Find your next tech and IT Job or contract Endpoint detection and response (EDR)

45 results
Contractor

Contractor jobAnalyste Senior CyberSOC L3 / CSIRT H/F

Comet
Published on
AWS Cloud
Azure
Google Cloud Platform (GCP)

1 year
Ile-de-France, France
Au sein du département Group Digital and IT International, vous rejoignez l'équipe REACT, le pôle d'expertise et de réponse à incident du CyberSOC. En tant qu'Analyste Senior CyberSOC L3 / CSIRT, vous êtes au cœur de la stratégie de cyberdéfense du Groupe. Vous pilotez les incidents majeurs, menez des investigations technologiques poussées (DFIR, Threat Hunting) et contribuez activement à l'amélioration continue des capacités de détection, de réponse et d'automatisation. Vos Missions1. Réponse à incident & Gestion de crisePiloter les incidents majeurs et coordonner la gestion de crise avec les équipes IT, Cloud, Infrastructures et métiers. Mener les analyses post-compromission sur les postes, serveurs, environnements cloud, identités, applications et environnements industriels (OT). Définir et superviser les stratégies de confinement, d'éradication, de remédiation et de restauration sécurisée. 2. Digital Forensics & Threat HuntingRéaliser des investigations numériques (DFIR) approfondies sur infrastructures hybrides (SaaS, Cloud, On-premise). Collecter, préserver et analyser les preuves numériques en garantissant la chaîne de traçabilité. Traquer proactivement les menaces (Threat Hunting) pour identifier les compromissions silencieuses (IoC, TTPs MITRE ATT&CK). Produire les rapports d'incident et piloter les retours d'expérience (RETEX). 3. Expertise technique & Amélioration continueCréer et maintenir les procédures, playbooks de réponse et use-cases de détection. Faire évoluer la pile technologique du CyberSOC (XDR, SIEM, SOAR). Participer aux exercices Purple Team pour challenger et renforcer la posture de sécurité. 4. Leadership technique & MentoratAssurer un rôle d'escalade et d'expertise auprès des analystes L1/L2. Accompagner la montée en compétences technique de l'équipe SOC. Collaborer étroitement avec les pôles CTI, Offensive Security, Architecture Sécurité et Cyber Défense.
View this job
Permanent

Job VacancyAI & Machine Learning Engineer

█ █ █ ██ █ █
Published on
CI/CD
Docker
Python

Manchester, England, United Kingdom

Imported from

Job from the tech market, identified automatically to give you a complete view of the opportunities.

Restricted access to the community

Join our platform to access the details of this job and get access to the best offers on the market.

View this job
Permanent
Contractor

Job VacancyIngénieur Sécurité Confirmé H/F

CONSORT GROUP
Published on
Active Directory
Azure
CrowdStrike

1 month
45k-55k €
Vierzon
Chaque moment compte. Surtout ceux que vous vivez à fond. Bienvenue chez Consort Group. Consort Group, accompagne depuis plus de 30 ans les entreprises dans la valorisation de leurs données et infrastructures. Elle s'appuie sur deux leaders, Consortis et Consortia, et place l'humain et la responsabilité sociétale au cœur de ses valeurs. C'est votre future équipe Créée en 2010, l'agence Ouest rassemble aujourd'hui près de 230 collaborateurs. Elle s'est fortement orientée vers les expertises en intégration applicative et en testing, en s'appuyant sur ses Centres de Services. Le tout dans un esprit de convivialité et de proximité, au service des régions de Nantes, Rennes et Angers. Ingénieur Sécurité Confirmé H/F C'est votre missionVous êtes passionné·e par la cybersécurité et la protection des systèmes d'information ? Ce poste est fait pour vous. En tant qu'Ingénieur Sécurité Confirmé, vous êtes responsable du renforcement de la posture de sécurité et de l'intégration des bonnes pratiques cyber au sein d'un environnement multisites combinant infrastructures IT, cloud et environnements industriels. Côté build :Intégrer la sécurité dans les projets DSI selon une approche Security by Design. Réaliser des revues d'architecture, analyses de risques et recettes de sécurité. Participer au durcissement des environnements Windows, Linux, Active Directory, Microsoft 365 et Azure. Contribuer à la sécurisation des environnements industriels OT/IoT des sites de production. Participer aux projets de mise en conformité NIS2 et aux audits internes ou externes. Faire évoluer les outils de sécurité du groupe : EDR/XDR, pare-feu, proxy, WAF, filtrage des messageries. Côté run :Administrer et maintenir les solutions de sécurité du SI. Piloter le programme de gestion des vulnérabilités : scans, priorisation et suivi de remédiation. Assurer le suivi des alertes remontées par le SOC et qualifier les incidents de sécurité. Participer aux investigations, actions de containment et plans de remédiation. Maintenir et tester les procédures de réponse à incident ainsi que le plan de continuité SI. Produire les indicateurs, tableaux de bord et KPI sécurité à destination du RSSI et de la direction. Mener des actions de sensibilisation auprès des utilisateurs et des filiales. C'est votre parcoursVous avez au moins 4 ans d'expérience en cybersécurité opérationnelle, idéalement au sein d'environnements multisites ou industriels. Vous aimez relever les défis liés à la sécurisation des systèmes d'information tout en accompagnant les équipes dans l'évolution des pratiques. Vous recherchez un environnement où expertise technique, autonomie et collaboration avancent ensemble. C'est votre expertiseInfrastructures réseaux : TCP/IP, segmentation réseau, VPN. Systèmes Windows, Linux et Active Directory. Solutions EDR/XDR (CrowdStrike, SentinelOne, Microsoft Defender ou équivalent). Pare-feu et solutions de sécurité réseau (Fortinet, Palo Alto, Stormshield). SIEM (Microsoft Sentinel, Splunk, QRadar). Outils de gestion des vulnérabilités (Tenable, Qualys). Environnements Microsoft Azure, Entra ID et Microsoft 365 Security. Référentiels ISO 27001, NIST, guides ANSSI et réglementation NIS2. Scripting PowerShell et/ou Python. Une connaissance des environnements OT/ICS (IEC 62443) constitue un atout. C'est votre manière de faire équipeAutonomie et sens des priorités dans un environnement multi-entités. Esprit d'analyse et rigueur dans la gestion des risques et incidents. Réactivité et capacité à prendre des décisions en contexte sensible. Excellentes qualités relationnelles et pédagogiques auprès d'interlocuteurs techniques et métiers. Capacité à vulgariser les enjeux de cybersécurité et à fédérer les équipes. Anglais technique permettant la lecture et l'exploitation de documentations spécialisées. C'est notre engagementChez Consort Group, vous êtes un·e expert·e qu'on accompagne pour que chaque mission devienne une étape qui compte. Un onboarding attentif et humain. Une vraie proximité managériale. Des formations accessibles en continu. Des engagements concrets : inclusion, égalité, solidarité. Un package RH complet : mutuelle, carte TR, CSE, prévoyance. Une culture du feedback et des projets qui font sens. C'est clairLe process de recrutement : Un premier échange téléphonique avec notre team recrutement. Un entretien RH ainsi qu'un échange métier avec un·e Ingénieur·e d'Affaires. Un test ou un échange technique avec un·e de nos expert·e·s. Un dernier point avec votre futur·e manager ou responsable de mission. Et si on se reconnaît : on démarre ensemble. C'est bon à savoirLieu : Angers Contrat : CDI Télétravail : 2 jours/semaine Salaire : De 45 K€ à 55 K€ brut annuel (selon expérience) Famille métier : Cybersécurité / Infrastructure & Sécurité des SI Ce que vous ferez ici, vous ne le ferez nulle part ailleurs. Ce moment, c'est le vôtre.
View this job
Contractor

