SOC Solutions Engineer - QRadar and Splunk

Stratford, Greater London

We specialise in delivering cutting-edge IT and cybersecurity solutions to our diverse client base. We provide expert-managed services to help clients protect their data, comply with regulations, and manage evolving cyber threats. We are looking for a skilled Information Security Manager to join our team and be billed out to a key client to enhance their information security posture.,

  • The primary function of the Senior SOC Engineer is to enhance our security operations capabilities. This role requires deep expertise in SIEM platforms including Splunk, IBM QRadar, Microsoft Defender, Microsoft Sentinel, and Google Chronicle, with a strong focus on playbook development, analytical rule creation, and threat modelling. You will be instrumental in building and optimizing our detection and response strategies.
  • SIEM Engineering & Management
  • Deploy, configure, and maintain SIEM platforms (Splunk, QRadar, Sentinel, Defender, Chronicle).
  • Onboard and normalize log sources across cloud and on-prem environments.
  • Develop and optimize analytical rules for threat detection, anomaly detection, and behavioural analysis.
  • Playbook Development & Automation
  • + Design and implement incident response playbooks for various threat scenarios (e.g., phishing, lateral movement, data exfiltration). + Integrate playbooks with SOAR platforms (e.g., Microsoft Logic Apps, XSOAR) to automate triage and response. + Continuously refine playbooks based on threat intelligence and incident feedback.
  • Threat Detection & Response
  • + Monitor and analyse security alerts and events to identify potential threats. + Perform in-depth investigations and coordinate incident response activities. + Collaborate with threat intelligence teams to enrich detection logic.
  • Threat Modelling & Use Case Development
  • + Conduct threat modelling exercises using frameworks like MITRE ATT&CK, STRIDE, or Kill Chain. + Translate threat models into actionable detection use cases and SIEM rules. + Prioritize detection engineering efforts based on risk and business impact.
  • Reporting & Collaboration
  • + Generate reports and dashboards for stakeholders on security posture and incident trends. + Work closely with IT, DevOps, and compliance teams to ensure secure system configurations. + Provide mentorship and guidance to junior analysts and engineers. + Maintain accurate and up-to-date documentation of security procedures, incident response plans, and analysis reports. + Support the creation of monthly reporting packs as per contractual requirements. + Create and document robust event and incident management processes, Runbooks & Playbooks
  • Other responsibilities:
  • + Involvement in scoping and standing up new solutions for new opportunities + Assisting Pre-Sales team with requirements on new opportunities + Demonstrations of SOC tools to clients + Continual Service Improvement - Recommendations for change to address incidents or persistent events., We offer a range of tailored benefits that support your physical, emotional, and financial wellbeing. Our Learning and Development team ensure that there are continuous growth and development opportunities for our people. We also offer the opportunity to have flexible work options., We are an equal opportunities employer. We believe in the fair treatment of all our employees and commit to promoting equity and diversity in our employment practices. We are also a proud Disability Confident Committed Employer - we are committed to creating a diverse and inclusive workforce. We actively collaborate with individuals who have disabilities and long-term health conditions which have an effect on their ability to do normal daily activities, ensuring that barriers are eliminated when it comes to employment opportunities. In line with our commitment, we guarantee an interview to applicants who declare to us, during the application process, that they have a disability and meet the minimum requirements for the role. If you require any reasonable adjustments during the recruitment process, please let us know. Join us in building a truly diverse and empowered team.

  • Must be able to obtain SC Clearance or already hold SC clearance.
  • SIEM Expertise: Hands-on experience of IBM QRadar
  • Technical Skills:
  • + Strong knowledge of log formats, parsing, and normalization. + Experience with KQL, SPL, AQL, or other SIEM query languages. + Familiarity with scripting (Python, PowerShell) for automation and enrichment.
  • Security Knowledge:
  • + Deep understanding of threat detection, incident response, and cyber kill chain. + Familiarity with MITRE ATT&CK, NIST, and CIS frameworks.
  • Strong verbal and written English communication.
  • Strong interpersonal and presentation skills.
  • Strong analytical skills
  • Must have good understanding on network traffic flows and able to understand normal and suspicious activities.
  • Must have good understanding of Vulnerability Scanning and management as well as Ethical Hacking (Penetration Testing)
  • Knowledge of ITIL disciplines such as Incident, Problem and Change Management.
  • Ability to work with minimal levels of supervision.
  • Willingness to work in a job that involves 24/7 on call.
  • Education Requirements & Experience
  • Minimum of 3 to 5 years of experience in the IT security industry, preferably working in a SOC/NOC environment.
  • Preferably holds Cyber Security Certification e.g. ISC2 CISSP, GIAC, SC-200, Splunk Certified Admin/Power User, IBM QRadar Certified Specialist, Google Chronicle Security Engineer etc
  • Experience with Service Now Security suite
  • Experience with Cloud platforms (AWS and/or Microsoft Azure)
  • Excellent knowledge of Microsoft Office products, especially Excel and Word

