Line Security Analyst

Xact Placements
Reading, UK
1 day ago
Apply on www.xactplacements.co.uk
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Compensation
£55,000.0 - £60,000.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Amazon Web Services Microsoft Azure Cyber Security Digital Forensics Intrusion Detection and Prevention Information Systems Security Architecture Professional Python (Programming Language) Windows PowerShell Azure Active Directory Kusto Query Language Runbook
+9 more
Security Information and Event Management Computer Networking Systems Microsoft Power Automate Mitre Att&ck Malware Microsoft InTune Cybercrime Microsoft Sentinel Api Management

Job description

My client, a well-established organisation within the ICT Services sector, are looking to recruit an experienced 3rd Line Security Analyst to join their Security Operations function.

This is a senior, hands-on technical role rather than a queue-driven analyst position. The successful candidate will take ownership of the engineering, administration, health and continuous improvement of the security platforms, detection content and automation that underpin threat monitoring, detection and incident response across my client’s internal and managed customer environments. They will act as the final internal escalation point for complex and high-severity security incidents, the technical design authority for detection and automation content, and a mentor who raises the technical capability of the wider 2nd line team.

Reporting to the Security Operations Manager, this role sits within ICT Services and carries genuine scope and technical authority, including sign-off on detection content, SOAR playbooks and hunting queries, named administrative ownership of key security platforms, and the authority to take immediate containment action during live incidents., * Lead the end-to-end management of complex and high-severity security incidents, including investigation, containment, eradication, recovery and post-incident review.

  • Conduct digital forensic investigations across cloud, identity, endpoint and network platforms, and carry out malware analysis and threat validation.
  • Design, implement and optimise detection content across Microsoft Sentinel, Defender XDR, CrowdStrike and associated platforms, developing advanced KQL queries and analytics rules aligned to MITRE ATT&CK.
  • Act as senior technical owner for security platforms including Microsoft Sentinel, Defender XDR, CrowdStrike Falcon, Entra ID, Intune, Darktrace and supporting technologies, managing platform health, onboarding and configuration.
  • Design and maintain automation and orchestration workflows using Logic Apps, Sentinel Playbooks, Power Automate, PowerShell, Python and API integrations to reduce manual operational effort.
  • Conduct proactive, intelligence-led and hypothesis-driven threat hunting, translating findings into detections, hunts and customer recommendations.
  • Monitor, investigate and respond to security events across Microsoft 365, Azure, AWS and hybrid environments.
  • Support compliance activities relating to ISO 27001 and Cyber Essentials, maintaining technical documentation, runbooks and standard operating procedures.
  • Provide technical leadership, mentoring and knowledge transfer to Security Analysts and Service Desk teams.

Requirements

  • Significant experience within a Security Operations Centre (SOC), Cyber Security Operations or Security Engineering function, including at a senior technical level.
  • Strong hands-on experience administering and engineering Microsoft Sentinel, Microsoft Defender XDR, CrowdStrike Falcon and associated security technologies.
  • Proven experience in incident response, threat hunting, malware analysis, digital forensics and security investigations.
  • Advanced KQL skills, with the ability to develop and optimise complex detections and threat hunting queries.
  • Strong scripting and automation experience using PowerShell and/or Python, including API integrations and workflow automation.
  • Experience administering Microsoft Entra ID, Conditional Access, Intune and Microsoft 365 security solutions.
  • Good understanding of Azure, AWS and hybrid infrastructure security, with strong knowledge of networking, operating systems and attacker techniques.
  • Practical understanding of MITRE ATT&CK, Cyber Kill Chain, NIST and SANS incident response frameworks.
  • Experience working within regulated and audited environments, including ISO 27001 and Cyber Essentials.
  • Excellent communication, stakeholder management and documentation skills, with the ability to engage effectively across technical and non-technical audiences.

Desirable

  • CISSP (Certified Information Systems Security Professional) certification.
  • Experience designing or improving SOC operating models, detection strategies, or security platforms at scale.
  • Exposure to security architecture or security engineering activities beyond day-to-day SOC operations.
  • Experience contributing to or leading continuous improvement initiatives, automation strategy, or security service maturity.

Additional Requirements

  • Ability to prioritise work under pressure and meet strict deadlines.
  • Excellent written and verbal communication skills.
  • Candidates must be able to pass security vetting (BS7858).
Salary: £60,000 Location: Reading / hybrid 2 days from home

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.xactplacements.co.uk
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

5:11 min

Deploying manual Seccomp profiles to block malware

Dimitrij Klesev +1 · LIVE

2:50 min

Introduction and the value of runbooks

Hila Fish · World Congress 2023

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

1:27 min

Differences between autonomous AI agents and traditional malware

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all