Security Operations Engineer

Context Recruitment

Greater London

On-site

GBP 68,000 - 83,000

Full time

11 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Context Recruitment is seeking an experienced SecOps Engineer for a permanent role in the UK. The position focuses on securing Microsoft 365, cloud and on-premises infrastructure, maintaining ISO 27001 and CE+ compliance, and driving security improvements.

The role involves monitoring SIEM (QRadar), vulnerability management, patching, and collaborating with external SOCs. Four days per week onsite in Central London initially, with a move to two days after probation.

Qualifications

  • Hands-on SecOps or incident response experience.
  • Strong governance of Microsoft 365 environments.
  • Experience with security tooling (QRadar, Qualys, Defender).
  • Familiar with ISO 27001 and CE+ controls.

Responsibilities

  • Monitor SIEM and respond to threat alerts.
  • Assess vulnerabilities and coordinate remediation.
  • Manage patching for servers and endpoints.
  • Review and optimize conditional access and policies.
  • Collaborate with external SOCs and govern security controls.
  • Produce security reports and drive automation via scripting.

Skills

Security operations
Microsoft 365
PowerShell
Incident response
Cloud security
ISO 27001
CE+ compliance

Tools

QRadar
Qualys
Entra ID
Intune
Defender
NinjaOne
ServiceNow
Sophos
Cisco Umbrella

Job description

Up to £75,000 PA

Well-established and highly profitable construction engineering business is seeking an experienced SecOps Engineer to join them on a permanent basis. This is a critical role within an organisation undergoing significant digital transformation, with ambitious growth and acquisition plans driving the need for secure, scalable and standardised IT services.

This role is ideal for a proactive security professional with strong technical expertise across Microsoft 365, cloud, infrastructure and network security. You will play a key part in implementing security controls, mitigating risk, improving the organisation's overall security posture and ensuring systems remain compliant with ISO 27001 and Cyber Essentials Plus (CE+).

Responsibilities:

  • Monitor security tools including SIEM (QRadar) and respond to threat detection alerts
  • Triage, analyse and prioritise security incidents via ServiceNow
  • Investigate root causes of security issues and design effective remediation solutions
  • Oversee Patch Management across servers, endpoints and infrastructure
  • Conduct vulnerability scans using Qualys, analyse findings and prioritise remediation activities
  • Take ownership of the Microsoft 365 security platform, proactively analysing the environment and remediating security recommendations across Microsoft Defender, Entra ID and Intune
  • Review, optimise and maintain Conditional Access Policies, Compliance Policies and Configuration Profiles to ensure user accounts and endpoint devices remain secure and compliant
  • Implement and continuously improve Microsoft 365 security controls, identity protection and endpoint compliance in line with Microsoft best practices
  • Support the organisation's ISO 27001 and Cyber Essentials Plus (CE+) compliance by implementing and maintaining appropriate Microsoft security controls
  • Manage end-user device (EUD) security through Microsoft Intune, Sophos and NinjaOne
  • Schedule and assess vulnerability scans on critical infrastructure
  • Maintain patching compliance for Windows OS, Microsoft 365 applications and third-party software
  • Collaborate with external SOC providers to investigate and respond to security incidents
  • Automate security processes and operational tasks using PowerShell, Batch or similar scripting languages
  • Produce post-incident reports, root cause analyses and security recommendations
  • Document SecOps processes and create knowledge base articles in line with best practices
  • Support infrastructure teams to deploy systems, strengthen security policies and manage security-related changes
  • Produce weekly security operations and compliance reports
  • Manage Cisco Umbrella web filtering and SSL inspection policies

Requirements:

  • Previous hands-on experience within a Security Operations (SecOps), Cyber Security or Incident Response role
  • Strong experience administering and securing Microsoft 365 environments
  • Hands-on experience with Microsoft Entra ID, Microsoft Intune, Microsoft Defender and Microsoft 365 security capabilities
  • Experience reviewing and optimising Conditional Access Policies, Compliance Policies and Configuration Profiles
  • Experience assessing Microsoft Secure Score and remediating Microsoft 365 security recommendations
  • Experience implementing Microsoft security controls to support ISO 27001 and Cyber Essentials Plus (CE+) compliance
  • Strong knowledge of Microsoft Windows security and system hardening
  • Working PowerShell scripting ability for automation tasks
  • Solid understanding of cloud security across Microsoft 365, Azure and AWS
  • Experience supporting enterprise IT infrastructure
  • Recognised security certifications such as Security+, CEH, Microsoft Security certifications or equivalent

Any experience with the following will be highly favoured:

  • Qualys Vulnerability Management
  • QRadar SIEM
  • Varonis
  • Microsoft Purview (Compliance, Information Protection or Data Loss Prevention)
  • ServiceNow
  • Network security knowledge covering TCP/IP, VPNs, routing, firewalls and network segmentation
  • Sophos security solutions

Initially 4 days per week onsite in Central London, reducing to 2 days per week after probation.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Hybrid SecOps Engineer - Microsoft 365 & ISO 27001
Hybrid SecOps Engineer - Microsoft 365 & ISO 27001

Context Recruitment • Greater London

On-site
GBP 68,000 - 83,000
Security & Infrastructure Engineer
Security & Infrastructure Engineer

Amplity • Chalfont St. Peter

Hybrid
GBP 65,000 - 90,000
Hybrid working arrangement
Senior Security Engineer
Senior Security Engineer

Sanderson • Greater London

On-site
GBP 70,000 - 90,000
Cyber Security Operations Specialist
Cyber Security Operations Specialist

Sanderson • West of England

Hybrid
GBP 120,000 - 150,000
Cyber Security Operations Specialist
Cyber Security Operations Specialist

Tank Recruitment • Bath

On-site
GBP 55,000 - 85,000
Security Operations Engineer
Security Operations Engineer

ComputAppoint • City Of London

Hybrid
GBP 65,000 - 74,000
Senior Security Architect
Senior Security Architect

develop • Greater London

Hybrid
GBP 90,000 - 110,000
Up to £110,000 salary
Benefits package
Remote or hybrid working
Senior Security Consultant
Senior Security Consultant

ITC Secure • Greater London

Hybrid
GBP 70,000 - 90,000
25 days annual leave
Private health insurance
Enhanced maternity and paternity leave
+2
Security Operations Architect
Security Operations Architect

Searchability • Greater London

Hybrid
GBP 68,000 - 83,000
Tailored professional development
Hybrid working arrangements
Access to industry experts
+1
Security Engineer
Security Engineer

Optima Recruitment • Merstham

On-site
GBP 45,000 - 55,000
25 days holiday
Bank holidays
Contributory pension