SecOps Engineer

SecOps Engineer

Full-Time 51750 - 63250 £ / year (est.) No working from home possible
Manchester Arndale

At a Glance

  • Tasks: Strengthen cyber defence by detecting, investigating, and responding to security threats.
  • Company: Join OCS, a leading facilities management company with a commitment to innovation and community.
  • Benefits: Enjoy competitive pay, digital learning, flexible pay options, and exclusive retail perks.
  • Other info: Be part of a diverse team that values trust, respect, unity, and empowerment.
  • Why this job: Make a real impact in cybersecurity while growing your skills in a supportive environment.
  • Qualifications: Experience in SecOps, strong scripting skills, and a proactive mindset are essential.

The predicted salary is between 51750 - 63250 £ per year.

About The Company

OCS UK & Ireland is a leading facilities management company with 50,000+ colleagues and a turnover in excess of £2bn.

We deliver innovative, award-winning services within facilities management, hard services, cleaning, security and catering.

Our mission is to make people and places the best they can be for our colleagues, customers and the communities we serve.

Our commitment to doing business the right way is rooted in our TRUE values - Trust, Respect, Unity, and Empowerment.

Why Work for OCS?

  • Award-Winning Employer: Ranked 36th on Glassdoor’s Best Companies to Work For 2025 — we value and motivate our people.
  • Digital Learning: The OCS Academy offers digital courses and resources to help you build skills and grow your career.
  • Retail Perks With our Hapi app, you can gain access to exclusive discounts, rewards and wellbeing resources.
  • Professional Growth: 600+ live learners across UK&I — Empowering colleagues with further development and qualifications!
  • Flexible Pay: Access a portion of earned wages before payday with our Wagestream App! (Contract Specific)

About The Role

The Security Operations Analyst plays a central role in strengthening OCS’s cyber defence capability.

The role exists to make our Sec Ops function measurably more effective every quarter, by improving how we detect, investigate and respond to threats, and by removing the friction that holds analysts back.

We are looking for a proactive engineer who does not wait to be told where the problems are.

The successful candidate will actively look for weaknesses in our detection coverage, configuration drift in our security platforms, gaps in our automation and inefficiencies in our processes.

They will then propose pragmatic fixes, build them, and measure the outcome

Main Duties & Responsibilities of the Role

  • Detection engineering and tuning
  • Build, test and maintain high-quality detections across our SIEM, XDR and email security platforms, mapped to the MITRE ATT&CK framework
  • Continuously tune existing detections to reduce false positives and improve fidelity, using a data-driven approach
  • Identify gaps in detection coverage proactively and propose engineering work to close them
  • Develop and maintain detection-as-code practices, including version control, peer review and CI/CD where appropriate
  • Automation and tooling
  • Identify repetitive analyst tasks and engineer automation to remove them, using SOAR, native platform automation, scripting or low-code approaches
  • Build and maintain integrations between security tools and adjacent platforms such as identity, endpoint management and ticketing
  • Develop and maintain dashboards that give analysts and leadership a clear view of operational health
  • Platform health and configuration
  • Own the configuration and ongoing health of assigned Sec Ops platforms, including SIEM, EDR, email security and identity protection
  • Monitor for configuration drift, agent coverage gaps and ingestion failures, and resolve them at source
  • Lead technical onboarding of new log sources, telemetry and integrations, ensuring that data is usable, normalised and well documented
  • Threat hunting and proactive defence
  • Conduct regular threat hunts based on intelligence, recent incidents and known weaknesses, documenting hypotheses, methodology and findings
  • Translate hunt findings into durable detections, automation or process changes
  • Contribute to purple team exercises and adversary emulation, working with internal and external partners
  • Incident response support
  • Provide deep technical support during significant incidents, including forensic data collection, log analysis and containment engineering
  • Capture lessons learned from incidents and translate them into engineering improvements that prevent recurrence
  • Continuous improvement
  • Maintain a backlog of identified weaknesses, ideas and improvements, and work with the Senior Sec Ops Lead to prioritise it
  • Document standards, runbooks and engineering decisions clearly, so that knowledge does not live only in individual heads
  • Stay current with the threat landscape, vendor road maps and the broader security engineering community, and bring relevant ideas back into OCS

Professional Qualifications required for the job (particularly for compliance purposes or technical requirements of the role)

  • Extensive Sec Ops experience with a multitude of different tools
  • Relevant Industry Certifications
  • Experience -previous experience -desirable/essential for technical competence of the role
  • Demonstrable hands-on experience as a security engineer or senior SOC analyst with engineering responsibilities
  • Strong working knowledge of at least one enterprise SIEM and one EDR or XDR platform, with the ability to write detections, tune content and operate at a deep technical level
  • Solid scripting ability, for example in Python, Power Shell or KQL, with a working understanding of APIs and integration patterns
  • Practical understanding of common attack techniques mapped to MITRE ATT&CK, and how they manifest in telemetry
  • A proactive mindset: the candidate must be able to point to specific examples where they have identified a problem, designed a solution and delivered it end to end
  • Strong written communication, including the ability to document detections, runbooks and engineering decisions to a high standard
  • Personal Characteristics/Attributes
  • Organisational and time management skills
  • Strong interpersonal skills
  • Exceptional written and verbal communication skills
  • Ability to work under own initiative, as well as part of a team
  • Willingness and ability to undertake national travel as required
  • Confidence to stand their ground and drive a Security First environment
  • The ability to learn new tools quickly and effectively

We are an equal opportunities employer and rely on a diverse workforce with a broad range of knowledge, skills, and backgrounds to deliver our goals.

We offer an inclusive and welcoming environment and actively encourage applications from all individuals regardless of race, gender, nationality, religion, sexual orientation, disability, or age.

#J-18808-Ljbffr

SecOps Engineer employer: Manchester Arndale

At Manchester Arndale, we pride ourselves on being an excellent employer by fostering a supportive and inclusive work culture that values every team member. Our part-time Evening Cleaner role offers flexible hours, allowing for a great work-life balance while contributing to a safe and welcoming environment for our customers. We are dedicated to employee growth, providing opportunities for training and development within a vibrant retail setting in the heart of Manchester.

Manchester Arndale

Contact Details:

Manchester Arndale Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land SecOps Engineer

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Manchester Arndale, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Manchester Arndale

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Manchester Arndale. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace SecOps Engineer

Detection Engineering
SIEM
XDR
Email Security Platforms
MITRE ATT&CK Framework
Automation and Tooling
Scripting (Python, PowerShell, KQL)

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Manchester Arndale insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Manchester Arndale that you’re committed to staying ahead in the game.

How to prepare for a job interview at Manchester Arndale

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Manchester Arndale to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Manchester Arndale.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.