Senior SOC Incident Lead & Detection Engineer

Xact Placements Limited

Reading

Hybrid

GBP 50,000 - 60,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid work arrangement
Competitive salary

Job summary

Xact Placements Limited is recruiting a 2nd/3rd Line Security Analyst in Reading. This hybrid role centers on hands-on incident response, detection engineering and automation within the SOC.

You will own end-to-end incidents and provide senior technical depth across multiple toolchains. Key duties include designing SIEM detections aligned to MITRE ATT&CK, mentoring analysts, and driving improvements in detections and playbooks while working with Sentinel, Defender XDR, CrowdStrike, Entra

Qualifications

  • Proven ownership of complex security incidents from triage through closure.
  • Hands-on experience writing and tuning SIEM detection logic and understanding MITRE ATT&CK.
  • Practical scripting/automation experience (Python, REST APIs) or hands-on SOAR configuration.

Responsibilities

  • Own complex security incidents end-to-end from alert validation through containment and closure.
  • Act as senior escalation point when investigations stall, reviewing prior work and coaching analysts.
  • Investigate identity and cloud-based compromise including anomalous sign-ins and OAuth issues.
  • Design, build and test SIEM detection rules mapped to MITRE ATT&CK and tune false positives.
  • Build automation for SOC processes using Python, Logic Apps, APIs or SOAR.
  • Correlate evidence across SIEM, endpoint, identity and cloud platforms to scope blast radius.
  • Run hypothesis-led threat hunts and mentor junior analysts to improve detections.

Skills

SIEM tuning
MITRE ATT&CK
KQL
Threat hunting
Python scripting
SOAR platforms
Incident response

Tools

Microsoft Sentinel
Defender XDR
CrowdStrike
Entra ID/Azure AD
Microsoft 365
AWS security tooling

Job description

Xact Placements Limited is recruiting a 2nd/3rd Line Security Analyst in Reading. This hybrid role centers on hands-on incident response, detection engineering and automation within the SOC.

You will own end-to-end incidents and provide senior technical depth across multiple toolchains. Key duties include designing SIEM detections aligned to MITRE ATT&CK, mentoring analysts, and driving improvements in detections and playbooks while working with Sentinel, Defender XDR, CrowdStrike, Entra

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Analyst: Threat Hunting & Incident Response
Senior Security Analyst: Threat Hunting & Incident Response

Xact Placements Limited • Reading

Hybrid
GBP 50,000 - 60,000
Senior 3rd Line Security Analyst - Hybrid (2 days WFH)
Senior 3rd Line Security Analyst - Hybrid (2 days WFH)

Xact Placements Limited • Reading

Hybrid
GBP 51,000 - 69,000
2nd/3rd Line Security Analyst
2nd/3rd Line Security Analyst

Xact Placements Limited • Reading

Hybrid
GBP 50,000 - 60,000
Hybrid work arrangement
Competitive salary
Senior SOC Investigator & Detection Lead
Senior SOC Investigator & Detection Lead

Redline Group Ltd • Aylesbury

Hybrid
GBP 50,000 - 70,000
Senior Security Analyst
Senior Security Analyst

Xact Placements Limited • Reading

Hybrid
GBP 50,000 - 60,000
3rd Line Security Analyst
3rd Line Security Analyst

Xact Placements Limited • Reading

Hybrid
GBP 51,000 - 69,000
Senior SOC Engineer: Lead Threat Detection & Incident Response
Senior SOC Engineer: Lead Threat Detection & Incident Response

MTI • Greater London

On-site
GBP 60,000 - 80,000
Security Operations Center Analyst
Security Operations Center Analyst

Queen Square • Reading

Hybrid
GBP 101,000 - 138,000
Senior SOC Analyst
Senior SOC Analyst

Jobtailor • Manchester

On-site
GBP 50,000 - 55,000
Lead SOC Analyst - Incident Response & Threat Analysis
Lead SOC Analyst - Incident Response & Threat Analysis

Anson McCade • Greater London

On-site
GBP 70,000 - 100,000