Contractor jobAnalyste CyberSoc anglais bilingue mission en Chine

IBSI
Published on
CyberSoc
Google Security Operations (SecOps)
Threat hunting

12 months
€510-580
China
Cyber Security Operations Center (SOC) Analyst [Shanghai] About the Role Join an elite operational cybersecurity team whose mission is to rapidly detect, investigate, and respond to cyber threats and security incidents. As a SOC Analyst, you will be at the forefront of cyber defense, leveraging advanced security technologies to identify malicious activity, conduct investigations, and support incident response efforts. • Be part of a highly skilled cyber defense team operating in a dynamic and challenging environment. • Work with advanced security technologies and modern detection capabilities. • Develop expertise in incident response, threat hunting, and digital forensics. • Investigate real-world cyber threats and contribute to the protection of a global organization. • Collaborate with international cybersecurity teams and security experts. • Play a key role in enhancing detection capabilities and strengthening cyber resilience. Key Responsibilities • Monitor and analyze security events and alerts from multiple security platforms. • Perform triage, investigation, and escalation of security incidents. • Conduct root cause analysis and support digital forensic investigations. • Execute incident response activities, including containment, eradication, and recovery. • Perform proactive threat hunting activities to identify potential threats. • Develop and improve detection rules, playbooks, and security use cases. • Collaborate with global cybersecurity teams to ensure effective threat monitoring and response. • Document incidents and produce clear reports for both technical and non-technical stakeholders. • Contribute to the continuous improvement of SOC processes, tools, and operational capabilities. Technical Environment • SOAR: Palo Alto Cortex - EDR: SentinelOne - NDR: Vectra - SIEM: Google SecOps - Sandbox : Joe Sandbox Proven experience in a Security Operations Center (SOC) environment. Strong knowledge of cybersecurity operations, threat detection, and incident response. Hands-on experience with SIEM, EDR, NDR, and SOAR technologies. Excellent analytical, investigation, and problem-solving skills. Ability to operate effectively in a fast-paced, global cybersecurity environment. Fluency in both English and Mandarin Chinese is mandatory. Strong communication skills, with the ability to present technical findings to both technical and non-technical stakeholders. Compétences SIEM (Google SecOps) Confirmé Threat Hunting Expert Threat Detection & Analysis Expert Incident Response Expert Security Operations Center (SOC) Expert
View this job
Permanent

Job VacancyData Scientist

█ █ █ ██ █ █
Published on
Apache Kafka
Apache Spark
CI/CD

South Sudan

Imported from

Job from the tech market, identified automatically to give you a complete view of the opportunities.

Restricted access to the community

Join our platform to access the details of this job and get access to the best offers on the market.