    NTT Data is a leading Managed Service Provider (MSP) with a global reach empowering local team, undertaking hugely exciting work and is genuinely changing the world., We're a business with a global reach that empowers local teams, and we undertake hugely exciting work that is genuinely changing the world. Our advanced portfolio of consulting, applications, business process, cloud, and infrastructure services will allow you to achieve great things by working with brilliant colleagues, and clients, on exciting projects.
  • Our inclusive work environment prioritises mutual respect, accountability, and continuous learning for all our people. This approach fosters collaboration, well-being, growth, and agility, leading to a more diverse, innovative, and competitive organisation. We are also proud to share that we have a range of Inclusion Networks such as: the Women's Business Network, Cultural and Ethnicity Network, LGBTQ+ & Allies Network, Neurodiversity Network and the Parent Network.
Posted 2025-10-24

Recommended Jobs

Part-time Housekeeper in SW15, Job ID J1D97C

Little Ones UK Ltd
Wandsworth, Greater London

A lovely family in Wandsworth, London, seeks a Part-time Housekeeper to help maintain their property to a high standard and prepare meals for the family, starting January 2025. The ideal candidate mu…

View Details
Posted 2025-08-25

An Elective with a Difference at Medical Protection Society, Leeds or London

Medical Protection Society
London

Job Introduction An Elective with a Difference at Medical Protection Society We are offering a unique opportunity to spend your elective with the Medical Protection Society (MPS), the world’s lea…

View Details
Posted 2025-05-20

Member of Technical Staff, AI Pretraining

Microsoft
London

Help deliver one of the best foundational models in the world at Microsoft AI. At Microsoft AI, we are on a mission to train the world’s most capable AI frontier models, pushing the boundaries of …

View Details
Posted 2025-09-27

Retail Manager - Automotive Sales

Romford, Greater London

Salary: £30,000 basic + OTE £60,000 Lead. Motivate. Drive performance. We’re seeking a results-driven Retail Manager with a strong track record in automotive sales to take charge of sales …

View Details
Posted 2025-10-12

Supply Chain Assistant

coty
London

SUPPLY CHAIN ASSISTANT – DEMAND PLANNING COTY UK&I 13 MONTH INTERNSHIP We’re Coty, a global leader in beauty. We’re #1 in the world for Fragrance and #3 in the world in Colour Cosmetics w…

View Details
Posted 2025-10-18

Third Party Assurance Manager

Our Future Health
London

We are looking for a Third Party Assurance Manager who will play a key role in supporting Our Future Health to deliver on its strategic aims by ensuring supplier risks are well understood, effectivel…

View Details
Posted 2025-08-01

Aviation Underwriter

Harrison Holgate
London

Position: Senior Aviation Underwriter Salary: £130,000 + package Location: City of London An exciting new opportunity has arisen for an experienced Aviation Underwriter with strong London Marke…

View Details
Posted 2025-08-24

Corporate Tax Senior

Buckley Consulting
London

Corporate Tax Senior London/remote c£48,000 + Benefits Are you an ambitious tax professional looking to build on your background in corporate tax compliance, and an interest in advisory work? I…

View Details
Posted 2025-07-25

Independent Panel Member

London Borough of Havering
Havering, Greater London

Job Category :Interims Client Location :Romford Library, London Borough of Havering Hours Per Week :36.00 Start Date : Immediate Start               Start Time :09:00 End Time :17:30 Sa…

View Details
Posted 2025-08-29

Head of Operations

Broadwick
London

Role: Head of Operations Reports into:  Director of Live Operations Location: London Contract Type: Full Time, Permanent, 42.5 hours per week  Who we are: Broadwick Live is a multifa…

View Details
Posted 2025-07-29