Security Operations Analyst, UK
Core
Monitor and respond to adversarial activity for critical defense technologies, serving as an incident commander for senior roles.
Role type
Senior Security Operations Analyst (SOC)
Builds
Detection signatures, response playbooks, and automation using detection-as-code principles
Domain
Defense technology, Cybersecurity, Cloud Security
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
Security monitoring, Log analysis, Detection engineering, Python development, SIEM query languages (SPL, KQL, SQL), Data lake analysis, Threat modeling, Threat hunting, Incident response, Security controls design, Mentoring
Preferred skills
Cloud incident response (AWS, Azure, GCP), Digital forensics, Reverse engineering
Technologies
Python, SIEM, AWS, Azure, GCP, Windows, Linux, MacOS
Responsibilities
Triage and respond to security alerts across endpoints, network, cloud, and SaaS; Build and optimize detection signatures and response automation; Conduct threat hunting and data baselines to identify anomalies; Lead incident response investigations and serve as incident commander; Collaborate on threat modeling scenarios; Mentor junior analysts
Seniority
Senior, hands-on IC with mentorship responsibilities