Senior SOC Analyst London (Hybrid) £58,620 Package 24/7 Shift Pattern Permanent Nights / Weekends / Bank Holidays all worked from home. Day Shifts on Tuesdays and Thursday all worked from home. We're recruiting multiple Senior Cyber Security Analysts to join a BRAND NEW growing Security Operations team within a leading international technology and cyber security provider. This is far more than a traditional SOC role. You'll be involved in incident response, threat hunting, vulnerability management, detection engineering and proactive cyber defence activities across a modern Microsoft security environment. What You'll Be Doing Investigating and managing security incidents end-to-end Monitoring security events across cloud, endpoint, identity and network environments Threat hunting and proactive security investigations Querying and analysing data using KQL within Microsoft Sentinel Working with Microsoft Defender XDR technologies Supporting vulnerability management and security posture improvements Detection engineering, alert tuning and security tooling optimisation Producing technical reports and recommendations Supporting governance and compliance requirements Technology Environment Microsoft Sentinel Microsoft Defender XDR Defender for Endpoint Defender for Cloud Defender for Identity Defender for Cloud Apps Microsoft Intune Qualys AttackIQ XM Cyber We're Interested In Candidates with experience in: SOC Operations Security Monitoring Incident Response Threat Hunting Cyber Defence Vulnerability Management Security Operations Engineering You may currently be working as a: Senior SOC Analyst SOC Analyst Cyber Security Analyst Security Analyst Security Operations Analyst Incident Response Analyst Blue Team Analyst Experience with Microsoft Sentinel, KQL and the wider Microsoft security ecosystem would be highly advantageous. Package £48,654.60 base salary £9,965.40 shift allowance 4 on / 4 off 12-hour shifts Hybrid working Home-based night shifts Private medical cover Enhanced pension Life assurance Industry certifications and training Genuine career progression A fantastic opportunity to join a highly respected cyber security organisation supporting enterprise-scale environments and operating at the forefront of modern security operations.
14/07/2026
Full time
Senior SOC Analyst London (Hybrid) £58,620 Package 24/7 Shift Pattern Permanent Nights / Weekends / Bank Holidays all worked from home. Day Shifts on Tuesdays and Thursday all worked from home. We're recruiting multiple Senior Cyber Security Analysts to join a BRAND NEW growing Security Operations team within a leading international technology and cyber security provider. This is far more than a traditional SOC role. You'll be involved in incident response, threat hunting, vulnerability management, detection engineering and proactive cyber defence activities across a modern Microsoft security environment. What You'll Be Doing Investigating and managing security incidents end-to-end Monitoring security events across cloud, endpoint, identity and network environments Threat hunting and proactive security investigations Querying and analysing data using KQL within Microsoft Sentinel Working with Microsoft Defender XDR technologies Supporting vulnerability management and security posture improvements Detection engineering, alert tuning and security tooling optimisation Producing technical reports and recommendations Supporting governance and compliance requirements Technology Environment Microsoft Sentinel Microsoft Defender XDR Defender for Endpoint Defender for Cloud Defender for Identity Defender for Cloud Apps Microsoft Intune Qualys AttackIQ XM Cyber We're Interested In Candidates with experience in: SOC Operations Security Monitoring Incident Response Threat Hunting Cyber Defence Vulnerability Management Security Operations Engineering You may currently be working as a: Senior SOC Analyst SOC Analyst Cyber Security Analyst Security Analyst Security Operations Analyst Incident Response Analyst Blue Team Analyst Experience with Microsoft Sentinel, KQL and the wider Microsoft security ecosystem would be highly advantageous. Package £48,654.60 base salary £9,965.40 shift allowance 4 on / 4 off 12-hour shifts Hybrid working Home-based night shifts Private medical cover Enhanced pension Life assurance Industry certifications and training Genuine career progression A fantastic opportunity to join a highly respected cyber security organisation supporting enterprise-scale environments and operating at the forefront of modern security operations.
Senior SOC Analyst Bristol (Hybrid) £58,620 Package 24/7 Shift Pattern Permanent Nights / Weekends / Bank Holidays all worked from home. Day Shifts on Tuesdays and Thursday all worked from home. We're recruiting multiple Senior Cyber Security Analysts to join a BRAND NEW growing Security Operations team within a leading international technology and cyber security provider. This is far more than a traditional SOC role. You'll be involved in incident response, threat hunting, vulnerability management, detection engineering and proactive cyber defence activities across a modern Microsoft security environment. What You'll Be Doing Investigating and managing security incidents end-to-end Monitoring security events across cloud, endpoint, identity and network environments Threat hunting and proactive security investigations Querying and analysing data using KQL within Microsoft Sentinel Working with Microsoft Defender XDR technologies Supporting vulnerability management and security posture improvements Detection engineering, alert tuning and security tooling optimisation Producing technical reports and recommendations Supporting governance and compliance requirements Technology Environment Microsoft Sentinel Microsoft Defender XDR Defender for Endpoint Defender for Cloud Defender for Identity Defender for Cloud Apps Microsoft Intune Qualys AttackIQ XM Cyber We're Interested In Candidates with experience in: SOC Operations Security Monitoring Incident Response Threat Hunting Cyber Defence Vulnerability Management Security Operations Engineering You may currently be working as a: Senior SOC Analyst SOC Analyst Cyber Security Analyst Security Analyst Security Operations Analyst Incident Response Analyst Blue Team Analyst Experience with Microsoft Sentinel, KQL and the wider Microsoft security ecosystem would be highly advantageous. Package £48,654.60 base salary £9,965.40 shift allowance 4 on / 4 off 12-hour shifts Hybrid working Home-based night shifts Private medical cover Enhanced pension Life assurance Industry certifications and training Genuine career progression A fantastic opportunity to join a highly respected cyber security organisation supporting enterprise-scale environments and operating at the forefront of modern security operations.
