2nd/3rd Line Security Analyst

Xact Placements Limited

Reading

On-site

GBP 50,000 - 60,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid work arrangement
Competitive salary

Job summary

Xact Placements Limited is recruiting a 2nd/3rd Line Security Analyst in Reading. This hybrid role centers on hands-on incident response, detection engineering and automation within the SOC.

You will own end-to-end incidents and provide senior technical depth across multiple toolchains. Key duties include designing SIEM detections aligned to MITRE ATT&CK, mentoring analysts, and driving improvements in detections and playbooks while working with Sentinel, Defender XDR, CrowdStrike, Entra

Qualifications

  • Proven ownership of complex security incidents from triage through closure.
  • Hands-on experience writing and tuning SIEM detection logic and understanding MITRE ATT&CK.
  • Practical scripting/automation experience (Python, REST APIs) or hands-on SOAR configuration.

Responsibilities

  • Own complex security incidents end-to-end from alert validation through containment and closure.
  • Act as senior escalation point when investigations stall, reviewing prior work and coaching analysts.
  • Investigate identity and cloud-based compromise including anomalous sign-ins and OAuth issues.
  • Design, build and test SIEM detection rules mapped to MITRE ATT&CK and tune false positives.
  • Build automation for SOC processes using Python, Logic Apps, APIs or SOAR.
  • Correlate evidence across SIEM, endpoint, identity and cloud platforms to scope blast radius.
  • Run hypothesis-led threat hunts and mentor junior analysts to improve detections.

Skills

SIEM tuning
MITRE ATT&CK
KQL
Threat hunting
Python scripting
SOAR platforms
Incident response

Tools

Microsoft Sentinel
Defender XDR
CrowdStrike
Entra ID/Azure AD
Microsoft 365
AWS security tooling

Job description

2nd / 3rd Line Security Analyst

Location: Reading (Hybrid)

Salary: £50,000 – £60,000

Our client is looking for a 2nd/3rd Line Security Analyst to join their Security Operations Centre as a senior technical escalation point. This is a genuinely hands‑on role - ideal for someone who wants to keep working close to the tooling and the day-to-day operational workload rather than move straight into a purely managerial or architectural position. You'll own complex incidents end-to-end, drive detection engineering and automation, and provide senior technical depth across the SOC.

Duties of the Role
  • Own complex security incidents end-to-end - from alert validation through investigation, containment and closure
  • Act as the senior escalation point when earlier-stage investigations stall, reviewing prior work and coaching the original analyst
  • Investigate identity and cloud-based compromise (e.g. anomalous sign-ins, malicious OAuth consent, mailbox access), including session/token revocation
  • Design, build and test SIEM detection rules mapped to MITRE ATT&CK, and tune out false positives without blanket whitelisting
  • Build automation for SOC processes - enrichment, ticketing, containment - using Python, Logic Apps, APIs or a SOAR platform
  • Correlate evidence across SIEM, endpoint, identity and cloud platforms (Sentinel, Defender XDR, CrowdStrike, Entra ID, Microsoft 365, AWS) to scope the full blast radius of an incident
  • Run hypothesis-led threat hunts, not just reactive alert triage
  • Mentor junior analysts and help drive measurable improvements to SOC detections, playbooks and workflow
What we're looking for
  • Proven, personal ownership of complex security incidents from triage through to closure
  • Hands‑on experience writing and tuning SIEM detection logic, with a solid understanding of MITRE ATT&CK and KQL (or equivalent)
  • Practical scripting/automation experience (Python, Logic Apps, REST APIs) or hands‑on SOAR platform configuration
  • Working knowledge of several of: Microsoft Sentinel, Defender XDR, CrowdStrike, Microsoft Entra ID/Azure AD, Microsoft 365, AWS security tooling
  • Experience investigating identity and cloud-based compromise, including OAuth consent abuse and Conditional Access/MFA
  • A track record of proactive, hypothesis‑driven threat hunting
  • Strong investigative writing skills, with the ability to explain technical findings to non-technical stakeholders
  • Comfortable acting as a technical escalation point, including reviewing and correcting the work of other analysts constructively
Nice to have
  • Security certifications (e.g. SC-200, GCIH, GCFA, CySA+ or equivalent)
  • Experience mentoring or formally training junior SOC analysts
  • Exposure to non‑Microsoft cloud, EDR or SIEM tooling
  • Familiarity with SOAR platforms beyond Logic Apps (e.g. Sentinel Automation, Tines, Cortex XSOAR)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Analyst
Senior Security Analyst

Xact Placements Limited • Reading

Hybrid
GBP 50,000 - 60,000
Senior SOC Analyst
Senior SOC Analyst

Jobtailor • Manchester

On-site
GBP 50,000 - 55,000
L3 SOC Analyst
L3 SOC Analyst

Saviynt • United Kingdom

On-site
GBP 60,000 - 80,000
Level 1 SOC Analyst - MSP
Level 1 SOC Analyst - MSP

Hamilton Barnes Associates Limited • West Yorkshire

On-site
GBP 29,250 - 35,750
Career progression pathways
Hands-on experience with industry-leading security tools
Mentorship from experienced analysts
+2
Security Operations Center Analyst
Security Operations Center Analyst

Frontier Resourcing • Milton Keynes

On-site
GBP 55,000 - 75,000
Senior SOC Specialist
Senior SOC Specialist

Morson Talent • Crawley

Hybrid
GBP 65,000 - 80,000
Lead SOC Analyst
Lead SOC Analyst

Anson McCade • Greater London

On-site
GBP 70,000 - 100,000
SOC Engineer
SOC Engineer

Proactive.IT Appointments Ltd. • Milton Keynes

On-site
GBP 55,000 - 85,000
Security clearance sponsorship
Exposure to diverse customer envs
SOC Team Lead
SOC Team Lead

Fynity • Aylesbury

On-site
GBP 60,000 - 90,000
Senior SOC Analyst
Senior SOC Analyst

InfoSec People Ltd • England

Hybrid
GBP 69,000 - 82,000
Annual performance bonus
Hybrid working model
Clear progression opportunities