Senior Cyber Security Lead in Slough

Senior Cyber Security Lead in Slough

Slough Full-Time 85000 - 85000 € / year (est.) Home office (partial)
TRIA

At a Glance

  • Tasks: Lead cyber security incidents and enhance detection capabilities in a global environment.
  • Company: Join a leading global Cyber Defense function in Central London.
  • Benefits: Competitive salary of c£85,000 plus benefits and flexible working.
  • Other info: Dynamic role with opportunities for professional growth and collaboration across global teams.
  • Why this job: Make a real impact in cyber security while working with cutting-edge Microsoft technologies.
  • Qualifications: Proven experience in cyber security incident management and strong technical skills.

The predicted salary is between 85000 - 85000 € per year.

We are seeking an experienced Senior Cyber Security Analyst to join a global Cyber Defense function. This is not a traditional SOC analyst position focused purely on alert investigation. Instead, this role requires an individual capable of leading cyber incidents operationally, technically and commercially from end-to-end.

You will act as a senior technical subject matter expert across incident response, detection engineering, cloud security and vulnerability management, while also providing calm, structured leadership during high-pressure situations.

The environment is heavily Microsoft-focused, with particular emphasis on:

  • Microsoft Sentinel
  • Microsoft Defender XDR
  • Azure security and secure-by-design principles
  • Detection engineering and automation
  • Threat and vulnerability management

You will work closely with global technology and cyber teams to continuously improve monitoring, detection, response and remediation capabilities across hybrid cloud and on-premise environments.

Key Responsibilities

Incident Response & Major Incident Management

  • Lead the end-to-end management of cyber security incidents across global environments.
  • Take ownership of incident triage, severity assessment and response coordination across P1–P4 incidents.
  • Lead incident bridge calls and coordinate technical and business stakeholders throughout the incident lifecycle.
  • Assess technical, operational and commercial impact to support effective decision-making under pressure.
  • Provide clear, calm and structured communications to both technical teams and senior leadership.
  • Drive containment, eradication, recovery and post-incident improvement activities.
  • Conduct root cause analysis and ensure lessons learned are embedded into operational processes and controls.
  • Develop and maintain incident response procedures, playbooks and documentation aligned to industry best practice.

Detection Engineering & Security Automation

  • Configure, optimise and continuously improve Microsoft Sentinel and Microsoft Defender technologies.
  • Develop and tune detection logic using KQL to identify emerging threats and attacker behaviours.
  • Build and maintain automated SOAR workflows using Logic Apps and related technologies.
  • Integrate Microsoft security tooling with third-party technologies and service providers.
  • Identify monitoring gaps and improve visibility across cloud and on-premise environments.
  • Maintain high-quality technical documentation for detections, automations and operational workflows.

Cloud Security & Secure-by-Design

  • Support secure configuration and operational security across Azure and associated cloud services.
  • Collaborate with infrastructure and engineering teams to embed secure-by-design principles.
  • Evaluate configuration changes and ensure alignment with security standards and controls.
  • Support implementation and optimisation of Microsoft Defender security policies across endpoint, identity, cloud and email platforms.
  • Contribute to the continuous improvement of cloud security posture across global operations.

Threat & Vulnerability Management

  • Support and enhance the vulnerability management programme across infrastructure, cloud and endpoint environments.
  • Work with tools such as Microsoft Defender Vulnerability Management and Tenable to identify and prioritise vulnerabilities.
  • Translate vulnerability findings into actionable remediation plans with technology stakeholders.
  • Leverage cyber threat intelligence to improve detection capabilities and prioritisation decisions.
  • Track remediation progress and provide meaningful risk reporting to cyber leadership.

Stakeholder Management & Collaboration

  • Partner with Group IT, Regional IT and wider technology teams across multiple geographies.
  • Act as a trusted advisor across operational security, incident response and cyber defence activities.
  • Balance technical risk with operational realities and business priorities.
  • Demonstrate strong stakeholder management and communication skills at all levels of the organisation.
  • Contribute to a positive cyber security culture and continuous improvement mindset across the business.

What We’re Looking For

Essential Experience

  • Proven experience leading cyber security incidents end-to-end within enterprise environments.
  • Strong background in Security Operations, Cyber Defence, Incident Response or Blue Team functions.
  • Experience operating within hybrid cloud and on-premise environments.
  • Hands-on experience with Microsoft Sentinel, Microsoft Defender XDR and Azure security technologies.
  • Experience with detection engineering, threat detection and security automation.
  • Exposure to vulnerability management platforms such as Tenable or Microsoft Defender Vulnerability Management.
  • Experience managing stakeholder communications during high-severity incidents.
  • Strong understanding of attacker tactics, techniques and procedures (TTPs).

Technical Skills

  • Strong Microsoft security ecosystem expertise.
  • Advanced KQL experience for investigations, detections and reporting.
  • Experience building automation workflows using Logic Apps or similar technologies.
  • Knowledge of cloud security principles across Azure and ideally AWS or Google Cloud.
  • Familiarity with industry frameworks such as NIST and ISO 27001.

Personal Attributes

We are particularly interested in individuals who demonstrate:

  • Calmness under pressure
  • Strong ownership and accountability
  • Excellent communication and stakeholder management skills
  • Commercial awareness alongside technical depth
  • Gravitas and confidence leading senior incident discussions
  • The ability to know when to stop investigating and start managing the wider incident process

To apply for this fantastic opportunity please send your CV.

Senior Cyber Security Lead in Slough employer: TRIA

Join a leading global Cyber Defense function in Central London, where you will thrive in a dynamic work culture that prioritises innovation and collaboration. With a strong focus on employee growth, we offer extensive training opportunities and the chance to work with cutting-edge Microsoft technologies, all while enjoying a flexible work arrangement that promotes work-life balance. Our commitment to fostering a positive cyber security culture ensures that you will be part of a team that values your expertise and contributions, making this an exceptional place to advance your career.

TRIA

Contact Detail:

TRIA Recruiting Team

StudySmarter Expert Advice🤫

We think this is how you could land Senior Cyber Security Lead in Slough

Tip Number 1

Network like a pro! Reach out to your connections in the cyber security field and let them know you're on the hunt for a Senior Cyber Security Analyst role. You never know who might have the inside scoop on job openings or can put in a good word for you.

Tip Number 2

Prepare for those interviews by brushing up on your technical skills and incident management experience. Be ready to discuss specific examples of how you've led cyber incidents and improved security measures in past roles. Confidence is key!

Tip Number 3

Don’t forget to showcase your calmness under pressure during interviews. Share stories where you’ve successfully managed high-severity incidents, as this will demonstrate your ability to lead effectively in challenging situations.

Tip Number 4

Finally, apply through our website! We want to see your application come through directly, so make sure to submit your CV there. It’s a great way to ensure it lands in the right hands and shows your enthusiasm for joining our team.

We think you need these skills to ace Senior Cyber Security Lead in Slough

Incident Response
Cyber Defence
Microsoft Sentinel
Microsoft Defender XDR
Azure Security
Detection Engineering
Threat Detection

Some tips for your application 🫡

Tailor Your CV:Make sure your CV reflects the specific skills and experiences mentioned in the job description. Highlight your expertise in incident response, detection engineering, and cloud security to show us you're the right fit for the Senior Cyber Security Lead role.

Showcase Your Leadership Skills:Since this role involves leading cyber incidents, it's crucial to demonstrate your leadership abilities. Include examples of how you've managed high-pressure situations and coordinated with stakeholders during incidents to give us a clear picture of your capabilities.

Be Clear and Concise:When writing your application, keep it straightforward and to the point. Use bullet points where possible to make it easy for us to see your qualifications and achievements at a glance. We appreciate clarity!

Apply Through Our Website:We encourage you to apply directly through our website. This way, we can ensure your application is processed smoothly and you get the best chance to showcase your talents to us!

How to prepare for a job interview at TRIA

Know Your Tech Inside Out

Make sure you’re well-versed in Microsoft Sentinel, Microsoft Defender XDR, and Azure security technologies. Brush up on your KQL skills for detection logic and be ready to discuss how you've used these tools in past incidents.

Showcase Your Incident Management Skills

Prepare to share specific examples of how you've led cyber security incidents from start to finish. Highlight your ability to assess severity, coordinate responses, and communicate effectively with both technical teams and senior leadership.

Demonstrate Calmness Under Pressure

During the interview, convey your ability to remain calm and structured in high-pressure situations. You might even want to role-play a scenario where you lead an incident response to show how you handle stress and decision-making.

Engage with Stakeholder Management

Be ready to discuss your experience in managing stakeholder communications during critical incidents. Emphasise your ability to balance technical risks with business priorities and how you’ve built trust across different teams.