×
Register Here to Apply for Jobs or Post Jobs. X

Remote L3 SOC Analyst - Microsoft XDR​/Defender​/Sentinel

Remote / Online - Candidates ideally in
Greater London, London, Greater London, W1B, England, UK
Listing for: Robert Walters UK
Contract, Remote/Work from Home position
Listed on 2026-02-18
Job specializations:
  • IT/Tech
    Cybersecurity, Security Manager
Salary/Wage Range or Industry Benchmark: 450 - 500 GBP Daily GBP 450.00 500.00 DAY
Job Description & How to Apply Below
Position: (Remote) L3 SOC Analyst - Microsoft XDR/ Defender/ Sentinel
Location: Greater London

Robert Walters Operations Limited is an employment business and welcomes applications from all candidates

What you'll do:
  • Lead and manage high‑severity security incidents from identification through containment, eradication, recovery, and post‑incident reporting
  • Perform advanced threat hunting using Microsoft Defender XDR, Sentinel, KQL, and other telemetry sources to identify emerging threats, anomalous behaviour, and undetected malicious activity
  • Develop, tune, and maintain Sentinel analytics rules, workbooks, playbooks (Logic Apps), and custom detection use cases to improve SOC detection capability
  • Act as a subject matter expert for the Microsoft security ecosystem, including Defender for Endpoint, Office 365, Identity, Cloud Apps, Defender for Cloud, and Azure security controls
  • Create and maintain Kusto Query Language (KQL) queries, automation workflows, and enrichment logic to enhance detections and investigation efficiency
  • Support purple‑team activities, threat modelling, and attack‑simulation scenarios aligned to MITRE ATT&CK
  • Provide technical escalation support and mentorship to L1/L2 SOC analysts
  • Perform root‑cause analysis, identify systemic issues, and drive continuous improvement across SOC processes.
  • Collaborate with engineering, cloud, and cybersecurity teams to enhance log ingestion, telemetry quality, and SIEM/SOAR architecture
  • Produce clear, structured incident reports, threat briefs, and stakeholder updates
What you'll bring:
  • Extensive hands‑on experience with Microsoft Sentinel (SIEM) and Microsoft Defender XDR (formerly M365 Defender)
  • Strong proficiency in KQL, analytic rule creation, hunting queries, custom detection engineering, and automation
  • Deep understanding of Windows, Azure AD / Entra , M365, network security, and cloud workloads
  • Advanced knowledge of attacker TTPs, threat intelligence sources, and MITRE ATT&CK mapping
  • Proven experience leading major incidents in an enterprise SOC environment
  • Strong understanding of SOAR automation and experience building Logic Apps‑based playbooks
  • Ability to interpret log data from diverse sources and build correlation logic that reduces false positives
  • Experience with Power Shell, Python, or tooling integration for enrichment and automation (are strong advantages)
  • Familiarity with EDR tuning, threat intelligence platforms, and cloud workload security (Azure/AWS/GCP)
  • Excellent analytical, documentation, and communication skills
About the job
  • Contract Type:
    Temporary
  • Focus:
    Information Security
  • Workplace Type:
    Remote
  • Experience Level: Associate
  • Location:

    London
  • Salary: £450 - £500 per day
  • Specialism:
    Technology & Digital
  • Industry: FMCG

Job Reference: 4

FVVPN-6

EEE1E0E

Date posted: 16 February 2026

#J-18808-Ljbffr
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary