Назад
Company hidden
3 дня назад

Information Security Analyst - Security Operations Centre (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
UK
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Information Security Analyst - Security Operations Centre (Cybersecurity): Monitoring and investigating security alerts across SIEM, EDR/XDR, cloud, identity, email, network, and data loss prevention tooling with an accent on incident response, threat hunting, and detection engineering. Focus on analysing complex security events, coordinating containment and remediation, improving detection coverage, and supporting digital forensics and vulnerability management.

Location: Hybrid in Melbourn, Royston, UK, with 2–3 office days per week. Candidates must have resided in the UK continuously for at least five years to obtain the required security clearance.

Company

hirify.global is a global consulting firm combining strategy, technology, innovation, science, engineering, and design to help clients adapt and transform.

What you will do

  • Monitor and investigate alerts across SIEM, EDR/XDR, email security, cloud, identity, network security, and data loss prevention platforms.
  • Triage security events, assess scope and impact, coordinate containment and remediation, and maintain investigation evidence.
  • Conduct proactive threat hunting using threat intelligence, attacker techniques, and relevant hypotheses.
  • Develop and tune detections, dashboards, playbooks, use cases, and automation to improve coverage and reduce alert noise.
  • Support digital forensics, malware and phishing analysis, post-incident reviews, and vulnerability exposure management.
  • Participate in security improvement projects, reporting, documentation, knowledge sharing, and a paid out-of-hours on-call rota.

Requirements

  • Practical experience in a SOC, incident response, security monitoring, detection engineering, or a closely related technical security role.
  • Strong investigation, log analysis, and correlation skills across endpoint, identity, email, cloud, and network telemetry.
  • Experience using SIEM and EDR/XDR platforms to investigate alerts and support containment and remediation.
  • Understanding of attacker techniques, phishing, account compromise, malware, vulnerabilities, and cloud security risks.
  • Ability to document investigations, preserve evidence, explain findings to technical and non-technical stakeholders, and collaborate across operational teams.
  • At least five years of continuous UK residency is required for the security clearance.

Nice to have

  • Experience in threat hunting, detection-rule development, alert tuning, malware analysis, or digital forensics.
  • Knowledge of vulnerability and exposure management, penetration-testing remediation, and security-control assurance.
  • Knowledge of ISO 27001/27002, Cyber Essentials Plus, MITRE ATT&CK, or comparable security frameworks.
  • Relevant certifications or equivalent practical knowledge, such as CompTIA CySA+, Microsoft Security Operations Analyst, or Cyber Security Blue Team qualifications.

Culture & Benefits

  • Private healthcare for employees and families, health and lifestyle perks, and a generous company pension scheme.
  • 25 days of annual leave plus a bonus half day on Christmas Eve, with the option to buy five additional days.
  • Annual performance-based bonus and PA share ownership.
  • Tax-efficient benefits, including cycle-to-work and give-as-you-earn schemes.
  • Opportunities for professional growth and participation in community and charity initiatives.

Hiring process

  • Complete the online application and undergo the required background checks.
  • Successful candidates must meet Baseline Personnel Security Standard requirements and any higher UK security-vetting requirements for the role.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →