> Markdown version of [/jobs/ext/2311340-security-operations-analyst](https://www.wearedevelopers.com/jobs/ext/2311340-security-operations-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Operations Analyst - **Company:** Nucleus Financial - **Location:** Edinburgh, UK - **Contract:** Permanent contract - **Skills:** Cyber Security, Intrusion Detection and Prevention, Security Information and Event Management, Office365, Software Security, Cybercrime - **Published:** August 30, 2026 - **Apply:** https://www.collegerecruiter.com/job/2815459796-security-operations-analyst ## About the Role We are looking for a high-calibre Security Operations Analyst to help lead and mature Security Operations at Nucleus. This is a key role in our first line of defence and is suited to someone who can combine excellent investigation skills with strong operational judgement, stakeholder management, and a passion for improving detection and response capability., Your friends might describe you as "the safe pair of hands." You pay attention to the details, identifying where things can go wrong, before they go wrong. Being hands on and collaborating to put solutions in place to catch them before it can happen. You are naturally inquisitive - you ask "why?" or "what does good look like?" and you do not stop at the first obvious answer. You enjoy being a problem solver, building a clear picture from incomplete information, and working methodically through an investigation. You will enjoy working within a fast-paced, sometimes high-pressure environment, where priorities can change quickly and you may need to make progress with incomplete information. You stay calm, communicate clearly, and can balance urgency with accuracy during live investigations and incidents. You will be dependable in your abilities to investigate a wide range of incidents, but still confident enough to ask for help or a second opinion when needed. You will also enjoy working as part of a diverse and supportive team, collaborating with your colleagues to share ideas and knowledge, and suggest improvements. You take strong ownership of your work, are accountable for tasks from start to finish, and you follow through to clear outcomes., * Experience working in financial services / a regulated financial institution (audit-heavy, high integrity operational requirements). * Strong experience in Security Operations, including monitoring, investigation, and incident response in complex environments. * Proven capability to manage and lead security incidents (decision-making, coordination across teams, and clear stakeholder communications). * Strong knowledge of common attack techniques and defensive concepts across identity, email threats, endpoint, networking, and cloud fundamentals. * Ability to produce high-quality investigation notes, evidence packs, and audit trails suitable for regulated environments. * Excellent written and verbal communication skills, including creating clear summaries, executive-ready updates, and presentations. * Ability to prioritise, stay agile under pressure, and drive work to completion. * Building dashboards and meaningful reporting. * Strong experience building and maintaining security playbooks/runbooks and partnering with development/engineering teams to review and improve them. * Experience raising the bar through coaching/mentoring and improving operational processes/runbooks. * Managing detection lifecycle (use cases, change control, continuous tuning). Preferred * Security engineering / detection engineering / SIEM engineering experience, specifically: creating, tuning, and managing detections/correlation rules to improve coverage and reduce noise. * Automation experience, such as creating workflows/flows to enrich alerts, reduce manual effort, improve triage consistency, and speed response. ## Description This role is responsible for helping ensure Nucleus identifies, analyzes, and responds to security threats across our technology estates. As a Security Operations Analyst, you will support the monitoring of the security resilience of our technology estate by operating the processes that enable us to detect and respond to potentially disruptive events. You will help manage our queues and dashboards; work with teams across Nucleus to collaborate on response actions; and identify opportunities for continuous improvement. The Information Security team aims to make sure that Nucleus is a trusted partner to the firms and people we work with. Being able to demonstrate that our systems are secure, by effectively managing our security controls, is a core component of building that trust. This role is critical to delivering that outcome as part of our first line of defence. You will work with SMEs across Nucleus, and within the team you will help ensure that the Information Security Analysis team has appropriate evidence to demonstrate that our risks are effectively managed and provide input to the Application Security team that facilitates an effective change programme., * Subject Matter Expert for security monitoring, ensuring we have capabilities that enable appropriate detective controls and response processes to mitigate Nucleus' security risks. * Threat hunting to ensure emerging or unforeseen threats are identified and managed. * Ensuring data and audit trails are maintained to support effective reporting. * Able to effectively engage with stakeholders across the business. * Ensure appropriate management of security incidents by creating clarity in complex and developing circumstances and making rapid decisions, and providing input to the company-wide Incident, Crisis, and Operational Resilience plans. * Support Audit and Due Diligence activities to help evidence Nucleus's capabilities. * Manage security queues and dashboards, setting high standards for triage quality, documentation, and follow-through. * Maintain high-quality investigation records, evidence, and audit trails suitable for regulated environments and audit scrutiny. * Drive post-incident reviews / lessons learned, ensuring improvement actions are owned, tracked, and completed. * Own investigations and incident actions through to closure, including follow-ups and verification that outcomes are complete and effective. * Provide regular incident updates using agreed cadence and formats, including concise written updates, timelines, and stakeholder-ready summaries. * Create clear written updates and presentations for the wider security team and stakeholders (e.g., incident summaries, monthly reporting, trends, improvement proposals). * Deliver continuous improvement by identifying, prioritising, delivering, and tracking improvements to detection, response, and operational processes. * Build, maintain, and regularly review security playbooks/runbooks, ensuring they remain current, technically accurate, and aligned with how teams across Nucleus operate. * Mentor and support less experienced analysts, sharing knowledge, coaching investigation quality, and helping raise operational consistency across the team. * Take responsibility in everything you do to deliver good outcomes for our customers. * Be able to take part in an on-call rota / Out-Of-Hours if this was to be implemented., Our key Security Operations tools currently include: Rapid7 Insight IDR, Microsoft 365 suite with Security and Compliance features. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Data Engineer Salary UK](https://www.wearedevelopers.com/magazine/253-data-engineer-salary-uk) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Data Analyst Salary in Switzerland](https://www.wearedevelopers.com/magazine/276-data-analyst-salary-in-switzerland)