Senior SOC Analyst
Working Hours: The working hours are 0900-1730hrs Mon-Fri, and you would be expected to be working and contactable throughout those times. There is no scheduled out of hours work but may be required in emergency situations only.
- Monitor global customer environments for potential threats, vulnerabilities, and indicators of compromise.
- Perform advanced analysis and investigation of security alerts utilising Microsoft Sentinel, Microsoft Defender XDR and associated security platforms across the MXDR technology stack, including Splunk, CrowdStrike, SentinelOne and Carbon Black.
- Act as a senior incident responder and technical lead during high-priority security incidents.
- Provide incident remediation guidance, technical recommendations and preventative security advice to customers.
- Actively contribute to the triage and investigation queue, ensuring incidents are handled in accordance with service level agreements.
- Act as the primary escalation point for analysts during complex investigations and security incidents.
- Provide out-of-hours escalation support when required for customer incidents.
- Work closely with Automation Development (ADEV) teams to tune existing detections and develop new analytics and use cases.
- Identify detection gaps through investigations, threat hunting activities and customer feedback, proposing improvements to monitoring coverage.
- Contribute to the development and optimisation of detection content, automation workflows and response playbooks.
- Support customer onboarding and service transition activities, ensuring effective implementation of monitoring and detection capabilities.
- Act as a technical point of contact for customer escalations and service related security discussions.
- Serve as a Subject Matter Expert (SME) across the MXDR technology stack, providing technical leadership, guidance and support during investigations, service improvements and customer engagements.
- Conduct proactive threat hunting activities to identify malicious activity, validate detections and strengthen customer security posture.
- Provide technical mentoring and guidance to analysts, supporting capability development across the SOC.
- Contribute to the continual improvement of MXDR processes, procedures, documentation and service offerings.
- Perform other duties as assigned.
- Extensive experience investigating and responding to cyber security incidents within a MXDR SOC environment.
- Strong understanding of incident response methodologies, threat hunting techniques and attacker behaviours.
- Ability to lead technical investigations and coordinate response activities during major security incidents.
- Experience analysing endpoint, identity, cloud, email and network based threats.
- Advanced and practical knowledge of enterprise security monitoring technologies, including Microsoft Sentinel, Splunk, CrowdStrike, SentinelOne, Carbon Black and associated cloud security platforms used within the MXDR service.
- Strong understanding of security telemetry, log analysis, threat detection methodologies and investigation workflows across endpoint, identity, cloud, email, and network security domains.
- Experience developing and tuning detection logic, analytics, correlation rules and automated response capabilities across multiple security technologies.
- Ability to leverage platform specific query languages, hunting capabilities and investigation tools to identify threats, validate detections and support incident response activities.
- Experience tuning and improving security analytics to reduce false positives and improve detection fidelity.
- Ability to identify detection gaps and develop recommendations for enhanced monitoring coverage.
- Experience collaborating with engineering and development teams to deliver security use cases and automation solutions.
- Strong written and verbal communication skills with the ability to explain technical concepts to both technical and non technical audiences.
- Experience supporting customer facing investigations and escalations.
- Strong understanding of operating systems, networking fundamentals, authentication protocols and cloud technologies.
- Knowledge of MITRE ATT&CK, Cyber Kill Chain and common adversary behaviours.
- Experience working with SOAR, SIEM, EDR and threat intelligence platforms.
- Ability to act as a senior technical authority and escalation point within the MXDR team.
- Experience mentoring analysts and supporting technical development initiatives.
- Ability to work collaboratively across operations, engineering, onboarding and customer success teams.
- Flexible Working: Balance your work and personal life with our flexible working options.
- Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave.
- Medicash & Critical Illness Scheme
- Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme.
- Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities.
- Green Car Scheme: Drive green and save money with our eco-friendly car scheme.
- Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme.
- Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet.
- Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.