We are looking for a Senior Cyber Security Analyst to join our security function, with responsibility for investigating security events, handling incidents and improving the controls used to detect and respond to threats.
You will work across SIEM, endpoint, identity, network and cloud security data. The role involves investigating alerts that are not always straightforward, establishing what actually happened, determining the systems or accounts involved and working with IT and engineering teams to contain and remediate confirmed issues.You'll also have responsibility for improving the quality of security monitoring. This includes tuning existing detections, identifying gaps in logging, developing new use cases and using incident findings to strengthen preventative controls.
Key Responsibilities
- Investigate security alerts from SIEM, EDR, identity, email, network and cloud security platforms.
- Take ownership of security investigations from initial triage through containment, remediation and closure.
- Analyse authentication records, process activity, endpoint telemetry, network connections and other available evidence to establish the sequence of events.
- Investigate suspected account compromise, phishing, malware, unauthorised access, privilege misuse and suspicious endpoint activity.
- Correlate events from multiple sources to determine whether activity is isolated or part of a wider incident.
- Escalate confirmed incidents appropriately and work with Infrastructure, IT and Engineering teams on containment and recovery.
- Develop and maintain SIEM detection rules and queries, with particular attention to reducing false positives and identifying meaningful attacker behaviour.
- Review security logs and telemetry to identify gaps that could prevent effective investigation of future incidents.
- Carry out targeted threat-hunting exercises using indicators, known attacker techniques and patterns identified through previous incidents.
- Review vulnerability scan results, assess the practical risk to affected systems and work with technical owners to track remediation.
- Investigate suspicious activity within Microsoft 365, Entra ID and cloud environments.
- Analyse phishing reports and determine whether messages, links, attachments or credentials present a security risk.
- Maintain incident timelines, technical evidence and investigation records to an appropriate standard.
- Produce clear post-incident reports covering the cause, impact, actions taken and recommended improvements.
- Review recurring security events and work with infrastructure and application teams to address the underlying issue.
- Contribute to incident response procedures, detection playbooks and security monitoring standards.
- Support security reviews, incident exercises and improvements to operational security controls.
Technical RequirementsEssential
- 5+ years' professional experience in Cyber Security, Security Operations, Incident Response, SOC or a related discipline.
- Strong practical experience investigating security incidents in an enterprise environment.
- Hands-on experience with a SIEM platform such as Microsoft Sentinel, Splunk, QRadar or Elastic Security.
- Strong experience analysing endpoint telemetry using Microsoft Defender for Endpoint, CrowdStrike, SentinelOne or an equivalent EDR platform.
- Good understanding of Windows security events, Active Directory, Entra ID and authentication activity.
- Experience investigating suspicious logins, privilege changes, credential misuse, malware and endpoint compromise.
- Strong understanding of TCP/IP, DNS, HTTP/S, VPNs, firewalls and common network attack techniques.
- Experience creating, testing or tuning SIEM detection rules and queries.
- Working knowledge of the MITRE ATT&CK framework and how it can be applied to security investigations.
- Experience with vulnerability management and remediation tracking.
- Ability to work with incomplete evidence, form a defensible assessment and determine the appropriate response.
- Strong technical writing skills, particularly when documenting incidents and investigation findings.
- Ability to work directly with infrastructure, cloud and engineering teams during active security incidents.
Desirable
- Strong Microsoft Sentinel and KQL experience.
- Splunk SPL experience.
- Experience investigating AWS or Azure security events.
- Experience with Microsoft 365 security investigations.
- Knowledge of Tenable, Qualys, Rapid7 or comparable vulnerability management platforms.
- Experience with threat intelligence and IOC enrichment.
- Practical PowerShell, Python or Bash experience for investigation and automation.
- Experience conducting structured threat-hunting exercises.
- Experience contributing to detection engineering or SOC use-case development.
- Security certification such as CISSP, CISM, GIAC or equivalent.
Benefits
- Competitive salary with annual performance review
- 25 days annual leave plus bank holidays
- Private medical insurance
- Company pension scheme
- £1,500 annual learning and development budget
Apply
If you have substantial experience investigating security incidents and can work confidently across SIEM, endpoint, identity and cloud security data, we'd like to hear from you.
Please submit your CV detailing your security operations experience, the security platforms you have worked with and the types of investigations you have handled. Please include relevant experience in incident response, detection development or threat hunting where applicable.
Pay: £62,000.00-£66,000.00 per year
Benefits:
- Bereavement leave
- Canteen
- Company pension
- Cycle to work scheme
- Free parking
- Life insurance
- On-site parking
- Sick pay
Work Location: In person