Security Operations Analyst, UK
Core
Monitor and respond to adversarial activity, conduct threat hunting, and optimize detection signatures for critical defense technologies.
Role type
Security Operations Analyst (SOC)
Builds
Detection signatures, response playbooks, and automation using detection-as-code principles
Domain
Defense technology, Cybersecurity
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
Security monitoring, Log analysis, Detection engineering, Python development, SIEM query languages (SPL, KQL, SQL), Threat modeling, Threat hunting, Incident response
Preferred skills
Cloud incident response (AWS, Azure, GCP), Digital forensics, Reverse engineering
Technologies
Python, SIEM, AWS, Azure, GCP, Windows, Linux, MacOS
Responsibilities
Triage and respond to security alerts across endpoints, network, cloud, and SaaS; Build and optimize detection signatures and response automation; Conduct threat hunting and data baseline analysis; Participate in on-call rotation for incident response investigations; Lead feedback loops to fine-tune detections and reduce false positives.
Seniority
Individual Contributor