Security Analyst III – SOC – Welwyn Garden City, United Kingdom of Great Britain and Northern Ireland

Company: Tesco
Apply for the Security Analyst III – SOC – Welwyn Garden City, United Kingdom of Great Britain and Northern Ireland
Location: Welwyn Garden City
Job Description:

Overview

In this Security Analyst III role, you are the technical authority of the SOC, leading high-quality investigations and proactive threat hunting to protect Tesco from evolving threats. You combine hands-on expertise with leadership, coaching analysts and driving SOC maturity to set the standard of excellence. You’ll enhance tooling, identify automation opportunities, and contribute to CSIRT activities on major incidents. This is a chance to shape security operations and mentor a team within a collaborative, high-impact environment.

Pay / Benefits

  • annual bonus up to 20%
  • 25 days holiday + personal day + bank holidays
  • private medical insurance
  • maternity/adoption leave with full pay
  • paternity leave
  • 24/7 virtual GP service and EAP for family wellbeing

Responsibilities

  • Deliver high-quality investigative analysis to resolve incidents rapidly and accurately
  • Act as escalation point and technical authority for complex SOC investigations
  • Lead proactive threat-hunting initiatives to identify and mitigate emerging threats
  • Role-model analytical excellence and decision-making to set SOC performance benchmarks
  • Coach and mentor analysts to build technical depth and confidence
  • Drive SOC maturity objectives, improving processes, tooling, and automation
  • Enhance SOC tool utilisation and workflow optimization
  • Identify and implement automation, AI-driven enhancements, and playbook developments
  • Support CSIRT activities during major incidents with coordinated response
  • Monitor MSSP performance to ensure quality and timeliness of investigations

Key requirements

  • Over 2 years’ experience in an internal SOC or 3 years at an MSSP in a senior role
  • Deep knowledge of MITRE ATT&CK, Cyber Kill Chain, Incident Response Lifecycle, Pyramid of Pain
  • Threat hunting expertise and advanced investigative analysis
  • Strong understanding of attacker TTPs and threat actor behaviors
  • Proficiency with SIEM/XDR platforms and tuning detection logic
  • Advanced querying and scripting skills (KQL, SPL)
  • Ability to recommend tooling and process improvements
  • Practical networks, OS, and scripting knowledge for investigations
  • Experience leading technical initiatives and driving service maturity
  • Proven coaching and team development abilities
  • coaching and mentoring
  • analytical rigor
  • leadership
  • SIEM/XDR platforms
  • detection engineering
  • tuning detection logic

…

Posted: September 15th, 2026