14/07/2026
Full time
Senior SOC Analyst Bristol (Hybrid) £58,620 Package 24/7 Shift Pattern Permanent Nights / Weekends / Bank Holidays all worked from home. Day Shifts on Tuesdays and Thursday all worked from home. We're recruiting multiple Senior Cyber Security Analysts to join a BRAND NEW growing Security Operations team within a leading international technology and cyber security provider. This is far more than a traditional SOC role. You'll be involved in incident response, threat hunting, vulnerability management, detection engineering and proactive cyber defence activities across a modern Microsoft security environment. What You'll Be Doing Investigating and managing security incidents end-to-end Monitoring security events across cloud, endpoint, identity and network environments Threat hunting and proactive security investigations Querying and analysing data using KQL within Microsoft Sentinel Working with Microsoft Defender XDR technologies Supporting vulnerability management and security posture improvements Detection engineering, alert tuning and security tooling optimisation Producing technical reports and recommendations Supporting governance and compliance requirements Technology Environment Microsoft Sentinel Microsoft Defender XDR Defender for Endpoint Defender for Cloud Defender for Identity Defender for Cloud Apps Microsoft Intune Qualys AttackIQ XM Cyber We're Interested In Candidates with experience in: SOC Operations Security Monitoring Incident Response Threat Hunting Cyber Defence Vulnerability Management Security Operations Engineering You may currently be working as a: Senior SOC Analyst SOC Analyst Cyber Security Analyst Security Analyst Security Operations Analyst Incident Response Analyst Blue Team Analyst Experience with Microsoft Sentinel, KQL and the wider Microsoft security ecosystem would be highly advantageous. Package £48,654.60 base salary £9,965.40 shift allowance 4 on / 4 off 12-hour shifts Hybrid working Home-based night shifts Private medical cover Enhanced pension Life assurance Industry certifications and training Genuine career progression A fantastic opportunity to join a highly respected cyber security organisation supporting enterprise-scale environments and operating at the forefront of modern security operations.
Senior SOC Analyst Leeds (Hybrid) £58,620 Package 24/7 Shift Pattern Permanent Nights / Weekends / Bank Holidays all worked from home. Day Shifts on Tuesdays and Thursday all worked from home. We're recruiting multiple Senior Cyber Security Analysts to join a BRAND NEW growing Security Operations team within a leading international technology and cyber security provider. This is far more than a traditional SOC role. You'll be involved in incident response, threat hunting, vulnerability management, detection engineering and proactive cyber defence activities across a modern Microsoft security environment. What You'll Be Doing Investigating and managing security incidents end-to-end Monitoring security events across cloud, endpoint, identity and network environments Threat hunting and proactive security investigations Querying and analysing data using KQL within Microsoft Sentinel Working with Microsoft Defender XDR technologies Supporting vulnerability management and security posture improvements Detection engineering, alert tuning and security tooling optimisation Producing technical reports and recommendations Supporting governance and compliance requirements Technology Environment Microsoft Sentinel Microsoft Defender XDR Defender for Endpoint Defender for Cloud Defender for Identity Defender for Cloud Apps Microsoft Intune Qualys AttackIQ XM Cyber We're Interested In Candidates with experience in: SOC Operations Security Monitoring Incident Response Threat Hunting Cyber Defence Vulnerability Management Security Operations Engineering You may currently be working as a: Senior SOC Analyst SOC Analyst Cyber Security Analyst Security Analyst Security Operations Analyst Incident Response Analyst Blue Team Analyst Experience with Microsoft Sentinel, KQL and the wider Microsoft security ecosystem would be highly advantageous. Package £48,654.60 base salary £9,965.40 shift allowance 4 on / 4 off 12-hour shifts Hybrid working Home-based night shifts Private medical cover Enhanced pension Life assurance Industry certifications and training Genuine career progression A fantastic opportunity to join a highly respected cyber security organisation supporting enterprise-scale environments and operating at the forefront of modern security operations.
14/07/2026
Full time
Senior SOC Analyst Leeds (Hybrid) £58,620 Package 24/7 Shift Pattern Permanent Nights / Weekends / Bank Holidays all worked from home. Day Shifts on Tuesdays and Thursday all worked from home. We're recruiting multiple Senior Cyber Security Analysts to join a BRAND NEW growing Security Operations team within a leading international technology and cyber security provider. This is far more than a traditional SOC role. You'll be involved in incident response, threat hunting, vulnerability management, detection engineering and proactive cyber defence activities across a modern Microsoft security environment. What You'll Be Doing Investigating and managing security incidents end-to-end Monitoring security events across cloud, endpoint, identity and network environments Threat hunting and proactive security investigations Querying and analysing data using KQL within Microsoft Sentinel Working with Microsoft Defender XDR technologies Supporting vulnerability management and security posture improvements Detection engineering, alert tuning and security tooling optimisation Producing technical reports and recommendations Supporting governance and compliance requirements Technology Environment Microsoft Sentinel Microsoft Defender XDR Defender for Endpoint Defender for Cloud Defender for Identity Defender for Cloud Apps Microsoft Intune Qualys AttackIQ XM Cyber We're Interested In Candidates with experience in: SOC Operations Security Monitoring Incident Response Threat Hunting Cyber Defence Vulnerability Management Security Operations Engineering You may currently be working as a: Senior SOC Analyst SOC Analyst Cyber Security Analyst Security Analyst Security Operations Analyst Incident Response Analyst Blue Team Analyst Experience with Microsoft Sentinel, KQL and the wider Microsoft security ecosystem would be highly advantageous. Package £48,654.60 base salary £9,965.40 shift allowance 4 on / 4 off 12-hour shifts Hybrid working Home-based night shifts Private medical cover Enhanced pension Life assurance Industry certifications and training Genuine career progression A fantastic opportunity to join a highly respected cyber security organisation supporting enterprise-scale environments and operating at the forefront of modern security operations.
Senior Infrastructure AnalystApplylocations: Bristol: Londontime type: Full timeposted on: Posted Todayjob requisition id: JR101996 The role: We are looking for a Senior Cloud Infrastructure Analyst to join our IT department in Bristol.At Simmons & Simmons, technology is central to delivering exceptional client service. We are seeking a talented and motivated Senior Cloud Infrastructure Analyst to join our Platforms team and help build, automate and operate the Azure platform underpinning our applications and services.This is a hands-on engineering role focused on designing and delivering secure, scalable and resilient cloud solutions in Microsoft Azure, using Infrastructure as Code and CI/CD automation as the default approach. You will work closely with architects, security and application teams to implement cloud platform patterns and enable delivery teams to deploy safely and consistently. You will be required to act as senior technical authority within the platforms team, supporting decision-making, mentoring engineers, and shaping the Azure roadmap. What will you do: Azure Infrastructure as Code (IaC) & CI/CD automation Build, deploy, and maintain Azure infrastructure using IaC (Bicep and/or Terraform) with peer review and version control. Strong familiarity working in IaC and pipelines to ensure quality, security and adherence to baseline standards. Cloud reliability, operations & incident/problem support (engineering-led) Act as a senior escalation point for complex Azure platform incidents; leading to troubleshoot, perform root cause analysis, and implement sustainable fixes (automation over repeated manual intervention). Monitor and improve platform health using Azure observability tooling (e.g., Azure Monitor, Log Analytics/KQL, Application Insights, Science Logic), and improve alerting and diagnostics. Lead reliability and resilience improvements such as such as performance tuning, resource optimisation, cost optimization using FinOps and provide availability enhancements, aligned to our service- level expectations. A senior analyst is expected to be a point of contact and escalation at all times, taking ownership of incident management, while providing 3rd & 4th level and technical support. Any experience working within the Agile framework using Scrum. Security, compliance & governance Embed security controls and compliance checks into delivery pipelines (DevSecOps approach), ensuring cloud systems are configured securely and remain compliant. Contribute to platform governance initiatives such as naming/tagging conventions, logging standards, Key Vault/secret patterns, and controlled change via Github Push/Pull requests. Work closely with Security and CISO stakeholders and the wider networks team to maintain a strong and compliant security posture across our Azure public cloud subscription. Delivery collaboration & technical project contribution Collaborate with stakeholders, architects and engineers to translate requirements into Azure designs and deliver working solutions. Contribute to planning and execution of cloud-focused initiatives, identifying risks and dependencies early and supporting smooth transition into support. Maintain clear technical documentation (design notes, runbooks, standard operating procedures) in the team's knowledge base. What we are looking for: The role deliberately covers a relatively broad brief of technologies, targeted at enabling effective communication and efficient working practices. We would expect the role holder to be able to demonstrate a skill base that spans a range of the following topics and, where necessary, to demonstrate the aptitude and desire to develop to meet the entire brief. Knowledge of a range of enterprise IT application technologies, including a demonstrated track record in operating and administering or working with infrastructure applications as part of the: Microsoft Application Stack such as Exchange 365; Active Directory, AD connect, Azure site recovery (ASR) and Azure Virtual Desktop (AVD) and Azure SQL. Experience of working with VMware vSphere, HPE Servers & Storage, upgrades and maintenance procedures. Hands-on experience engineering solutions in Microsoft Azure, including a solid understanding of Azure IaaS and PaaS services (e.g., VMs, Storage, App Services, Front Door, API Management, Azure Functions, Azure SQL, Azure Networking). Strong experience with Infrastructure as Code in either (Bicep and/or Terraform; ARM knowledge acceptable where relevant). Practical experience with Azure DevOps (Pipelines, Repos, CI/CD concepts) and Git-based version control. Azure networking knowledge including VNETs, vWAN, ExpressRoute, VPN gateways, hub-and-spoke, and traffic management concepts. Azure security fundamentals including Managed Identities, Key Vault, Conditional Access, Defender for Cloud/Security Centre. Strong scripting capability in PowerShell (and/or Bash), and the ability to automate operational tasks and deployments. Strong troubleshooting mindset: diagnosing complex issues and driving them to resolution with appropriate escalation and RCA. Clear communication skills, including the ability to explain technical topics in plain English in a professional services environment. A Strong problem-solver with proactive, engineering-led mindset. Self-motivated technical lead and mentor. Comfortable working as a senior engineer in a collaborative, geographically diverse and inclusive team. Preferably either: 5-years relevant experience working in a similar role, or a qualification in Computer Science or Engineering or Microsoft accredited Azure Certifications (e.g., Azure Administrator / DevOps / Cloud Engineering) and relevant experience working in a similar role. Excellent Knowledge of the Azure and Windows Stack. Career Level: The career level assigned to this role is level 3. The career level framework provides a formal structure for the business services functions at the firm. The framework, which ranges from level 1 to level 7, clearly defines the responsibilities, skills and competencies required at each level. Here at Simmons & Simmons: At Simmons, we are proud of our collaborative, open and non-hierarchical culture, where everyone is treated with respect and dignity and the wellbeing of our people is paramount. Our dynamic minds work as one integrated team, partnering with leading organisations on inspirational and thought-provoking projects that matter. From day one, irrespective of job title, qualification or background, everyone's voice is heard, and you are encouraged to have an enquiring mind and share ideas that drive the firm forward. Through innovative learning and development opportunities, you will have a platform to excel, exceed your career ambitions, and achieve things you never thought possible. Some key information: We offer a competitive package including bonuses dependant on role/level, private medical insurance and pension contribution. Our global skills academy provides our people, regardless of their role and location, with excellent learning opportunities (including live workshops, podcasts, short videos and practical learning experiences). We have adopted a hybrid working approach with a requirement for a minimum of three days in the office with flexibility dependant on role/team/client demands. We are proud to rank as a Times Top 50 Employer for Gender Equality, a Stonewall Top Global Employer, and a Top 75 Employer for Social Mobility. We have a range of social and sports committees, summer and winter parties and monthly get togethers. We have a range of diversity networks to connect people and celebrate our differences which is integral to our inclusive culture. All UK offices have their own artwork collections - including Damien Hirst and Tracey Emin pieces in the London office. We have a long-standing history in supporting the art community especially up-and-coming artists. We have recently introduced a Strategic Advisory Council which is a mix of associates and business services who will propose strategic initiatives that align with our firm's mission and support the delivery of our business plan, shaping the future of our next-generation law firm. Our in-house generative AI tool, Percy, won the 'Innovation in Automation and AI Tools' category at the 2024 FT Innovative Lawyers Europe Awards. This achievement highlights our commitment to technological