Senior Cyber Security Analyst
Anson McCade · Greater London
Senior Cyber Security Analyst at Anson McCade, based in Greater London. This is a permanent role.
- Salary
- Competitive
- Location
- Greater London
- Contract
- Permanent
- Posted
- 2 days ago
- Closes
- 26 Sep 2026
- Sector
- Security Officer
Reference 103506
About the role
An opportunity exists for an experienced Cyber Security Operations Specialist to join a fast-growing Blue Team within a dynamic Cyber Practice. This senior role offers the chance to work on high-profile client engagements, delivering threat detection, monitoring, incident response, and security operations expertise. The role is ideal for a self-motivated professional with strong technical skills, inquisitive thinking, and a passion for protecting enterprise systems from evolving cyber threats.The RoleThe Cyber Security Operations Specialist will use advanced tools and threat intelligence to ensure effective incident detection and response across client environments. Working closely with security analysts and wider teams, the role combines detection engineering, monitoring, incident response and advisory responsibilities, with opportunities for mentoring junior staff and engaging with senior stakeholders.Key ResponsibilitiesDetection Engineering: Develop, maintain, and enhance security detection content for SIEM platforms (primarily Splunk) to identify threats across cloud, endpoints, and networksIdentify gaps in detection coverage, log ingestion, and alerting, aligned with business risks and threat landscapesReview and optimise SecOps standards and capabilities, including logging requirements, detection trends, and operational improvementsConduct security monitoring, triage triggered alerts, and recommend enhancements (rota basis 9:00–17:30)Respond to and investigate cyber security incidents, escalating where necessaryProvide mentorship and support for junior analysts, acting as a technical escalation pointServe as a technical SME on client engagements, including presenting findings and guidance to senior stakeholdersParticipate in alert testing, incident response exercises, and tabletop simulationsStay current with emerging threats and TTPs relevant to client environmentsAdditional Responsibilities (Client Dependent):Proactive threat hunting and development of tradecraftIncident response and playbook creationCollection and interpretation of threat intelligence and emerging attacker TTPsVulnerability scanning, reporting, and managementLeadership opportunities in client environments, including incident and operations managementNote: The role includes approximately one week per month on-call for high-priority incident response, with additional compensation. Frequency varies by client.About the CandidateThe ideal candidate will have hands-on experience in cybersecurity operations and threat detection, with knowledge spanning network, cloud, and endpoint security. Key skills include:Essential / Desirable Skills:Working knowledge of threat intelligence concepts (Pyramid of Pain, IPCE, Threat Intelligence Lifecycle)Detection engineering and alert development experienceScripting or programming skills (Python, Bash, C/C++, Java)Understanding of core cybersecurity concepts: network security, cryptography, cloud security, forensicsKnowledge of network protocols and how they may be exploited by attackersUp-to-date awareness of APT groups and their TTPsExperience analysing Windows and/or Linux environmentsWhy This RoleThis position offers the opportunity to work on high-profile, technically challenging security engagements, protecting critical systems and contributing to the growth of a leading cyber security practice. It is ideal for professionals seeking hands-on technical impact combined with mentoring, advisory, and potential leadership opportunities.
Reference: 103506 · Posted 2 days ago · Closes 26 Sep 2026 · Listed via Anson McCade
Apply for this job
This role is listed via Anson McCade. Applications are handled on the employer's site.
Apply on employer siteOpens the employer's website in a new tab.
Safe applying: a genuine employer will never ask you to pay for a DBS check, training or equipment, or move you onto WhatsApp before you are hired. If this listing does, report it and do not pay anything.