The Role
We are looking for a Senior Security Analyst – AI SOC to join our Security Operations team. The role will focus on security monitoring, incident investigation, threat detection and response, with increasing use of AI and automation to support SOC operations.
The successful candidate will have strong hands-on SOC experience and should be comfortable taking ownership of complex investigations, working across multiple security technologies, and supporting junior members of the team.
Key Responsibilities
- Monitor, investigate and respond to security events and incidents across SIEM, EDR/XDR, network, identity and cloud environments.
- Perform detailed analysis of security alerts to determine scope, impact and appropriate response.
- Lead investigations for high-priority incidents and support containment, remediation and root cause analysis.
- Conduct threat hunting and identify suspicious activity that may not be covered by existing detection rules.
- Develop, review and tune SIEM detection rules and use cases, including mapping to MITRE ATT&CK.
- Use AI-assisted capabilities for alert triage, investigation, enrichment and analysis, while validating findings before further action.
- Identify opportunities to automate repetitive SOC activities through SOAR, scripting and APIs.
- Review investigation quality and act as an escalation point for junior analysts.
- Maintain SOC playbooks, investigation procedures and supporting documentation.
- Work with internal teams and customers during incident investigation and response.
Skills & Experience
- 5–8 years of relevant experience in Security Operations, Incident Response or Cyber Defense.
- Strong hands-on experience with SIEM platforms such as Microsoft Sentinel, Splunk, Google SecOps/Chronicle or QRadar.
- Experience with EDR/XDR platforms such as Microsoft Defender XDR, CrowdStrike, SentinelOne or Cortex XDR.
- Strong understanding of incident investigation, threat hunting and detection engineering.
- Good understanding of MITRE ATT&CK, common attack techniques and the incident response lifecycle.
- Working knowledge of Windows/Linux, Active Directory/Entra ID, networking and cloud environments.
- Experience with AWS, Azure or GCP security monitoring would be preferred.
- Exposure to SOAR, security automation and AI-assisted security operations.
- Working knowledge of Python, PowerShell or similar scripting would be an advantage.
- Ability to analyse security incidents and communicate findings clearly to technical and non-technical stakeholders.
Preferred Qualifications
Relevant security certifications such as
SC-200, GCIH, GCIA, CySA+, CISSP or equivalent
would be an advantage.
Practical experience in security monitoring and incident investigation will be given greater consideration than certifications alone.
Key Skills
SOC
SIEM
Incident Response
Threat Hunting
Detection Engineering
EDR/XDR
MITRE ATT&CK
Microsoft Sentinel
Splunk
CrowdStrike
Defender XDR
SOAR
Security Automation
Cloud Security
AI SOC