Назад
Company hidden
обновлено 2 дня назад

Security Analyst III - SOC

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
UK
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Analyst III - SOC (Cybersecurity): Leading advanced SOC investigations and proactive threat hunting to protect a retail organisation from evolving threats with an accent on incident response, detection engineering, and SOC maturity. Focus on coaching analysts, optimising SIEM/XDR tooling, developing automation and AI-driven enhancements, and supporting CSIRT response to major incidents.

Location: Welwyn Garden City, United Kingdom; hybrid working

Company

Tesco is a large retail business focused on serving customers, communities, and the planet through its shopping operations.

What you will do

  • Lead complex SOC investigations as the escalation point and technical authority.
  • Deliver high-quality investigative analysis and proactive threat hunting to identify and mitigate emerging threats.
  • Coach and mentor SOC analysts, raising technical capability and analytical rigour.
  • Drive SOC maturity through process improvement, workflow optimisation, tooling enhancements, and automation.
  • Develop playbooks and identify AI-driven improvements for threat detection and response.
  • Support CSIRT activities during major incidents and monitor MSSP investigation quality and timeliness.

Requirements

  • Hybrid role based in Welwyn Garden City, United Kingdom.
  • More than 2 years of experience in an internal SOC or 3 years in a senior MSSP role.
  • Deep knowledge of MITRE ATT&CK, Cyber Kill Chain, Incident Response Lifecycle, and Pyramid of Pain.
  • Expertise in threat hunting, advanced investigative analysis, attacker TTPs, and threat actor behaviour.
  • Proficiency with SIEM/XDR platforms, detection logic, use cases, alert optimisation, and advanced querying with KQL or SPL.
  • Experience with networks, operating systems, scripting, technical initiatives, service maturity, and analyst coaching.

Nice to have

  • GIAC certification.
  • CISSP or CISM certification.
  • Relevant degree combined with professional experience.

Culture & Benefits

  • Blended office and remote working environment.
  • Annual bonus scheme of up to 20% of base salary.
  • At least 25 days of holiday plus a personal day and bank holidays.
  • Private medical insurance and a free 24/7 virtual GP service.
  • Employee Assistance Programme and family wellbeing support.
  • Paid maternity, adoption, and paternity leave subject to stated eligibility conditions.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →