A variety of soft skills and experience may be required for the following role Please ensure you check the overview below carefully.
3rd Line Security Analyst
My client, a well-established organisation within the ICT Services sector, are looking to recruit an experienced 3rd Line Security Analyst to join their Security Operations function.
This is a senior, hands-on technical role rather than a queue-driven analyst position. The successful candidate will take ownership of the engineering, administration, health and continuous improvement of the security platforms, detection content and automation that underpin threat monitoring, detection and incident response across my clients internal and managed customer environments. They will act as the final internal escalation point for complex and high-severity security incidents, the technical design authority for detection and automation content, and a mentor who raises the technical capability of the wider 2nd line team.
Reporting to the Security Operations Manager, this role sits within ICT Services and carries genuine scope and technical authority, including sign-off on detection content, SOAR playbooks and hunting queries, named administrative ownership of key security platforms, and the authority to take immediate containment action during live incidents.
Key Responsibilities
- Lead the end-to-end management of complex and high-severity security incidents, including investigation, containment, eradication, recovery and post-incident review.
- Conduct digital forensic investigations across cloud, identity, endpoint and network platforms, and carry out malware analysis and threat validation.
- Design, implement and optimise detection content across Microsoft Sentinel, Defender XDR, CrowdStrike and associated platforms, developing advanced KQL queries and analytics rules aligned to MITRE ATT&CK.
- Act as senior technical owner for security platforms including Microsoft Sentinel, Defender XDR, CrowdStrike Falcon, Entra ID, Intune, Darktrace and supporting technologies, managing platform health, onboarding and configuration. xgikmsk
- Design and maintain automation and orchestration workflows using Logic Apps, Sentinel Playbooks, Power Automate, PowerShell, Python and API integrations to reduce manual operational effort.
- Conduct proactive, intelligence-led and hypothesi Please click on the apply button to read the full job description
Cyber Security Analyst in Reading employer: XACT PLACEMENTS LIMITED
Join a dynamic team in Reading where your drive and ambition as a Sales Development Representative will be rewarded with an uncapped commission scheme and a comprehensive benefits package. Our supportive work culture fosters personal growth and development, providing you with the tools and opportunities to excel in your career while making a significant impact across ICT, Content Services, and Managed Print Solutions. Experience the thrill of winning new business in a collaborative environment that values innovation and success.