At a Glance
- Tasks: Own complex security incidents and drive detection engineering in a hands-on role.
- Company: Join a leading Security Operations Centre in Reading with a hybrid work model.
- Benefits: Competitive salary, flexible working, and opportunities for professional growth.
- Other info: Dynamic team environment with a focus on innovation and continuous improvement.
- Why this job: Make a real impact in cybersecurity while mentoring junior analysts and enhancing SOC processes.
- Qualifications: Experience in security incident management and hands-on SIEM detection logic.
The predicted salary is between 50000 - 60000 £ per year.
Location: Reading (Hybrid)
Salary: £50,000 – £60,000
Our client is looking for a 2nd/3rd Line Security Analyst to join their Security Operations Centre as a senior technical escalation point. This is a genuinely hands-on role - ideal for someone who wants to keep working close to the tooling and the day-to-day operational workload rather than move straight into a purely managerial or architectural position. You'll own complex incidents end-to-end, drive detection engineering and automation, and provide senior technical depth across the SOC.
Duties of the Role
- Own complex security incidents end-to-end - from alert validation through investigation, containment and closure
- Act as the senior escalation point when earlier-stage investigations stall, reviewing prior work and coaching the original analyst
- Investigate identity and cloud-based compromise (e.g. anomalous sign-ins, malicious OAuth consent, mailbox access), including session/token revocation
- Design, build and test SIEM detection rules mapped to MITRE ATT&CK, and tune out false positives without blanket whitelisting
- Build automation for SOC processes - enrichment, ticketing, containment - using Python, Logic Apps, APIs or a SOAR platform
- Correlate evidence across SIEM, endpoint, identity and cloud platforms (Sentinel, Defender XDR, CrowdStrike, Entra ID, Microsoft 365, AWS) to scope the full blast radius of an incident
- Run hypothesis-led threat hunts, not just reactive alert triage
- Mentor junior analysts and help drive measurable improvements to SOC detections, playbooks and workflow
What we're looking for
- Proven, personal ownership of complex security incidents from triage through to closure
- Hands-on experience writing and tuning SIEM detection logic, with a solid understanding of MITRE ATT&CK and KQL (or equivalent)
- Practical scripting/automation experience (Python, Logic Apps, REST APIs) or hands-on SOAR platform configuration
- Working knowledge of several of: Microsoft Sentinel, Defender XDR, CrowdStrike, Microsoft Entra ID/Azure AD, Microsoft 365, AWS security tooling
- Experience investigating identity and cloud-based compromise, including OAuth consent abuse and Conditional Access/MFA
- A track record of proactive, hypothesis-driven threat hunting
- Strong investigative writing skills, with the ability to explain technical findings to non-technical stakeholders
- Comfortable acting as a technical escalation point, including reviewing and correcting the work of other analysts constructively
Nice to have
- Security certifications (e.g. SC-200, GCIH, GCFA, CySA+ or equivalent)
- Experience mentoring or formally training junior SOC analysts
- Exposure to non-Microsoft cloud, EDR or SIEM tooling
- Familiarity with SOAR platforms beyond Logic Apps (e.g. Sentinel Automation, Tines, Cortex XSOAR)
2nd/3rd Line Security Analyst - Reading employer: Xact Placements Limited Careers
As a Network Manager at our Dulwich location, you will join a supportive and dynamic work culture that prioritises employee growth and development. We offer competitive salaries alongside a comprehensive benefits package, including access to our wellbeing hub and innovative schemes like electric/hybrid car leasing. Our commitment to fostering effective communication and collaboration ensures that you will play a vital role in optimising our ICT network for both staff and students, making this an excellent opportunity for those passionate about IT in an educational setting.
Contact Details:
Xact Placements Limited Careers Recruitment Team