Cyber security Operation Manager

Agratas – A Tata Enterprise

Bridgwater

On-site

GBP 55,000 - 75,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Agratas – A Tata Enterprise in Bridgwater is seeking a skilled Cyber Security Engineer to enhance their cybersecurity operations. The ideal candidate will have 4–5 years of experience with a strong background in security monitoring, incident response, and threat hunting.

This role involves developing detection use cases, supporting incident response, and conducting threat hunts across various environments. The position offers an opportunity to work with modern security technologies and improve overall security posture.

Qualifications

  • 4–5 years of hands-on experience in cybersecurity operations.
  • Strong technical expertise in security operations.
  • Experience with EDR, NDR, and SIEM solutions.

Responsibilities

  • Develop detection use cases aligned with MITRE ATT&CK framework.
  • Support end-to-end incident response including triage and recovery.
  • Conduct threat hunts across network, endpoint, and cloud environments.

Skills

Cybersecurity operations
Incident response
Threat hunting
Security monitoring
Detection engineering
Microsoft 365 Security

Tools

Splunk
Microsoft Defender
CrowdStrike
Elastic

Job description

Role Overview

We are seeking a skilled and proactive cyber Security Engineer with 4 to 5 years of hands‑on experience in enterprise cybersecurity operations. The ideal candidate will have strong technical expertise across security operations, detection engineering, incident response, and threat hunting with proven experience working on modern security platforms. This role requires a practitioner who can actively defend enterprise environments and continuously improve security posture.

Key Responsibility Areas
Security Monitoring & Engineering
  • Develop and optimize detection use cases aligned with the MITRE ATT&CK framework and emerging threats.
  • Tune security controls and automate workflows to reduce false positives and improve detection accuracy.
  • Manage and secure Microsoft 365 Security and Microsoft Security platforms.
  • Strengthen identity security through attack surface analysis, privilege reviews, and policy optimization.
  • Review security architecture and provide guidance for secure deployment of new applications and technologies.
  • Create advanced correlation rules across multiple log sources to detect sophisticated attack patterns and generate high-fidelity alerts.
Incident Response
  • Support end‑to‑end incident response, including triage, investigation, containment, eradication, recovery, and reporting.
  • Perform digital forensic investigations across endpoints, servers, cloud environments, and other relevant sources.
  • Assist in malware removal, persistence eradication, root cause validation, and secure system recovery.
  • Maintain and enhance incident response playbooks to align with current threats and industry best practices.
Threat Hunting
  • Conduct structured, unstructured, and intelligence‑driven threat hunts across network, endpoint, and cloud environments.
  • Analyze security data to identify anomalous behavior, indicators of compromise (IOCs), and attack patterns.
  • Collaborate with security, incident response, and engineering teams to improve detections and strengthen security posture.
  • Present findings, recommendations, and remediation strategies to technical and management stakeholders.
  • Stay current with emerging threats, attack techniques, and security technologies through continuous learning.
Required Qualifications
Qualifications & Technical Skills
  • 4–5 years of hands‑on experience in cybersecurity operations, monitoring, or security engineering.
  • Strong experience with enterprise security solutions across endpoint, network, and cloud environments.
  • Proven expertise in handling security incidents through the full incident response lifecycle.
  • Solid understanding of networking fundamentals and security concepts.
  • Knowledge of attack techniques, threat detection methodologies, and threat hunting.
  • Experience analyzing logs, packet captures, endpoint artifacts, and collecting digital evidence.
  • Proficiency in Splunk SPL, KQL, SQL, or similar query languages.
Technology Expertise
  • 4+ years of experience with EDR, NDR, and SIEM platforms (Microsoft Defender, CrowdStrike, Splunk, Sentinel, Elastic).
  • Experience with Data Security technologies including DLP, IRM, and DSPM solutions.
  • 4+ years of experience configuring and investigating email security platforms.
  • Hands‑on experience with identity and access management solutions such as Entra ID and Active Directory.
  • Strong understanding of authentication and authorization protocols including SAML, OAuth 2.0, and OIDC.
  • Experience with security automation tools, orchestration platforms, and threat intelligence feeds.
Good to Have
  • Knowledge of OT (Operational Technology) security concepts and principles.
  • Familiarity with automation and scripting (PowerShell, Python, Bash).
  • Familiarity with securing cloud workloads on Azure, AWS
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Engineer
Cyber Security Engineer

La Fosse • Greater London

On-site
GBP 60,000 - 80,000
Senior Detection and Response Engineer
Senior Detection and Response Engineer

Jobtailor • Cambridge

On-site
GBP 65,000 - 95,000
Head of Security Operations
Head of Security Operations

Jobtailor • Greater London

On-site
GBP 70,000 - 110,000
Cyber Security Engineer
Cyber Security Engineer

Marks Sattin • England

On-site
GBP 60,000 - 80,000
Cybersecurity Operations Manager
Cybersecurity Operations Manager

Square One Resources • Sheffield

Hybrid
GBP 16,974,000 - 19,004,000
Senior Cyber Defence Analyst
Senior Cyber Defence Analyst

Harrington Starr • Birmingham

On-site
GBP 95,000 - 130,000
Lead Security Operations Engineer
Lead Security Operations Engineer

Jobtailor • Greater London

On-site
GBP 120,000 - 170,000
Security Operations Vice President
Security Operations Vice President

JP Morgan • Greater London

On-site
GBP 70,000 - 110,000
Senior Cyber Security Engineer
Senior Cyber Security Engineer

Jobtailor • Manchester

On-site
GBP 70,000 - 100,000
Senior Operational Security Engineer
Senior Operational Security Engineer

Crown Agents Bank Ltd. • Greater London

On-site
GBP 70,000 - 90,000