Senior Lead Security Operations Analyst - Companies House - G7

Manchester Digital

Manchester

Hybrid

GBP 90,000 - 130,000

Full time

7 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Companies House is seeking a Senior Lead Security Operations Analyst to shape and evolve our security monitoring and incident response capabilities. You will lead complex investigations, provide technical guidance, and drive improvements across Microsoft Sentinel, Defender and AWS environments.

You will balance hands-on monitoring with leadership responsibilities, mentoring analysts and coordinating across security, cloud and engineering teams to protect services and data.

Qualifications

  • Strong hands-on security operations experience.
  • Excellent analytical and investigative skills.
  • The technical knowledge to lead complex investigations and support the development of others.

Responsibilities

  • Lead security investigations and incident response, coordinating containment and remediation.
  • Provide technical leadership and mentoring to analysts.
  • Develop and tune security detections to improve monitoring coverage.
  • Oversee automation and response processes across Security Operations.
  • Coordinate with cloud/platform teams to investigate and respond to threats.

Skills

Security operations
Analytical skills
Investigations leadership
Technical leadership
Decision making under pressure

Tools

Microsoft Sentinel
Microsoft Defender
Amazon Web Services

Job description

Edinburgh Office Address

D0.33, Queen Elizabeth House, 1 Sibbald Walk, Edinburgh, EH8 8FT


Cardiff Office Address

Crown Way, Cardiff, CF14 3UZ


Edinburgh Office Address

D0.33, Queen Elizabeth House, 1 Sibbald Walk, Edinburgh, EH8 8FT


About The Job

Job summary


About The Role

We are looking for an experienced and technically skilled Senior Lead Security Operations Analyst to play a key role in the continued development of Security Operations at Companies House.


You will provide technical leadership within the Security Operations team, supporting analysts with complex investigations and helping to ensure security incidents are effectively identified, investigated, contained and escalated.


You will remain hands-on, using security monitoring and threat detection technologies including Microsoft Sentinel, Microsoft Defender and Amazon Web Services security tooling to investigate activity across our cloud and technology environments.


The role will also help drive improvements to our security monitoring capability, including developing and tuning detection rules, improving investigation and response processes, introducing automation and ensuring our monitoring continues to evolve alongside the threats facing Companies House.


We Are Looking For Someone With


  • Strong security operations experience

  • Excellent analytical and investigative skills

  • The technical knowledge to lead complex investigations and support the development of others.


You should be comfortable working with large volumes of security and log data, making evidence-based decisions and communicating technical security issues clearly to both technical and non-technical colleagues.


This is an opportunity to take a senior technical role within an evolving Security Operations capability and directly influence how Companies House detects, investigates and responds to cyber security threats.


Technical Frameworks

This role aligns with the Government Security Profession Secure Development Framework and the Government Digital and Data (GDaD) DevOps Engineer Capability Framework. Candidates may find these useful when preparing examples for their personal statement and demonstrating relevant technical skills and experience.



  • Government Security Profession: Secure Development Framework Secure Development - UK Government Security - Beta

  • Government Digital and Data Profession: DevOps Engineer Capability Framework https://ddat-capability-framework.service.gov.uk/role/development-operations-devops-engineer


Job Description

To be eligible for this role you also need to meet our Nationality requirements which are outlined below and also successful candidates must meet the security requirements for Security Clearance (SC) before they can be appointed. To gain (SC) clearance you will need to have been a UK resident for a minimum of 3 years out of the last 5 years. For more details, please refer to the ‘Things you need to know’ section below.


As the Senior Lead Security Operations Specialist, you will be a senior technical leader within the Companies House Security Operations team, helping to protect our services, systems and information from cyber security threats.


You will combine hands‑on technical expertise with leadership responsibility, leading complex security investigations, developing our monitoring and detection capabilities and providing technical guidance to the wider team. You will act as a senior escalation point and support the Head of Security Operations in developing the function.


You will be trusted to make operational security decisions, coordinate responses to significant incidents and engage with senior stakeholders when required.


Companies House operates across Microsoft Azure, Amazon Web Services and enterprise technology environments, with Microsoft Sentinel and Microsoft Defender forming key parts of our security monitoring and investigation capability.


Your Key Responsibilities Will Include


  • Leading security investigations and incident response – taking technical ownership of complex or high-impact incidents and coordinating investigation, containment, remediation and escalation.

  • Providing technical leadership – acting as a senior escalation point for analysts, providing guidance on complex investigations and supporting effective decision making.

  • Developing security monitoring and detection – creating, reviewing and tuning security detections to improve our ability to identify malicious and suspicious activity.

  • Managing and improving Microsoft Sentinel and Microsoft Defender – using and developing our security technologies to investigate threats, improve detection coverage and maintain effective monitoring.

  • Monitoring cloud environments – detecting and investigating security activity across Amazon Web Services and Microsoft Azure using cloud security services, logs and other security telemetry.

  • Improving automation and processes – identifying opportunities to automate Security Operations activities and improve monitoring, investigation and response workflows.

  • Developing incident response capability – improving investigation procedures, playbooks and escalation processes and supporting security exercises and readiness activities.

  • Developing the team – mentoring analysts, sharing technical knowledge and supporting the development of investigative and technical capability.

  • Supporting operational leadership – helping prioritise and coordinate Security Operations activity and providing operational leadership in the absence of the Head of Security Operations when required.

  • Working across Companies House – collaborating with security, cloud, platform, infrastructure and software engineering teams to investigate security issues and improve monitoring and response.

  • Advising senior stakeholders – communicating significant incidents, risks and technical findings clearly and providing evidence-based recommendations.

  • Driving continuous improvement – keeping pace with emerging threats and technologies and using lessons from incidents and operational activity to continually improve our security capability.


This is a hands‑on technical role with technical and operational leadership responsibility. You will remain actively involved in security monitoring, investigations, detection engineering and incident response while helping to develop the capability of the wider Security Operations team.


Companies House cannot offer Visa sponsorship to candidates through this campaign.


About The Team

The Security Operations team sits within the wider Security function at Companies House and is responsible for monitoring, detecting, investigating and responding to cyber security threats across our technology and cloud environments.


We are a collaborative and technically focused team made up of Security Operations analysts, senior specialists and threat intelligence capability, working closely with colleagues across security, cloud, platform and engineering teams as well as external security partners.


The team is continuing to develop and modernise its Security Operations capability, with a strong focus on Microsoft Sentinel and Microsoft Defender, alongside increasing security monitoring and response across Amazon Web Services. We are also investing in improved security telemetry, detection engineering, automation and threat intelligence to help us identify and respond to threats more effectively.


There is significant opportunity to influence how the capability develops. We encourage new ideas, continuous improvement and knowledge sharing, with team members given the opportunity to develop their technical skills, take ownership of meaningful work and contribute to the future direction of Security Operations at Companies House.


We have a supportive and collaborative culture where people are encouraged to challenge existing approaches, share knowledge and learn from each other. As a Senior Lead, you will play an important role in maintaining that culture and helping develop the technical capability of the wider team.


Where will you be working?

You will be aligned to either the Cardiff or Edinburgh office, where you will be expected to attend at least once a week. We are currently using a hybrid approach to the way we work which provides opportunities for you to be adaptable in the way you work so that you can achieve a healthy balance between your work and home life. Your manager will agree regular patterns of attendance with you; however, you may be required to make yourself available to attend the office more frequently when required to meet business needs.


Person specification

Whatwe’relooking For

The successful candidate will be an experienced cyber security professional with:



  • Strong hands‑on Security Operations expertise and the technical capability and judgement required to operate as a senior technical lead.

  • Significant hands‑on experience working within Security Operations, including investigating, triaging and responding to complex security alerts and incidents.

  • Strong practical experience using Microsoft Sentinel, including security monitoring, log analysis, incident investigation, developing and tuning detection rules, and improving monitoring coverage.

  • Strong experience working with Amazon Web Services, including investigating security activity using cloud security services and telemetry such as CloudTrail, GuardDuty and Identity and Access Management.

  • Experience leading complex security investigations, coordinating containment and remediation activities, and making risk‑based decisions during security incidents.

  • Experience developing and improving Security Operations capabilities, including monitoring processes, incident response procedures, playbooks and automation.

  • Advanced knowledge of Microsoft Sentinel, including Kusto Query Language, analytics rules, security investigations, log analysis and automation.

  • Strong knowledge of Amazon Web Services security, including cloud logging, identity and access management, threat detection and the investigation of activity across cloud environments.

  • Good working knowledge of Microsoft Defender security technologies and their use for threat detection, investigation and response.

  • Strong analytical and diagnostic skills, with the ability to correlate security information from multiple data sources, identify malicious or suspicious activity and determine appropriate response actions.

  • Practical knowledge of scripting and security automation using technologies such as PowerShell, Python, Terraform or equivalent tooling.

  • Strong understanding of cyber threats, attacker techniques and security monitoring principles, with knowledge of relevant frameworks and good practice such as MITRE ATT&CK and the National Cyber Security Centre Cyber Assessment Framework.

  • Leadership and Abilities Ability to provide technical leadership within Security Operations, lead complex investigations and provide authoritative guidance to analysts and other technical teams.

  • Ability to mentor and develop others while communicating complex security incidents, risks and recommendations clearly to technical, non‑technical and senior stakeholders

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Lead Security Operations Analyst- Cardiff & Edinburgh
Senior Lead Security Operations Analyst- Cardiff & Edinburgh

Companies House • Cardiff

On-site
GBP 90,000 - 110,000
Lead Security Analyst
Lead Security Analyst

Made Tech Limited • United Kingdom

On-site
GBP 90,000 - 120,000
3rd Line Security Analyst
3rd Line Security Analyst

Xact Placements Limited • Reading

On-site
GBP 51,000 - 69,000
Senior Security Analyst
Senior Security Analyst

Made Tech Limited • United Kingdom

On-site
GBP 60,000 - 80,000
Sponsorship for recognized cyber certifications
Support for achieving SC clearance
Senior Security Architect
Senior Security Architect

develop • Greater London

Hybrid
GBP 90,000 - 110,000
Up to £110,000 salary
Benefits package
Remote or hybrid working
Information & Cyber Security Specialist
Information & Cyber Security Specialist

Scotch Whisky • Cumbernauld

On-site
GBP 55,000 - 90,000
Private Healthcare
Doctor@Hand (remote GP)
Cycle to Work
+5
Security Engineer - Systems Integrator
Security Engineer - Systems Integrator

Hamilton Barnes Associates Limited • Greater London, Cardiff

Hybrid
GBP 41,000 - 50,000
Primarily remote work
Occasional office attendance (London /
Client-facing responsibilities
Senior Security Engineer - Contract
Senior Security Engineer - Contract

United States Digital Space LLC • Greater London

On-site
GBP 70,000 - 110,000
Senior Security Operations Lead - Cloud & Incident Response
Senior Security Operations Lead - Cloud & Incident Response

Manchester Digital • Manchester

Hybrid
GBP 90,000 - 130,000
SOC Lead
SOC Lead

SecurityHQ • Greater London

Hybrid
GBP 70,000 - 110,000