About this role
Salary: £50,000 - 60,000 per year
Requirements: Solid experience in a Security Operations or SOC environmentHands-on experience with SIEM, EDR and SOAR platformsProven detection engineering and SIEM rule-tuning experienceStrong grasp of MITRE ATT&CK and similar threat frameworksExperience automating processes with Python, Logic Apps or APIsComfortable investigating incidents across cloud, identity and endpoint environmentsExperience with platforms like Microsoft Sentinel, Defender XDR, CrowdStrike or similarKnowledge of Azure/AWS security monitoringUnderstanding of ISO 27001 and Cyber EssentialsCISSP or similar certification desirable but not essential Responsibilities: Owning security incidents end-to-end, including triage, investigation, remediation and closureRunning advanced investigations across SIEM, EDR and XDR platformsDesigning and tuning SIEM detection rules to reduce false positivesMapping detection and response work against the MITRE ATT&CK frameworkBuilding automated security workflows using tools like Logic Apps, Python and APIsProactively threat hunting using behavioural analytics and threat intelligenceMonitoring and responding to security events across Azure, Microsoft 365 and AWSInvestigating identity-based threats such as suspicious sign-ins and privilege escalationSupporting endpoint security, including EDR, AV and patchingActing as an escalation point for complex or high-risk incidentsSupporting ISO 27001 and Cyber Essentials complianceMentoring junior analysts and the wider service desk team Technologies: AWSAzureCloudSupportMicrosoft 365PythonSecurityOffice 365 More:
We are a well-established managed services organisation in Reading, offering a hybrid working arrangement for this Senior Security Analyst role. We are growing our SOC function and are looking for someone who enjoys hands-on detection and response, threat hunting, and improving the automation and effectiveness of our security operations. The role offers the opportunity to work across SIEM, EDR and XDR platforms, take ownership of incident response from start to finish, and support our compliance efforts while mentoring junior colleagues.
last updated 29 week of 2026