About this role
Salary: £28,000 - 68,000 per year
Requirements: Knowledge and understanding of incident response frameworks such as NIST CSF, SOC 2, or equivalentKnowledge and understanding of information security architecture and IT security policies relevant to logging, including secure transport, retention, and privacy by designStrong organisation and written and verbal communication skills, with the ability to explain technical information such as standards, runbooks, and feed specifications to non-technical audiencesCustomer-focused and proactive approach to resolving technical issues and challengesPrior experience in a Managed Service Provider or MSSP organisation is strongly preferred; candidates with similar experience outside a SOC will also be consideredExperience with other SIEM and related information security management platforms is desirable, such as AlienVault, Elastic, EDR/MDR tools, or vulnerability management platforms Responsibilities: Work with customers and internal stakeholders to identify development and improvement opportunities, and continually evaluate our cyber practices and capabilities to improve service effectiveness and timelinessUse security tools, automation, and best practices as part of our Engineering team to improve efficiency across our platforms and technical practicesDeliver end-to-end SIEM/Sentinel engineering, including customer onboarding, data connector and integration configuration, KQL, automation, dashboards, and reportingTune, enrich, and optimise Sentinel, aligning it with other SIEM toolsMaintain the reliability of our SIEM ingestion pipelines by investigating and resolving issues across connectors, parsing, content, automation, and transformation logicProactively monitor latency, throughput, and data fidelity to prevent data lossHelp deliver our Cyber Operations engineering strategy, apply best practices, continually develop our platforms and services, and maintain high standards across the function Technologies: SupportSecurityAI More:
We are Softcat, one of the UKs leading IT infrastructure providers and a FTSE 250 listed company. Our business is built on outstanding customer service and employee satisfaction, supported by our values of passion, intelligence, fun, and responsibility. Our Cyber Operations teams provide customers with cyber security monitoring, analysis, assessment, and remediation, while our Engineering team configures, deploys, and maintains the tools that support these services. We offer a supportive, collaborative, and inclusive working environment, with hybrid working (two days in the office and three days from home), flexible start and finish times, and flexibility around school drop-offs and pick-ups. We encourage applications from people with different backgrounds and can provide recruitment-process adjustments for disability or neurodiversity. This is a full-time, permanent role based in Manchester, within our Services Group.
last updated 40 week of 2026