2nd/3rd Line Security Analyst

IT & Telecoms
  • Reading
  • £50,000-£60,000
  • Permanent - Full time

2nd / 3rd Line Security Analyst

Location: Reading (Hybrid)

Salary: £50,000 – £60,000     

Our client is looking for a 2nd/3rd Line Security Analyst to join their Security Operations Centre as a senior technical escalation point. This is a genuinely hands-on role – ideal for someone who wants to keep working close to the tooling and the day-to-day operational workload rather than move straight into a purely managerial or architectural position. You’ll own complex incidents end-to-end, drive detection engineering and automation, and provide senior technical depth across the SOC.

Duties of the Role

  • Own complex security incidents end-to-end – from alert validation through investigation, containment and closure
  • Act as the senior escalation point when earlier-stage investigations stall, reviewing prior work and coaching the original analyst
  • Investigate identity and cloud-based compromise (e.g. anomalous sign-ins, malicious OAuth consent, mailbox access), including session/token revocation
  • Design, build and test SIEM detection rules mapped to MITRE ATT&CK, and tune out false positives without blanket whitelisting
  • Build automation for SOC processes – enrichment, ticketing, containment – using Python, Logic Apps, APIs or a SOAR platform
  • Correlate evidence across SIEM, endpoint, identity and cloud platforms (Sentinel, Defender XDR, CrowdStrike, Entra ID, Microsoft 365, AWS) to scope the full blast radius of an incident
  • Run hypothesis-led threat hunts, not just reactive alert triage
  • Mentor junior analysts and help drive measurable improvements to SOC detections, playbooks and workflow

What we’re looking for

  • Proven, personal ownership of complex security incidents from triage through to closure
  • Hands-on experience writing and tuning SIEM detection logic, with a solid understanding of MITRE ATT&CK and KQL (or equivalent)
  • Practical scripting/automation experience (Python, Logic Apps, REST APIs) or hands-on SOAR platform configuration
  • Working knowledge of several of: Microsoft Sentinel, Defender XDR, CrowdStrike, Microsoft Entra ID/Azure AD, Microsoft 365, AWS security tooling
  • Experience investigating identity and cloud-based compromise, including OAuth consent abuse and Conditional Access/MFA
  • A track record of proactive, hypothesis-driven threat hunting
  • Strong investigative writing skills, with the ability to explain technical findings to non-technical stakeholders
  • Comfortable acting as a technical escalation point, including reviewing and correcting the work of other analysts constructively

Nice to have

  • Security certifications (e.g. SC-200, GCIH, GCFA, CySA+ or equivalent)
  • Experience mentoring or formally training junior SOC analysts
  • Exposure to non-Microsoft cloud, EDR or SIEM tooling
  • Familiarity with SOAR platforms beyond Logic Apps (e.g. Sentinel Automation, Tines, Cortex XSOAR)
Apply for this role
Job Ref: 3357929

Apply for this role

Close the application form
2nd/3rd Line Security Analyst
Drop Files Here
Tick

Thank you.
Your application was sent successfully.
Please check your email for a record of your application.

Return to role
Close the form

Drop us your CV to be added into our candidate database.

Tick

Thank you.
Your application was sent successfully.

Please check your email for a record of your application.

Close