Security Operations Analyst

G-Research
London, UK
20 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Amazon Web Services Microsoft Azure Cloud Computing Cyber Security Linux File Systems Intrusion Detection and Prevention Python (Programming Language) Network Security Windows PowerShell Security Information and Event Management
+4 more
Scripting High Performance Computing HybridCloud Cybercrime

Job description

We’re looking for a Security Operations Analyst to join Security Operations Centre (SOC).

This team monitors, investigates and responds to security incidents across G-Research’s high-performance compute (HPC) environments, hybrid cloud platforms and corporate estate.

Operating on the front line of our defensive capability, the SOC analyses alerts, investigates threats and supports their detection, containment and eradication.

As a Security Operations Analyst, you will work across a broad range of technologies and investigative disciplines, developing your skills in triage, incident response, detection engineering, and forensic analysis. You will collaborate closely with the wider security function and engineering teams to continuously improve of our detection and response capabilities.

This role is ideal for someone with experience in a SOC or incident response team who wants to deepen their technical skills, contribute directly to meaningful defensive work and progress towards senior responsibilities.

Key responsibilities

  • Performing triage, investigation and escalation of security alerts across HPC, cloud and corporate environments
  • Supporting incident response activities including containment, remediation and reporting
  • Conducting host and log-based forensic analysis across Windows, Linux, cloud, network and application environments
  • Executing threat hunting tasks to identify abnormal or suspicious behaviours beyond existing detections
  • Developing and refining detection rules, analytics and playbooks alongside senior analysts
  • Maintaining accurate investigation records and case documentation
  • Contributing to the continuous improvement of workflows, tooling and operational processes
  • Collaborating with colleagues, engineers and internal stakeholders to support investigations, knowledge sharing and ongoing improvements

Requirements

The ideal candidate will have the following skills and experience:

  • Experience in a SOC, CSIRT or security operations role with hands-on involvement in alert handling and investigations
  • Strong understanding of security fundamentals, including network security, endpoint artefacts, authentication patterns, malware behaviours and common attack techniques
  • Experience using SIEM, XDR or SOAR tools such as Elastic Security, Sentinel, Azure Defender XDR or AWS Security Hub
  • Ability to analyse logs, correlate events and develop investigative hypotheses
  • Familiarity with forensic concepts, including filesystems, memory artefacts, persistence mechanisms, log sources and cloud control-plane events
  • Strong technical curiosity and desire to develop expertise in incident response, forensics and detection engineering
  • Strong written and verbal communication skills with a collaborative approach to working with analysts and engineers
  • Experience with scripting or automation using Python or PowerShell is desirable
  • Exposure to cloud platforms, HPC environments or relevant certifications such as GCIH or GCIA is beneficial

Benefits & conditions

Pulled from the full job description

  • Annual leave
  • Company pension
  • Company events, * Highly competitive compensation plus annual discretionary bonus
  • Lunch provided via Just Eat for Business and dedicated barista bar
  • 30 days’ annual leave
  • 9% company pension contributions
  • Informal dress code and excellent work-life balance
  • Comprehensive healthcare and life assurance
  • Cycle-to-work scheme
  • Monthly company events

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on uk.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

52 sec

Defining application, pipeline, and security operations roles

Aarno Aukia · LIVE

2:39 min

Experiencing core Linux capabilities for DevOps administration

Michael Cade · LIVE

Videos

See all

Related articles

See all