communication skills

Ability to work under own initiative, as well as part of a team

Willingness and ability to undertake national travel as required

Confidence to stand their ground and drive a Security First environment

The ability to learn new tools quickly and effectively

About The Company:

OCS UK & Ireland is a leading facilities management company with 50,000+ colleagues and a turnover in excess of £2bn. We deliver innovative, award-winning services within facilities management, hard services, cleaning, security and catering.

Our mission is to make people and places the best they can be for our colleagues, customers and the communities we serve. Our commitment to doing business the right way is rooted in our TRUE values - Trust, Respect, Unity, and Empowerment.

Why Work for OCS?

Award-Winning Employer : Ranked 36th on Glassdoor’s Best Companies to Work For 2025 — we value and motivate our people.

Digital Learning : The OCS Academy offers digital courses and resources to help you build skills and grow your career.

Retail Perks With our Hapi app, you can gain access to exclusive discounts, rewards and wellbeing resources.

Professional Growth : 600+ live learners across UK&I — Empowering colleagues with further development and qualifications!

Flexible Pay : Access a portion of earned wages before payday with our Wagestream App! (Contract Specific)

We are an equal opportunities employer and rely on a diverse workforce with a broad range of knowledge, skills, and backgrounds to deliver our goals. We offer an inclusive and welcoming environment and actively encourage applications from all individuals regardless of race, gender, nationality, religion, sexual orientation, disability, or age.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Officer
Security Officer

Manchester Arndale • Dundee

On-site
GBP 21,000 - 27,000
Award-winning employer
Digital learning
Retail discounts
+2
Regional Director
Regional Director

OCS • Cambridgeshire and Peterborough

On-site
GBP 90,000 - 130,000
Career progression
OCS Learning platform access
Training and upskilling
+5
Security Officer
Security Officer

Manchester Arndale • Glasgow

Hybrid
GBP 21,000 - 27,000
Security Officer
Security Officer

OCS • Greater Manchester

On-site
GBP 14,000 - 19,000
Wagestream early access
Hapi app discounts
OCS Academy access
Area Support Officer
Area Support Officer

OCS • Leicester

On-site
GBP 24,000 - 30,000
Security Officer
Security Officer

OCS • Derry/Londonderry

On-site
GBP 21,000 - 26,000
Award-Winning Employer
Digital Learning
Retail perks
Area Support Officer
Area Support Officer

OCS • Aylesford

On-site
GBP 24,000 - 30,000
Security Leading Officer
Security Leading Officer

OCS • West of England

On-site
GBP 22,000 - 26,000
Security Officer
Security Officer

OCS • East Kilbride

On-site
GBP 21,000 - 27,000
Award-Winning Employer
Digital Learning
Retail Perks via Wagestream
+2
Security Fire Officer
Security Fire Officer

Manchester Arndale • Knowsley

On-site
GBP 18,000 - 24,000