Senior Cyber Security Analyst / Engineer
Senior Cyber Security Analyst / Engineer
Remote – UK
£50,000–£60,000 + Bonus & Benefits
We're working with a leading global law firm that is looking to hire a Senior Cyber Security Analyst / Engineer to join its Cyber Security function.
This is a hands-on technical security role with a strong focus on security operations, threat detection, incident response and security engineering, working across a modern Microsoft security environment.
You'll play an important role in protecting the firm's systems and highly sensitive client data, while helping to develop and improve its security capability across cloud, endpoint, identity and data.
A major part of the position will involve Microsoft Sentinel, including developing and refining detection logic, improving alerting and investigation capabilities, and working closely with an outsourced SOC to continually strengthen the firm's ability to identify and respond to threats.
The firm is also investing heavily in the use of AI within cyber security, including Microsoft Security Copilot and AI-driven security automation. You'll have the opportunity to explore how emerging technologies can improve detection, investigation and incident response, while also helping the firm defend against new AI-enabled and agentic threats.
It's an excellent opportunity for someone who wants to remain technically hands-on while having the freedom to help shape and improve the wider security capability of a major international organisation.
The Role
Working closely with senior members of the Cyber Security team, you'll help operate, engineer and continuously improve the firm's security capability.
Your responsibilities will include:
- Supporting security monitoring, threat detection and incident response across the organisation.
- Developing and refining detection logic within Microsoft Sentinel, improving visibility and response capabilities.
- Investigating complex and high-severity security incidents and helping coordinate effective responses.
- Improving alert quality through detection engineering, tuning and optimisation.
- Developing and improving incident response processes, playbooks and security automation.
- Using Microsoft Security Copilot and other AI-assisted security capabilities to improve investigation, triage and analysis.
- Exploring and developing AI-driven tooling and automation to enhance security operations and analyst capabilities.
- Working closely with an outsourced SOC / MDR provider, helping drive service quality, responsiveness and continuous improvement.
- Identifying and responding to emerging threats including ransomware, identity attacks, cloud-based threats and AI-enabled attacks.
- Supporting security across Azure, endpoint, identity and data environments.
- Working with Infrastructure, Networking, Architecture, Data and other technology teams to embed security into new solutions and platform changes.
- Supporting the design and implementation of practical technical security controls.
- Contributing to security audits, compliance requirements and client security assurance activities.
- Helping continuously improve the firm's security tooling, processes and overall defensive capability.
What We're Looking For
We're looking for a technically strong Cyber Security Analyst / Engineer who has experience working within Security Operations, Incident Response, Threat Detection or Security Engineering.
You'll ideally have experience across:
- Microsoft Sentinel / SIEM
- Detection engineering and alert tuning
- Security monitoring and incident response
- Microsoft security technologies
- Microsoft Security Copilot or similar AI-assisted security tooling
- Azure security
- Cloud security
- Identity-based threats
- Endpoint security
- Threat investigation and analysis
- Incident response playbooks
- Security automation
- Working alongside an outsourced SOC or MDR provider
You'll also have a strong understanding of the modern threat landscape, including ransomware, identity compromise, cloud misconfiguration and increasingly AI-driven and automated attack techniques.
AI & Security Automation
One of the particularly interesting aspects of this position is the firm's focus on the changing role of AI within cyber security.
You'll help assess emerging AI and agentic threats while also exploring how technologies such as generative AI, machine learning and security automation can be used defensively.
This could include improving:
- Threat detection
- Incident investigation
- Alert triage
- Security automation
- Analyst decision-making
- Response processes
- Identification of emerging threats
You don't necessarily need to be an AI specialist already, but you'll need a genuine interest in the area and an appetite to develop your knowledge as the technology evolves.
Stakeholder Management
Although this is a highly technical position, you'll work with teams and stakeholders across the organisation.
You'll need to be comfortable:
- Translating technical threats into clear business risks.
- Explaining security issues to both technical and non-technical audiences.
- Working collaboratively with Infrastructure, Data, Architecture and Service Management teams.
- Challenging existing approaches constructively where security improvements are needed.
- Working with third-party security partners and suppliers.
- Producing clear documentation covering incidents, processes, controls and security recommendations.
Certifications
Relevant industry certifications would be beneficial, including:
Security+ | SC-200 | AZ-500 | SSCP | CySA+ | or similar
More important is strong hands-on security experience, sound technical judgement and the ability to approach security challenges pragmatically.
Why Consider This Opportunity?
This is a chance to join the Cyber Security function of a major global law firm and work within an environment where protecting sensitive information and client data is absolutely critical.
You'll have the opportunity to work across security engineering, detection and response, Azure security, Microsoft Sentinel and AI-driven security, while helping shape how the firm's security capability develops.
The position offers a genuine combination of hands-on technical security work and longer-term security improvement, with exposure to some of the most interesting emerging challenges facing modern security teams.