CybersecurityJobs.io
← Back to all jobs

Job Description

Beazley Security is looking for a Security Engineer to help run and improve the operational backbone of the SOC’s detection technology. In this role, you will own core Endpoint Detection and Response (EDR) and Network Detection and Response (NDR) platforms, ensuring reliable coverage across the enterprise estate and enabling the SOC to act with better visibility and alert quality.

Working remotely, you will combine platform engineering and security operations to maintain detection telemetry health, optimize detection logic, and support incident investigations end to end. Beazley Security also offers flexible working arrangements, robust benefits, and opportunities for ongoing training and career advancement.

What you’ll do

  • Act as the technical owner for SOC systems and operations, maintaining full operational coverage and enterprise integration.
  • Maintain physical and virtual infrastructure for EDR/NDR components, including appliances, sensors, collectors, and required upgrades or configuration changes.
  • Oversee policy, sensor deployment, and version control for EDR/NDR agents and connectors.
  • Validate data flow and health between endpoints, appliances, and the central XDR platform used by the SOC.
  • Coordinate with the SOC, vendors, and IT infrastructure teams to schedule upgrades, patching, and feature enablement.
  • Tune detection logic, behavioural models, and response policies to improve threat visibility and reduce false positives.
  • Implement NDR optimisation enhancements such as target model tuning, device tagging, and subnet labelling for faster investigations.
  • Maintain EDR configuration baselines and analytics dashboards.
  • Support integration and data quality within the Beazley Security XDR platform to ensure dependable event correlation.
  • Document configuration changes, tuning decisions, and engineering work in line with IT Security change management processes.
  • Collaborate with the SOC to ensure the right visibility, alert quality, and context for first-line detection and triage.
  • Join the escalation group for security cases from the centralized SOC and support containment or isolation activities when needed.
  • Provide subject-matter expertise on EDR/NDR telemetry during investigations and post-incident reviews.
  • Support root-cause analysis and recommend platform-level improvements following potential incidents.
  • Partner with Threat Intelligence and the MDR organization to proactively hunt for malicious activity and validate emerging TTPs.
  • Feed newly identified patterns back into SOC detection content and threat models.
  • Produce operational and executive reporting across managed detection platforms.
  • Participate in recurring technical optimisation sessions and quarterly business reviews with vendors.
  • Track detection efficacy, platform uptime, and configuration drift metrics as part of the IT Security KPI set.
  • Continuously assess opportunities for automation, enrichment, and process improvement.

What you bring

  • Minimum 3 years experience in security operations, cyber engineering, or platform management.
  • Hands-on experience administering and optimising leading NDR and EDR platforms.
  • Strong understanding of endpoint telemetry, network analytics, and SOC workflows.
  • Experience planning and performing platform upgrades, integrations, and lifecycle management.
  • Familiarity with MITRE ATT&CK and threat-hunting principles.
  • Ability to collaborate with SOC analysts, infrastructure teams, and vendors.
  • Excellent documentation, analytical, and communication skills.

Technologies you’ll work with

EDR, NDR, XDR, MITRE ATT&CK, SQL, PowerShell, Python, Identity Threat Detection & Response (ITDR)

Benefits

  • Competitive salary and bonus.
  • Flexible working arrangements.
  • Generous leave policies including 3 months paid parental.
  • 100% of employee-only insurance premiums covered (healthcare, dental and vision).
  • Up to 5% matched 401k contribution.
  • Opportunities for career advancement and ongoing training.
  • Participation in industry conferences and events.

Desirable skills

  • Experience working within hybrid SOC models (internal plus managed service).
  • Exposure to ITDR solutions.
  • Certifications such as CySA+, GCIA, or equivalent.
  • Scripting or query language capability (SQL, PowerShell, Python).

How you work

  • Highly organised and proactive, with strong ownership of assigned technologies.
  • Analytical approach to improving systems and processes.
  • Collaborative and approachable, bridging operations, engineering, and intelligence teams.
  • Calm under pressure, with a methodical and disciplined approach to incident support.

Key interfaces

Internal: Head of IT Security, SOC Manager, Incident Response, Infrastructure, Cloud, and Networking teams.

External: Beazley Security MDR SOC

Similar Jobs