Назад
Company hidden
обновлено 1 месяц назад

Lead Security Analyst (Cybersecurity)

65 000 - 80 000GBP
Формат работы
hybrid
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
UK
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Lead Security Analyst (Cybersecurity): Setting the technical direction for SOC engagements and building detection, threat intelligence, telemetry, and incident response capabilities with an accent on KQL, SPL, EQL, Sigma, MITRE ATT&CK, and UK government security frameworks. Focus on designing detection and telemetry pipelines, leading complex investigations and significant incident responses, developing L1/L2 analysts, and translating SOC findings into client security decisions.

Location: Any UK Office Hub: Bristol, London, Manchester, or Swansea; part-time remote working is available

Salary: £65,000–£80,000 per year

Company

hirify.global helps UK public sector organisations build and run digital services, including cybersecurity services for government departments, agencies, and critical national infrastructure.

What you will do

  • Set the technical direction and detection engineering standards for SOC engagements, authoring, tuning, and peer-reviewing detections in KQL, SPL, EQL, or Sigma.
  • Own the threat-landscape narrative by turning NCSC advisories, sector feeds, and threat actor reporting into hunt themes, coverage analysis, and detection priorities.
  • Manage the intelligence cycle, including collection planning, intelligence production, and continuous feedback.
  • Establish incident response practices through playbooks, severity models, exercises, significant-incident leadership, and blameless post-mortems.
  • Design log and telemetry pipelines, including application telemetry from cloud-hosted services.
  • Act as the technical interface for client security stakeholders and mentor L1/L2 analysts through pairing, coaching, and structured development.

Requirements

  • Lead-level experience in detection engineering, SOC operations, threat hunting, and incident response.
  • CISSP, CISM, CASP+, or equivalent senior cyber operations leadership credential; equivalent demonstrated capability may also be considered.
  • Experience with KQL, SPL, EQL, or Sigma and MITRE ATT&CK coverage management.
  • Experience designing log and telemetry pipelines, including application-level cloud telemetry; AWS experience is strongly preferred.
  • Working knowledge of NCSC CAF Objective C, GovAssure, and OFFICIAL handling requirements.
  • Eligibility for SC clearance requires five years of UK residency and a five-year employment history, or history back to full-time education.

Nice to have

  • Familiarity with SOAR tooling and automated triage and enrichment workflows.
  • Experience with Kanban-led operating models, WIP limits, triage queues, and class-of-service for incidents.
  • Experience running skills-based technical assessments.
  • AWS experience at this grade.

Culture & Benefits

  • 30 days of paid annual leave.
  • Flexible working hours and part-time remote working.
  • Flexible parental leave.
  • Flexible benefits platform with Smart Tech, Cycle to Work, healthcare cash plan, and pension options.
  • Paid counselling plus financial and legal advice.
  • Optional social and wellbeing events and support for professional cyber certification attainment.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →