Posted 11 August, 2026
Security Operations Analyst
Cpl UK
London, ENG, GB
Full Time
Job Description
Title: Security Operations Analyst
\nType: Contract | ASAP START - 31/03/2027
\nDay Rate: £537.49 (Umbrella Equivalent Rate)
\nLocation: Remote
\n\nMUST HAVE SC - SECURITY CLEARANCE!
\n\nOur client a seeking a Security Operations Analyst to join their security team on an IMPORTANT Project!
\n\nNote: This role requires an approximately 1-week month on-call availability for high priority incident response. Please note there is additional compensation for this, and the frequency is client dependent.
\n\n\nResponsibilities
\n- \n
- Detection engineering - Develop, maintain, and enhance security detection content primarily for the Splunk SIEM, to enable the detection of threats across diverse platforms (e.g. cloud, endpoints, and networks) \n
- Collaborate with the extended security team to identify gaps in detection coverage, log ingestion and alerting based on business risks and threats \n
- Review and improve existing SecOps standards and capabilities e.g. by highlighting requirements for additional logging, identifying incident or threat trends and detection and business-as-usual optimisation opportunities \n
- Perform security monitoring, reviewing and triaging triggered alerts, and suggesting improvements (on a rota basis 9AM to 5:30PM) \n
- Respond to and investigate identified cyber security incidents \n
- Act as a point of escalation for junior analysts, supporting them through mentorship and shadowing \n
- Operate as a technical subject matter expert on client engagements and be prepared to interact with, and present to, senior stakeholders in a consulting capacity \n
- Participate in alert testing and incident response tabletop exercises as required \n
- Remain up to date with latest threat intelligence which may be of interest to our clients \n
- Additional responsibilities may include (client dependent):Proactive threat hunting and tradecraft development \n
- Incident response and playbook development Change approvals (where applicable) \n
- Collection and interpretation of different sources of threat intelligence and researching emerging threats and TTPs. \n
- Vulnerability scanning, management and reporting \n
Desirable Attributes
\n- \n
- Working knowledge of key threat intelligence concepts such as the Pyramid of Pain, Intelligence Preparation for the Cyber Environment (IPCE), and the Threat Intelligence Lifecycle \n
- Detection Engineering and Alert Development \n
- Experience with Scripting and Programming – e.g. Python/Bash/c/c++/JavaCore cybersecurity concepts such as network security, cryptography, cloud security, forensics \n
- Understanding of network protocols and how they can be abused by attackers \n
- Up to date knowledge of the most prevalent APTs and their TTPs. \n
- Knowledge of common analysis techniques associated with Windows and/or Linux \n
