At a Glance
- Tasks: Develop and optimise detection content to identify threats across various environments.
- Company: Join a leading cybersecurity firm in Glasgow with a hybrid work model.
- Benefits: Competitive salary, on-call compensation, and opportunities for professional growth.
- Other info: Mentor junior analysts and collaborate on high-priority incident responses.
- Why this job: Make a real impact in cybersecurity while working with cutting-edge technologies.
- Qualifications: 2+ years in Cyber Security Operations and strong scripting skills required.
We are seeking an accomplished Senior Cyber Operations Analyst to join a high-performing Blue Team operating at the forefront of modern security operations. This is a technical role suited to an experienced analyst with strong engineering instincts, hands-on coding capabilities, and a deep understanding of incident response, detection engineering, and adversary tradecraft.
This position includes approximately one week per month of on-call availability for high-priority incident response. Additional compensation is provided, and frequency may vary by client.
We are looking for a senior analyst who brings curiosity, technical depth, and a proactive mindset. This role is ideal for someone who has likely grown from an engineering background and can write scripts (Python, Bash) to automate, enhance, and refine detection and response workflows. Experience with Splunk, SIEM operations, cloud endpoints, networks, and detection engineering will be highly advantageous.
Key Responsibilities
- Develop, maintain, and optimise detection content (primarily within Splunk SIEM) to identify threats across cloud, endpoint, and network environments.
- Collaborate across security functions to identify gaps in logging, alerting, and detection coverage aligned to business risk.
- Improve SecOps processes by recommending enhanced logging, identifying trends, and driving operational optimisation.
- Conduct security monitoring, alert triage, and continuous improvement of detection rules (core hours 9:00-17:30 on rotation).
- Lead and support incident response investigations, ensuring high-quality documentation and escalation.
- Mentor and support junior analysts, providing guidance, coaching, and technical oversight.
- Serve as a technical SME on client engagements; present findings and recommendations to senior stakeholders.
- Participate in alert testing, readiness exercises, and incident response tabletop sessions.
- Stay current on emerging threat intelligence, attacker techniques, and relevant research.
Required Experience
- 2+ years experience as a Cyber Security Operations Analyst
- Experience working with Splunk
- Familiarity with threat intelligence frameworks and methodologies
- End-to-end incident response lifecycle experience
- Detection engineering and alert development expertise.
- Strong scripting or programming skills (Python, Bash, C/C++, Java).
- Solid grounding in cybersecurity fundamentals: network security, cloud security, cryptography, forensics.
- Understanding of common network protocols and attacker abuse patterns.
- Awareness of current APT groups and their TTPs.
- Knowledge of analysis techniques for Windows and/or Linux environments.
If you are a technically driven senior analyst ready to advance, apply today.
Cyber Security Operations Specialist in Glasgow employer: ANSON MCCADE
Join a dynamic and innovative team in Glasgow as a Senior Cyber Operations Analyst, where you will be at the forefront of cybersecurity operations. Our company fosters a collaborative work culture that prioritises employee growth through mentorship and continuous learning opportunities, alongside competitive compensation packages including on-call bonuses. With a focus on cutting-edge technology and a commitment to professional development, we offer a unique environment for those looking to make a meaningful impact in the field of cyber security.
StudySmarter Expert Advice🤫
We think this is how you could land Cyber Security Operations Specialist in Glasgow
✨Tip Number 1
Network, network, network! Get out there and connect with professionals in the cyber security field. Attend meetups, webinars, or conferences to meet potential employers and learn about job openings that might not be advertised.
✨Tip Number 2
Show off your skills! Create a portfolio showcasing your projects, scripts, or any incident response scenarios you've handled. This will give you an edge during interviews and demonstrate your hands-on experience.
✨Tip Number 3
Prepare for technical interviews by brushing up on your coding skills and incident response knowledge. Practice common interview questions and scenarios related to Splunk, detection engineering, and threat intelligence to impress your interviewers.
✨Tip Number 4
Don’t forget to apply through our website! We’ve got some fantastic opportunities waiting for you, and applying directly can sometimes give you a better chance of landing that dream role.
We think you need these skills to ace Cyber Security Operations Specialist in Glasgow
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the Cyber Security Operations Specialist role. Highlight your experience with Splunk, incident response, and any scripting skills you have. We want to see how your background aligns with what we're looking for!
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to showcase your curiosity and proactive mindset. Tell us why you're passionate about cyber security and how your engineering background makes you a perfect fit for our team.
Showcase Your Technical Skills:Don’t hold back on your technical skills! Mention your experience with detection engineering, alert development, and any programming languages you’re proficient in. We love seeing candidates who can automate and enhance workflows!
Apply Through Our Website:We encourage you to apply through our website for the best chance of getting noticed. It’s super easy, and we’ll be able to review your application quickly. Don’t miss out on this opportunity to join our high-performing Blue Team!
How to prepare for a job interview at ANSON MCCADE
✨Know Your Tech Inside Out
Make sure you brush up on your technical skills, especially around Splunk and scripting languages like Python and Bash. Be ready to discuss specific projects where you've used these tools, as well as any challenges you faced and how you overcame them.
✨Showcase Your Incident Response Experience
Prepare to talk about your experience with the end-to-end incident response lifecycle. Have examples ready that demonstrate your ability to lead investigations, document findings, and collaborate with teams to improve security processes.
✨Stay Current with Threat Intelligence
Familiarise yourself with the latest trends in cyber threats and attacker techniques. Being able to discuss recent incidents or emerging APT groups will show your proactive mindset and curiosity, which are key traits for this role.
✨Be Ready to Mentor
Since mentoring junior analysts is part of the job, think about how you can demonstrate your leadership skills. Share experiences where you've guided others or contributed to team development, as this will highlight your collaborative spirit.