Hackajob Ltd

Hackajob Ltd

Bristol, South West

Lead Security Analyst

Full-Time£80,000 - 80,000 per yearआजUnited Kingdom
IT

Job Description

Salary: £80,000 - 80,000 per year

Requirements:
  • Were looking for someone who holds one of the following, or an equivalent senior cyber operations leadership credential: CISSP, CISM, or CASP.
  • Experience leading detection engineering in a SOC or similar environment, including writing and tuning detections in KQL, SPL, EQL, or Sigma, and managing coverage against MITRE ATT&CK.
  • Experience designing or improving a log and telemetry pipeline, including application-level telemetry from cloud-hosted services, with AWS preferred at this grade.
  • An understanding of how to design monitoring for failure modes and degraded states.
  • Evidence of running the intelligence cycle as a managed discipline, including collection planning, production, and feedback.
  • Working knowledge of UK government security standards and frameworks, including NCSC CAF Objective C, GovAssure, and OFFICIAL handling requirements.
  • Experience establishing incident response practice, including playbooks, severity models, and exercises.
  • Evidence of growing the technical capability of less experienced analysts through pairing, structured mentoring, or coaching, with clear goals and progress tracking.
  • Experience anchoring delivery on client outcomes rather than task completion.
  • Evidence of contributing reusable assets such as detection playbooks, runbooks, templates, or accelerators back into a practice or community.
  • Familiarity with SOAR tooling and automation of triage and enrichment workflows.
  • Experience working in Kanban-led operating models, including managing triage queues, WIP limits, and class-of-service for incidents.
  • Experience running or contributing to skills-based technical assessments that evaluate demonstrated capability rather than credentials or years of experience.
  • We sponsor attainment of recognised cyber certifications for staff in scope, and well also consider candidates working toward the listed credentials or demonstrating equivalent capability through experience.
Responsibilities:
  • Set the detection engineering standard by authoring, tuning, and peer-reviewing detections in KQL, SPL, EQL, or Sigma; managing the false-positive backlog; mapping coverage to MITRE ATT&CK; and training L1/L2 analysts to write and tune detections themselves.
  • Own the threat-landscape narrative for your engagement by turning intelligence from NCSC advisories, sector feeds, and threat actor reporting into hunt themes, coverage gap analysis, and detection priorities.
  • Run the intelligence cycle as a managed discipline by maintaining a collection plan, producing timely and rigorous intelligence products, and building feedback loops that keep the cycle improving.
  • Establish and lead security incident response practice by building playbooks, defining the severity model, running exercises, and leading the teams response to significant incidents.
  • Run blameless post-mortems that the team actually learns from.
  • Design the log and telemetry pipeline that detections run on, including bespoke application telemetry in cloud environments, and ensure the right signals are collected, parsed, and retained for detection and investigation.
  • Be the trusted technical interface for client security stakeholders by communicating what the SOC is detecting, investigating, and covering without losing fidelity, and by aligning the teams priorities to the clients risk picture.
  • Grow the analysts around you by pairing on detection authorship and incident response, setting pairing as the team norm, and actively building the capability of L1 and L2 analysts through structured mentoring and coaching.
  • Contribute to the Cyber practice beyond your engagement by feeding detection content, runbooks, and lessons learned back into shared practice resources; contributing to analyst assessment and hiring; and engaging with public-sector security communities including NCSC CISP and relevant ISACs.
Technologies:
  • AWS
  • Cloud
  • Support
  • Kanban
  • LESS
  • Security

More:

We help UK public sector organisations build and run better digital services, and our Cyber practice sits at the heart of that mission. In this Lead Security Analyst role, youll be the most senior analyst on your engagement, setting the technical direction for the SOC and shaping everything from detection engineering and threat hunting to incident response. We work alongside government departments, agencies, and critical national infrastructure owners, with our work aligned to NCSC guidance, the Cyber Assessment Framework, and OFFICIAL handling requirements. Were a company that values continuous improvement, knowledge-sharing, and building capability across our teams, and we offer benefits including 30 days holiday, flexible working hours, flexible parental leave, remote working, paid counselling, a flexible benefits platform, and an optional social and wellbeing calendar. Were hiring directly, and successful candidates must have eligibility for SC clearance. We also encourage applicants from underrepresented groups and support reasonable adjustments during the application process.

last updated 31 week of 2026

Interested in this role?

Submit your application now

How to Apply

Ready to apply for this position? Here's what you need:

  • An updated resume highlighting relevant experience
  • A compelling cover letter (if required)
  • Portfolio or work samples (for relevant positions)

About Hackajob Ltd

Hackajob Ltd

Hackajob Ltd

Bristol

IT

Skills & Technologies

GoRustAWSGitAIUI

Inferred from job description

Salary Insight

£80,000

This role

£85,000

UK median

This salary is 6% below the UK median for Lead roles85,000/yr).

Based on 2024–2025 UK technology sector benchmarks

Explore More UK Opportunities

Thousands of tech jobs across the United Kingdom