Security Operations Lead: Detection, IR & Forensics

Jobtailor

Greater London

On-site

GBP 70,000 - 110,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking an experienced Security Operations leader to own and evolve the detection and response program using Microsoft Sentinel. You will define detection strategies aligned with MITRE ATT&CK, onboard new data sources, and lead L3 incident response and forensic activities in a cloud/endpoint environment.

You will also oversee MSSP relationships, manage vulnerability programs, and contribute to incident communications and RCAs, ensuring strong written reporting and clear security

Qualifications

  • Deep Microsoft Sentinel experience with KQL, detection rule authoring and playbooks
  • Onboarding new data sources into a SIEM and scaling detection coverage
  • Hands-on incident response and digital forensics across cloud and endpoint
  • Sharing ownership of the incident management process
  • Applied MITRE ATT&CK knowledge used in detection engineering
  • Experience managing a vulnerability management program
  • Identity governance and access risk awareness
  • Managing MSSP/outsourced SOC relationships
  • Strong written incident reporting and RCA skills

Responsibilities

  • Own security operations: incident response, vulnerability management, and identity governance
  • Define and maintain the detection strategy mapped to MITRE ATT&CK
  • Review standards for Microsoft Sentinel content (rules, workbooks, playbooks)
  • Onboard log sources and systems into the detection pipeline
  • Translate threat intelligence into detection priorities
  • Lead MSSP/outsourced SOC relationship end-to-end
  • Oversee incident response (L3) and forensic analysis
  • Support CISO with incident communications and reporting

Skills

Microsoft Sentinel Experience
KQL Proficiency
Incident Response & Digital Forensics
Vulnerability Management Program
MSSP Management

Tools

Microsoft Sentinel
SIEM

Job description

Jobtailor is seeking an experienced Security Operations leader to own and evolve the detection and response program using Microsoft Sentinel. You will define detection strategies aligned with MITRE ATT&CK, onboard new data sources, and lead L3 incident response and forensic activities in a cloud/endpoint environment.

You will also oversee MSSP relationships, manage vulnerability programs, and contribute to incident communications and RCAs, ensuring strong written reporting and clear security

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior SecOps Architect: Detection, IR & Automation
Senior SecOps Architect: Detection, IR & Automation

Jobtailor • Greater London

On-site
GBP 120,000 - 170,000
Senior Threat Detection & Incident Response Engineer
Senior Threat Detection & Incident Response Engineer

Jobtailor • Cambridge

On-site
GBP 65,000 - 95,000
Head of Security Operations
Head of Security Operations

Jobtailor • Greater London

On-site
GBP 70,000 - 110,000
Detection Engineer
Detection Engineer

Cybanetix • Greater London

On-site
GBP 65,000 - 95,000
Hands-on experience with modern SIEM and XDR platforms
Exposure to real-world attacker behaviors
Opportunity for career advancement
Senior Detection and Response Engineer
Senior Detection and Response Engineer

Jobtailor • Cambridge

On-site
GBP 65,000 - 95,000
Senior Detection & Response Engineer - Telemetry & IR
Senior Detection & Response Engineer - Telemetry & IR

Techfellow Limited • Greater London

Hybrid
GBP 250,000 - 350,000
Senior Microsoft Sentinel Detection Engineer
Senior Microsoft Sentinel Detection Engineer

Sopra Steria • Farnborough

Hybrid
GBP 50,000 - 60,000
25 days annual leave
Health Shields
Life assurance
+1
Head of Security Operations Technology · London, Dubai · Hybrid
Head of Security Operations Technology · London, Dubai · Hybrid

Sokin • Greater London

Hybrid
GBP 120,000 - 180,000
Head of Security Operations
Head of Security Operations

Sokin • Harrow

On-site
GBP 120,000 - 170,000
Senior SOC Incident Lead & Detection Engineer
Senior SOC Incident Lead & Detection Engineer

Xact Placements Limited • Reading

Hybrid
GBP 50,000 - 60,000
Hybrid work arrangement
Competitive salary