Senior Security Operations Analyst
Full-time Mid-Senior LevelJob Overview
Join our Security Operations Centre as a Senior Security Operations Analyst, where you will play a leading role in strengthening our detection capability and responding to complex cyber security incidents. With a primary focus on detection engineering, you will translate threat intelligence, hunting outcomes and incident findings into effective, tested and maintainable detection content across our SOC technology platforms.
Your Opportunity
As a senior cyber security practitioner, you will own the end-to-end lifecycle of detection content and provide Level 3 technical support to the SOC. You will act as the final escalation point for complex and high-severity incidents, while mentoring analysts and supporting the continuous improvement of our security operations capability.
Your responsibilities will include:
Detection engineering
- Own the detection lifecycle, including requirements intake, research, development, testing, deployment, tuning and retirement.
- Develop and maintain detection content across SIEM and XDR platforms, including analytics rules, correlation logic and custom queries.
- Write and optimise advanced queries using technologies such as KQL in Microsoft Sentinel and Microsoft Defender XDR.
- Apply detection-as-code practices, including version control, peer review, change management and automated testing.
- Map detection coverage to the MITRE ATT&CK framework, identify gaps against prioritised threats and maintain a documented detection backlog.
- Validate detections through adversary emulation, purple team exercises and controlled test scenarios before deployment to production.
- Maintain clear documentation covering detection rationale, data dependencies, expected true-positive behaviour, triage guidance and response actions.
- Measure and report detection performance using metrics such as alert volumes, precision, false-positive rates and time to detect.
- Review, rewrite or retire detections that no longer provide value, including where platform, telemetry or environmental changes affect existing content.
Data, telemetry and platform enablement
- Assess log-source coverage and data quality, and define onboarding requirements for new telemetry sources.
- Develop and maintain parsers, data normalisation and schema alignment to support consistent and portable detection logic.
- Partner with security engineering and platform teams to address gaps in logging, retention and telemetry fidelity.
- Contribute to the configuration and optimisation of SIEM, SOAR and supporting SOC technologies, including ingestion cost management.
- Build and maintain automation, enrichment and SOAR playbooks to improve triage consistency and reduce manual effort.
Level 3 security operations support
- Act as the final technical escalation point for complex, ambiguous or high-severity incidents raised by Level 1 and Level 2 analysts.
- Lead deep technical analysis across endpoint, identity, network and cloud evidence sources during major incidents.
- Provide technical leadership across incident workstreams and support incident commanders with findings, timelines and containment options.
- Conduct post-incident reviews, identify detection and response gaps, and translate findings into improved detection content.
- Participate in escalation and on-call arrangements were required to support extended-hours coverage.
Threat intelligence and threat hunting
- Translate threat intelligence into prioritised detection requirements aligned with the firm’s threat profile.
- Conduct structured, hypothesis-driven threat hunts across SIEM, endpoint, identity and cloud telemetry.
- Convert threat-hunting findings into repeatable detection logic, automation and documented hunting queries.
- Monitor adversary tradecraft, vulnerabilities and emerging threats, assessing their relevance and detection implications.
Collaboration and continuous improvement
- Mentor and coach Level 1 and Level 2 analysts in investigation techniques, query development and detection engineering concepts.
- Peer review detection content created by other analysts and engineers, ensuring agreed quality standards are maintained.
- Improve SOC playbooks, triage guidance and response workflows associated with detection content.
- Work closely with internal technology teams and security specialists to deliver effective security outcomes.
- Support client and stakeholder engagements where the SOC provides managed or advisory security services.
How are you extraordinary?
- You are an analytical problem-solver who can navigate ambiguity, connect complex technical evidence and make sound decisions during high-pressure security incidents.
- You are a collaborative technical leader who builds trusted relationships, shares knowledge and supports others to strengthen their investigation and detection capabilities.
- You are a clear and influential communicator who can translate complex technical findings into concise guidance for analysts, incident leaders, stakeholders and clients.
Your Experience
To be successful in this role, you will bring:
- Demonstrated experience developing and maintaining detection content within SIEM or XDR platforms, including rule authoring, testing and tuning.
- Advanced capability in query languages such as KQL, SPL or equivalent, with experience writing and optimising complex queries.
- Practical knowledge of MITRE ATT&CK and experience assessing and improving detection coverage against prioritised threats.
- Senior-level experience in a Security Operations Centre or an equivalent operational cyber security environment.
- Proven experience leading the analysis of complex security incidents across endpoint, identity, network and cloud environments.
- Strong knowledge of enterprise and cloud log sources, telemetry, data quality and normalisation.
- A sound understanding of cyber security frameworks, standards and industry-leading practices.
- Strong written and verbal communication skills, including the ability to clearly document detection logic, investigation guidance and response actions.
The following experience will be highly regarded:
- Experience applying detection-as-code practices, including source control and CI/CD pipelines for security content.
- Scripting and automation capability using Python, PowerShell or SOAR playbook development.
- Experience conducting adversary emulation or purple team testing to validate detection coverage.
- Experience within professional services, consulting or a managed security services environment.
- A tertiary qualification in Cyber Security, Computer Science, Information Technology or another relevant technical discipline.
- Relevant industry certifications, such as SC-200, SC-300, AZ-500, CISSP, CompTIA Security+, ISC2 certifications or GIAC certifications including GCDA, GCIA, GCFA or GCTI.
- Advanced training in detection engineering, threat hunting or SIEM technologies, supported by an ongoing commitment to professional development.
Make Your Resume Now