Security Operations Engineer
Indexed description
- Health, Medical Science & Generative Biology
- Food Security & Sustainable Agriculture
- Climate Change & Managing CO₂
- Artificial Intelligence & Robotics
Your Role:
As EIT continues to expand its research programmes, digital platforms and scientific infrastructure, we are looking for an experienced and proactive Security Operations Engineer to help protect our people, platforms and world-class research.
This is an opportunity to play a meaningful role within a growing cyber security team, combining security monitoring, incident response, detection engineering and continuous improvement. You'll work closely with colleagues across IT, research computing, governance and legal functions to help create a secure environment that enables scientific discovery and innovation to thrive.
We are looking for individuals who enjoy solving complex problems, collaborating with others and continuously developing their skills in an environment where security is viewed as a trusted partner to the organisation.
Whether your background comes from a Security Operations Centre, incident response team or another security discipline, you'll have the opportunity to contribute, learn and grow while helping safeguard research that could shape the future.
Working as part of a collaborative cyber security team, you'll help strengthen our security capabilities while supporting the scientists, researchers and technology teams delivering work with global impact.
You will:
- Help operate and continuously improve security monitoring across endpoints, servers, cloud platforms and networks
- Maintain and optimise security tooling, including SIEM, EDR and cloud security platforms, to improve visibility and detection capabilities
- Investigate, triage and respond to security alerts, working with colleagues to identify and address potential threats
- Support incident response activities, helping to coordinate containment, remediation and recovery efforts
- Produce clear and accurate documentation, including incident reports, lessons learned and root cause analyses
- Contribute to the development of detection rules, automation workflows and threat-based use cases
- Use threat intelligence and emerging security trends to strengthen monitoring and detection capabilities
- Support vulnerability management activities, including assessment, prioritisation and remediation tracking
- Partner with colleagues across IT, research computing and governance teams to embed secure ways of working
- Contribute to security documentation, audit preparation, compliance activities and risk assessments
- Share knowledge and support a culture of continuous learning and improvement across the team
Essential Skills, Qualifications & Experience
We're particularly interested in candidates who can demonstrate:
- Experience working within Security Operations, a Security Operations Centre (SOC), Incident Response, or a similar cyber security function
- Hands-on experience using SIEM platforms such as Azure Sentinel, Splunk, Sophos Taegis, or equivalent technologies
- Familiarity with Endpoint Detection and Response (EDR) solutions such as SentinelOne, CrowdStrike or similar tools
- A good understanding of common cyber threats, attack techniques and detection methodologies, including familiarity with the MITRE ATT&CK framework
- Working knowledge of Windows and Linux operating systems, networking fundamentals and identity management technologies
- Experience supporting or securing cloud environments, ideally within a complex or enterprise setting
- Strong analytical and problem-solving skills, with the ability to investigate and respond to security events effectively
- The ability to communicate technical information clearly to both technical and non-technical audiences
- A collaborative approach and a desire to work closely with colleagues across a range of disciplines
- A commitment to continuous learning and professional development
- Experience with scripting or automation using Python, PowerShell, Bash or similar languages
- Experience working in research, higher education, healthcare, scientific or other innovation-focused environments
- Familiarity with SOAR platforms and security automation technologies
- Experience supporting organisations aligned to ISO27001:2022 or other recognised security frameworks
- Relevant certifications such as ISC2 Certified in Cybersecurity (CC), CompTIA Security+, CISSP, SSCP, CySA+, or similar
- Experience supporting large-scale data platforms, research computing environments or high-performance computing (HPC) infrastructure
- Curious and motivated to learn
- Calm and methodical when solving problems
- Collaborative and supportive team players
- Comfortable building relationships across technical and non-technical teams
- Passionate about using technology to enable meaningful scientific and societal impact
- Salary - £60,000 - £70,000 + travel allowance + bonus
- Enhanced holiday. Our annual leave allowance is 25 days plus 8 bank holidays and an additional 3 days between Christmas and New Year. You will also have the opportunity to purchase an additional 5 days annual leave in January and July.
- Pension - Employer contribution 7.5%, minimum employee contribution 5%
- Life Assurance.
- Income Protection
- Private Medical Insurance as standard for you, your partner and any dependents. Including hospital Cash Plan
- Employee discounts
- Electric car scheme
- Nursery Salary Sacrifice scheme
- Cycle to Work Scheme
- Family Planning
- Neurodiversity support including advise and assessments
- Coaching & Therapy services
- You must have the right to work permanently in the UK with a willingness to travel as necessary. In certain cases, we can consider sponsorship, and this will be assessed on a case-by-case basis and volume of local applications
- You will live in, or within easy commuting distance of, Oxford (or be willing to relocate)
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search