обновлено 2 дня назад
Security Analyst III - SOC
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Analyst III - SOC (Cybersecurity): Leading advanced SOC investigations and proactive threat hunting to protect a retail organisation from evolving threats with an accent on incident response, detection engineering, and SOC maturity. Focus on coaching analysts, optimising SIEM/XDR tooling, developing automation and AI-driven enhancements, and supporting CSIRT response to major incidents.
Location: Welwyn Garden City, United Kingdom; hybrid working
Company
Tesco is a large retail business focused on serving customers, communities, and the planet through its shopping operations.
What you will do
- Lead complex SOC investigations as the escalation point and technical authority.
- Deliver high-quality investigative analysis and proactive threat hunting to identify and mitigate emerging threats.
- Coach and mentor SOC analysts, raising technical capability and analytical rigour.
- Drive SOC maturity through process improvement, workflow optimisation, tooling enhancements, and automation.
- Develop playbooks and identify AI-driven improvements for threat detection and response.
- Support CSIRT activities during major incidents and monitor MSSP investigation quality and timeliness.
Requirements
- Hybrid role based in Welwyn Garden City, United Kingdom.
- More than 2 years of experience in an internal SOC or 3 years in a senior MSSP role.
- Deep knowledge of MITRE ATT&CK, Cyber Kill Chain, Incident Response Lifecycle, and Pyramid of Pain.
- Expertise in threat hunting, advanced investigative analysis, attacker TTPs, and threat actor behaviour.
- Proficiency with SIEM/XDR platforms, detection logic, use cases, alert optimisation, and advanced querying with KQL or SPL.
- Experience with networks, operating systems, scripting, technical initiatives, service maturity, and analyst coaching.
Nice to have
- GIAC certification.
- CISSP or CISM certification.
- Relevant degree combined with professional experience.
Culture & Benefits
- Blended office and remote working environment.
- Annual bonus scheme of up to 20% of base salary.
- At least 25 days of holiday plus a personal day and bank holidays.
- Private medical insurance and a free 24/7 virtual GP service.
- Employee Assistance Programme and family wellbeing support.
- Paid maternity, adoption, and paternity leave subject to stated eligibility conditions.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
4 дня назад
SOC Analyst (Cybersecurity)
3 дня назад
Information Security Analyst - Security Operations Centre (Cybersecurity)
7 дней назад
Threat Analyst 2 (Cybersecurity)
7 дней назад
Security Operations Specialist - 12 Month FTC
8 дней назад
Staff Security Engineer (Security Operations)
3 дня назад