> Markdown version of [/jobs/ext/3332174-senior-security-operations-analyst-temporary](https://www.wearedevelopers.com/jobs/ext/3332174-senior-security-operations-analyst-temporary). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Operations Analyst (Temporary) - **Company:** Proact - **Location:** Holytown, UK - **Experience:** Expert - **Contract:** Temporary contract - **Skills:** Cloud Computing, Cyber Security, Monitoring of Systems, Intrusion Detection and Prevention, Microsoft Security Essentials, Azure Active Directory, ArcSight SIEM Tool, Phishing, Security Information and Event Management, QRadar, Azure Security Center, Microsoft Sentinel, Splunk - **Published:** September 29, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=fc91efa2c851fee7 ## About the Role This role requires a highly self-motivated individual who can also motivate and inspire others. The successful candidate will be able to effectively manage multiple tasks and competing priorities across a range of timelines, while also demonstrating the ability to focus exclusively on high-priority activities when required. Excellent verbal and written communication skills are essential, along with a strong attention to detail in planning, implementation, documentation, and follow-up. Candidates must be capable of working both independently and collaboratively as part of a team, adapting their approach to suit the needs of the business. The ideal candidate will be reliable, punctual, personable, and customer-focused, with the ability to remain calm, patient, and professional when providing phone-based technical support. They should be comfortable working in both remote and in-person environments and possess the flexibility to quickly adapt to changing priorities and switch effectively between tasks. A positive and energetic attitude, combined with a genuine desire to learn and continuously develop new skills, is essential for success in this role. Professional Skills and Experience * At least three years' experience working within a Security Operations Centre (SOC), with demonstrable experience investigating, managing, and responding to security incidents within an operational environment. * Strong understanding of Security Operations Centre processes, incident lifecycle management, alert triage, threat detection, and incident response. * Hands-on experience working with Security Information and Event Management (SIEM) platforms, preferably Microsoft Sentinel. * Working with Microsoft security technologies, including Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, Microsoft Defender for Cloud, and Microsoft Entra. ## Description * Conducting proactive threat hunting activities using security telemetry, threat intelligence, and behavioural analysis techniques. * Investigating and responding to advanced threats, including phishing, malware, ransomware, compromised accounts, insider threats, and suspicious network activity. * Detection engineering, including the development, tuning, testing, and optimisation of detection logic, analytics rules, correlation searches, use cases, and alerting mechanisms to improve detection coverage and reduce false positives. * Experience with additional SIEM and security monitoring platforms, such as Splunk, IBM QRadar, LogRhythm, Elastic, Google Chronicle, ArcSight, or similar technologies, would be advantageous. * Strong understanding of change control and change management principles, ensuring changes are implemented in a controlled and coordinated manner while promoting adherence to established processes and best practices. * Mentoring, coaching, or supporting the development of less experienced analysts would be advantageous. Core Responsibilities * Conduct threat hunting and incident response activities to identify, investigate, and mitigate security threats. * Monitor, investigate, and respond to security alerts generated through Microsoft Sentinel, Microsoft Defender, and other security monitoring technologies. * Lead complex incident investigations and coordinate response activities across technical and business stakeholders. * Act as a key point of contact, collaborator, and escalation path for Security Operations, Security Engineering, Service Operations, and other business teams. * Provide senior technical and process guidance to Security Operations Analysts, acting as an escalation point for complex issues and incidents. * Mentor junior analysts and graduates, supporting their technical development and operational effectiveness. * Deliver and support both individual and collaborative projects and operational tasks. * Lead by example in day-to-day Security Operations activities, supporting team objectives and maintaining high operational standards. * Perform proactive threat hunting activities using telemetry from Microsoft Defender and other security platforms. * Develop and improve detection logic, analytics rules, automation playbooks, workbooks, and SOC operational processes. * Maintain and develop expertise through relevant training and industry-recognised certifications. * Contribute to the development, review, and continuous improvement of security processes, procedures, and policies. * Work as part of the SOC's 24x7x365 shift rota, consisting of 12-hour shifts on a four-on, four-off basis, including weekends and public holidays. Additional Duties * Contribute to the response to security incidents, with a proactive focus on root cause analysis and the prevention of recurrence. * Willingness to travel occasionally to other Proact offices to support collaboration, knowledge sharing, and cross-team engagement. * Support knowledge-sharing initiatives across the wider SOC, contributing to team capability, operational maturity, and continuous improvement. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) - [MFA? Game over! Watch your protection collapse – live](https://www.wearedevelopers.com/videos/100322-mfa-game-over-watch-your-protection-collapse-live) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)