innovation and client service. We have been commended in The Times Best Law Firms 2026 across three categories: construction, employment, and intellectual property. Our profile is highly positive, highlighting our sector specialisms and notable case and transactional work. Equal opportunities: We are committed to fostering equality, diversity and inclusion within our firm and to ensuring equal employment opportunities. We believe that this commitment creates a vibrant and rewarding work environment. We are therefore committed to: Upholding equal opportunities, regardless of race, ethnicity, religion, belief, age, disability, sexual orientation, sex, gender reassignment, gender identity, marital status, or pregnancy, including maternity and paternity. This commitment extends to addressing any instances of perceived or associative discrimination and harassment. We also ensure fair treatment during recruitment and selection processes for those who are serving or have served in the armed forces, along with their families. Accommodating requests for flexible working arrangements whenever possible. We encourage you to discuss your needs with us if this is something you require. Making our roles accessible to individuals with diverse abilities. If you need any reasonable adjustments during the recruitment process, please let us know so we can meet your needs. We offer a range of employee networks to support our colleagues . click apply for full job details
11/07/2026
Full time
Senior Infrastructure AnalystApplylocations: Bristol: Londontime type: Full timeposted on: Posted Todayjob requisition id: JR101996 The role: We are looking for a Senior Cloud Infrastructure Analyst to join our IT department in Bristol.At Simmons & Simmons, technology is central to delivering exceptional client service. We are seeking a talented and motivated Senior Cloud Infrastructure Analyst to join our Platforms team and help build, automate and operate the Azure platform underpinning our applications and services.This is a hands-on engineering role focused on designing and delivering secure, scalable and resilient cloud solutions in Microsoft Azure, using Infrastructure as Code and CI/CD automation as the default approach. You will work closely with architects, security and application teams to implement cloud platform patterns and enable delivery teams to deploy safely and consistently. You will be required to act as senior technical authority within the platforms team, supporting decision-making, mentoring engineers, and shaping the Azure roadmap. What will you do: Azure Infrastructure as Code (IaC) & CI/CD automation Build, deploy, and maintain Azure infrastructure using IaC (Bicep and/or Terraform) with peer review and version control. Strong familiarity working in IaC and pipelines to ensure quality, security and adherence to baseline standards. Cloud reliability, operations & incident/problem support (engineering-led) Act as a senior escalation point for complex Azure platform incidents; leading to troubleshoot, perform root cause analysis, and implement sustainable fixes (automation over repeated manual intervention). Monitor and improve platform health using Azure observability tooling (e.g., Azure Monitor, Log Analytics/KQL, Application Insights, Science Logic), and improve alerting and diagnostics. Lead reliability and resilience improvements such as such as performance tuning, resource optimisation, cost optimization using FinOps and provide availability enhancements, aligned to our service- level expectations. A senior analyst is expected to be a point of contact and escalation at all times, taking ownership of incident management, while providing 3rd & 4th level and technical support. Any experience working within the Agile framework using Scrum. Security, compliance & governance Embed security controls and compliance checks into delivery pipelines (DevSecOps approach), ensuring cloud systems are configured securely and remain compliant. Contribute to platform governance initiatives such as naming/tagging conventions, logging standards, Key Vault/secret patterns, and controlled change via Github Push/Pull requests. Work closely with Security and CISO stakeholders and the wider networks team to maintain a strong and compliant security posture across our Azure public cloud subscription. Delivery collaboration & technical project contribution Collaborate with stakeholders, architects and engineers to translate requirements into Azure designs and deliver working solutions. Contribute to planning and execution of cloud-focused initiatives, identifying risks and dependencies early and supporting smooth transition into support. Maintain clear technical documentation (design notes, runbooks, standard operating procedures) in the team's knowledge base. What we are looking for: The role deliberately covers a relatively broad brief of technologies, targeted at enabling effective communication and efficient working practices. We would expect the role holder to be able to demonstrate a skill base that spans a range of the following topics and, where necessary, to demonstrate the aptitude and desire to develop to meet the entire brief. Knowledge of a range of enterprise IT application technologies, including a demonstrated track record in operating and administering or working with infrastructure applications as part of the: Microsoft Application Stack such as Exchange 365; Active Directory, AD connect, Azure site recovery (ASR) and Azure Virtual Desktop (AVD) and Azure SQL. Experience of working with VMware vSphere, HPE Servers & Storage, upgrades and maintenance procedures. Hands-on experience engineering solutions in Microsoft Azure, including a solid understanding of Azure IaaS and PaaS services (e.g., VMs, Storage, App Services, Front Door, API Management, Azure Functions, Azure SQL, Azure Networking). Strong experience with Infrastructure as Code in either (Bicep and/or Terraform; ARM knowledge acceptable where relevant). Practical experience with Azure DevOps (Pipelines, Repos, CI/CD concepts) and Git-based version control. Azure networking knowledge including VNETs, vWAN, ExpressRoute, VPN gateways, hub-and-spoke, and traffic management concepts. Azure security fundamentals including Managed Identities, Key Vault, Conditional Access, Defender for Cloud/Security Centre. Strong scripting capability in PowerShell (and/or Bash), and the ability to automate operational tasks and deployments. Strong troubleshooting mindset: diagnosing complex issues and driving them to resolution with appropriate escalation and RCA. Clear communication skills, including the ability to explain technical topics in plain English in a professional services environment. A Strong problem-solver with proactive, engineering-led mindset. Self-motivated technical lead and mentor. Comfortable working as a senior engineer in a collaborative, geographically diverse and inclusive team. Preferably either: 5-years relevant experience working in a similar role, or a qualification in Computer Science or Engineering or Microsoft accredited Azure Certifications (e.g., Azure Administrator / DevOps / Cloud Engineering) and relevant experience working in a similar role. Excellent Knowledge of the Azure and Windows Stack. Career Level: The career level assigned to this role is level 3. The career level framework provides a formal structure for the business services functions at the firm. The framework, which ranges from level 1 to level 7, clearly defines the responsibilities, skills and competencies required at each level. Here at Simmons & Simmons: At Simmons, we are proud of our collaborative, open and non-hierarchical culture, where everyone is treated with respect and dignity and the wellbeing of our people is paramount. Our dynamic minds work as one integrated team, partnering with leading organisations on inspirational and thought-provoking projects that matter. From day one, irrespective of job title, qualification or background, everyone's voice is heard, and you are encouraged to have an enquiring mind and share ideas that drive the firm forward. Through innovative learning and development opportunities, you will have a platform to excel, exceed your career ambitions, and achieve things you never thought possible. Some key information: We offer a competitive package including bonuses dependant on role/level, private medical