Tatton Recruitment

Tatton Recruitment

Stevenage, North West

Cyber Security Engineer / SOC Analyst

Contract£? - ? per yearavant-hierUnited Kingdom
IT

Job Description

Salary: £? - ? per year

Requirements:
  • Strong coding and scripting background in PowerShell, Python, and Regex
  • Proven ability to work with APIs, including HTTP/S headers and responses, and JSON objects
  • Proven experience with proxy administration and changes
  • Experience with Windows (SMB) and *Nix (NFS) remote storage
  • Experience with IIS (Windows Web Server) configuration and Active Directory/LDAP authentication
  • Experience applying certificates, software updates, and end-of-life refresh activity
  • Experience with VMware/Hyper-V virtual machines and virtual switches
  • Experience setting up, implementing, and maintaining cyber security tooling
  • Experience with the creation, testing, and maintenance of AI or machine learning technologies to optimise workflows or playbooks
  • Experience with SIEM technologies
Responsibilities:
  • Lead the technical aspects of ensuring cyber security appliance efficiency to support alert tuning, network visibility, and log ingesting into relevant toolsets
  • Advise on implementation of new tools and lead the updating and expansion of existing capabilities
  • Provide support by ensuring availability, readiness, and resilience of cyber security toolsets within in-scope environments
  • Support the Cyber Security Capability Manager in ensuring we meet the challenges and demands of countering the cyber threat
  • Work with other UK Cyber Security members on back-end refresh, playbook scripting, fault finding, cyber security tool upgrades, capability implementation, tool integration, data source onboarding, and investigation activity
  • Account for the effective mapping and topology of SOC toolsets, including integrations and feeds between solutions
  • Enrich the visibility and optimisation of SOC tools through data modelling and tuning
  • Maintain the primary SOC toolsets, ensuring their availability, functionality, and optimisation
  • Be responsible for the daily muster and availability of all cyber security technologies within in-scope environments
  • Track product lifecycle accurately and advise management on EOL/EOS roadmaps
  • Support coordination, planning, and execution of SOC appliance upgrades
  • Support all cyber security pillars with new capability implementation and integration to existing solutions
  • Implement cyber security tool changes and configurations, ensuring efficient reporting into CAB and control boards
  • Lead playbook scripting activities, ensuring they are well documented and tested, including fault finding and review of false positives
  • Act as SME on SOC connectivity and visibility across all in-scope networks and infrastructure, ensuring connections and integrations are understood and documented
  • Lead back-end refresh activity on cyber security appliances, including certificate updates, patch releases, and software updates
  • Attend DEX CAB and collate all impacting activities on cyber security alerting
  • Attend DEX Incident and Issue red teams in support of root cause analysis, advising on cyber security changes which may impact other services
  • Collaborate closely with DEX back office to maintain availability and efficiency of cyber security tools and recover any service outages or disruption
  • Support the SOC in investigation activity using security platforms, custom searches, advanced queries, and scripts to find the root cause or IOC of an alert
Technologies:
  • AI
  • Active Directory
  • HTTP
  • Hyper-V
  • Support
  • JSON
  • LDAP
  • Machine Learning
  • Network
  • NFS
  • PowerShell
  • Python
  • Security
  • SMB
  • VMware
  • Web
  • Windows

More:

We are a world-class defence organisation recruiting a Cyber Security Engineer subcontractor for an initial 24-month contract within our Cyber Security Operations Centre (SOC) in Digital Excellence (DEX) UK. The role is based in Stevenage, with onsite working five days per week, on a 37-hour week contract with overtime paid at time and a quarter for hours worked over 37 per week. The arrangement is inside IR35 (umbrella). We are looking for someone with experience in SOC and cyber security tooling to help maintain, improve, and support our security capabilities across in-scope UK networks and environments.

last updated 35 week of 2026

Interested in this role?

Submit your application now

How to Apply

Ready to apply for this position? Here's what you need:

  • An updated resume highlighting relevant experience
  • A compelling cover letter (if required)
  • Portfolio or work samples (for relevant positions)

About Tatton Recruitment

Tatton Recruitment

Tatton Recruitment

Stevenage

IT

Skills & Technologies

PythonGitMachine LearningAIUI

Inferred from job description

Explore More UK Opportunities

Thousands of tech jobs across the United Kingdom