Security Engineer in England

Security Engineer in England

England Full-Time 50000 - 70000 € / year (est.) Home office (partial)
NTT Ltd.

At a Glance

  • Tasks: Deploy and maintain SIEM platforms for robust threat detection and incident response.
  • Company: Join a forward-thinking cybersecurity firm with a focus on innovation.
  • Benefits: Enjoy flexible work options, tailored benefits, and continuous learning opportunities.
  • Other info: Mentorship opportunities available to help you grow in your career.
  • Why this job: Make a real difference in cybersecurity while developing your skills in a dynamic environment.
  • Qualifications: Experience with SIEM platforms and strong analytical skills are essential.

The predicted salary is between 50000 - 70000 € per year.

Responsibilities

  • Deploy, configure, and maintain SIEM platforms such as Splunk, QRadar, Sentinel, and Chronicle to enable robust threat detection.
  • Normalize and onboard diverse log sources from cloud and on‑premises environments for seamless monitoring.
  • Develop and continually refine SIEM rules and queries for use cases involving advanced threat behaviours and anomaly detection.

Playbook Automation & Incident Response

  • Design and implement incident response playbooks for threats such as phishing, lateral movement, malware infections, and more.
  • Integrate response automation into SOAR platforms (e.g., XSOAR, Azure Logic Apps), reducing response times and manual overhead.
  • Use feedback from simulated incidents and threat intelligence to refine existing playbooks and workflows.

Threat Detection & Response

  • Monitor security alerts for potential threats, investigate incidents, and coordinate cross‑team response activities.
  • Collaborate with threat intelligence teams to enhance detection logic and fine‑tune resolution processes.
  • Perform root‑cause analysis (RCA) of recurring incidents and help define corrective actions to reduce future risks.

Threat Modelling & Use Case Development

  • Perform threat modelling using industry frameworks such as MITRE ATT&CK, STRIDE, or the Cyber Kill Chain.
  • Design actionable SIEM use cases, detection rules, and workflows aligned with risk prioritisation.
  • Evaluate use‑case effectiveness through continual testing and KPIs, prioritising iteration based on business relevance.

Reporting & Documentation

  • Develop dashboards and metrics‑driven reports to showcase security posture and incident trends for leadership.
  • Maintain detailed documentation of incident procedures, runbooks, playbooks, and analysis reports for audit or team use.
  • Support monthly managerial reporting packs to present SOC effectiveness metrics (e.g., incident response times, detection improvements).

Training, Mentorship, & Pre‑Sales Support

  • Provide mentorship to junior SOC analysts, transferring technical expertise on threat detection and response best practices.
  • Assist pre‑sales teams by demonstrating SOC tools to prospective clients and refining operational delivery proposals.
  • Scope, deploy, and operationalise new SOC solutions, benchmarking against industry and client expectations.

Technical Skills

  • Proven hands‑on experience with SIEM platforms such as Splunk, QRadar, Sentinel, Microsoft Defender, or Chronicle.
  • Expertise with SIEM query languages (e.g., KQL, SPL, AQL) and strong knowledge of log normalisation and parsing.
  • Proficiency in scripting (e.g., Python, PowerShell) to automate tasks and build SOC efficiencies.
  • Deep familiarity with cyber threat detection techniques related to frameworks like MITRE ATT&CK and vulnerability management.
  • Experience managing ITIL processes, including Incident, Problem, and Change Management.

Certifications Required

  • CISSP, GIAC, SC-200, Splunk Power User/Admin, QRadar Specialist, or Chronicle Security Engineer certifications preferred.
  • Candidates must be eligible to obtain UK SC clearance.

Professional Skills

  • Strong analytical and communication skills to present complex information to technical and non‑technical stakeholders.
  • Experience in collaborative team dynamics and independent problem‑solving.
  • Proven ability to transfer knowledge and mentor junior SOC team members effectively.

Benefits

We offer a range of tailored benefits that support your physical, emotional, and financial wellbeing. Our Learning and Development team ensures continuous growth and development opportunities for our people. Flexible work options are also available.

Security Engineer in England employer: NTT Ltd.

As a leading employer in the cybersecurity sector, we pride ourselves on fostering a dynamic work culture that prioritises employee wellbeing and professional growth. Our commitment to continuous learning is reflected in our tailored benefits and flexible work options, ensuring that our Security Engineers thrive both personally and professionally while contributing to cutting-edge threat detection and response initiatives.

NTT Ltd.

Contact Detail:

NTT Ltd. Recruiting Team

StudySmarter Expert Advice🤫

We think this is how you could land Security Engineer in England

Network Like a Pro

Get out there and connect with folks in the industry! Attend meetups, webinars, or even online forums. The more people you know, the better your chances of hearing about job openings before they hit the market.

Show Off Your Skills

Don’t just list your skills on your CV; demonstrate them! Create a portfolio or GitHub repository showcasing your projects, especially those related to SIEM platforms and threat detection. This gives potential employers a taste of what you can do.

Ace the Interview

Prepare for common interview questions but also be ready to discuss specific scenarios from your past experiences. Use the STAR method (Situation, Task, Action, Result) to structure your answers and highlight your problem-solving skills.

Apply Through Our Website

When you find a role that excites you, apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are genuinely interested in joining our team.

We think you need these skills to ace Security Engineer in England

SIEM Platforms (Splunk, QRadar, Sentinel, Chronicle)
Log Normalization and Parsing
SIEM Query Languages (KQL, SPL, AQL)
Scripting (Python, PowerShell)
Threat Detection Techniques (MITRE ATT&CK)
Incident Response Playbook Design
Automation Integration (SOAR platforms)

Some tips for your application 🫡

Tailor Your CV:Make sure your CV speaks directly to the role of Security Engineer. Highlight your experience with SIEM platforms and any relevant certifications. We want to see how your skills match up with what we're looking for!

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about security engineering and how your background makes you a great fit for our team. Keep it engaging and personal – we love to see your personality!

Showcase Your Technical Skills:Don’t hold back on detailing your technical expertise! Mention specific tools, languages, and frameworks you've worked with, especially those related to threat detection and incident response. We’re keen to know what you bring to the table!

Apply Through Our Website:We encourage you to apply through our website for a smoother process. It helps us keep track of your application and ensures you don’t miss out on any important updates. Plus, it’s super easy!

How to prepare for a job interview at NTT Ltd.

Know Your SIEM Platforms

Make sure you’re well-versed in the SIEM platforms mentioned in the job description, like Splunk and QRadar. Brush up on your knowledge of their functionalities, query languages, and how they can be used for threat detection. Being able to discuss specific use cases or experiences with these tools will definitely impress.

Showcase Your Incident Response Skills

Prepare to talk about your experience designing incident response playbooks. Think of examples where you’ve automated responses or improved processes. Highlight any specific incidents you’ve managed and how you coordinated with teams to resolve them. This will show your practical understanding of the role.

Familiarise Yourself with Threat Modelling

Get comfortable discussing threat modelling frameworks like MITRE ATT&CK or STRIDE. Be ready to explain how you’ve applied these frameworks in past roles to develop actionable use cases. This shows that you not only understand the theory but can also apply it effectively in real-world scenarios.

Prepare Questions for Them

Interviews are a two-way street, so come prepared with insightful questions. Ask about their current security challenges, how they measure SOC effectiveness, or what tools they’re looking to implement next. This demonstrates your genuine interest in the role and helps you assess if the company is the right fit for you.