insurance and pension contribution. Our global skills academy provides our people, regardless of their role and location, with excellent learning opportunities (including live workshops, podcasts, short videos and practical learning experiences). We have adopted a hybrid working approach with a requirement for a minimum of three days in the office with flexibility dependant on role/team/client demands. We are proud to rank as a Times Top 50 Employer for Gender Equality, a Stonewall Top Global Employer, and a Top 75 Employer for Social Mobility. We have a range of social and sports committees, summer and winter parties and monthly get togethers. We have a range of diversity networks to connect people and celebrate our differences which is integral to our inclusive culture. All UK offices have their own artwork collections - including Damien Hirst and Tracey Emin pieces in the London office. We have a long-standing history in supporting the art community especially up-and-coming artists. We have recently introduced a Strategic Advisory Council which is a mix of associates and business services who will propose strategic initiatives that align with our firm's mission and support the delivery of our business plan, shaping the future of our next-generation law firm. Our in-house generative AI tool, Percy, won the 'Innovation in Automation and AI Tools' category at the 2024 FT Innovative Lawyers Europe Awards. This achievement highlights our commitment to technological innovation and client service. We have been commended in The Times Best Law Firms 2026 across three categories: construction, employment, and intellectual property. Our profile is highly positive, highlighting our sector specialisms and notable case and transactional work. Equal opportunities: We are committed to fostering equality, diversity and inclusion within our firm and to ensuring equal employment opportunities. We believe that this commitment creates a vibrant and rewarding work environment. We are therefore committed to: Upholding equal opportunities, regardless of race, ethnicity, religion, belief, age, disability, sexual orientation, sex, gender reassignment, gender identity, marital status, or pregnancy, including maternity and paternity. This commitment extends to addressing any instances of perceived or associative discrimination and harassment. We also ensure fair treatment during recruitment and selection processes for those who are serving or have served in the armed forces, along with their families. Accommodating requests for flexible working arrangements whenever possible. We encourage you to discuss your needs with us if this is something you require. Making our roles accessible to individuals with diverse abilities. If you need any reasonable adjustments during the recruitment process, please let us know so we can meet your needs. We offer a range of employee networks to support our colleagues . click apply for full job details
At IBM Consulting UK FutureNow, you'll build a career at the forefront of hybrid cloud and AI, working with leading clients across the public and private sectors. You'll collaborate with top industry professionals, gain hands on experience with cutting edge technologies, and deliver solutions that create real business impact. From day one, you'll work on meaningful, high profile programmes that stretch your skills and accelerate your growth. We invest heavily in you-supporting continuous learning, in demand skills development, and long term career progression. You'll thrive in a flexible, inclusive environment that values curiosity, encourages reinvention, and recognises what makes you unique. We offer: Tools and policies to support your work-life balance from flexible working approaches, sabbatical programs, paid paternity leave, maternity leave and an innovative maternity returners scheme More traditional benefits, such as 25 days holiday (in addition to public holidays), private medical, dental & optical cover, online shopping discounts, an Employee Assistance Program, life assurance and a group pension plan through salary sacrifice. In this role, you'll work in one of our IBM Consulting Client Innovation Centers (Delivery Centers), where we deliver deep technical and industry expertise to a wide range of public and private sector clients around the world. Our delivery centers offer our clients locally based skills and technical expertise to drive innovation and adoption of new technology. Your role and responsibilities As a Technical Consultant specialising in Threat Detection, Response & Intelligence, you will support and lead the monitoring, detection, and initial response to cyber security threats within a 24 7 SOC consulting environment. You will play a key role in maintaining operational excellence on shift, supporting incident investigation, and ensuring consistent delivery of high-quality security operations across client environments. Working across SIEM platforms, security tooling, and incident response workflows, you will help ensure threats are identified, triaged, and escalated effectively, while contributing to the continuous improvement of SOC processes and capabilities. This is a hands on operational role with responsibility for incident leadership, team support, and quality assurance, alongside exposure to client environments and senior stakeholders. Key Responsibilities Monitor, triage, and investigate security alerts and incidents across a range of SIEM and security platforms Lead or support incident response activities, including: Containment coordination Escalation to relevant teams Act as a senior presence on shift, supporting Tier 1/2 analysts and ensuring smooth SOC operations Drive incident quality and consistency, ensuring playbooks and procedures are followed Support major incident initiation and coordination, including communication across technical and non-technical stakeholders Analyse security events and identify: Patterns Threat behaviours Opportunities for improvement Contribute to playbook development and refinement, improving SOC efficiency and response capability Work with detection and engineering teams to: Reduce false positives Support operational effectiveness Produce clear and structured incident reports and handovers Participate in shift handovers, retrospectives, and continuous improvement activities Support client interactions where required, providing updates and operational insights Required education None Preferred education Bachelor's Degree Required Professional and/or Technical Expertise Proven experience working in a SOC environment (L2 / L3 level) within a 24 7 operational setting Strong experience with SIEM platforms, such as: Microsoft Sentinel QRadar Splunk Elastic or similar Practical experience in: Incident triage and investigation Security event analysis Alert validation and escalation Understanding of: Incident response processes and workflows Exposure to security tooling, such as: EDR/XDR platforms Network security technologies Identity and access systems Ability to interpret logs and identify suspicious behaviour across: Networks Cloud environments Strong communication skills, with the ability to clearly articulate incidents and risks Experience working in client-facing or service-based environments This role is subject to pre employment screening in line with the UK Government's Baseline Personnel Security Standard (BPSS). An additional range of Personal Security Controls referred to as National Security Vetting (NVS) may apply; this could include meeting the eligibility requirements for The Security Check (SC) or Developed Vetting (DV). Preferred Professional/Technical Expertise Experience acting as a shift lead or senior escalation point within a SOC Exposure to threat hunting or detection improvement activities Experience working with: MITRE ATT&CK Familiarity with SOAR platforms and automated response workflows Relevant certifications such as: SC-200 GCIH / GIAC Experience working in regulated or public sector environments Understanding of SOC performance metrics and continuous improvement approaches IBM is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin, genetics, pregnancy, disability, neurodivergence, age, or other characteristics protected by the applicable law. IBM is also committed to compliance with all fair employment practices regarding citizenship and immigration status.