View this job
Permanent

Job VacancyInformation Security Manager with Network Engineering Skills

Nexus Jobs Limited
Published on

£85k-100k
London, England, United Kingdom
Information Security Manager with Network Engineering Skills Our Client is bank based in Central London who are looking to recruit a seasoned professional with at least 7 to 10 years expertise level Information Security coupled with Hands-on Network Engineering. The role is mainly Information Security – Data Security and split circa 80% with 20% Network Engineering – so you do need to be hands-on technically. You will ideally have circa 5+ years of work experience with Network Engineering coupled with over 10 years experience with Cisco Systems Products Role Description The Information Security Manager with Network Engineering Skills is a full-time hybrid role based in London, with the flexibility to work from home part of the week. The role oversees the design, implementation, and continuous improvement of information security policies, procedures, and controls across networks and systems. Day-to-day responsibilities include managing the Information Security Management System (ISMS), monitoring cybersecurity and network security events, coordinating incident response, and ensuring compliance with relevant standards and regulations. The person in this role will collaborate with IT and business stakeholders to assess risks, implement technical and procedural safeguards, and support secure network architecture and configuration. Additional tasks include producing security documentation, leading security awareness initiatives, and providing guidance on secure network engineering practices. Qualifications Strong skills in Information Security Management and Information Security, with experience defining and enforcing security policies and governance. Hands-on expertise with Information Security Management Systems (ISMS), including implementation, maintenance, and audit readiness. Proficiency in Cybersecurity and Network Security, covering threat detection, vulnerability management, network hardening, and incident response. Demonstrated network engineering experience (e.g., routing, switching, firewalls, VPNs, secure network design). Relevant certifications such as CISSP, CISM, CISA, CompTIA Security+, or similar are beneficial. Experience with regulatory and compliance frameworks (e.g., ISO 27001, GDPR, NIST) and security best practices. Ability to analyze complex technical environments, communicate clearly with both technical and non-technical stakeholders, and document security requirements and processes. Bachelor's degree in computer science, information security, engineering, or a related field, or equivalent professional experience. Key Networking Skills Required: Cisco Network Switches Layer 2 and 3 (Catalyst 9K) – CCNP Level, Expert Level Preferred Routing protocol – OSPF (Catalyst 9K) – CCNP Level, Expert Level Preferred Cisco Switch Stacking (Cat 9K Switches 9600, 9300. 9200) Virtual Routing and Forwarding – (Catalyst 9600) Internetworking Troubleshooting - CCNP Level, Expert Level Preferred High Availability and Disaster Recovery - CCNP Level, Expert Level Preferred Security/Cyber Security Skills Required: Cisco Firepower Firewalls (ASA, FTD) - CCNP Level, Expert Level Preferred Palo Alto Firewalls – Specialist Level, Architect Level Preferred Cisco Layer 2 Port Security Network Access Control including Cisco ISE, TACACS etc Network Detection and Response Network Encryption (Site to Site VPN's) Cisco Secure Client (ASA) Network IPS (Trellix) Network Zero Day (Trellix NX or similar) Host Zero Day (Trellix HX or similar) Cyber Security Network Control Incident Investigation with the assistance of group cyber security experts – Tier 1, Tier 2 to 3 preferred, using LogRhythm SIEM a bonus Host End Point Protection (Symantec) Host IPS Preferred Skills and Knowledge Vulnerability Management (Scanning for Vulnerabilities and classifying the risk, CIS Benchmark Scanning and compliance) – Using Rapid7 a bonus Knowledge of Penetration Testing, understanding of the types of testing and their advantages and disadvantages Security Zone Design and considerations Network and Security Architecture Design and Considerations Understanding of Information Security (Confidentiality, Integrity, Availability), MITRE ATT&CK, NIST, ISO 27001, SIEM use cases for key controls etc Risk Management in Cyber Security, SSL Blind spots, what causes them and how to mitigate Malware/Ransomware and how to mitigate along with Penetration testing concepts Understanding of White/Black/Grey Box penetration testing. Developing Security policies and procedures and conducting audits/risk assessments Handling crisis situations during security incidents The role is hybrid 3 days in the office in Central London. The salary for this role will be in the range £85K - £100K + Benefits. Do send your CV to us in Word format along with your salary and notice period.
View this job
Contractor

