At a Glance
- Tasks: Own complex security incidents and drive detection engineering in a hands-on role.
- Company: Join a leading Security Operations Centre with a focus on innovation.
- Benefits: Competitive salary, hybrid work model, and opportunities for professional growth.
- Other info: Dynamic team environment with excellent career advancement opportunities.
- Why this job: Make a real impact in cybersecurity while working with cutting-edge tools.
- Qualifications: Experience in security analysis and strong problem-solving skills.
The predicted salary is between 50000 - 60000 £ per year.
Location: Reading (Hybrid)
Salary: £50,000 – £60,000
Our client is looking for a 2nd/3rd Line Security Analyst to join their Security Operations Centre as a senior technical escalation point. This is a genuinely hands-on role - ideal for someone who wants to keep working close to the tooling and the day-to-day operational workload rather than move straight into a purely managerial or architectural position. You'll own complex incidents end-to-end, drive detection engineering and automation, and provide senior technical depth across the SOC.
Duties of the Role:
- Own complex security incidents end-to-end - from alert validation through investigation, containment and closure.
- Act as the senior escalation point when earlier-stage investigations stall, reviewing prior work and coaching the original analyst.
- Investigate identity and cloud-based compromise (e.g. anomalous sign-ins, malicious OAuth consent, mailbox access), including session/token revocation.
- Design, build and test SIEM detection rules mapped to MITRE ATT&CK, and tune out false positives without blanket whitelisting.
- Build automation for SOC processes - enrichment, ticketing, containment - using Python, Logic Apps, APIs or a SOAR platform.
- Correlate evidence across SIEM, endpoint, identity and cloud sources.
2nd/3rd Line Security Analyst employer: Xact Placements Limited
Xact Placements Limited is an excellent employer for a Senior Security Analyst, offering a dynamic hybrid work environment in Reading that fosters innovation and collaboration. With a strong emphasis on employee growth, you will have access to advanced security technologies and opportunities to enhance your threat detection skills while being part of a supportive team culture that values your contributions. The company prioritises work-life balance and provides a platform for meaningful impact in the ever-evolving field of cybersecurity.