05/07/2026
Full time
At IBM Consulting UK FutureNow, you'll build a career at the forefront of hybrid cloud and AI, working with leading clients across the public and private sectors. You'll collaborate with top industry professionals, gain hands on experience with cutting edge technologies, and deliver solutions that create real business impact. From day one, you'll work on meaningful, high profile programmes that stretch your skills and accelerate your growth. We invest heavily in you-supporting continuous learning, in demand skills development, and long term career progression. You'll thrive in a flexible, inclusive environment that values curiosity, encourages reinvention, and recognises what makes you unique. We offer: Tools and policies to support your work-life balance from flexible working approaches, sabbatical programs, paid paternity leave, maternity leave and an innovative maternity returners scheme More traditional benefits, such as 25 days holiday (in addition to public holidays), private medical, dental & optical cover, online shopping discounts, an Employee Assistance Program, life assurance and a group pension plan through salary sacrifice. In this role, you'll work in one of our IBM Consulting Client Innovation Centers (Delivery Centers), where we deliver deep technical and industry expertise to a wide range of public and private sector clients around the world. Our delivery centers offer our clients locally based skills and technical expertise to drive innovation and adoption of new technology. Your role and responsibilities As a Technical Consultant specialising in Threat Detection, Response & Intelligence, you will support and lead the monitoring, detection, and initial response to cyber security threats within a 24 7 SOC consulting environment. You will play a key role in maintaining operational excellence on shift, supporting incident investigation, and ensuring consistent delivery of high-quality security operations across client environments. Working across SIEM platforms, security tooling, and incident response workflows, you will help ensure threats are identified, triaged, and escalated effectively, while contributing to the continuous improvement of SOC processes and capabilities. This is a hands on operational role with responsibility for incident leadership, team support, and quality assurance, alongside exposure to client environments and senior stakeholders. Key Responsibilities Monitor, triage, and investigate security alerts and incidents across a range of SIEM and security platforms Lead or support incident response activities, including: Containment coordination Escalation to relevant teams Act as a senior presence on shift, supporting Tier 1/2 analysts and ensuring smooth SOC operations Drive incident quality and consistency, ensuring playbooks and procedures are followed Support major incident initiation and coordination, including communication across technical and non-technical stakeholders Analyse security events and identify: Patterns Threat behaviours Opportunities for improvement Contribute to playbook development and refinement, improving SOC efficiency and response capability Work with detection and engineering teams to: Reduce false positives Support operational effectiveness Produce clear and structured incident reports and handovers Participate in shift handovers, retrospectives, and continuous improvement activities Support client interactions where required, providing updates and operational insights Required education None Preferred education Bachelor's Degree Required Professional and/or Technical Expertise Proven experience working in a SOC environment (L2 / L3 level) within a 24 7 operational setting Strong experience with SIEM platforms, such as: Microsoft Sentinel QRadar Splunk Elastic or similar Practical experience in: Incident triage and investigation Security event analysis Alert validation and escalation Understanding of: Incident response processes and workflows Exposure to security tooling, such as: EDR/XDR platforms Network security technologies Identity and access systems Ability to interpret logs and identify suspicious behaviour across: Networks Cloud environments Strong communication skills, with the ability to clearly articulate incidents and risks Experience working in client-facing or service-based environments This role is subject to pre employment screening in line with the UK Government's Baseline Personnel Security Standard (BPSS). An additional range of Personal Security Controls referred to as National Security Vetting (NVS) may apply; this could include meeting the eligibility requirements for The Security Check (SC) or Developed Vetting (DV). Preferred Professional/Technical Expertise Experience acting as a shift lead or senior escalation point within a SOC Exposure to threat hunting or detection improvement activities Experience working with: MITRE ATT&CK Familiarity with SOAR platforms and automated response workflows Relevant certifications such as: SC-200 GCIH / GIAC Experience working in regulated or public sector environments Understanding of SOC performance metrics and continuous improvement approaches IBM is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin, genetics, pregnancy, disability, neurodivergence, age, or other characteristics protected by the applicable law. IBM is also committed to compliance with all fair employment practices regarding citizenship and immigration status.
