2nd/3rd Line Security Analyst - Reading
2nd / 3rd Line Security Analyst Location: Reading (Hybrid) Salary: £50,000 - £60,000 Our client is looking for a 2nd/3rd Line Security Analyst to join their Security Operations Centre as a senior technical escalation point. This is a genuinely hands-on role - ideal for someone who wants to keep working close to the tooling and the day-to-day operational workload rather than move straight into a purely managerial or architectural position. You''ll own complex incidents end-to-end, drive detection engineering and automation, and provide senior technical depth across the SOC. Duties of the Role Own complex security incidents end-to-end - from alert validation through investigation, containment and closure Act as the senior escalation point when earlier-stage investigations stall, reviewing prior work and coaching the original analyst Investigate identity and cloud-based compromise (e.g. anomalous sign-ins, malicious OAuth consent, mailbox access), including session/token revocation Design, build and test SIEM detection rules mapped to MITRE ATTandCK, and tune out false positives without blanket whitelisting Build automation for SOC processes - enrichment, ticketing, containment - using Python, Logic Apps, APIs or a SOAR platform Correlate evidence across SIEM, endpoint, identity and cloud platforms (Sentinel, Defender XDR, CrowdStrike, Entra ID, Microsoft 365, AWS) to scope the full blast radius of an incident Run hypothesis-led threat hunts, not just reactive alert triage ..... full job details .....
Other jobs of interest...
Perform a fresh search...
-
Create your ideal job search criteria by
completing our quick and simple form and
receive daily job alerts tailored to you!