Security Operations Engineer

Required ITBromleyreedpublished 10/05/2026
Must-have:CloudSecurityLeadHybrid

Working pattern: Monday–Friday, 40 hours per week Working hours: Flexible start between 7:30am and 9:30am Hybrid working: 2 day per week from home after successful completion of training

We’re looking for a Security Operations Engineer to join our cyber security team and play a key role in protecting our organisation from an ever-changing threat landscape. This is a genuinely hands-on operational security role , ideal for someone who enjoys investigating incidents, getting to the root cause of security events, working across a range of security technologies, and making a tangible difference to an organisation’s cyber resilience. You’ll sit at the heart of our cyber defence operations, working with technologies including Microsoft Defender, Microsoft Entra ID, Intune, Rapid7 SIEM and Sophos Antivirus . From investigating suspicious activity and responding to security incidents through to improving detection capabilities and strengthening our security controls, you’ll have real responsibility and the opportunity to see the impact of your work. At Foresters , we’re proud to offer a supportive and collaborative environment where you’ll have ongoing opportunities to develop your technical skills, broaden your experience and grow your career in cyber security. What you’ll be doing Security Monitoring & Incident Response Monitor security alerts and telemetry across endpoints, identities, email and cloud services using Rapid7 SIEM, Microsoft Defender and Sophos . Investigate and respond to suspected cyber attacks, including malware infections, phishing campaigns, identity compromise and unauthorised access attempts. Perform security incident triage, root cause analysis, containment and remediation. Lead or support incident response activities in line with established policies and procedures. Escalate significant incidents appropriately and provide clear, timely updates to relevant stakeholders. Threat Detection & Prevention Identify emerging threats, vulnerabilities and attack patterns that could impact the organisation. Tune and optimise security tools to improve detection accuracy and reduce false positives. Implement, manage and maintain endpoint protection and security policies. Support vulnerability management activities, including remediation planning, prioritisation and risk tracking. Help identify opportunities to strengthen our preventative and detective security controls. Security Operations & Continuous Improvement Maintain and enhance security monitoring rules, alerts and dashboards. Develop and maintain security runbooks and incident response playbooks. Support security audits, compliance activities and risk assessments. Identify opportunities to improve security processes, tooling and operational efficiency. Contribute to the continued development of our overall cyber security maturity. Collaboration & Communication Work closely with IT, infrastructure and service desk teams to investigate and resolve security-related issues. Produce clear and structured technical and non-technical incident reports. Identify trends in phishing and risky user behaviour and support security awareness initiatives. Contribute to security projects and the implementation of new technologies and controls. Communicate complex security issues clearly to both technical and non-technical audiences. What we’re looking for We’re looking for someone with practical security operations experience who is comfortable investigating incidents, analysing evidence and taking action. You’ll ideally have: Experience working as a Cyber Security Engineer, SOC Analyst, Security Operations Engineer or in a similar security-focused role. Hands-on experience with Microsoft Defender , particularly Endpoint and/or Microsoft 365 security. Experience using Rapid7 SIEM or another SIEM platform for security monitoring, alerting and investigations. Experience managing or supporting Sophos Antivirus or another endpoint protection platform. A strong understanding of common cyber threats, attack techniques and incident response processes. The ability to analyse logs, alerts and endpoint activity to establish scope, impact and root cause. Good working knowledge of Windows environments and fundamental networking concepts. Strong documentation, reporting and communication skills. Practical experience with security and vulnerability assessment tools such as IDS/IPS, Metasploit, Nexpose, Nmap, Nessus, Wireshark, L0phtCrack, John the Ripper or similar technologies. Familiarity with recognised security frameworks such as ISO 27001 and the NIST Cybersecurity Framework .