Job Description To support the Head of Security Operations in delivering effective day-to-day security operations, ensuring AJ Bell maintains the appropriate capability to detect, investigate and respond to security events and incidents. The Security Operations Technical Lead is responsible for ensuring that security operations activities are executed efficiently, consistently and in line with defined SLAs and operational standards, through hands on technical leadership across SOC, Incident Response, Threat Intelligence, Insider Risk and Vulnerability Management. This role acts as a senior technical escalation point, supporting complex investigations and driving improvements in detection, response, automation and operational processes. The role holder is expected to lead through expertise, supporting analysts and ensuring Security Operations operates with discipline, quality and continuous improvement. The key responsibilities of the role are: Act as the primary technical escalation point for security events and incidents identified by the Security Operations team. Support the Head of Security Operations in ensuring AJ Bell has the appropriate capability to detect and respond to security events and incidents. Oversee the day to day execution of security operations, ensuring alerts and incidents are handled in line with defined processes and SLAs. Ensure security operations SLAs and OLAs are met, including alert triage, escalation and incident response timelines, highlighting and addressing risks where required. Ensure adherence to our KRI and KPI's and any variation in these are raised to the Head of Security Operations. Provide hands on support in the investigation and response to security incidents, including endpoint, identity, network, cloud and insider related threats. Ensure consistent execution and continuous improvement of incident response playbooks and operational runbooks, validating them through real incidents and simulations. Support the optimisation and tuning of security monitoring and detection capabilities, including SIEM and endpoint tooling, to improve signal quality and reduce false positives. Support the execution of the end to end vulnerability management process, including validation of findings and tracking remediation activities. Work closely with MSSP and security vendors to ensure effective delivery of security operations services. Challenge and validate vendor outputs, driving operational efficiency, quality improvements and better use of tooling capabilities. Actively design and implement automation and orchestration to reduce manual effort, repetitive or high volume tasks, improve response times and increase consistency across security operations processes. Work with the Security Engineering team to ensure tooling, logging and detection gaps are identified and addressed. Support the effective operation of 24x7 security monitoring, including coordination with third party providers. Contribute to the development and delivery of operational MI and reporting, ensuring accuracy and insight into security trends and performance. Maintain visibility of security incidents, trends and operational risks, escalating issues where required. Technical Skills: Strong hands on experience of Security Operations tools and capabilities, including SIEM and SOAR platforms (e.g. Sentinel, ServiceNow, Splunk SOAR, Cortex), Endpoint Detection & Response (EDR/XDR), Strong hands on experience of Threat Intelligence platforms (e.g. Recorded Future, Doppel, ZeroFox, Google Threat Intelligence), Vulnerability management solutions (e.g. Tenable, Rapid7), and Insider Risk and DLP tools (e.g. Purview, Netskope). Strong hands on experience with Network security solutions like Next Gen Firewalls, Network Anomaly, WAF & DDoS solutions. Experience of leading and responding to Cyber Incident Response aligned to NIST Knowledge of threat detection techniques and use case development Experience of applying threat intelligence in an operational context Strong experience with vulnerability management tools and processes Strong awareness of cloud services and supporting security controls and monitoring capabilities Working knowledge of Microsoft security stack (Defender, Sentinel, Purview), Active Directory and Azure AD, Windows and Linux environments. Experience with data loss prevention and insider risk tooling advantageous Hands on experience with automation and scripting (e.g. PowerShell, Python) highly desirable Competence Experience working within recognised Information Security frameworks and best practices such as ISO27001, NIST, MITRE ATT&CK Knowledge of relevant regulatory requirements (e.g. GDPR, FCA/PRA) Experience in an Information Security role gained in a financial services environment preferred Experience working in a Security Operations role for a minimum 7 years and operating within a Lead / Senior Analyst role for at least 3 years. Knowledge & Skills Strong analytical and investigative capability Ability to work under pressure and manage multiple concurrent incidents and priorities Strong ownership of tasks, attention to detail and follow through to conclusion Ability to provide technical leadership without formal line management responsibility Ability to challenge approach, tooling and processes to improve operational effectiveness Structured, self starting and able to work under own initiative Effective communication skills, both written and verbal Ability to plan, organise and deliver tasks with minimal supervision Collaborative approach to working with analysts, engineering teams and external partners Strong focus on quality, consistency and continuous improvement About AJ Bell At AJ Bell, we believe investing should feel good. Whether you're looking for an ISA, pension or dealing account, whether you want to invest with the help of a financial adviser or do it yourself, we have easy to use solutions to suit people from all walks of life. We're one of the UK's fastest growing investment platform businesses, trusted by everyone from professional financial advisers to first time investors. Today, over 723,000 customers trust us to manage more than £108.7 billion of assets. By continually striving to make investing simpler and more accessible, we're helping more people take control of their financial futures. We're proud to be recognised as one of the UK's Best 100 Companies to Work For for six consecutive years, and a Great Place to Work in 2025 and 2026, a reflection of our supportive and collaborative culture. What we offer Competitive starting salary 26days holiday, increasing with service + buy/sell scheme + bank holidays 7% Pension with matched contributions Discretionary bonus scheme Share schemes (including free shares and BAYE) Health Cash Plan and discounted private healthcare Free gym Enhanced family leave (subject to qualifying criteria) Travel and bike loan schemes Employee Assistance Programme Life at AJ Bell Regular social events including summer and Christmas parties Learning and development opportunities tailored to you Casual dress code Friendly, supportive team environment Our ways of working At AJ Bell, our people are the heart of our culture. We believe in building strong connections by working together. That's why we offer a hybrid working model, where you'll spend a minimum of 50% of working time per month in the office. For new team members, an initial period will be spent full time in the office to help you immerse yourself in our business and build valuable relationships with your colleagues. Inclusion & diversity We're committed to creating an inclusive environment where everyone feels respected, supported and able to be themselves at work. We welcome applications from all backgrounds and make hiring decisions based on skills, experience and potential. Agency information This vacancy is being managed exclusively by our in house Recruitment team. We are not partnering with recruitment agencies on this opportunity and will only accept applications submitted directly by candidates
28/06/2026