Contractor jobInformation Security Manager with Network Engineering Skills

Nexus Jobs Limited
Published on

£500-650
London, England, United Kingdom
Information Security Manager with Network Engineering Skills Our Client is bank based in Central London who are looking to recruit a seasoned professional with at least 7 to 10 years expertise level Information Security coupled with Hands-on Network Engineering. The role is mainly Information Security – Data Security and split circa 80% with 20% Network Engineering – so you do need to be hands-on technically. You will ideally have circa 5+ years of work experience with Network Engineering coupled with over 10 years experience with Cisco Systems Products Role Description The Information Security Manager with Network Engineering Skills is a full-time hybrid role based in London, with the flexibility to work from home part of the week. The role oversees the design, implementation, and continuous improvement of information security policies, procedures, and controls across networks and systems. Day-to-day responsibilities include managing the Information Security Management System (ISMS), monitoring cybersecurity and network security events, coordinating incident response, and ensuring compliance with relevant standards and regulations. The person in this role will collaborate with IT and business stakeholders to assess risks, implement technical and procedural safeguards, and support secure network architecture and configuration. Additional tasks include producing security documentation, leading security awareness initiatives, and providing guidance on secure network engineering practices. Qualifications Strong skills in Information Security Management and Information Security, with experience defining and enforcing security policies and governance. Hands-on expertise with Information Security Management Systems (ISMS), including implementation, maintenance, and audit readiness. Proficiency in Cybersecurity and Network Security, covering threat detection, vulnerability management, network hardening, and incident response. Demonstrated network engineering experience (e.g., routing, switching, firewalls, VPNs, secure network design). Relevant certifications such as CISSP, CISM, CISA, CompTIA Security+, or similar are beneficial. Experience with regulatory and compliance frameworks (e.g., ISO 27001, GDPR, NIST) and security best practices. Ability to analyze complex technical environments, communicate clearly with both technical and non-technical stakeholders, and document security requirements and processes. Bachelor's degree in computer science, information security, engineering, or a related field, or equivalent professional experience. Key Networking Skills Required: Cisco Network Switches Layer 2 and 3 (Catalyst 9K) – CCNP Level, Expert Level Preferred Routing protocol – OSPF (Catalyst 9K) – CCNP Level, Expert Level Preferred Cisco Switch Stacking (Cat 9K Switches 9600, 9300. 9200) Virtual Routing and Forwarding – (Catalyst 9600) Internetworking Troubleshooting - CCNP Level, Expert Level Preferred High Availability and Disaster Recovery - CCNP Level, Expert Level Preferred Security/Cyber Security Skills Required: Cisco Firepower Firewalls (ASA, FTD) - CCNP Level, Expert Level Preferred Palo Alto Firewalls – Specialist Level, Architect Level Preferred Cisco Layer 2 Port Security Network Access Control including Cisco ISE, TACACS etc Network Detection and Response Network Encryption (Site to Site VPN's) Cisco Secure Client (ASA) Network IPS (Trellix) Network Zero Day (Trellix NX or similar) Host Zero Day (Trellix HX or similar) Cyber Security Network Control Incident Investigation with the assistance of group cyber security experts – Tier 1, Tier 2 to 3 preferred, using LogRhythm SIEM a bonus Host End Point Protection (Symantec) Host IPS Preferred Skills and Knowledge Vulnerability Management (Scanning for Vulnerabilities and classifying the risk, CIS Benchmark Scanning and compliance) – Using Rapid7 a bonus Knowledge of Penetration Testing, understanding of the types of testing and their advantages and disadvantages Security Zone Design and considerations Network and Security Architecture Design and Considerations Understanding of Information Security (Confidentiality, Integrity, Availability), MITRE ATT&CK, NIST, ISO 27001, SIEM use cases for key controls etc Risk Management in Cyber Security, SSL Blind spots, what causes them and how to mitigate Malware/Ransomware and how to mitigate along with Penetration testing concepts Understanding of White/Black/Grey Box penetration testing. Developing Security policies and procedures and conducting audits/risk assessments Handling crisis situations during security incidents The role is hybrid 3 days in the office in Central London. The rate for this role will be in the range £500 pd to £650 pd. This is a 3 month assignment. Do send your CV to us in Word format along with your salary and notice period.
View this job
Permanent

