Senior Lead Security Operations Analyst - Companies House - G7 in Manchester

Senior Lead Security Operations Analyst - Companies House - G7 in Manchester

Manchester Full-Time 63000 - 77000 £ / year (est.) Home office (partial)
M

At a Glance

  • Tasks: Lead complex security investigations and enhance our monitoring capabilities.
  • Company: Join Companies House, a key player in UK cyber security.
  • Benefits: Hybrid working, competitive salary, and opportunities for professional growth.
  • Other info: Collaborative culture with a focus on continuous improvement and innovation.
  • Why this job: Make a real impact in protecting vital services from cyber threats.
  • Qualifications: Strong experience in security operations and cloud technologies.

The predicted salary is between 63000 - 77000 £ per year.

We are looking for an experienced and technically skilled Senior Lead Security Operations Analyst to play a key role in the continued development of Security Operations at Companies House. You will provide technical leadership within the Security Operations team, supporting analysts with complex investigations and helping to ensure security incidents are effectively identified, investigated, contained and escalated.

You will remain hands-on, using security monitoring and threat detection technologies including Microsoft Sentinel, Microsoft Defender and Amazon Web Services security tooling to investigate activity across our cloud and technology environments. The role will also help drive improvements to our security monitoring capability, including developing and tuning detection rules, improving investigation and response processes, introducing automation and ensuring our monitoring continues to evolve alongside the threats facing Companies House.

We Are Looking For Someone With:

  • Strong security operations experience
  • Excellent analytical and investigative skills
  • The technical knowledge to lead complex investigations and support the development of others

You should be comfortable working with large volumes of security and log data, making evidence-based decisions and communicating technical security issues clearly to both technical and non-technical colleagues. This is an opportunity to take a senior technical role within an evolving Security Operations capability and directly influence how Companies House detects, investigates and responds to cyber security threats.

Your Key Responsibilities Will Include:

  • Leading security investigations and incident response – taking technical ownership of complex or high-impact incidents and coordinating investigation, containment, remediation and escalation.
  • Providing technical leadership – acting as a senior escalation point for analysts, providing guidance on complex investigations and supporting effective decision making.
  • Developing security monitoring and detection – creating, reviewing and tuning security detections to improve our ability to identify malicious and suspicious activity.
  • Managing and improving Microsoft Sentinel and Microsoft Defender – using and developing our security technologies to investigate threats, improve detection coverage and maintain effective monitoring.
  • Monitoring cloud environments – detecting and investigating security activity across Amazon Web Services and Microsoft Azure using cloud security services, logs and other security telemetry.
  • Improving automation and processes – identifying opportunities to automate Security Operations activities and improve monitoring, investigation and response workflows.
  • Developing incident response capability – improving investigation procedures, playbooks and escalation processes and supporting security exercises and readiness activities.
  • Developing the team – mentoring analysts, sharing technical knowledge and supporting the development of investigative and technical capability.
  • Supporting operational leadership – helping prioritise and coordinate Security Operations activity and providing operational leadership in the absence of the Head of Security Operations when required.
  • Working across Companies House – collaborating with security, cloud, platform, infrastructure and software engineering teams to investigate security issues and improve monitoring and response.
  • Advising senior stakeholders – communicating significant incidents, risks and technical findings clearly and providing evidence-based recommendations.
  • Driving continuous improvement – keeping pace with emerging threats and technologies and using lessons from incidents and operational activity to continually improve our security capability.

This is a hands-on technical role with technical and operational leadership responsibility. You will remain actively involved in security monitoring, investigations, detection engineering and incident response while helping to develop the capability of the wider Security Operations team.

About The Team:

The Security Operations team sits within the wider Security function at Companies House and is responsible for monitoring, detecting, investigating and responding to cyber security threats across our technology and cloud environments. We are a collaborative and technically focused team made up of Security Operations analysts, senior specialists and threat intelligence capability, working closely with colleagues across security, cloud, platform and engineering teams as well as external security partners.

We have a supportive and collaborative culture where people are encouraged to challenge existing approaches, share knowledge and learn from each other. As a Senior Lead, you will play an important role in maintaining that culture and helping develop the technical capability of the wider team.

What we’re looking For:

  • Strong hands-on Security Operations expertise and the technical capability and judgement required to operate as a senior technical lead.
  • Significant hands-on experience working within Security Operations, including investigating, triaging and responding to complex security alerts and incidents.
  • Strong practical experience using Microsoft Sentinel, including security monitoring, log analysis, incident investigation, developing and tuning detection rules, and improving monitoring coverage.
  • Strong experience working with Amazon Web Services, including investigating security activity using cloud security services and telemetry such as CloudTrail, GuardDuty and Identity and Access Management.
  • Experience leading complex security investigations, coordinating containment and remediation activities, and making risk-based decisions during security incidents.
  • Experience developing and improving Security Operations capabilities, including monitoring processes, incident response procedures, playbooks and automation.
  • Advanced knowledge of Microsoft Sentinel, including Kusto Query Language, analytics rules, security investigations, log analysis and automation.
  • Strong knowledge of Amazon Web Services security, including cloud logging, identity and access management, threat detection and the investigation of activity across cloud environments.
  • Good working knowledge of Microsoft Defender security technologies and their use for threat detection, investigation and response.
  • Strong analytical and diagnostic skills, with the ability to correlate security information from multiple data sources, identify malicious or suspicious activity and determine appropriate response actions.
  • Practical knowledge of scripting and security automation using technologies such as PowerShell, Python, Terraform or equivalent tooling.
  • Strong understanding of cyber threats, attacker techniques and security monitoring principles, with knowledge of relevant frameworks and good practice such as MITRE ATT&CK and the National Cyber Security Centre Cyber Assessment Framework.

Senior Lead Security Operations Analyst - Companies House - G7 in Manchester employer: Manchester Digital

Join a dynamic SaaS company in Wigan as a Lead Software Engineer, where you'll thrive in a collaborative and innovative work culture that values your expertise and contributions. With competitive compensation of up to £80k plus benefits like a 5% matched pension, share options, and private healthcare, you’ll have the resources to grow both personally and professionally while enjoying the flexibility of hybrid working. This is an exciting opportunity to take ownership of system design and implementation in a supportive environment that encourages modern engineering practices.

M

Contact Details:

Manchester Digital Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Senior Lead Security Operations Analyst - Companies House - G7 in Manchester

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Manchester Digital, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Manchester Digital

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Manchester Digital. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Senior Lead Security Operations Analyst - Companies House - G7 in Manchester

Security Operations Expertise
Analytical Skills
Incident Response Coordination
Microsoft Sentinel
Amazon Web Services Security
Kusto Query Language
Log Analysis

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Manchester Digital insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Manchester Digital that you’re committed to staying ahead in the game.

How to prepare for a job interview at Manchester Digital

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Manchester Digital to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Manchester Digital.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.