Security Operations Analyst

1 day ago


London, Greater London, United Kingdom Attio Full time
Attio is on a mission to redefine CRM for the AI era.

We're building the first AI-native CRM — designed for the most ambitious go-to-market teams. We recently announced our $52M Series B, led by GV (Google Ventures), with support from Redpoint, Balderton, Point Nine, and 01A. Our team thrives on solving complex technical challenges, delighting our users, and setting a new standard for the industry.

About the Role

The Security Operations Analyst is a mission-critical role within the Security, Infrastructure and Performance team, directly responsible for maintaining a vigilant and robust security posture for the entire organisation. This position focuses on the real-time protection of all organisational assets, infrastructure, and data.

The role requires a deep understanding of security frameworks, network protocols and adversarial tactics, techniques, and procedures (TTPs). The Analyst is the frontline defender, dedicated to ensuring business continuity and protecting the confidentiality, integrity, and availability of all critical resources.

Core Responsibilities and Duties
  • Security Monitoring, Triage & Improvement: Rapidly detect and prioritise active threats and vulnerabilities through continuous monitoring (SIEM, EDR, Cloud), ensuring that insights from root cause analysis and proactive threat hunting are directly fed back into the engineering process and used refine detection capabilities.

  • Incident Response: Serve as the initial responder to security events. Rapidly analyse, classify, and prioritise reported or detected security incidents, determining the scope, severity, and potential impact to the platform.

  • Compliance: Enforce the compliance with internal security policies and regulatory requirements maintaining meticulous records of all detected security events, analysis findings, and incident response activities.

Competencies and Skills
  • Security Information and Event Management (SIEM) Platform Expertise:

    • Must have: Hands-on experience in the operation, administration, and ongoing maintenance of a major SIEM platform

    • Desirable: Experience with Google SecOps (formerly Chronicle), including advanced knowledge of data ingestion, rule creation, dashboard development, and optimisation for performance and cost-effectiveness. The ability to leverage the platform for proactive threat hunting and complex query construction is expected.

    • Desirable: Proficiency in Google SecOps (formerly Chronicle) SOAR (security orchestration, automation, and response) tooling. This includes developing SOAR actions and workflows to automate alert triage, immediate incident mitigation, and response procedures.

  • Security Incident Response:

    • Must have: Proven experience in the end-to-end development, documentation, and execution of comprehensive security incident response playbooks and procedures.

    • Must have: Practical experience in incident triage, containment, eradication, recovery, and post-mortem analysis for a wide range of security events (e.g., malware outbreaks, unauthorised access, data exfiltration, cloud compromises).

    • Desirable: The ability to lead and coordinate incident response efforts across cross-functional teams under pressure is crucial.

  • Security Log and Network Analysis:

    • Must have: Deep expertise in the analysis of security logs from diverse sources (e.g., operating systems, firewalls, endpoint protection, cloud environments) to identify anomalies, indicators of compromise (IOCs), and root causes of incidents.

    • Must have: Expert-level knowledge of common attack vectors, attacker methodologies (e.g., MITRE ATT&CK framework), and techniques, tactics, and procedures (TTPs) used by various threat actors.

    • Desirable: Comprehensive understanding of network protocols (e.g., TCP/IP, DNS, HTTP/S) and their associated traffic patterns to effectively detect malicious activity and understand its propagation.

  • Vulnerability Management:

    • Must have: Solid familiarity with industry-standard vulnerability scanning tools (e.g., Nessus, Qualys, Rapid7, Trivy).

    • Desirable: Experience managing a vulnerability disclosure or bug bounty program. Testing disclosed vulnerabilities and working with external security researchers.

    • Desirable: Experience in establishing, running, and managing a continuous vulnerability management lifecycle, including scanning, reporting, prioritisation, and tracking of remediation efforts in coordination with engineering and system owner teams.