Job VacancyCyber Security Manager

Nexus Jobs Limited
Published on

£70k-80k
Paddington, England, United Kingdom
Cyber Security Manager Our Client to be secured and protected from increased cyber threats and compliant to industry standards. This role covers information protection, including data loss protection and data classification, and threat protection, including security information and event management (SIEM), user and entity behaviour analytics (UEBA), point products like anti-virus (AV) and intrusion detection system/intrusion prevention system (IDS/IPS) and penetration testing. The Service Delivery team consists of approximately 20 staff who support and operate the Company's services and there is an opportunity in that team for a Cyber Security Manager to oversee and govern all security services. Reporting Lines This role reports to Head of Service Delivery Main Accountabilities Technical leadership for all security solutions, including all the 3rd party managed services Maintain the overall security of Company's network, systems, and data Monitor security access and manage IDS/IPS configurations Establishing and implementing security 'best-practice' standards as well as departmental policies and procedures Responsible for Security scanning and the efficient remediation of vulnerabilities Responsible for analysing all security incidents to determine root cause Determine, recommend, and implement upgrade security measures and controls Delivery security responses for customer and client compliance requirements Developing and managing security plans with vendors Audit activities of administrators and conduct Security awareness training Requirements Demonstrable skills and capability in Security leadership and 3rd party management experience CISSP certification preferred. Compliance knowledge required in ISO27001, PCI and GDPR. Possibly a certified ethical hacker Knowledge of Security technologies is essential, such as network appliances, firewall administration, AD, IAM, PAM, SIEM, UEBA, AV, IDS/IPS and MDM solutions Understanding of common frameworks, such as ITIL or LEAN is preferred Good exposure of user environment management, including desktops/laptops, profile management, access control methodologies Must be very proactive in understanding and staying up to date with current security technologies and industry technology trends The job/Client is located at our head office in Paddington, London with hybrid working The Client holds a Licence to Sponsor (grade A) and will always consider sponsoring employees if needed We welcome applications from Ukrainian Refugees The salary for this position is circa £70K - £80K plus Benefits. Please do send your CV to us in Word format along with your salary.
View this job
Permanent

Job VacancySenior Data Engineer

█ █ █ ██ █ █
Published on
BigQuery
CI/CD
DevOps

London, England, United Kingdom

Imported from

Job from the tech market, identified automatically to give you a complete view of the opportunities.

Restricted access to the community

Join our platform to access the details of this job and get access to the best offers on the market.

View this job
Contractor
Permanent

Job VacancyInformation Security Architect / Manager

Nexus Jobs Limited
Published on

£500-550
London, England, United Kingdom
Information Security Architect / Manager Our Client is an International company with offices in Central London. They are looking to bring on-board an Information Security Architect / Manager with at least 5 to 8 years proven expertise within Information Security. The function of the position will be as follows: Assess the current environment against industry standards and trends. Implement robust security and control measures, in line with the global IT team Streamline current processes and execute changes for a secured and optimised technology and data landscape. Subject matter expert in application and network security, with operational experience of managing security operations, SIEM solutions, incident, and response management. Collaborate to develop the Infosec strategy and associated operating model. Conduct an in-depth security risk assessment across the technology stack and provide end-to-end mitigation steps for resilience. Working closely with key stakeholders to ensure compliance with security policies, and promotion of strong information security culture. Provide weekly governance, risk and compliance reports utilising key risk and key performance indicators and metrics. Skills/Competencies Required: Experience developing information security policy, process and procedure design and implementation. Excellent troubleshooting, problem solving, and root-cause analytical (RCA) skills. Good working knowledge of Cisco Meraki and associated technologies. Practical knowledge of Continual Service Improvement (CSI) methodologies. Vulnerability management and assessment. Intrusion detection and prevention analysis / frameworks. Solid exposure to cloud based applications security and provisioning. Experience in writing policy, process, and standard playbooks. Experience in SOC and SIEM platforms Excellent communications skills in framing and messaging issues of highly technical nature, into meaningful and relevant information for a varied audience. Excellent analytical skills, with an ability to manage multiple projects under tight guidelines. Experience with common Information security frameworks such as ISO, ITIL, and COBIT. Information security professional qualifications (CISMP, CISSM, SSCP, CAP..etc) ** Occasional travel to other sites may be required. This is 6 month contract assignment based in Central London. Rate will be circa £500 per day. Please do send your CV to us in Word format along with your daily rate and availability.
View this job

Connecting Tech-Talent

Free-Work, THE platform for all IT professionals.

Free-workers
Resources
About
Recruiters area
2026 © Free-Work / AGSI SAS
Follow us