Now hiring

SOC - Cyber Threat Operations Specialist @ Tatton Recruitment

Stamford Place, StevenageOnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

Salary: £? - ? per year

Requirements: A career background in cyber security.Security awareness and experience across all areas of IT, primarily network security and infrastructure, with operating systems and applications as a secondary area.Demonstrable experience with YARA and Sigma rulesets.Knowledge of IT security standard methodologies.Demonstrable understanding of the OSI Reference Model and network communication protocols, including DNS, HTTP/S, SSL, SMTP, FTP/S, and LDAP/S.Demonstrable experience with security information event monitoring tools and/or network packet capture tools.Hands-on experience with IDS/IPS technologies and threat hunting activities.Strong analytical experience and mindset.Experience within defensive cyber-attack methodologies and frameworks.Understanding of malware capabilities, attack vectors, propagation, and impact.Good communication skills for liaising with the business and suppliers. Responsibilities: Support the Active Defence Incident Response Manager in helping us meet the challenges and demands of countering the cyber threat.Support the operational functions of the UK SOC.Work with other UK SOC members, including the UK InfoSec team and the IM domains.Carry out threat hunting, analysis, monitoring, optimisation, reporting, alerting, and investigation activities using a wide range of security platforms and technologies.Conduct proactive threat hunting in collaboration with the CTI function.Lead threat detection engineering efforts working with the ISR function.Assist with the maintenance of security technologies.Support the Cyber Eng team with project activity.Support incident responders with HR and InfoSec-related investigations.Attend routine security meetings.Conduct analysis and assist the incident response team with investigations that need to be escalated to an embedded member of staff. Technologies: EmbeddedHTTPSupportLDAPNetworkSecurityAI More:

We are a world-class defence organisation currently looking to recruit a Cyber Threat Operations Specialist subcontractor on an initial 12-month contract. The role is based in Stevenage with onsite working five days per week, following a shift pattern of 07:00-15:00 or 09:00-18:00 subject to change. The contract is for 37 hours per week, with overtime paid at time and a quarter for hours worked over 37 per week. This is an initial 12-month assignment with the potential for ongoing and long-term work, and it is inside IR35 (umbrella). You do not need current security clearance to apply, although SC clearance will be required before starting and DV clearance will be required eventually. The role sits within our Active Defence Incident Response Team within Digital Excellence (DEX), where we focus on proactive threat hunting, detection engineering, and robust analysis in a high-performing team environment.

last updated 36 week of 2026

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores