At a Glance
- Tasks: Lead the evolution of cyber security, focusing on SIEM and cloud security.
- Company: Join Arqiva, a leader in connectivity and media technology.
- Benefits: Enjoy competitive salary, flexible working, and a unique wellbeing programme.
- Other info: Be part of a diverse team committed to growth and community.
- Why this job: Shape the future of cyber security while making a real impact.
- Qualifications: Strong background in SIEM and cloud security, with a passion for technology.
The predicted salary is between 60000 - 75000 £ per year.
Location: Crawley Court, Winchester & Newman Street, London. We operate a flexible, hybrid working environment – requirement to travel to either our Winchester or London office up to twice a week.
Competitive salary 10% bonus. Work Life Smarter – our commitment to a flexible and hybrid working culture. Generous pension scheme starting at 6% rising to 10%. A unique wellbeing programme that looks after the whole you. Access to multiple learning platforms to support your individual development. Active and diverse networks that build community, support wellbeing and advocate for change. A comprehensive set of benefits including discounts on big brands, gymflex memberships and paid volunteering leave.
The Role: The Senior Threat & Response Specialist is uniquely positioned to drive the evolution of our cyber security capability, combining deep operational expertise with advanced, cutting‑edge technologies. Through this role, the specialist plays a pivotal part in shaping an innovative, intelligence‑led security function, one that anticipates threats, automates responses, and sets new standards of excellence across our organisation and the wider industry. Candidates with a strong SIEM engineering background who want to broaden their scope into 3rd‑line SOC investigation and incident response will be particularly well suited to this opportunity. This position provides a unique opportunity to own and shape the role, as we establish best practices and effective ways of working across our organisation. Experience in Cloud Security, especially across Azure, AWS or hybrid environments, will be highly advantageous, enabling you to support Arqiva’s shift toward secure‑by‑design cloud adoption.
You will work within Arqiva’s Information Security Operations Teams, reporting to the Head of Threat and Response, and collaborating closely with the broader Security organisation as well as technical teams across Arqiva. Together, you will help deliver and mature our core Cyber Defence capabilities, including SIEM and Monitoring, Vulnerability Management, Incident Response and Analysis, and Threat Intelligence.
Key Responsibilities:
- Lead the engineering, optimisation and continuous improvement of Arqiva’s SIEM platform, ensuring high‑quality detections, effective log ingestion pipelines, and strong operational performance.
- Design, develop and tune advanced detection use cases aligned to evolving attacker behaviours, leveraging threat intelligence and frameworks such as MITRE ATT&CK.
- Support the onboarding and normalisation of new data sources, including cloud telemetry, application logs and platform services, ensuring full visibility across hybrid environments.
- Collaborate with DevOps and platform engineering teams to embed security controls, monitoring and detection within CI/CD pipelines and infrastructure‑as‑code deployments.
- Utilise cloud‑native and third‑party tooling such as Wiz to assess cloud posture, improve asset visibility, enrich threat detection logic, and drive proactive remediation.
- Act as an escalation point for complex 3rdline SOC investigations, providing analytical support.
- Collaborate with suppliers, customers and Arqiva stakeholders, to deliver Threat & Response services, drive improvement and enhance the effectiveness of Arqiva’s Security Capabilities.
- Provide technical analysis and interpretation of Arqiva’s internal and external landscape, advising and supporting the Head of Threat & Response in embedding the incident response and cyber continuity elements of Arqiva’s information security strategy across the organisation.
- Mentor junior Threat & Response colleagues across any of the Threat & Response services.
- Coordinate with stakeholders of varying seniority and technical background as an authoritative representative of the Threat & Response function.
Key Attributes & Experience:
- Technical background, mindset and approach.
- Genuine enthusiasm for technology and Cyber Security.
- Adaptability and self‑sufficiency.
- Inquisitive and analytical.
- Strong communication, reporting and stakeholder management skills.
- Able to understand technical concepts and scenarios and translate in clear language for non‑technical stakeholders and executives.
- Honest, open and genuine in your interactions with others.
- Deep, tooling‑agnostic engineering, architectural and operational expertise, across all key Security platforms, such as VM/SIEM/EDR, and able to transfer knowledge between toolsets.
- Knowledge and experience of working within organisations that implement relevant Cyber frameworks and methodologies, such as MITRE ATT&CK, NIST, ISF, ISO27000.
- Relevant industry qualifications, such as SANS, GIAC, CEH, CCNA, AZ-500.
- Extensive experience of performing technical threat analysis and incident response activities against several kinds of attack, including malware, data breach, supply chain compromise and others.
- Experience in the management and handling of Security incidents, including assessment, categorisation and prioritisation and root cause analysis.
- Familiarity with common attack methodologies and methods used by Cyber threat actors during the threat lifecycle.
- Experience interpreting and actioning Threat Intelligence.
- Experience with both on‑prem and AWS and Azure cloud environments and Security solutions.
Please note that the successful candidate will be required to successfully undergo UK Security Clearance and must have been resident within the UK for at least five years.
Why Arqiva: We enable a switched‑on world to flow. As the UK’s leader in TV and radio broadcast and the country’s top smart utilities platform, we are shaping the future of connectivity. Our infrastructure delivers media and data exactly where they’re needed - whether that’s bringing TV and radio to your home or sending smart meter data to your utility provider. Our technology works quietly behind the scenes, connecting millions every day. But it’s not just what we do, it’s how we do it. At Arqiva, you’ll find real connection: supportive teams, active colleague networks and plenty of ways to get involved and feel part of our community. We’ll give you the space and support to grow - whether that’s developing your skills, trying something new or taking on fresh challenges. And because there is more to life than work, our rewards and benefits are designed to support your wellbeing, your lifestyle and what matters most to you.
Our commitment to Diversity & Inclusion: At Arqiva, we’re committed to building a workplace where everyone feels valued, heard and empowered to succeed. We welcome applications from all backgrounds and experiences, and we work hard to remove barriers so every colleague can thrive. If you need any adjustments at any stage of the recruitment process, please reach out to talent@arqiva.com. If this sounds like the right next step for you, we’d love to hear from you!
Senior Threat & Response Engineer - SIEM & Cloud Security in Winchester employer: 慨正橡扯
Arqiva is an exceptional employer, offering a flexible hybrid working environment that promotes work-life balance and personal wellbeing. With a strong commitment to employee development through access to multiple learning platforms, generous pension schemes, and a unique wellbeing programme, Arqiva fosters a supportive and inclusive culture where every team member can thrive and contribute to shaping the future of connectivity in the UK.
StudySmarter Expert Advice🤫
We think this is how you could land Senior Threat & Response Engineer - SIEM & Cloud Security in Winchester
✨Tip Number 1
Network like a pro! Reach out to current employees at Arqiva on LinkedIn or through mutual connections. Ask them about their experiences and any tips they might have for the interview process. This insider info can give you a leg up!
✨Tip Number 2
Prepare for the technical side! Brush up on your SIEM and cloud security knowledge, especially around Azure and AWS. Be ready to discuss specific scenarios where you've tackled similar challenges in your past roles.
✨Tip Number 3
Show your passion for cyber security! During interviews, share your enthusiasm for technology and how you stay updated with the latest trends and threats. This will demonstrate your commitment to the field and make you stand out.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, it shows you’re genuinely interested in joining the Arqiva team. Let’s get you that job!
We think you need these skills to ace Senior Threat & Response Engineer - SIEM & Cloud Security in Winchester
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the Senior Threat & Response Engineer role. Highlight your experience with SIEM, cloud security, and any relevant certifications. We want to see how your skills align with what we're looking for!
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about cyber security and how your background makes you a great fit for our team. Keep it engaging and personal – we love to see your personality come through.
Showcase Your Technical Skills:In your application, don’t forget to showcase your technical expertise. Mention specific tools and frameworks you've worked with, like MITRE ATT&CK or AWS. We’re keen on candidates who can demonstrate their hands-on experience in the field.
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, you’ll find all the details about the role and our company culture there!
How to prepare for a job interview at 慨正橡扯
✨Know Your Stuff
Make sure you brush up on your SIEM and cloud security knowledge. Be ready to discuss specific tools and technologies you've worked with, especially in Azure and AWS environments. This will show that you're not just familiar with the concepts but have hands-on experience.
✨Show Your Problem-Solving Skills
Prepare to share examples of complex incidents you've handled in the past. Think about how you approached the problem, what tools you used, and the outcome. This will demonstrate your analytical skills and ability to think on your feet.
✨Communicate Clearly
Since you'll be coordinating with stakeholders of varying technical backgrounds, practice explaining technical concepts in simple terms. This will help you connect with non-technical interviewers and showcase your communication skills.
✨Ask Insightful Questions
Prepare thoughtful questions about the company's security strategy and how they implement frameworks like MITRE ATT&CK. This shows your genuine interest in the role and helps you understand if the company aligns with your career goals.