3rd Line Security Analyst

3rd Line Security Analyst

My client, a well-established organisation within the ICT Services sector, are looking to recruit an experienced 3rd Line Security Analyst to join their Security Operations function.

This is a senior, hands-on technical role rather than a queue-driven analyst position. The successful candidate will take ownership of the engineering, administration, health and continuous improvement of the security platforms, detection content and automation that underpin threat monitoring, detection and incident response across my client’s internal and managed customer environments. They will act as the final internal escalation point for complex and high-severity security incidents, the technical design authority for detection and automation content, and a mentor who raises the technical capability of the wider 2nd line team.

Reporting to the Security Operations Manager, this role sits within ICT Services and carries genuine scope and technical authority, including sign-off on detection content, SOAR playbooks and hunting queries, named administrative ownership of key security platforms, and the authority to take immediate containment action during live incidents.

Key Responsibilities

  • Lead the end-to-end management of complex and high-severity security incidents, including investigation, containment, eradication, recovery and post-incident review.
  • Conduct digital forensic investigations across cloud, identity, endpoint and network platforms, and carry out malware analysis and threat validation.
  • Design, implement and optimise detection content across Microsoft Sentinel, Defender XDR, CrowdStrike and associated platforms, developing advanced KQL queries and analytics rules aligned to MITRE ATT&CK.
  • Act as senior technical owner for security platforms including Microsoft Sentinel, Defender XDR, CrowdStrike Falcon, Entra ID, Intune, Darktrace and supporting technologies, managing platform health, onboarding and configuration.
  • Design and maintain automation and orchestration workflows using Logic Apps, Sentinel Playbooks, Power Automate, PowerShell, Python and API integrations to reduce manual operational effort.
  • Conduct proactive, intelligence-led and hypothesis-driven threat hunting, translating findings into detections, hunts and customer recommendations.
  • Monitor, investigate and respond to security events across Microsoft 365, Azure, AWS and hybrid environments.
  • Support compliance activities relating to ISO 27001 and Cyber Essentials, maintaining technical documentation, runbooks and standard operating procedures.
  • Provide technical leadership, mentoring and knowledge transfer to Security Analysts and Service Desk teams.

What My Client Is Looking For

  • Significant experience within a Security Operations Centre (SOC), Cyber Security Operations or Security Engineering function, including at a senior technical level.
  • Strong hands-on experience administering and engineering Microsoft Sentinel, Microsoft Defender XDR, CrowdStrike Falcon and associated security technologies.
  • Proven experience in incident response, threat hunting, malware analysis, digital forensics and security investigations.
  • Advanced KQL skills, with the ability to develop and optimise complex detections and threat hunting queries.
  • Strong scripting and automation experience using PowerShell and/or Python, including API integrations and workflow automation.
  • Experience administering Microsoft Entra ID, Conditional Access, Intune and Microsoft 365 security solutions.
  • Good understanding of Azure, AWS and hybrid infrastructure security, with strong knowledge of networking, operating systems and attacker techniques.
  • Practical understanding of MITRE ATT&CK, Cyber Kill Chain, NIST and SANS incident response frameworks.
  • Experience working within regulated and audited environments, including ISO 27001 and Cyber Essentials.
  • Excellent communication, stakeholder management and documentation skills, with the ability to engage effectively across technical and non-technical audiences.

Desirable

  • CISSP (Certified Information Systems Security Professional) certification.
  • Experience designing or improving SOC operating models, detection strategies, or security platforms at scale.
  • Exposure to security architecture or security engineering activities beyond day-to-day SOC operations.
  • Experience contributing to or leading continuous improvement initiatives, automation strategy, or security service maturity.

Additional Requirements

  • Ability to prioritise work under pressure and meet strict deadlines.
  • Excellent written and verbal communication skills.
  • Candidates must be able to pass security vetting (BS7858).

Salary: £60,000 | Location: Reading / hybrid 2 days from home

Job Details

Company
Xact Placements Limited
Location
Reading, Berkshire, United Kingdom
Hybrid / Remote Options
Employment Type
Full-Time
Salary
£55,000 - £60,000 per annum
Posted