> Markdown version of [/jobs/ext/2797635-senior-cyber-security-analyst-l3](https://www.wearedevelopers.com/jobs/ext/2797635-senior-cyber-security-analyst-l3). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cyber Security Analyst (L3) - **Company:** InfoSec People Ltd - **Location:** London, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Software as a Service, Cyber Security, Intrusion Detection and Prevention, Security Information and Event Management, Data Logging, Data Ingestion, Mitre Att&ck - **Published:** September 8, 2026 - **Apply:** https://www.collegerecruiter.com/job/2840570806-senior-cyber-security-analyst-l3 ## About the Role We are seeking a highly capable Senior SOC Analyst (Level 3) to act as a technical and operational lead within a growing Security Operations function. This role is ideal for someone confident in leading incident investigations, developing advanced detection content, managing client communication, and contributing to the ongoing maturation of SOC capabilities. This position requires independence, strong stakeholder communication skills, and the ability to operate within a fast-paced environment with minimal procedural guardrails., * Accountability and humility - ability to self-reflect and drive personal performance. * Calmness under pressure - capable of managing high-severity incidents confidently. * Proactive leadership - steps in where needed without waiting for instruction. * Strong communication skills - able to simplify complex topics for diverse audiences. * Mentorship ability - provides constructive guidance to junior team members. * Commercial awareness - understands client context and can identify value-adding opportunities., * Degree-level education in a relevant field or equivalent experience. * Strong problem-solving abilities and adaptability. * Clear, confident communication skills at a business level. * Ability to collaborate in a fast-paced and evolving environment. * Self-driven mindset with comfort operating in an environment without rigid processes. * Living within commutable distance to a major office hub for regular face-to-face collaboration. ## Description Client Delivery & Stakeholder Communication * Serve as the primary point of contact for clients on SOC-related matters. * Lead incident investigations and deliver clear briefings to technical and non-technical stakeholders. * Represent the SOC in governance meetings and executive-level discussions. * Produce concise weekly/monthly threat reports and post-incident summaries. Detection Engineering & Threat Response * Lead development and refinement of detection content across multiple SIEM and monitoring platforms. * Design new queries, alerts, and automated workflows to improve visibility and reduce analyst workload. * Tune existing detection rules, reduce false positives, and increase detection fidelity. * Map detections to frameworks (e.g., MITRE ATT&CK) and identify visibility gaps. Data Onboarding & Logging Strategy * Own the process for onboarding new data sources such as endpoint, cloud, and SaaS telemetry. * Validate data quality and ensure alignment with detection and threat hunting use cases. * Maintain a coverage matrix to monitor completeness and highlight improvement areas. * Perform rigorous testing of all logic and data sources before deployment. * Oversee the development and deployment of automation workflows using SOAR or equivalent technologies. * Identify opportunities to automate enrichment, response, and triage processes. * Define engineering standards for repeatable automation tasks and track their operational impact. * Support SOC governance by managing shift rotas, ensuring cover, and monitoring SLA adherence. Documentation & Strategic Development * Maintain accurate SOC documentation including runbooks, playbooks, SOPs, and knowledge-base content. * Provide strategic context behind workflows to support consistency and audit readiness. * Contribute to developing the SOC's long-term service architecture and capability roadmap. Operational Excellence * Mentor junior analysts and guide them through complex investigations. * Support intelligence gathering, contribute to threat landscape assessments, and lead threat hunting missions. * Ensure incidents are documented with clear learning outcomes and client-ready reporting. * Assist in maintaining organisational compliance with standards such as ISO 27001 and Cyber Essentials. Practice Development & Business Support * Assist with the design of internal processes, workflows, and automation initiatives. * Lead the SOC readiness component of onboarding new clients. * Support business development by contributing technical content for proposals and participating in pre-sales discussions. * Identify opportunities to upsell monitoring enhancements, custom detections, or proactive threat hunting services. Professional Development * Work toward relevant technical certifications to support ongoing growth. * Stay up to date with attacker behaviours, modern detection engineering practices, and emerging technologies. * Proactively seek feedback and continuously improve. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)