Location: Crawley Court, Winchester & Newman Street, London. We operate a flexible, hybrid working environment – requirement to travel to either our Winchester or London office up to twice a week.
Benefits
- Competitive salary
- 10% bonus
- Work Life Smarter – commitment to a flexible and hybrid working culture
- Generous pension scheme starting at 6% rising to 10%
- Unique wellbeing programme that looks after the whole you
- Access to multiple learning platforms to support your individual development
- Active and diverse networks that build community, support wellbeing and advocate for change
- Comprehensive set of benefits including discounts on big brands, gymflex memberships and paid volunteering leave – see our full list of benefits.
Role Overview
The Senior Threat & Response Specialist is uniquely positioned to drive the evolution of our cyber security capability, combining deep operational expertise with advanced, cutting‑edge technologies. The specialist plays a pivotal part in shaping an innovative, intelligence‑led security function that anticipates threats, automates responses and sets new standards of excellence across our organisation and the wider industry.
Candidates with a strong SIEM engineering background who want to broaden their scope into 3rd‑line SOC investigation and incident response will be particularly well suited. This position offers the opportunity to own and shape the role as we establish best practices and effective ways of working across the organisation.
Experience in Cloud Security, especially across Azure, AWS or hybrid environments, will be highly advantageous, enabling support of Arqiva’s shift toward secure‑by‑design cloud adoption.
Key Responsibilities
- Lead the engineering, optimisation and continuous improvement of Arqiva’s SIEM platform, ensuring high‑quality detections, effective log ingestion pipelines and strong operational performance.
- Design, develop and tune advanced detection use cases aligned to evolving attacker behaviours, leveraging threat intelligence and frameworks such as MITRE ATT&CK.
- Support the onboarding and normalisation of new data sources, including cloud telemetry, application logs and platform services, ensuring full visibility across hybrid environments.
- Collaborate with DevOps and platform engineering teams to embed security controls, monitoring and detection within CI/CD pipelines and infrastructure‑as‑code deployments.
- Utilise cloud‑native and third‑party tooling such as Wiz to assess cloud posture, improve asset visibility, enrich threat detection logic and drive proactive remediation.
- Act as an escalation point for complex 3rd‑line SOC investigations, providing analytical support.
- Collaborate with suppliers, customers and Arqiva stakeholders to deliver Threat & Response services, drive improvement and enhance effectiveness of Arqiva’s Security Capabilities.
- Provide technical analysis and interpretation of Arqiva’s internal and external landscape, advising and supporting the Head of Threat & Response in embedding incident response and cyber continuity across the organisation.
- Mentor junior Threat & Response colleagues across any of the Threat & Response services.
- Coordinate with stakeholders of varying seniority and technical background as an authoritative representative of the Threat & Response function.
Key Attributes & Experience
- Technical background, mindset and approach.
- Genuine enthusiasm for technology and Cyber Security.
- Adaptability and self‑sufficiency.
- Inquisitive and analytical.
- Strong communication, reporting and stakeholder management skills.
- Able to translate technical concepts into clear language for non‑technical stakeholders and executives.
- Honest, open and genuine in interactions with others.
- Deep, tooling‑agnostic engineering, architectural and operational expertise across all key Security platforms, such as VM/SIEM/EDR, and able to transfer knowledge between toolsets.
- Knowledge and experience of working within organisations implementing relevant Cyber frameworks and methodologies such as MITRE ATT&CK, NIST, ISF, ISO27000.
- Relevant industry qualifications such as SANS, GIAC, CEH, CCNA, AZ‑500.
- Extensive experience performing technical threat analysis and incident response against malware, data breach, supply chain compromise and other attacks.
- Experience in incident management, assessment, categorisation, prioritisation and root cause analysis.
- Familiarity with common threat actor methodologies during the threat lifecycle.
- Experience interpreting and actioning Threat Intelligence.
- Experience with on‑prem, AWS and Azure cloud environments and Security solutions.
Please note that the successful candidate will be required to successfully undergo UK Security Clearance and must have been resident within the UK for at least five years.
Why Arqiva
We enable a switched‑on world to flow. As the UK’s leader in TV and radio broadcast and the country’s top smart utilities platform, we are shaping the future of connectivity. Our infrastructure delivers media and data exactly where they’re needed – whether that’s bringing TV and radio to your home or sending smart meter data to your utility provider. Our technology works quietly behind the scenes, connecting millions every day.
But it’s not just what we do, it’s how we do it. At Arqiva, you’ll find supportive teams, active colleague networks and plenty of ways to get involved and feel part of our community. We’ll give you the space and support to grow – whether that’s developing your skills, trying something new or taking on fresh challenges. And because there is more to life than work, our rewards and benefits are designed to support your wellbeing, your lifestyle and what matters most to you.
Our commitment to Diversity & Inclusion
At Arqiva, we’re committed to building a workplace where everyone feels valued, heard and empowered to succeed. We welcome applications from all backgrounds and experiences, and we work hard to remove barriers so every colleague can thrive. If you need any adjustments at any stage of the recruitment process, please reach out to talent@arqiva.com.
If this sounds like the right next step for you, we’d love to hear from you!