What we offer
  • Competitive salary of £80,000 to £95,000

  • Equity in an early-stage tech company on an incredible trajectory

  • 25 days holiday plus local public holidays

  • Apple hardware

  • Private medical insurance through AXA

  • Pension contribution through Hargreaves Lansdown

  • Enhanced family leave

  • Team off-site in fun places (We've been to Barcelona, Lisbon, Malta, and Split so far)



  • London, Greater London, United Kingdom NETbuilder Full time

    London (Close to Liverpool St. station)6 Month Fixed-Term ContractOn-call rota (Allowance Provided)NETbuilder is a leading provider of innovative technology solutions, helping clients achieve operational excellence through expertise in observability and cybersecurity. We foster a collaborative environment where security professionals can grow, make an...


  • London, Greater London, United Kingdom Pearson Full time

    DescriptionAbout the Role:Pearson is looking for an experienced Security Operations Center (SOC) analyst. This role is responsible for performing day-to-day security operations, continuous process improvement, detection engineering and project work related to SOC functions.Responsibilities:Identify, triage and contain security events, using automation and AI...

  • IT Security Analyst

    2 weeks ago


    London, Greater London, United Kingdom hireful Full time £50,000 - £60,000 per year

    Are you looking to join a global software technology company, with their main base of operations here, in the UK, as an experienced GRC IT Security Analyst?Do you have experience in the GRC IT Security space with audits, ISO27001, PCI DSS, SOC2, NIST & current compliance regulations? (Some, or all is fine)If so & you are looking to expand your IT Security...

  • Security Analyst

    2 weeks ago


    London, Greater London, United Kingdom Inter-Quest Full time £50,000 - £53,250 per year

    Location:London, Greater London, EnglandSalary:£50, ,250 per yearCategorySecuritySector:IT and DigitalContract typePermanentConsultant:Paul BentleyIT Security Analyst - Permanent role - £50,000 - £53,250 - London/ HybridJob purpose:The security analyst will join a small security team for one of our clients in Central London. you will be a subject matter...

  • IT Security Analyst

    1 week ago


    London, Greater London, United Kingdom -c93b-4d6f-896e-b30a0ca86446 Full time £40,000 - £60,000 per year

    Location:London, Greater London, EnglandSalary:£50k - 55k per yearCategoryCyber SecuritySector:IT and DigitalContract typePermanentConsultant:Megan Trulsson-EllisIT Security AnalystLocation: London - Remote with occasional travel to officeSalary: £50,000 + Flexible Benefits SchemeContract type: PermanentAbout the RoleMorson Edge have partnered with a...


  • London, Greater London, United Kingdom Department for Energy Security and Net Zero Full time £34,815 - £41,355 per year

    DetailsReference number433659Salary£34,815 - £41,355National: £34,815 - £37,600 London: £38,295 - £41,355 (pro-rata for part-time hours)A Civil Service Pension with an employer contribution of 28.97%GBPJob gradeHigher Executive OfficerContract typePermanentBusiness areaDESNZ - Integrated Corporate Services - DigitalType of roleDigitalWorking...


  • London, Greater London, United Kingdom Squarepoint Capital Full time £104,000 - £128,000 per year

    Position Overview:Squarepoint is seeking an Information Security Analyst to join the Security Operations team. The Information security Analyst provides first line of support for security inquires, manages vulnerability assessments, assesses third-party vendors and software requests, and investigates and responds to security alerts. The ideal candidate has a...


  • London, Greater London, United Kingdom Vurke Full time £60,000 - £80,000 per year

    Job Description: About the Role:We are looking for a SOC Analyst to join our 24/7 security operations team, monitoring real-time security alerts and responding to incidents.Responsibilities:Monitor SIEM dashboards for alerts and anomalies.Triage, escalate, and investigate security incidents.Perform malware analysis and forensic reviews.Develop and maintain...


  • London, Greater London, United Kingdom Meta Full time £60,000 - £120,000 per year

    Meta is seeking a Security Analyst to join the Global Security Operations team. The Analyst will serve on the front lines of Meta's Security team and will lead and support security investigations across the company's global infrastructure as well as respond to escalations from the Tier1 team. The analyst will leverage an armory of tools to investigate and...


  • London, Greater London, United Kingdom Synapri Full time

    Location: London (hybrid working - occasional site visits)Duration: 6 months +Vetting: SC security clearance will be requiredWe are seeking a proactive and detail-oriented Cyber Security Analyst to serve as the first line of defence in our organization's cybersecurity operations. The "Front Door" role involves monitoring and managing security systems,...