Full time
Job Description To support the Head of Security Operations in delivering effective day-to-day security operations, ensuring AJ Bell maintains the appropriate capability to detect, investigate and respond to security events and incidents. The Security Operations Technical Lead is responsible for ensuring that security operations activities are executed efficiently, consistently and in line with defined SLAs and operational standards, through hands on technical leadership across SOC, Incident Response, Threat Intelligence, Insider Risk and Vulnerability Management. This role acts as a senior technical escalation point, supporting complex investigations and driving improvements in detection, response, automation and operational processes. The role holder is expected to lead through expertise, supporting analysts and ensuring Security Operations operates with discipline, quality and continuous improvement. The key responsibilities of the role are: Act as the primary technical escalation point for security events and incidents identified by the Security Operations team. Support the Head of Security Operations in ensuring AJ Bell has the appropriate capability to detect and respond to security events and incidents. Oversee the day to day execution of security operations, ensuring alerts and incidents are handled in line with defined processes and SLAs. Ensure security operations SLAs and OLAs are met, including alert triage, escalation and incident response timelines, highlighting and addressing risks where required. Ensure adherence to our KRI and KPI's and any variation in these are raised to the Head of Security Operations. Provide hands on support in the investigation and response to security incidents, including endpoint, identity, network, cloud and insider related threats. Ensure consistent execution and continuous improvement of incident response playbooks and operational runbooks, validating them through real incidents and simulations. Support the optimisation and tuning of security monitoring and detection capabilities, including SIEM and endpoint tooling, to improve signal quality and reduce false positives. Support the execution of the end to end vulnerability management process, including validation of findings and tracking remediation activities. Work closely with MSSP and security vendors to ensure effective delivery of security operations services. Challenge and validate vendor outputs, driving operational efficiency, quality improvements and better use of tooling capabilities. Actively design and implement automation and orchestration to reduce manual effort, repetitive or high volume tasks, improve response times and increase consistency across security operations processes. Work with the Security Engineering team to ensure tooling, logging and detection gaps are identified and addressed. Support the effective operation of 24x7 security monitoring, including coordination with third party providers. Contribute to the development and delivery of operational MI and reporting, ensuring accuracy and insight into security trends and performance. Maintain visibility of security incidents, trends and operational risks, escalating issues where required. Technical Skills: Strong hands on experience of Security Operations tools and capabilities, including SIEM and SOAR platforms (e.g. Sentinel, ServiceNow, Splunk SOAR, Cortex), Endpoint Detection & Response (EDR/XDR), Strong hands on experience of Threat Intelligence platforms (e.g. Recorded Future, Doppel, ZeroFox, Google Threat Intelligence), Vulnerability management solutions (e.g. Tenable, Rapid7), and Insider Risk and DLP tools (e.g. Purview, Netskope). Strong hands on experience with Network security solutions like Next Gen Firewalls, Network Anomaly, WAF & DDoS solutions. Experience of leading and responding to Cyber Incident Response aligned to NIST Knowledge of threat detection techniques and use case development Experience of applying threat intelligence in an operational context Strong experience with vulnerability management tools and processes Strong awareness of cloud services and supporting security controls and monitoring capabilities Working knowledge of Microsoft security stack (Defender, Sentinel, Purview), Active Directory and Azure AD, Windows and Linux environments. Experience with data loss prevention and insider risk tooling advantageous Hands on experience with automation and scripting (e.g. PowerShell, Python) highly desirable Competence Experience working within recognised Information Security frameworks and best practices such as ISO27001, NIST, MITRE ATT&CK Knowledge of relevant regulatory requirements (e.g. GDPR, FCA/PRA) Experience in an Information Security role gained in a financial services environment preferred Experience working in a Security Operations role for a minimum 7 years and operating within a Lead / Senior Analyst role for at least 3 years. Knowledge & Skills Strong analytical and investigative capability Ability to work under pressure and manage multiple concurrent incidents and priorities Strong ownership of tasks, attention to detail and follow through to conclusion Ability to provide technical leadership without formal line management responsibility Ability to challenge approach, tooling and processes to improve operational effectiveness Structured, self starting and able to work under own initiative Effective communication skills, both written and verbal Ability to plan, organise and deliver tasks with minimal supervision Collaborative approach to working with analysts, engineering teams and external partners Strong focus on quality, consistency and continuous improvement About AJ Bell At AJ Bell, we believe investing should feel good. Whether you're looking for an ISA, pension or dealing account, whether you want to invest with the help of a financial adviser or do it yourself, we have easy to use solutions to suit people from all walks of life. We're one of the UK's fastest growing investment platform businesses, trusted by everyone from professional financial advisers to first time investors. Today, over 723,000 customers trust us to manage more than £108.7 billion of assets. By continually striving to make investing simpler and more accessible, we're helping more people take control of their financial futures. We're proud to be recognised as one of the UK's Best 100 Companies to Work For for six consecutive years, and a Great Place to Work in 2025 and 2026, a reflection of our supportive and collaborative culture. What we offer Competitive starting salary 26days holiday, increasing with service + buy/sell scheme + bank holidays 7% Pension with matched contributions Discretionary bonus scheme Share schemes (including free shares and BAYE) Health Cash Plan and discounted private healthcare Free gym Enhanced family leave (subject to qualifying criteria) Travel and bike loan schemes Employee Assistance Programme Life at AJ Bell Regular social events including summer and Christmas parties Learning and development opportunities tailored to you Casual dress code Friendly, supportive team environment Our ways of working At AJ Bell, our people are the heart of our culture. We believe in building strong connections by working together. That's why we offer a hybrid working model, where you'll spend a minimum of 50% of working time per month in the office. For new team members, an initial period will be spent full time in the office to help you immerse yourself in our business and build valuable relationships with your colleagues. Inclusion & diversity We're committed to creating an inclusive environment where everyone feels respected, supported and able to be themselves at work. We welcome applications from all backgrounds and make hiring decisions based on skills, experience and potential. Agency information This vacancy is being managed exclusively by our in house Recruitment team. We are not partnering with recruitment agencies on this opportunity and will only accept applications submitted directly by candidates