Lead Security Analyst

Made Tech Limited

Bristol

On-site

GBP 65,000 - 80,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

30 days Holiday
Flexible Working Hours
Remote Working – part-time
Paid counselling
Smart Tech scheme
Cycle to work scheme
Benefits allowance
Wellbeing events

Job summary

Made Tech Limited is seeking a Lead Security Analyst to shape threat detection, incident response, and client-facing security leadership. You will own the SOC’s detection content, drive the threat-landscape narrative, and mentor analysts in a high-impact government-aligned cyber practice.

You will align work to NCSC guidance and CAF frameworks, coordinating with cross-government communities and ensuring rigorous, scalable security operations across UK clients.

Qualifications

  • Experience leading detection engineering in a SOC or similar environment, including writing and tuning detections in KQL, SPL, EQL, or Sigma, and mapping to MITRE ATT&CK.

Responsibilities

  • Set the detection engineering standard: author, tune, and peer-review detections; manage false-positives; map coverage to MITRE ATT&CK; train L1/L2 analysts.

Skills

CISSP
CISM
CASP+
SOC leadership
Threat hunting
Detection engineering
KQL
SPL
EQL
Sigma
MITRE ATT&CK
Incident response
Mentoring

Tools

KQL
SPL
EQL
Sigma
MITRE ATT&CK

Job description

Lead Security Analyst

Department: Technology

Employment Type: Permanent

Location: Any UK Office Hub (Bristol / London / Manchester / Swansea)

Compensation: GBP 65,000 - GBP 80,000 / year

Description

Made Tech helps UK public sector organisations build and run better digital services. Our Cyber practice sits at the heart of that mission – working alongside government departments, agencies, and critical national infrastructure owners to improve how they detect, respond to, and learn from cyber threats. As a Lead Security Analyst, you will be the most senior analyst on your engagement, setting the technical direction for the SOC and owning the quality of what the team produces – from detection engineering to threat‑hunting to incident response.

This isn’t a role where you disappear into a ticket queue. You will shape the threat‑landscape narrative for your engagement, drive the detection backlog, and build the capability of the analysts around you. That means pairing on complex investigations, setting tradecraft standards, and ensuring the team's detection content is version‑controlled, peer‑reviewed, and continuously improved – not left to age in a SIEM. You will also be the trusted technical interface for client security stakeholders, translating what the SOC is seeing into the language that informs decisions.

The UK public sector context matters here. You will align your work to NCSC guidance, the Cyber Assessment Framework, and OFFICIAL handling requirements – not because compliance is the goal, but because those frameworks reflect the real risk environment your clients operate in. You will engage with cross‑government security communities, feed detection content and runbooks back into the Cyber practice, and help grow a bench of analysts who can operate at the same standard.

Key Responsibilities
  • Set the detection engineering standard: author, tune, and peer‑review detections in KQL, SPL, EQL, or Sigma; manage the false‑positive backlog; map coverage to MITRE ATT‑CK; and train L1/L2 analysts to write and tune detections themselves.
  • Own the threat‑landscape narrative for your engagement: turn intelligence from NCSC advisories, sector feeds, and threat actor reporting into hunt themes, coverage gap analysis, and detection priorities that the SOC and client stakeholders can act on.
  • Run the intelligence cycle as a managed discipline: maintain a collection plan, produce timely and rigorous intelligence products, and build feedback loops that keep the cycle honest and improving.
  • Establish and lead security incident response practice: build playbooks, define the severity model, run exercises, and lead the team's response to significant incidents; run blameless post‑mortems that the team actually learns from.
  • Design the log and telemetry pipeline that detections run on: include bespoke application telemetry in cloud environments, not just commodity endpoint feeds; ensure the right signals are collected, parsed, and retained for both detection and investigation.
  • Be the trusted technical interface for client security stakeholders: communicate what the SOC is detecting, investigating, and covering without losing fidelity; surface risks early and honestly, and align the team's priorities to the client's risk picture.
  • Grow the analysts around you: pair on detection authorship and incident response as a default, set pairing as the team norm, and actively build the capability of L1 and L2 analysts through structured mentoring and coaching so knowledge isn’t concentrated in one person.
  • Contribute to the Cyber practice beyond your engagement: feed detection content, runbooks, and lessons learned back into shared practice resources; contribute to analyst assessment and hiring; and engage with public‑sector security communities including NCSC CISP and relevant ISACs.
Skills, Knowledge & Expertise
  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Security Manager (CISM)
  • CompTIA Advanced Security Practitioner (CASP+)
  • Experience leading detection engineering in a SOC or similar environment – including writing and tuning detections in KQL, SPL, EQL, or Sigma, and managing coverage against MITRE ATT‑CK
  • Experience designing or improving a log and telemetry pipeline, including application‑level telemetry from cloud‑hosted services (AWS is a strong preference at this grade), with an understanding of how to design monitoring for failure modes and degraded states
  • Evidence of running the intelligence cycle as a managed discipline – collection planning, production, and feedback – rather than consuming finished intelligence
  • Working knowledge of UK government security standards and frameworks, including NCSC CAF Objective C, GovAssure, and OFFICIAL handling requirements
  • Experience establishing incident response practice – playbooks, severity models, and exercises – not just responding to individual incidents
  • Evidence of growing the technical capability of less‑experienced analysts through pairing, structured mentoring, or coaching, including setting clear goals and tracking progress over time
  • Experience anchoring delivery on client outcomes rather than task completion – challenging the brief where it serves the client and making value visible rather than reporting effort
  • Evidence of contributing reusable assets – detection playbooks, runbooks, templates, or accelerators – back into a practice or community, rather than leaving knowledge within a single team
Tools and Practices
  • Familiarity with SOAR tooling and automation of triage and enrichment workflows
  • Experience working in Kanban‑led operating models, including managing triage queues, WIP limits, and class‑of‑service for incidents
  • Experience running or contributing to skills‑based technical assessments that evaluate demonstrated capability rather than credentials or years of experience
Job Benefits
  • 30 days Holiday – we offer 30 days of paid annual leave
  • Flexible Working Hours – we are flexible with what hours you work
  • Flexible Parental Leave – we offer flexible parental leave options
  • Remote Working – we offer part‑time remote working for all our staff
  • Paid counselling – we offer paid counselling as well as financial and legal advice
  • Smart Tech scheme, Cycle to work scheme, and an individual benefits allowance which you can invest in a Health care cash plan or Pension plan
  • Optional social and wellbeing calendar of events for all employees
Eligibility

SC Eligibility: An increasing number of our customers are specifying a minimum of SC (security check) clearance in order to work on their projects. As a result, we’re looking for all successful candidates for this role to have eligibility. Eligibility for SC requires 5 years’ UK residency and 5 year’ employment history (or back to full‑time education). Please note that if at any point during the interview process it is apparent that you may not be eligible for SC, we won’t be able to progress your application and we will contact you to let you know why.

Equal Opportunity

We believe we can use tech to make public services better. We also believe this can happen best when our own team represents the society that actually uses the services we work on. We're collectively continuing to grow a culture that is happy, healthy, safe and inspiring for people of all backgrounds and experiences, so we encourage people from underrepresented groups to apply for roles with us. We also welcome any feedback on how we can improve the experience for future candidates.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Security Analyst
Lead Security Analyst

Made Tech Limited • United Kingdom

On-site
GBP 90,000 - 120,000
Lead Security Engineer
Lead Security Engineer

Made Tech Limited • Bristol

On-site
GBP 75,000 - 90,000
30 days Holiday
Flexible Working Hours
Flexible Parental Leave
+2
Senior Security Analyst
Senior Security Analyst

Made Tech Limited • United Kingdom

On-site
GBP 60,000 - 80,000
Sponsorship for recognized cyber certifications
Support for achieving SC clearance
Senior Security Engineer
Senior Security Engineer

Made Tech Limited • Bristol

On-site
GBP 55,000 - 75,000
30 days Holiday
Flexible Working Hours
Flexible Parental Leave
+2
Senior Security Analyst
Senior Security Analyst

Made Tech Limited • West of England

On-site
GBP 50,000 - 60,000
Lead Security Engineer
Lead Security Engineer

Made Tech • Manchester

Hybrid
GBP 60,000 - 80,000
30 days of paid annual leave
Flexible working hours
Remote working options
+1
Senior Security Engineer
Senior Security Engineer

Made Tech Limited • Manchester

Hybrid
GBP 90,000 - 120,000
30 days Holiday
Flexible Working Hours
Remote Working
+1
Senior SOC Analyst
Senior SOC Analyst

Sopra Steria Ltd • Farnborough

On-site
GBP 52,200 - 63,800
25 days annual leave
Health cash plan
Life assurance
+2
Cyber Security Analyst/Lead
Cyber Security Analyst/Lead

Chambers & Partners • Greater London

Hybrid
GBP 90,000 - 130,000
Senior SOC Analyst - Manchester
Senior SOC Analyst - Manchester

BAE Systems Digital Intelligence • Manchester

Hybrid
GBP 60,000 - 90,000
£5,000 referral bonus
Hybrid working