Talent.com
Made Tech
Lead Security AnalystMade Tech • London, England, UK
Lead Security Analyst

Lead Security Analyst

Made Tech • London, England, UK
27 days ago
Salary
£65,000.00 yearly
Job type
  • Full-time
  • Part-time
Job description
Made Tech helps UK public sector organisations build and run better digital services. Our Cyber practice sits at the heart of that mission working alongside government departments agencies and critical national infrastructure owners to improve how they detect respond to and learn from cyber threats. As a Lead Security Analyst youll be the most senior analyst on your engagement setting the technical direction for the SOC and owning the quality of what the team produces from detection engineering to threat-hunting to incident response.

This isnt a role where you disappear into a ticket queue. Youll shape the threat-landscape narrative for your engagement drive the detection backlog and build the capability of the analysts around you. That means pairing on complex investigations setting tradecraft standards and making sure the teams detection content is version-controlled peer-reviewed and continuously improved not left to age in a SIEM. Youll also be the trusted technical interface for client security stakeholders translating what the SOC is seeing into the language that informs decisions.

The UK public sector context matters here. Youll align your work to NCSC guidance the Cyber Assessment Framework and OFFICIAL handling requirements not because compliance is the goal but because those frameworks reflect the real risk environment your clients operate in. Youll engage with cross-government security communities feed detection content and runbooks back into the Cyber practice and help grow a bench of analysts who can operate at the same standard.

Key Responsibilities


  • Set the detection engineering standard author tune and peer-review detections in KQL SPL EQL or Sigma; manage the false-positive backlog; map coverage to MITRE ATT&CK; and train L1/L2 analysts to write and tune detections themselves.

  • Own the threat-landscape narrative for your engagement turn intelligence from NCSC advisories sector feeds and threat actor reporting into hunt themes coverage gap analysis and detection priorities that the SOC and client stakeholders can act on.

  • Run the intelligence cycle as a managed discipline maintain a collection plan produce timely and rigorous intelligence products and build feedback loops that keep the cycle honest and improving.

  • Establish and lead security incident response practice build playbooks define the severity model run exercises and lead the teams response to significant incidents; run blameless post-mortems that the team actually learns from.

  • Design the log and telemetry pipeline that detections run on including bespoke application telemetry in cloud environments not just commodity endpoint feeds; ensure the right signals are collected parsed and retained for both detection and investigation.

  • Be the trusted technical interface for client security stakeholders communicate what the SOC is detecting investigating and covering without losing fidelity; surface risks early and honestly and align the teams priorities to the clients risk picture.

  • Grow the analysts around you pair on detection authorship and incident response as a default set pairing as the team norm and actively build the capability of L1 and L2 analysts through structured mentoring and coaching so knowledge isnt concentrated in one person.

  • Contribute to the Cyber practice beyond your engagement feed detection content runbooks and lessons learned back into shared practice resources; contribute to analyst assessment and hiring; and engage with public-sector security communities including NCSC CISP and relevant ISACs.

Skills Knowledge & Expertise


Were looking for someone who holds one of the following or an equivalent senior cyber operations leadership credential:
  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Security Manager (CISM)
  • CompTIA Advanced Security Practitioner (CASP)
  • Experience leading detection engineering in a SOC or similar environment including writing and tuning detections in KQL SPL EQL or Sigma and managing coverage against MITRE ATT&CK

  • Experience designing or improving a log and telemetry pipeline including application-level telemetry from cloud-hosted services (AWS is a strong preference at this grade) with an understanding of how to design monitoring for failure modes and degraded states

  • Evidence of running the intelligence cycle as a managed discipline collection planning production and feedback rather than consuming finished intelligence

  • Working knowledge of UK government security standards and frameworks including NCSC CAF Objective C GovAssure and OFFICIAL handling requirements

  • Experience establishing incident response practice playbooks severity models and exercises not just responding to individual incidents

  • Evidence of growing the technical capability of less experienced analysts through pairing structured mentoring or coaching including setting clear goals and tracking progress over time

  • Experience anchoring delivery on client outcomes rather than task completion challenging the brief where it serves the client and making value visible rather than reporting effort

  • Evidence of contributing reusable assets detection playbooks runbooks templates or accelerators back into a practice or community rather than leaving knowledge within a single team

Tools and practices
  • Familiarity with SOAR tooling and automation of triage and enrichment workflows

  • Experience working in Kanban-led operating models including managing triage queues WIP limits and class-of-service for incidents

  • Experience running or contributing to skills-based technical assessments that evaluate demonstrated capability rather than credentials or years of experience

Made Tech sponsors attainment of recognised cyber certifications for staff in scope. If you dont yet hold the essential credentials listed above but are working toward them or can demonstrate equivalent capability through your experience wed still like to hear from you.

Job Benefits


We are always listening to our growing teams and evolving the benefits available to our people. As we scale as do our benefits and we are scaling quickly. Weve recently introduced a flexible benefit platform which includes a Smart Tech scheme Cycle to work scheme and an individual benefits allowance which you can invest in a Health care cash plan or Pension plan. Were also big on connection and have an optional social and wellbeing calendar of events for all employees to join should they choose to.

Here are some of our most popular benefits listed below:

30 days Holiday - we offer 30 days of paid annual leaveFlexible Working Hours - we are flexible with what hours you workFlexible Parental Leave - we offer flexible parental leave optionsRemote Working - we offer part time remote working for all our staffPaid counselling - we offer paid counselling as well as financial and legal advice

At this point we hope youre feeling excited about Made Tech and the job opportunity. Get in touch with our
talent team if youd like an informal chat about the role and your suitability before applying. We are hiring for this role directly so will not respond to any CVs sent via external recruitment agencies.

SC Eligibility
An increasing number of our customers are specifying a minimum of SC (security check) clearance in order to work on their projects. As a result were looking for all successful candidates for this role to have eligibility.
Eligibility for SC requires 5 years UK residency and 5 year employment history (or back to full-time education). Please note that if at any point during the interview process it is apparent that you may not be eligible for SC we wont be able to progress your application and we will contact you to let you know why.

Support in applyingIf you need this job description in another format or other support in applying please email .
We believe we can use tech to make public services better. We also believe this can happen best when our own team represents the society that actually uses the services we work on. Were collectively continuing to grow a culture that is happy healthy safe and inspiring for people of all backgrounds and experiences so we encourage people from underrepresented groups to apply for roles with us.
When you apply well put you in touch with a member of our talent team who can help with any needs or adjustments we may need to make to help with your application. Weve put together this blog as a resource to share more about reasonable adjustments and some examples of what this could include. We also welcome any feedback on how we can improve the experience for future candidates.

Working hours: Our standard hours are Monday to Friday but the nature of this role means some work outside normal hours may be required for example during release and change windows planned maintenance or to align with client operating hours. This is occasional rather than routine and well always give as much notice as we can and agree it with you in advance wherever possible.







Required Experience:

IC


Employment Type : Full-Time
Experience: years
Vacancy: 1
Yearly Salary Salary: 65000 - 80000
Create a job alert for this search

Lead Security Analyst • London, England, UK

Similar jobs

PAM/PAW Solution Architect - Enterprise Security Lead

Advanced Resource Managers LtdGreater London, England, United Kingdom
Temporary

Advanced Resource Managers Ltd is seeking a Solution Architect with PAM/PAW expertise for a 6-month contract in London.The role is hybrid, requiring 2 days on site per week, and focuses on deliveri... Show more

 • Promoted

Security Engineering Director — Lead Secure-by-Design Platform

MonzoGreater London, England, United Kingdom
Full-time

Monzo is looking for a Security Engineering Lead to drive their secure-by-design mandate and lead a high-performing team.This role requires proven leadership in engineering organizations of 30-50 p... Show more

 • Promoted

Security Research Lead — Ship AI Security Innovations

MazeGreater London, England, GB
Full-time

Maze is seeking a Security Research Lead to shape our cybersecurity products using AI.You will lead research initiatives to enhance product capabilities and establish methodologies for identifying ... Show more

 • Promoted

Senior SOC Analyst – DV Cleared Security Lead

Frontier ResourcingCity Of London, England, GB
Full-time

A cybersecurity recruitment firm is looking for experienced Senior SOC Analysts to join a skilled security operations team.In this hands-on role, you will monitor systems for security alerts, impro... Show more

 • Promoted

Senior Security Analyst

NinjakitchenGreater London, England, GB
Full-time

SharkNinja is a global product design and technology company, with a diversified portfolio of lifestyle solutions that aim to positively impact people’s lives in homes around the world.Powered by t... Show more

 • Promoted

Senior SOC Analyst - London

Interface RecruitmentGreater London, England, GB
Full-time

Salary: £58,600 - 58,600 per year.Experience in SOC operations, security monitoring, incident response, threat hunting, cyber defence, vulnerability management, or security operations engineering.E... Show more

 • Promoted

Security Solutions Analyst

World Wide TechnologyGreater London, England, GB
Full-time

The Analyst is responsible for solving business and technology problems within customer engagements, interacts with clients to understand their needs, and works with project teams to develop soluti... Show more

 • Promoted

Zero Trust Security Lead

Sanderson RecruitmentNot Specified, London, GB
Full-time

Sanderson are working with a consulting client who are looking to grow their Zero Trust capability.The client is seeking a Lead to come in and implement and optimise Zero Trust security architectur... Show more

 • Promoted

Senior Security Analyst

LGBT GreatGreater London, England, GB
Full-time

Act as a senior escalation point for complex/high‑severity alerts across SIEM, EDR, Cloud and Identity platforms.Lead end‑to‑end incident response (investigation, containment, eradication, and post... Show more

 • Promoted

Security Lead

TaktileGreater London, England, GB
Full-time

Taktile helps financial institutions make smarter, safer decisions with the power of AI.We're looking for a Security Lead to set the technical direction for security across our Platform Team while ... Show more

 • Promoted

Security Analyst, Incident Response (GSOC London)

Royal Bank of CanadaGreater London, England, GB
Permanent

You will be a key member of the RBC Global Security Incident Response team as an experienced Security Analyst.This role is a core position within the Global Security Operations Centre (GSOC), provi... Show more

 • Promoted

Zero Trust Security Lead - London

WeAreTechWomenGreater London, England, GB
Full-time

Role: Zero Trust Security Lead.Travel/Mobility Requirement: Flexibility to travel to client site where required.Please Note: Due to the nature of client work you will be undertaking, you will need ... Show more

 • Promoted

Senior Security Analyst

Spencer RoseGreater London, England, GB
Full-time

Senior Security Analyst (L3) / Security Architect.Location: [London / hybrid / remote].We are seeking a highly experienced Level 3 Security Analyst to join a global cyber security function in an or... Show more

 • Promoted

Security Awareness Lead

Tokio Marine HCCGreater London, England, GB
Full-time +1

Reporting to:** International CISO**Direct Reports:** N/A**Position Type:** Full Time, Permanent**Why**Standing still is not an option in the current world of Insurance.TMHCC is one of the world’s ... Show more

 • Promoted

Security Analyst, Incident Response (GSOC London)

RBCGreater London, England, GB
Full-time

We are looking for an experienced Security Analyst to join the RBC Global Security Incident Response team within the Global Security Operations Centre (GSOC).Global accountability to respond to cri... Show more

 • Promoted

Senior Cyber Security Analyst

Lightsource bpGreater London, England, GB
Full-time

For over a decadewe'vebeen actively working to diversify the way our world is powered with sustainable and responsible renewable power.We work to safely deliver affordable, reliable, large-scale on... Show more

 • Promoted

Senior Threat Modeling Architect - Enterprise Security Lead

State StreetGreater London, England, United Kingdom
Full-time

State Street is seeking a Principal Threat Modeling Architect to lead the enterprise Threat Modeling program and set governance across applications, cloud, and emerging tech.You will partner with S... Show more

 • Promoted

Security Analyst – Hybrid Role with Growth & Learning

WanstorGreater London, England, GB
Full-time

A leading IT solutions provider in the United Kingdom is seeking a Security Analyst to ensure the protection of digital assets from unauthorized access.This role involves monitoring security incide... Show more

 • Promoted

Offensive Security Analyst

GAP TalentGreater London, England, GB
Full-time

Direct message the job poster from GAP Talent.GAP Talent is partnering with a leading UK professional services and business advisory organisation that supports ambitious, high-growth and entreprene... Show more

 • Promoted

InfoSec Analyst II — Multi-Domain Security Lead

Checkout LtdGreater London, England, GB
Full-time

Checkout Ltd in Greater London is hiring an Information Security Analyst II to oversee various security initiatives, focusing on Governance, Risk, and Compliance (GRC), AI governance, data governan... Show more