
Security Operations Analyst - Detection Engineering & Threat Hunting, Global SOC
- London
- Permanent
- Full-time
- Monitor security alerts and events generated by various security tools and technologies, such as SIEM, IDS/IPS, firewalls, and endpoint detection and response (EDR) systems.
- Build and tune high-fidelity detections across endpoint, identity, cloud, and SaaS telemetry sources
- Reduce alert fatigue and false positives through improved severity tagging, disposal logic, and enrichment workflows
- Conduct hypothesis-driven threat hunts based on TTPs, anomalies, and threat intelligence
- Identify and close detection gaps uncovered during incident response or hunting operations
- Design and maintain SOAR playbooks and automation logic for triage, enrichment, and response
- Partner with CTI and detection engineers to operationalize threat intelligence and attacker behaviors
- Develop and maintain detection logic aligned with frameworks such as MITRE ATT&CK and MaGMa
- Contribute scripts and tooling (e.g., Python, PowerShell) to improve investigation and response efficiency
- Support 24/7 global operations by contributing to alert routing, follow-the-sun workflows, and detection health monitoring
- Assist in post-incident reviews to drive continuous improvement of detection coverage and response workflowsQualifications:Minimum Qualifications
- 5+ years in security operations, incident response, detection engineering, or threat hunting roles
- Experience working in or supporting a 24/7 global security operations environment
- Strong proficiency with SIEM platforms (e.g., Splunk, Chronicle, Elastic) and EDR tools (e.g., SentinelOne, CrowdStrike)
- Hands-on experience writing and tuning detection logic (e.g., Sigma, EQL, KQL, YARA)
- Deep understanding of attacker tactics and techniques (MITRE ATT&CK, threat modeling)
- Scripting ability in Python or similar languages to support automation, enrichment, or detection-as-code workflows
- Experience conducting investigations using logs from identity providers, endpoints, cloud, and network telemetry---
Preferred Qualifications
- Bachelor's degree in Computer Science, Cyber Security, or STEM field
- Familiarity with SOAR platforms and automation of incident response tasks
- Experience with detection-as-code pipelines, GitOps, or CI/CD rule deployment
- Experience contributing to threat hunt frameworks or purple team exercises