> Markdown version of [/jobs/ext/3563372-associate-cyber-security-analyst](https://www.wearedevelopers.com/jobs/ext/3563372-associate-cyber-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Associate Cyber Security Analyst - **Company:** CCL Global - **Location:** London, UK - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Agile Methodology, Amazon Web Services, Microsoft Antivirus, Cyber Security, Kusto Query Language, Security Information and Event Management, Cloud Platform System, SC Clearance, Cybercrime, Microsoft Sentinel, Splunk - **Published:** October 3, 2026 - **Apply:** https://www.securityclearedjobs.com/job/802084789/associate-cyber-security-analyst/ ## About the Role This is a hands-on role suited to analysts with experience using Splunk, Microsoft Defender, Sentinel and KQL in a security operations environment., * Active SC clearance. At least 2-3 years' experience in a Cyber Security Analyst or similar security operations role. * Practical experience investigating and responding to cyber security incidents. Working experience with Splunk. * Working knowledge of Microsoft 365 security tools, particularly Microsoft Defender, Microsoft Sentinel and KQL. * Experience using SIEM and endpoint detection and response (EDR) tools. * Understanding of common cyber threats, attacker techniques and incident response processes. * Strong analytical, problem-solving and communication skills. * Ability to make effective decisions, work collaboratively and contribute to continuous improvement. Desirable Experience * Experience working in an Agile environment. * Familiarity with AWS or other cloud environments. * Previous experience coaching or mentoring junior security analysts. ## Description * Triage and investigate cyber security alerts and incidents, including reports from users. * Analyse systems, files, network traffic and cloud environments to identify potential threats and determine the extent of incidents. * Support incident containment, eradication and recovery activities. Assist with incident coordination and contribute to post-incident reviews. * Use SIEM and endpoint security tools to investigate suspicious activity and support incident response. * Identify opportunities to improve detection, investigation and response processes. * Develop and maintain incident response playbooks, internal guidance and knowledge-base articles. * Work closely with other Cyber Defence teams to strengthen security capabilities. * Provide technical guidance, coaching and line management to apprentice security analysts. * Participate in an out-of-hours incident response rota.