> Markdown version of [/jobs/ext/2362945-senior-security-analyst](https://www.wearedevelopers.com/jobs/ext/2362945-senior-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Analyst - **Company:** Kocho - **Location:** Cardiff, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Azure, Big Data, Cyber Security, Email Management, JSON, Python (Programming Language), Log Analysis, Microsoft Security Essentials, Microsoft Software, Performance Tuning, Phishing, Azure DevOps Pipelines, Kusto Query Language, Runbook, Microsoft InTune, Information Technology, Bicep, Microsoft Sentinel, Wikis - **Published:** August 11, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=6a0eec78a7dcac42 ## About the Role * A degree in Computer Science, Cyber Security or a related field or equivalent and demonstrable experience * Solid experience in an Analytical Role revolving around Microsoft Defender XDR & Microsoft Sentinel * Strong knowledge of security best practices, particularly UK based requirements * Very strong ability to query large data sets using KQL and understand how data is structured in Log Analytics * Very strong knowledge of the Microsoft Security Stack, particularly everything available in Microsoft Defender XDR * Very strong written & verbal communication skills - you will be expected to be contribute to high stakes situations with Clients Would be great if you have: * Proficiency in certain languages, standards and assemblies/tools such as Python, Bicep, ARM, JSON * Professional certifications such as AZ-900, SC-300, SC-900, Security+, Network+, A+ * Experience in mentoring junior members of staff ## Description Kocho operate exclusively in the Microsoft Stack. We are experts in everything Microsoft - Azure, Intune, KQL - you name it - it's in the remit. We expect you to be experienced across the stack with familiarity of the Security Tooling, though you will largely be residing in the Unified Security Operations Platform (formerly Microsoft Defender XDR & Microsoft Sentinel). In this role, you will be responsible for: * Ensuring Incident SLAs are met by monitoring our "Work Queue", which contains high-priority Incidents that must be acknowledged, supported by a Team of Analysts * Participate on the On-Call Rota (Second Line Escalations Out of Hours) * Respond to Incidents on a first-line basis where Capacity levels require your intervention * Be the 'first responder' to Escalations from the Analytical Team, before they reach Senior Levels * Escalate as required, with fully enriched notes and findings into Senior Team Members * Assist the Analytical Team Lead in taking ownership of Incident Escalations, Incident Response & Client Communications. You may be expected to run an Incident Bridge in the event that the Analytical Team Lead is unavailable. * Become a master of our Runbook documentation and maintaining an industry standard 'Wiki', containing both information and expand our 'KQL Library' * Monitor and remediate our industry-leading Phishing & Email Management tool by responding to potential threats reported by our Users and our Clients * 'Bridge' relationships between Service Delivery, Engineering & our Architectural Team by feeding input into the Analytical Team Lead via regular cadences * Become a Subject Matter Expert in 'Tuning' Incidents - raise & review requests through our Azure DevOps Pipelines * Mentor our Analysts by being a Subject Matter Expert in KQL and all things Microsoft Security ## Related Videos - [Back(end) to the Future: Embracing the continuous Evolution of Infrastructure and Code](https://www.wearedevelopers.com/videos/440-back-end-to-the-future-embracing-the-continuous-evolution-of-infrastructure-and-code) - [Living Documentation That Can't Die](https://www.wearedevelopers.com/videos/2025-living-documentation-that-can-t-die) - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [The Impact of AI on Game Development and the Industry](https://www.wearedevelopers.com/videos/100297-the-impact-of-ai-on-game-development-and-the-industry) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer)