3rd Line Security Analyst

Xact Placements Limited

Reading

Hybrid

GBP 51,000 - 69,000

Full time

43 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Xact Placements Limited is recruiting a 3rd Line Security Analyst to join their Security Operations function in Reading. The role is senior and hands-on, owning the security platforms, detection content, and automation across client environments.

You will mentor the 2nd line team and serve as escalation for complex incidents. The role focuses on engineering and improving detection capabilities, implementing playbooks, and leading forensics and threat hunting activities within a hybrid

Qualifications

  • Senior technical level within a SOC/CSE/ security engineering function.
  • Experience administering Microsoft Sentinel, Defender XDR, CrowdStrike Falcon and related security tech.
  • Proven incident response, threat hunting, malware analysis and forensics experience.

Responsibilities

  • Lead end-to-end management of complex and high-severity security incidents.
  • Conduct digital forensic investigations across cloud, identity, endpoint and network platforms.
  • Design, implement and optimise detection content across security platforms with advanced queries.
  • Act as senior technical owner for security platforms and on-call containment during incidents.
  • Design and maintain automation workflows to reduce manual effort.
  • Conduct proactive threat hunting and translate findings into detections and recommendations.
  • Monitor and respond to events across Microsoft 365, Azure, AWS and hybrid environments.
  • Support ISO 27001 and Cyber Essentials compliance with runbooks and SOPs.
  • Provide technical leadership and mentoring to junior analysts.

Skills

SOC experience
Microsoft Sentinel
Defender XDR
CrowdStrike Falcon
KQL
PowerShell
Python
Automation
Threat Hunting
Incident Response

Tools

Logic Apps
Sentinel Playbooks
Power Automate
PowerShell
Python

Job description

3rd Line Security Analyst

My client, a well-established organisation within the ICT Services sector, are looking to recruit an experienced 3rd Line Security Analyst to join their Security Operations function.This is a senior, hands-on technical role rather than a queue-driven analyst position. The successful candidate will take ownership of the engineering, administration, health and continuous improvement of the security platforms, detection content and automation that underpin threat monitoring, detection and incident response across my client's internal and managed customer environments. They will act as the final internal escalation point for complex and high-severity security incidents, the technical design authority for detection and automation content, and a mentor who raises the technical capability of the wider 2nd line team.Reporting to the Security Operations Manager, this role sits within ICT Services and carries genuine scope and technical authority, including sign-off on detection content, SOAR playbooks and hunting queries, named administrative ownership of key security platforms, and the authority to take immediate containment action during live incidents.

Key Responsibilities
  • Lead the end-to-end management of complex and high-severity security incidents, including investigation, containment, eradication, recovery and post-incident review.
  • Conduct digital forensic investigations across cloud, identity, endpoint and network platforms, and carry out malware analysis and threat validation.
  • Design, implement and optimise detection content across Microsoft Sentinel, Defender XDR, CrowdStrike and associated platforms, developing advanced KQL queries and analytics rules aligned to MITRE ATT&CK.
  • Act as senior technical owner for security platforms including Microsoft Sentinel, Defender XDR, CrowdStrike Falcon, Entra ID, Intune, Darktrace and supporting technologies, managing platform health, onboarding and configuration.
  • Design and maintain automation and orchestration workflows using Logic Apps, Sentinel Playbooks, Power Automate, PowerShell, Python and API integrations to reduce manual operational effort.
  • Conduct proactive, intelligence-led and hypothesis-driven threat hunting, translating findings into detections, hunts and customer recommendations.
  • Monitor, investigate and respond to security events across Microsoft 365, Azure, AWS and hybrid environments.
  • Support compliance activities relating to ISO 27001 and Cyber Essentials, maintaining technical documentation, runbooks and standard operating procedures.
  • Provide technical leadership, mentoring and knowledge transfer to Security Analysts and Service Desk teams.
What My Client Is Looking For
  • Significant experience within a Security Operations Centre (SOC), Cyber Security Operations or Security Engineering function, including at a senior technical level.
  • Strong hands-on experience administering and engineering Microsoft Sentinel, Microsoft Defender XDR, CrowdStrike Falcon and associated security technologies.
  • Proven experience in incident response, threat hunting, malware analysis, digital forensics and security investigations.
  • Advanced KQL skills, with the ability to develop and optimise complex detections and threat hunting queries.
  • Strong scripting and automation experience using PowerShell and/or Python, including API integrations and workflow automation.
  • Experience administering Microsoft Entra ID, Conditional Access, Intune and Microsoft 365 security solutions.
  • Good understanding of Azure, AWS and hybrid infrastructure security, with strong knowledge of networking, operating systems and attacker techniques.
  • Practical understanding of MITRE ATT&CK, Cyber Kill Chain, NIST and SANS incident response frameworks.
  • Experience working within regulated and audited environments, including ISO 27001 and Cyber Essentials.
  • Excellent communication, stakeholder management and documentation skills, with the ability to engage effectively across technical and non-technical audiences.
Desirable
  • CISSP (Certified Information Systems Security Professional) certification.
  • Experience designing or improving SOC operating models, detection strategies, or security platforms at scale.
  • Exposure to security architecture or security engineering activities beyond day-to-day SOC operations.
  • Experience contributing to or leading continuous improvement initiatives, automation strategy, or security service maturity.
Additional Requirements
  • Ability to prioritise work under pressure and meet strict deadlines.
  • Excellent written and verbal communication skills.
  • Candidates must be able to pass security vetting (BS7858).

Salary: £60,000 | Location: Reading / hybrid 2 days from home

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

2nd/3rd Line Security Analyst
2nd/3rd Line Security Analyst

Xact Placements Limited • Reading

Hybrid
GBP 50,000 - 60,000
Hybrid work arrangement
Competitive salary
Senior Security Analyst
Senior Security Analyst

Xact Placements Limited • Reading

Hybrid
GBP 50,000 - 60,000
Level 1 SOC Analyst - MSP
Level 1 SOC Analyst - MSP

Hamilton Barnes Associates Limited • West Yorkshire

On-site
GBP 29,250 - 35,750
Career progression pathways
Hands-on experience with industry-leading security tools
Mentorship from experienced analysts
+2
Senior Security Analyst
Senior Security Analyst

Spencer Rose • Greater London

Hybrid
GBP 70,000 - 90,000
Senior Security Architect
Senior Security Architect

develop • Greater London

Hybrid
GBP 90,000 - 110,000
Up to £110,000 salary
Benefits package
Remote or hybrid working
Security Operations Engineer
Security Operations Engineer

Context Recruitment • Greater London

On-site
GBP 68,000 - 83,000
Senior SOC Analyst
Senior SOC Analyst

Jobtailor • Manchester

On-site
GBP 50,000 - 55,000
Senior SOC Engineer
Senior SOC Engineer

Experis • Greater London

On-site
GBP 90,000 - 120,000
Senior SOC Specialist
Senior SOC Specialist

Morson Talent • Crawley

Hybrid
GBP 65,000 - 80,000
Security Engineer
Security Engineer

IntaPeople: STEM Recruitment • Cardiff

Hybrid
GBP 55,000 - 85,000
Hybrid working
Training & certifications
Exposure to client environments
+2