2nd/3rd Line Security Analyst - Reading
hace 10 días
Reading
2nd / 3rd Line Security Analyst \n Location: Reading (Hybrid) \n Salary: £50,000 – £60,000 \n \n Our client is looking for a 2nd/3rd Line Security Analyst to join their Security Operations Centre as a senior technical escalation point. This is a genuinely hands-on role - ideal for someone who wants to keep working close to the tooling and the day-to-day operational workload rather than move straight into a purely managerial or architectural position. You'll own complex incidents end-to-end, drive detection engineering and automation, and provide senior technical depth across the SOC. \n \n Duties of the Role \n\n • Own complex security incidents end-to-end - from alert validation through investigation, containment and closure\n, • Act as the senior escalation point when earlier-stage investigations stall, reviewing prior work and coaching the original analyst\n, • Investigate identity and cloud-based compromise (e.g. anomalous sign-ins, malicious OAuth consent, mailbox access), including session/token revocation\n, • Design, build and test SIEM detection rules mapped to MITRE ATT&CK, and tune out false positives without blanket whitelisting\n, • Build automation for SOC processes - enrichment, ticketing, containment - using Python, Logic Apps, APIs or a SOAR platform\n, • Correlate evidence across SIEM, endpoint, identity and cloud platforms (Sentinel, Defender XDR, CrowdStrike, Entra ID, Microsoft 365, AWS) to scope the full blast radius of an incident\n, • Run hypothesis-led threat hunts, not just reactive alert triage\n, • Mentor junior analysts and help drive measurable improvements to SOC detections, playbooks and workflow\n\n \n What we're looking for \n\n • Proven, personal ownership of complex security incidents from triage through to closure\n, • Hands-on experience writing and tuning SIEM detection logic, with a solid understanding of MITRE ATT&CK and KQL (or equivalent)\n, • Practical scripting/automation experience (Python, Logic Apps, REST APIs) or hands-on SOAR platform configuration\n, • Working knowledge of several of: Microsoft Sentinel, Defender XDR, CrowdStrike, Microsoft Entra ID/Azure AD, Microsoft 365, AWS security tooling\n, • Experience investigating identity and cloud-based compromise, including OAuth consent abuse and Conditional Access/MFA\n, • A track record of proactive, hypothesis-driven threat hunting\n, • Strong investigative writing skills, with the ability to explain technical findings to non-technical stakeholders\n, • Comfortable acting as a technical escalation point, including reviewing and correcting the work of other analysts constructively\n\n Nice to have \n\n • Security certifications (e.g. SC-200, GCIH, GCFA, CySA+ or equivalent)\n, • Experience mentoring or formally training junior SOC analysts\n, • Exposure to non-Microsoft cloud, EDR or SIEM tooling\n, • Familiarity with SOAR platforms beyond Logic Apps (e.g. Sentinel Automation, Tines, Cortex XSOAR)\n\n