×
Register Here to Apply for Jobs or Post Jobs. X

2nd​/3rd Line Security Analyst

Job in Reading, Berkshire, RG1, England, UK
Listing for: Xact Placements Limited
Full Time position
Listed on 2026-08-14
Job specializations:
  • IT/Tech
    Security Management & Operations, Cybersecurity
Salary/Wage Range or Industry Benchmark: 50000 - 60000 GBP Yearly GBP 50000.00 60000.00 YEAR
Job Description & How to Apply Below

2nd / 3rd Line Security Analyst

Location: Reading (Hybrid)

Salary: £50,000 – £60,000

Our client is looking for a 2nd/3rd Line Security Analyst to join their Security Operations Centre as a senior technical escalation point. This is a genuinely hands‑on role - ideal for someone who wants to keep working close to the tooling and the day-to-day operational workload rather than move straight into a purely managerial or architectural position. You'll own complex incidents end-to-end, drive detection engineering and automation, and provide senior technical depth across the SOC.

Duties

of the Role
  • Own complex security incidents end-to-end - from alert validation through investigation, containment and closure
  • Act as the senior escalation point when earlier-stage investigations stall, reviewing prior work and coaching the original analyst
  • Investigate identity and cloud-based compromise (e.g. anomalous sign-ins, malicious OAuth consent, mailbox access), including session/token revocation
  • Design, build and test SIEM detection rules mapped to MITRE ATT&CK, and tune out false positives without blanket whitelisting
  • Build automation for SOC processes - enrichment, ticketing, containment - using Python, Logic Apps, APIs or a SOAR platform
  • Correlate evidence across SIEM, endpoint, identity and cloud platforms (Sentinel, Defender XDR, Crowd Strike, Entra , Microsoft 365, AWS) to scope the full blast radius of an incident
  • Run hypothesis-led threat hunts, not just reactive alert triage
  • Mentor junior analysts and help drive measurable improvements to SOC detections, playbooks and workflow
What we're looking for
  • Proven, personal ownership of complex security incidents from triage through to closure
  • Hands‑on experience writing and tuning SIEM detection logic, with a solid understanding of MITRE ATT&CK and KQL (or equivalent)
  • Practical scripting/automation experience (Python, Logic Apps, REST APIs) or hands‑on SOAR platform configuration
  • Working knowledge of several of:
    Microsoft Sentinel, Defender XDR, Crowd Strike, Microsoft Entra /Azure AD, Microsoft 365, AWS security tooling
  • Experience investigating identity and cloud-based compromise, including OAuth consent abuse and Conditional Access/MFA
  • A track record of proactive, hypothesis‑driven threat hunting
  • Strong investigative writing skills, with the ability to explain technical findings to non-technical stakeholders
  • Comfortable acting as a technical escalation point, including reviewing and correcting the work of other analysts constructively
Nice to have
  • Security certifications (e.g. SC-200, GCIH, GCFA, CySA+ or equivalent)
  • Experience mentoring or formally training junior SOC analysts
  • Exposure to non‑Microsoft cloud, EDR or SIEM tooling
  • Familiarity with SOAR platforms beyond Logic Apps (e.g. Sentinel Automation, Tines, Cortex XSOAR)
#J-18808-Ljbffr
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary