Overview
As a Senior Cyber Security Analyst, you will lead end-to-end cyber incidents, coordinate cross-functional response, and shape cyber defence practices across a global environment. You bring deep expertise in incident response, detection engineering, cloud security, and vulnerability management to drive resilient operations. You’ll work with Microsoft security tools and automation to raise monitoring, detection, and remediation capabilities. This role offers senior stakeholder exposure and clear progression toward lead or management responsibilities.
Pay / Benefits
- excellent benefits
- flexible hybrid working
- onsite 1 day per week in Central London
- global exposure and senior stakeholder engagement
- clear progression opportunities
Responsibilities
- Lead end-to-end cyber security incidents across global environments (P1-P4) and coordinate incident bridge calls with tech and business stakeholders
- Drive containment, eradication, recovery and post-incident improvements; perform root cause analyses and embed lessons learned
- Develop and maintain incident response playbooks and procedures aligned to industry best practices
- Configure and optimize Microsoft Sentinel and Microsoft Defender technologies; tune detection logic with KQL
- Build and maintain automated SOAR workflows using Logic Apps; integrate security tooling with third-party systems
- Enhance cloud and on-prem security postures (Azure-focused) and promote secure-by-design principles
- Support vulnerability management across infrastructure, cloud, and endpoints using Tenable and Defender VM
- Collaborate with global IT and engineering teams; communicate effectively with senior leadership
- Provide ongoing risk-based reporting and maintain high-quality technical documentation
Key requirements
- Proven experience leading cyber security incidents end-to-end in enterprise environments
- Strong background in Security Operations, Cyber Defence, Incident Response or Blue Team
- Experience with hybrid cloud and on-premise environments
- Hands-on with Microsoft Sentinel, Microsoft Defender XDR and Azure security technologies
- Experience in detection engineering, threat detection and security automation
- Exposure to vulnerability management platforms such as Tenable or Defender Vulnerability Management
- Ability to manage stakeholder communications during high-severity incidents
- Strong understanding of attacker TTPs
- Strong Microsoft security ecosystem expertise
- Advanced KQL for investigations and reporting
- Experience building automation workflows with Logic Apps
- Calmness under pressure
- Strong ownership and accountability
- Excellent communication and stakeholder management
- Microsoft Sentinel
- Microsoft Defender XDR
- Azure security
…
