Skip to main content
AfterDuty

Security Operations Engineer

Context Recruitment · London, Greater London

Type
Full-time
Posted
7 days ago

Overview

Your incident response and investigative discipline from policing transfer to triaging security alerts.

About this role

SecOps Engineer – Central London (hybrid working)

Up to £75,000 PA

Well-established and highly profitable construction engineering business is seeking an experienced SecOps Engineer to join them on a permanent basis. This is a critical role within an organisation undergoing significant digital transformation, with ambitious growth and acquisition plans driving the need for secure, scalable and standardised IT services.

This role is ideal for a proactive security professional with strong technical expertise across Microsoft 365, cloud, infrastructure and network security. You will play a key part in implementing security controls, mitigating risk, improving the organisation's overall security posture and ensuring systems remain compliant with ISO 27001 and Cyber Essentials Plus (CE+).

Responsibilities

  • Monitor security tools including SIEM (QRadar) and respond to threat detection alerts
  • Triage, analyse and prioritise security incidents via ServiceNow
  • Investigate root causes of security issues and design effective remediation solutions
  • Oversee Patch Management across servers, endpoints and infrastructure
  • Conduct vulnerability scans using Qualys, analyse findings and prioritise remediation activities
  • Take ownership of the Microsoft 365 security platform, proactively analysing the environment and remediating security recommendations across Microsoft Defender, Entra ID and Intune
  • Review, optimise and maintain Conditional Access Policies, Compliance Policies and Configuration Profiles to ensure user accounts and endpoint devices remain secure and compliant
  • Implement and continuously improve Microsoft 365 security controls, identity protection and endpoint compliance in line with Microsoft best practices
  • Support the organisation's ISO 27001 and Cyber Essentials Plus (CE+) compliance by implementing and maintaining appropriate Microsoft security controls
  • Manage end-user device (EUD) security through Microsoft Intune, Sophos and NinjaOne
  • Schedule and assess vulnerability scans on critical infrastructure
  • Maintain patching compliance for Windows OS, Microsoft 365 applications and third-party software
  • Collaborate with external SOC providers to investigate and respond to security incidents
  • Automate security processes and operational tasks using PowerShell, Batch or similar scripting languages
  • Produce post-incident reports, root cause analyses and security recommendations
  • Document SecOps processes and create knowledge base articles in line with best practices
  • Support infrastructure teams to deploy systems, strengthen security policies and manage security-related changes
  • Produce weekly security operations and compliance reports
  • Manage Cisco Umbrella web filtering and SSL inspection policies

Requirements

  • Previous hands-on experience within a Security Operations (SecOps), Cyber Security or Incident Response role
  • Strong experience administering and securing Microsoft 365 environments
  • Hands-on experience with Microsoft Entra ID, Microsoft Intune, Microsoft Defender and Microsoft 365 security capabilities
  • Experience reviewing and optimising Conditional Access Policies, Compliance Policies and Configuration Profiles
  • Experience assessing Microsoft Secure Score and remediating Microsoft 365 security recommendations
  • Experience implementing Microsoft security controls to support ISO 27001 and Cyber Essentials Plus (CE+) compliance
  • Strong knowledge of Microsoft Windows security and system hardening
  • Working PowerShell scripting ability for automation tasks
  • Solid understanding of cloud security across Microsoft 365, Azure and AWS
  • Experience supporting enterprise IT infrastructure
  • Recognised security certifications such as Security+, CEH, Microsoft Security certifications or equivalent

Any experience with the following will be highly favoured

  • Qualys Vulnerability Management
  • QRadar SIEM
  • Varonis
  • Microsoft Purview (Compliance, Information Protection or Data Loss Prevention)
  • ServiceNow
  • Cisco Umbrella
  • Network security knowledge covering TCP/IP, VPNs, routing, firewalls and network segmentation
  • Sophos security solutions
  • NinjaOne endpoint management

Initially 4 days per week onsite in Central London, reducing to 2 days per week after probation.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in London

Why this fits a police background

  • Incident command & response
  • Investigative casework
  • Working to legislation & regulation
  • Security operations

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • £35,000 – £40,000Estimated

    Your risk assessment and incident management skills from policing are directly applicable to this GRC role.

    Posted 3 days ago

  • Full-time

    Your incident command and multi-agency coordination experience translates directly to operational resilience and third-party oversight.

    Posted 3 days ago

  • Full-time

    Your investigative mindset and evidence-handling discipline from policing transfer directly to digital forensics and incident response.

    Posted 4 days ago

  • GRC Manager - 6 month FTC

    Trayport · London

    Full-time

    Your experience managing risk, policy, and regulatory compliance under frameworks like PACE transfers directly to GRC.

    Posted 6 days ago