обновлено 1 месяц назад
Lead Security Analyst (Cybersecurity)
65 000 - 80 000GBP
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Lead Security Analyst (Cybersecurity): Setting the technical direction for SOC engagements and building detection, threat intelligence, telemetry, and incident response capabilities with an accent on KQL, SPL, EQL, Sigma, MITRE ATT&CK, and UK government security frameworks. Focus on designing detection and telemetry pipelines, leading complex investigations and significant incident responses, developing L1/L2 analysts, and translating SOC findings into client security decisions.
Location: Any UK Office Hub: Bristol, London, Manchester, or Swansea; part-time remote working is available
Salary: £65,000–£80,000 per year
Company
helps UK public sector organisations build and run digital services, including cybersecurity services for government departments, agencies, and critical national infrastructure.
What you will do
- Set the technical direction and detection engineering standards for SOC engagements, authoring, tuning, and peer-reviewing detections in KQL, SPL, EQL, or Sigma.
- Own the threat-landscape narrative by turning NCSC advisories, sector feeds, and threat actor reporting into hunt themes, coverage analysis, and detection priorities.
- Manage the intelligence cycle, including collection planning, intelligence production, and continuous feedback.
- Establish incident response practices through playbooks, severity models, exercises, significant-incident leadership, and blameless post-mortems.
- Design log and telemetry pipelines, including application telemetry from cloud-hosted services.
- Act as the technical interface for client security stakeholders and mentor L1/L2 analysts through pairing, coaching, and structured development.
Requirements
- Lead-level experience in detection engineering, SOC operations, threat hunting, and incident response.
- CISSP, CISM, CASP+, or equivalent senior cyber operations leadership credential; equivalent demonstrated capability may also be considered.
- Experience with KQL, SPL, EQL, or Sigma and MITRE ATT&CK coverage management.
- Experience designing log and telemetry pipelines, including application-level cloud telemetry; AWS experience is strongly preferred.
- Working knowledge of NCSC CAF Objective C, GovAssure, and OFFICIAL handling requirements.
- Eligibility for SC clearance requires five years of UK residency and a five-year employment history, or history back to full-time education.
Nice to have
- Familiarity with SOAR tooling and automated triage and enrichment workflows.
- Experience with Kanban-led operating models, WIP limits, triage queues, and class-of-service for incidents.
- Experience running skills-based technical assessments.
- AWS experience at this grade.
Culture & Benefits
- 30 days of paid annual leave.
- Flexible working hours and part-time remote working.
- Flexible parental leave.
- Flexible benefits platform with Smart Tech, Cycle to Work, healthcare cash plan, and pension options.
- Paid counselling plus financial and legal advice.
- Optional social and wellbeing events and support for professional cyber certification attainment.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
13 дней назад
Threat Analyst 1 (Cybersecurity)
56 000 - 93 000CAD
Writer
13 дней назад
Staff Detection and Response Engineer (AI Security)
146 000 - 240 000$
10 дней назад
Threat Analyst 2 (Cybersecurity)
10 дней назад
Incident Response Engineer 2 (Cybersecurity)
11 дней назад
Staff Security Engineer (Security Operations)
Runway
12 дней назад
Detection & Response Engineer (AI Security)
240 000 - 290 000$