2nd/3rd Line Security Analyst - Reading

Xact Placements Limited
Reading, United Kingdom
Today
£50,000 – £60,000 pa

Salary

£50,000 – £60,000 pa

Job Type
Permanent
Work Pattern
Full-time
Work Location
Hybrid
Seniority
Senior
Security Clearance
Required
Posted
10 Aug 2026 (Today)

2nd / 3rd Line Security Analyst

Location:Reading (Hybrid)

Salary:£50,000 – £60,000

Our client is looking for a 2nd/3rd Line Security Analyst to join their Security Operations Centre as a senior technical escalation point. This is a genuinely hands-on role - ideal for someone who wants to keep working close to the tooling and the day-to-day operational workload rather than move straight into a purely managerial or architectural position. You'll own complex incidents end-to-end, drive detection engineering and automation, and provide senior technical depth across the SOC.

Duties of the Role

  • Own complex security incidents end-to-end - from alert validation through investigation, containment and closure
  • Act as the senior escalation point when earlier-stage investigations stall, reviewing prior work and coaching the original analyst
  • Investigate identity and cloud-based compromise (e.g. anomalous sign-ins, malicious OAuth consent, mailbox access), including session/token revocation
  • Design, build and test SIEM detection rules mapped to MITRE ATT&CK, and tune out false positives without blanket whitelisting
  • Build automation for SOC processes - enrichment, ticketing, containment - using Python, Logic Apps, APIs or a SOAR platform
  • Correlate evidence across SIEM, endpoint, identity and cloud platforms (Sentinel, Defender XDR, CrowdStrike, Entra ID, Microsoft 365, AWS) to scope the full blast radius of an incident
  • Run hypothesis-led threat hunts, not just reactive alert triage
  • Mentor junior analysts and help drive measurable improvements to SOC detections, playbooks and workflow

What we're looking for

  • Proven, personal ownership of complex security incidents from triage through to closure
  • Hands-on experience writing and tuning SIEM detection logic, with a solid understanding of MITRE ATT&CK and KQL (or equivalent)
  • Practical scripting/automation experience (Python, Logic Apps, REST APIs) or hands-on SOAR platform configuration
  • Working knowledge of several of: Microsoft Sentinel, Defender XDR, CrowdStrike, Microsoft Entra ID/Azure AD, Microsoft 365, AWS security tooling
  • Experience investigating identity and cloud-based compromise, including OAuth consent abuse and Conditional Access/MFA
  • A track record of proactive, hypothesis-driven threat hunting
  • Strong investigative writing skills, with the ability to explain technical findings to non-technical stakeholders
  • Comfortable acting as a technical escalation point, including reviewing and correcting the work of other analysts constructively

Nice to have

  • Security certifications (e.g. SC-200, GCIH, GCFA, CySA+ or equivalent)
  • Experience mentoring or formally training junior SOC analysts
  • Exposure to non-Microsoft cloud, EDR or SIEM tooling
  • Familiarity with SOAR platforms beyond Logic Apps (e.g. Sentinel Automation, Tines, Cortex XSOAR)

Related Jobs

View all jobs
Spotlight

Senior Data Engineer

Lab 1 London, Greater London, United Kingdom
£85,000 – £125,000 pa Hybrid

2nd Line Support Technician

InterAct Consulting Ashbourne, United Kingdom
£30,000 – £34,000 pa

IT Support Engineer - up to+ Bonus + Excellent Benefits

Involved Solutions London, United Kingdom
£35,000 – £40,000 pa

IT Technician

Rise Technical Recruitment Cambridge, United Kingdom
£32,000 – £36,000 pa

Systems Administrator \ Support Engineer

Profile 29 Ex109Hl, United Kingdom
£27,000 – £30,000 pa

2nd Line IT Engineer

EC Appointments Ltd St. Albans, United Kingdom
£30,000 – £33,000 pa On-site Clearance Required

2nd Line IT Engineer

EC Appointments Ltd Birmingham, United Kingdom
£30,000 – £33,000 pa

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.