Information Security Analyst
On-siteLondon, England, United Kingdom
Job Summary
Act as the security escalation point for IT across AWS infrastructure, identity providers, and data centre environments, building detection stacks from CloudTrail, GuardDuty, and endpoint logs. Own end-to-end incident response from detection through post-mortem, performing forensic analysis on compromised workloads and maintaining tested runbooks. Write and tune detection rules to reduce noise, track threat intelligence for energy and GPU infrastructure, and prioritize vulnerability remediation based on exploitability. Lead vulnerability management and external audit coordination while automating repetitive triage tasks with Python.
Required Qualifications
- Background in IT, SOC operations, or other hands-on technical work
- Solid grasp of cloud infrastructure, ideally AWS
- Strong networking knowledge: can read a PCAP, spot beaconing in flow logs, and reason about lateral movement across VLANs and firewalls
- Knows attacker tradecraft (initial access, persistence, privilege escalation, exfiltration) and can map an investigation to it
- Comfortable scripting in Python or similar to automate enrichment, triage, and response
- Strong ownership mindset: sees things through end-to-end with little guidance
Desired Qualifications
- Deep familiarity with an EDR platform (CrowdStrike, SentinelOne, Defender) as an investigation tool
- Detection-as-code experience (Sigma, detection rules in Git, CI-tested detections)
- SOAR or custom automation for response workflows
- Experience defending data centre or colocation environments (OOB networks, BMC/IPMI, physical access telemetry)
- Experience handling security audits (ISO27001 or SOC2)
- Familiarity with FortiGate logging and NetFlow/sFlow analysis
- DFIR certifications such as GCIH, GCFA, or GCIA
- Experience in energy, fintech, trading, or another high-value-target environment
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.