2nd/3rd Line Security Analyst - Reading
This role involves leading the investigation of complex security incidents within a Security Operations Centre, with end-to-end ownership from detection to resolution. The analyst will design and tune SIEM rules using MITRE ATT&CK, automate SOC workflows using Python and SOAR platforms, and conduct proactive threat hunting. A key focus is on cloud and identity compromise investigations across Microsoft and AWS environments, while also mentoring junior analysts and improving detection capabilities.