Principal Security Analyst
Listed on 2026-06-16
-
IT/Tech
Cybersecurity, IT Support, Security Manager
Insight Enterprises is a Fortune 500 Solutions Integrator helping organizations accelerate transformation by unlocking the power of people and technology.
With a 35-year foundation in hardware and software supply chain augmenting our deep expertise in cloud, data, AI, cybersecurity, and intelligent edge, we guide organizations through complex digital decisions to achieve extraordinary results.
Job Title: Principal Security Analyst
Location: UK – Uxbridge, Manchester, or Sheffield.
On‑call: Yes – 7‑day on‑call rota every other week.
We are looking for a Principal Security Analyst to play a key leadership role in our multi‑client SOC. This is a senior, day‑shift position where you will take ownership of complex security incidents, lead our security engineering function, and work closely with clients across onboarding, BAU and occasional pre‑sales activities.
You will join a growing SOC team supporting 3–4 key clients, working primarily with the Microsoft Defender and Sentinel ecosystem, Tenable for vulnerability management, and Service Now for ticketing and workflows.
So, if this is of interest to you then we would be keen to hear from you!
*** This role we are offering is a Hybrid position; you will be expected to come into the office three times a week as part of your responsibilities. ***
Key responsibilities- Lead and support the SOC team
- Provide day‑to‑day leadership and technical guidance to Security & Senior Security Analysts.
- Function as an escalation point for complex incidents and investigations.
- Coach, mentor, and develop teammates to continually raise the bar.
- Own incident investigation & response:
- Respond to complex security incidents, performing deep‑dive investigations and root‑cause analysis.
- Ensure accurate, high‑quality incident documentation and post‑incident review.
- Collaborate with other security and operations teams to drive timely resolution and clear stakeholder updates.
- Tune and maintain security platforms (e.g., SIEM, IDS/IPS, firewalls) to improve detection, triage, and response.
- Develop and maintain security tools and technologies to enhance SOC capabilities.
- Create and refine security procedures, playbooks, and guidelines for consistent, effective response.
- Drive continuous improvement & new services:
- Continuously monitor and review our security posture and recommend improvements.
- Function as a key contributor to new SOC service offers, such as Threat & Vulnerability Management.
- Work closely with the Senior Security Operations Manager and Senior Analysts to shape the SOC technology roadmap and align with Insight’s growth strategy.
- Partner with clients & Service Delivery Managers:
- Collaborate directly with clients to understand their unique security needs and tailor services accordingly.
- Support client‑specific rule sets and mitigation advice.
- Be a key technical advisor to Service Delivery Managers, contributing to strong, long‑term client relationships.
- Function as a senior point of escalation for SOC analysts on complex or high‑severity incidents.
- Monitor, investigate, and respond to security alerts across:
- Tune and optimise detection rules, playbooks and use cases to reduce noise and improve detection quality.
- Support and mentor junior SOC analysts – reviewing cases, coaching on investigation techniques, and helping them grow.
- Work tickets and workflows in Service Now as part of incident and request handling.
- Engage directly with clients to explain findings, remediation steps, and risk in clear, non‑jargon language.
- Lead / contribute to weekly incident review and threat review meetings.
- Collaborate with clients and internal teams on onboarding activities (new log sources, new use cases, new environments).
- Collaborate with security engineering and platform teams on improvements to the SOC toolset and processes.
- Participate in the on‑call rota every other week, providing out‑of‑hours escalation support.
- Own and drive continuous improvement initiatives for the SOC (use‑case roadmap, automation, reporting).
- Support vulnerability management cycles using Tenable – reviewing scan results, prioritising vulnerabilities, and advising on remediation.
- Contribute to client‑facing reports, service reviews, and…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: