About this role
Salary: £? - ? per year
Requirements: Strong coding and scripting background in PowerShell, Python, and RegexProven ability to work with APIs, including HTTP/S headers and responses, and JSON objectsProven experience with proxy administration and changesExperience with Windows (SMB) and *Nix (NFS) remote storageExperience with IIS (Windows Web Server) configuration and Active Directory/LDAP authenticationExperience applying certificates, software updates, and end-of-life refresh activityExperience with VMware/Hyper-V virtual machines and virtual switchesExperience setting up, implementing, and maintaining cyber security toolingExperience with the creation, testing, and maintenance of AI or machine learning technologies to optimise workflows or playbooksExperience with SIEM technologies Responsibilities: Lead the technical aspects of ensuring cyber security appliance efficiency to support alert tuning, network visibility, and log ingesting into relevant toolsetsAdvise on implementation of new tools and lead the updating and expansion of existing capabilitiesProvide support by ensuring availability, readiness, and resilience of cyber security toolsets within in-scope environmentsSupport the Cyber Security Capability Manager in ensuring we meet the challenges and demands of countering the cyber threatWork with other UK Cyber Security members on back-end refresh, playbook scripting, fault finding, cyber security tool upgrades, capability implementation, tool integration, data source onboarding, and investigation activityAccount for the effective mapping and topology of SOC toolsets, including integrations and feeds between solutionsEnrich the visibility and optimisation of SOC tools through data modelling and tuningMaintain the primary SOC toolsets, ensuring their availability, functionality, and optimisationBe responsible for the daily muster and availability of all cyber security technologies within in-scope environmentsTrack product lifecycle accurately and advise management on EOL/EOS roadmapsSupport coordination, planning, and execution of SOC appliance upgradesSupport all cyber security pillars with new capability implementation and integration to existing solutionsImplement cyber security tool changes and configurations, ensuring efficient reporting into CAB and control boardsLead playbook scripting activities, ensuring they are well documented and tested, including fault finding and review of false positivesAct as SME on SOC connectivity and visibility across all in-scope networks and infrastructure, ensuring connections and integrations are understood and documentedLead back-end refresh activity on cyber security appliances, including certificate updates, patch releases, and software updatesAttend DEX CAB and collate all impacting activities on cyber security alertingAttend DEX Incident and Issue red teams in support of root cause analysis, advising on cyber security changes which may impact other servicesCollaborate closely with DEX back office to maintain availability and efficiency of cyber security tools and recover any service outages or disruptionSupport the SOC in investigation activity using security platforms, custom searches, advanced queries, and scripts to find the root cause or IOC of an alert Technologies: AIActive DirectoryHTTPHyper-VSupportJSONLDAPMachine LearningNetworkNFSPowerShellPythonSecuritySMBVMwareWebWindows More:
We are a world-class defence organisation recruiting a Cyber Security Engineer subcontractor for an initial 24-month contract within our Cyber Security Operations Centre (SOC) in Digital Excellence (DEX) UK. The role is based in Stevenage, with onsite working five days per week, on a 37-hour week contract with overtime paid at time and a quarter for hours worked over 37 per week. The arrangement is inside IR35 (umbrella). We are looking for someone with experience in SOC and cyber security tooling to help maintain, improve, and support our security capabilities across in-scope UK networks and environments.
last updated 36 week of 2026