Principal Security Operations Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+8 more
Job description
Our client is undertaking a major transformation of its Security Operations capability and operating model. While the emphasis of the capability was previously on protective monitoring against commodity threats, reactive incident management, and escalation to third-party IT suppliers for remediation and response, the organisation is significantly expanding and developing its capability to create an industry-leading team focused on both the external threat landscape and internal business context, with responsibility for end-to-end technical cyber defence. The intended scope of services includes threat intelligence, attack surface management, proactive monitoring and threat hunting, incident management and response, supported by strong Security Engineering and DevSecOps practices.
To support this transition, the organisation requires an experienced Principal Security Operations Analyst to support the definition and shaping of transformation project outputs and then take responsibility for their production and delivery under the supervision of the Security Operations Lead and Product Owner.
The role will form part of the programme delivery team, working under the direction and guidance of the programme leadership., The Principal Security Operations Analyst will primarily be responsible for the day-to-day delivery of Security Operations projects and deliverables, while also helping shape these through their own experience and expertise. In addition to project responsibilities, there will be opportunities to support BAU teams by sharing knowledge and expertise, helping to build capability and prepare teams to ultimately take ownership of programme outputs.
The role will operate across both BAU and project delivery activities and will work closely with a range of stakeholders, including:
- IT and Architecture teams
- Cyber Security teams, including Security Operations, Assurance, Governance and Risk
- Third-party operational suppliers
- Application and workload teams
- Procurement and transition workstreams, * Security Operations Subject Matter Expertise
- Apply hands-on technical cyber defence expertise across a range of Security Operations services, workflows and activities to deliver project outcomes.
- Support the definition and shaping of project deliverables by applying practical Security Operations experience.
- Contribute to Security Operations technology selection, configuration and operating processes.
Security Operations Project Delivery
- Under the direction of the technical programme leadership, successfully deliver Security Operations project activities and deliverables to a high standard, ensuring alignment with BAU activities and workflows.
- Produce or enhance governance frameworks, processes, procedures and supporting project documentation.
- Provide regular progress updates to the programme technical lead to support wider planning, delivery and reporting.
Supplier & Stakeholder Engagement
- Work collaboratively with existing and future service providers to ensure effective integration of the organisation’s Security Operations capability.
- Participate in technical workshops, knowledge transfer sessions and transition activities.
- Review supplier deliverables and operational approaches.
- Provide practical guidance to both technical and non-technical stakeholders.
- Produce and maintain technical documentation, standards and operational artefacts.
Requirements
The successful candidate will have strong hands-on Security Operations expertise, with transferable skills across a range of technologies and platforms covering:
- Detection & Response
- Threat Operations
- Security Engineering
- DevSecOps
While operational experience is essential, this role is primarily focused on the delivery of project outputs rather than day-to-day operational security analysis or incident response. Candidates should therefore be able to apply their operational expertise within a project delivery environment., * Significant experience operating at a senior practitioner level within a live cyber defence capability, managing both commodity and advanced cyber threats relevant to modern organisations.
- Strong technical expertise that can be applied across multiple platforms and technologies rather than being tool-specific.
- Strong understanding of Security Operations disciplines, including:
- Protective monitoring and triage
- Security analysis
- Incident response and management
- Data Loss Prevention (DLP)
- Digital forensics and eDiscovery
- Threat intelligence
- Threat hunting
- Vulnerability management
- Security engineering and design, ideally within cloud and DevSecOps environments
- Detection engineering and content management
- Data management
- Endpoint and network security controls
- Desirable Skills & Experience
- Experience working within regulated or highly governed enterprise environments.
- Experience supporting complex transformation programmes within a consultancy or project delivery environment.
Experience with technologies including:
- Microsoft Defender Suite
- KQL / SPL
- ASIM / CIM
- Splunk Enterprise
- Cribl
- Wiz Suite
- Confluence
- Jira
- Akamai WAF
- Bolster.ai Brand Protection
- ServiceNow ITSM
- GitHub Actions
- Microsoft Azure
- Amazon Web Services (AWS)
Personal Attributes
- Delivery-focused with high standards balanced by pragmatism.
- Adaptable, intellectually agile and comfortable working within evolving environments.
- Strong analytical and problem-solving skills within a Security Operations context.
- Collaborative, with the ability to work effectively across organisational boundaries and with stakeholders of varying technical knowledge.
- Self-motivated and capable of delivering high-quality work with minimal supervision.
- Strong communication skills with both technical and non-technical audiences.
- Good understanding of the modern cyber threat landscape, security best practice and emerging technologies.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Best Companies to work for in London: Top 25 Companies in 2023
Data Analyst Salary in the UK
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
9 Ways to Make Money Hacking