Skip to main content
Posted 11 August, 2026

Security Operations Analyst

Cpl UK
London, ENG, GB Full Time

Job Description

Title: Security Operations Analyst

\n

Type: Contract | ASAP START - 31/03/2027

\n

Day Rate: £537.49 (Umbrella Equivalent Rate)

\n

Location: Remote

\n

\n

MUST HAVE SC - SECURITY CLEARANCE!

\n

\n

Our client a seeking a Security Operations Analyst to join their security team on an IMPORTANT Project!

\n

\n

Note: This role requires an approximately 1-week month on-call availability for high priority incident response. Please note there is additional compensation for this, and the frequency is client dependent.

\n

\n

\n

Responsibilities

\n
    \n
  • Detection engineering - Develop, maintain, and enhance security detection content primarily for the Splunk SIEM, to enable the detection of threats across diverse platforms (e.g. cloud, endpoints, and networks)
  • \n
  • Collaborate with the extended security team to identify gaps in detection coverage, log ingestion and alerting based on business risks and threats
  • \n
  • Review and improve existing SecOps standards and capabilities e.g. by highlighting requirements for additional logging, identifying incident or threat trends and detection and business-as-usual optimisation opportunities
  • \n
  • Perform security monitoring, reviewing and triaging triggered alerts, and suggesting improvements (on a rota basis 9AM to 5:30PM)
  • \n
  • Respond to and investigate identified cyber security incidents
  • \n
  • Act as a point of escalation for junior analysts, supporting them through mentorship and shadowing
  • \n
  • Operate as a technical subject matter expert on client engagements and be prepared to interact with, and present to, senior stakeholders in a consulting capacity
  • \n
  • Participate in alert testing and incident response tabletop exercises as required
  • \n
  • Remain up to date with latest threat intelligence which may be of interest to our clients
  • \n
  • Additional responsibilities may include (client dependent):Proactive threat hunting and tradecraft development
  • \n
  • Incident response and playbook development Change approvals (where applicable)
  • \n
  • Collection and interpretation of different sources of threat intelligence and researching emerging threats and TTPs.
  • \n
  • Vulnerability scanning, management and reporting
  • \n
\n

\n

Desirable Attributes

\n
    \n
  • Working knowledge of key threat intelligence concepts such as the Pyramid of Pain, Intelligence Preparation for the Cyber Environment (IPCE), and the Threat Intelligence Lifecycle
  • \n
  • Detection Engineering and Alert Development
  • \n
  • Experience with Scripting and Programming – e.g. Python/Bash/c/c++/JavaCore cybersecurity concepts such as network security, cryptography, cloud security, forensics
  • \n
  • Understanding of network protocols and how they can be abused by attackers
  • \n
  • Up to date knowledge of the most prevalent APTs and their TTPs.
  • \n
  • Knowledge of common analysis techniques associated with Windows and/or Linux
  • \n