Назад
Company hidden
3 дня назад

24 x 7 Security Analyst

Формат работы
onsite
Тип работы
fulltime
Английский
b2
Страна
UK
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
24 x 7 Security Analyst (Microsoft Sentinel/Defender): Detecting and responding to threats in a 24x7 SOC using SIEM, EDR, network monitoring, threat intelligence, and bespoke tooling with an accent on incident investigation, customer reporting, and defensive monitoring. Focus on threat hunting, malware analysis, detection tuning, security automation, and developing custom KQL analytics rules.

Location: Birmingham, United Kingdom

Company

Security Operations Centre providing defensive monitoring, threat detection, and response services to customers across multiple industries.

What you will do

  • Monitor customer environments as part of a 24x7 SOC shift team and triage security alerts using SIEM, EDR, network monitoring, threat intelligence, and bespoke tooling.
  • Investigate incidents, assess risk and threats, and produce actionable reports with recommendations, mitigations, and remediations.
  • Respond to alerts and customer requests within agreed SLAs and maintain clear communication with customers, suppliers, and internal stakeholders.
  • Perform threat hunting, malware analysis, detection development, and tuning of alerts, playbooks, and automations.
  • Support the implementation of new security technologies and strategic cross-team projects.
  • Maintain operational and management reporting, documentation, and security use cases.

Requirements

  • Professional experience with Microsoft Sentinel and Microsoft Defender, including deployment, configuration, and enterprise operational management.
  • Knowledge of SIEM and EDR/EPP technologies, security investigations using large datasets, and Kusto Query Language for custom queries and analytics rules.
  • Understanding of enterprise IT infrastructure, including Windows and Linux, networking, and third-party security tools.
  • Ability to analyse complex security data, identify patterns, prioritise threats, and distinguish normal from abnormal activity.
  • Knowledge of attack vectors, the MITRE ATT&CK framework, and adversary behaviours.
  • Strong communication skills and experience presenting technical findings and security risks to technical and non-technical stakeholders.

Nice to have

  • Microsoft SC-200 or SC-100 certification.
  • CrowdStrike CCFA or CCSA certification.
  • Python, PowerShell, and regular expression skills.

Culture & Benefits

  • High-trust, close-knit SOC team operating without traditional SOC tiers.
  • Opportunity to contribute to defensive monitoring capabilities and cross-team security projects.
  • Mentoring and development of junior staff members.
  • Work governed by documented analyst best practices, compliance standards, and organisational procedures.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →