The SecOps Engineer is responsible for the day-to-day monitoring, investigation and operational response to cybersecurity events across the organisation’s technology environment. The role ensures that security controls are actively monitored, security alerts are investigated, incidents are managed appropriately, and recurring security activities are performed consistently and evidenced.
Working closely with the Security Engineer, IT Operations, Cloud & Platform Engineering and other technology teams, the SecOps Engineer provides the operational security capability required to protect corporate, cloud, gaming, retail and digital environments.
Security Monitoring & Operations
- Perform daily and scheduled security monitoring activities in accordance with approved procedures and monitoring schedules.
- Monitor Microsoft Sentinel, Microsoft Defender XDR and other security platforms for alerts, anomalous behaviour and suspicious activity.
- Investigate and triage security alerts, determine severity and ensure timely escalation and response.
- Monitor identity, endpoint, network, cloud and externally exposed environments for cyber threats and control failures.
- Maintain accurate security operations records, logs, dashboards and supporting evidence.
Incident Response
- Support the investigation, containment, escalation and recovery of cyber security incidents.
- Coordinate technical response activities with relevant technology teams and external providers where required.
- Maintain incident records and ensure actions are tracked through to documented closure.
- Support phishing, malware, compromised-account and suspicious-activity investigations.
- Assist with evidence gathering and chain-of-custody requirements when applicable.
- Participate in post-incident reviews and ensure lessons learned are converted into practical improvements.
Data Loss Prevention (DLP)
- Perform recurring monitoring and review of DLP alerts and events.
- Investigate suspected data leakage, inappropriate information sharing or policy violations and escalate potential incidents appropriately.
- Maintain evidence of DLP monitoring, investigations and follow-up actions through a consistent and repeatable process.
- Support continuous improvement of DLP controls and procedures in conjunction with the CISO, DPO and Security Engineer.
Vulnerability & Threat Monitoring
- Support scheduled vulnerability scanning and external attack-surface monitoring.
- Review findings from vulnerability and threat-monitoring platforms, validate issues and coordinate remediation with system owners.
- Track outstanding vulnerabilities and ensure critical or overdue items are escalated.
- Monitor relevant threat intelligence and emerging security threats that may affect the organisation.
Identity, Endpoint & Cloud Security Operations
- Monitor Microsoft Entra ID security events, risky users, privileged activity and suspicious authentication behaviour.
- Support monitoring of MFA, Conditional Access and privileged access controls.
- Monitor Microsoft Defender endpoint alerts and investigate suspicious endpoint activity.
- Support device security and compliance monitoring through Microsoft Intune and associated platforms.
- Monitor security events across cloud and edge services, including AWS, GCP and Cloudflare where applicable.
Security Awareness & Operational Support
- Support phishing simulation exercises, security awareness initiatives and the investigation of reported phishing emails.
- Provide practical security guidance to employees and technology teams within the scope of approved policies and procedures.
- Support security exercises, operational reviews and improvement initiatives.
Audit, Compliance & Evidence Support
- Maintain evidence that recurring security operations are being performed consistently and in accordance with approved procedures.
- Support WLA-SCS and ISO/IEC 27001 audit preparation by providing security logs, monitoring records, incident evidence and operational records.
- Support corrective-action tracking arising from security reviews, audits and operational findings.
- Assist the CISO and Security Engineer in demonstrating that technical security controls are operating effectively in practice.
On-Call & Operational Support Obligations
The SecOps Engineer participates in the organisation's cyber security incident response and on-call arrangements and may be required to provide out-of-hours support for:
- Cyber security incidents and critical security alerts.
- Ransomware, malware or endpoint compromise events.
- Identity compromise or suspicious privileged activity.
- Data loss or suspected data leakage incidents.
- Critical vulnerabilities or major operational incidents with a security impact.
Security Tooling
The role is expected to work with security platforms including:
- Microsoft Sentinel and Microsoft Defender XDR.
- Microsoft Defender for Endpoint, Microsoft Entra ID and Microsoft Intune.
- Microsoft Purview / Data Loss Prevention capabilities.
- Tenable Nessus and Tenable Web Application Scanning.
- Shodan and other attack-surface monitoring tools.
- Cloudflare security and monitoring services.
Performance & Success Measures
- Timely review, escalation and closure of security alerts.
- Improved Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR).
- Consistent completion and evidence of scheduled SecOps activities.
- Quality and completeness of incident records and security evidence.
- Timely escalation and remediation of critical vulnerabilities.
- Effective DLP monitoring and investigation.
- Reduction in repeat security incidents and recurring control failures.
- Audit readiness and quality of operational security evidence.
Key Requirements
- Degree, Diploma or equivalent professional qualification in Cyber Security, Information Security, Computer Science, Information Technology or a related discipline.
- Typically 2–4 years of experience in cyber security, security operations, infrastructure security or a related technical environment.
- Experience monitoring and investigating security alerts and working with SIEM, XDR and endpoint protection technologies.
- Understanding of cyber incident response, vulnerability management and identity security.
- Familiarity with Microsoft cloud and security environments.
- Experience within regulated, gaming, financial-services or other compliance-driven environments is advantageous.
Preferred Certifications
- Microsoft Security Operations Analyst (SC-200).
- CompTIA Security+.
- Microsoft Identity & Access Administrator (SC-300).
- Blue Team Level 1 or equivalent SOC/security-operations certification.
- GIAC or equivalent security operations certification is advantageous.
Vacancy posted on: September 7, 2026
Apply for SecOps Engineer
Please fill out the following form. After you have completed your application an email will be sent to you with relevant information.

