# Security Operations Analyst, UK

**Company**: Anduril
**Location**: London
**Experience**: senior
**Job type**: full-time
**Salary**: Competitive equity grants and salary range estimate based on various factors
**Category**: IT
**Industry**: Technology

**Apply**: https://job-boards.greenhouse.io/andurilindustries/jobs/5222558007?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_47fcc997-f30

## Description

Anduril's Detection and Response team is seeking a Security Operations Analyst to monitor and respond to adversarial activity, while helping incorporate key detection feedback loops with the detection engineering team.

As a Security Operations Analyst on the detection and response team, you'll be responsible for monitoring and responding to adversarial activity. You'll serve as an incident commander alongside other senior analysts during incident response. When not responding to threats, you'll conduct threat hunting and data normalization operations across the organization to understand user behaviour and identify anomalies.

**Responsibilities**

- Triage and respond to alerts/incidents covering multiple disciplines, including phishing, endpoints, cloud infrastructure and services, and SaaS applications

- Build and optimize tailored detection signatures, response playbooks, and response automation using detection-as-code principles

- Lead the feedback loop for detections, ensuring alerts are fine-tuned to reduce false positives

- Participate in threat modeling scenarios with cross-functional partners to understand weaknesses across Cloud, Mobile, Endpoints, and other environments

- Organize and conduct threat hunting and data baselines to identify anomalous patterns in data

- Participate in an on-call rotation responding to security events and conducting incident response investigations

- Proactively collaborate with stakeholders, guiding detection and response maturity, leading incidents, and mentoring junior analysts

**Required Qualifications**

- Experience in security monitoring, log analysis, and detection engineering within large data sets

- Experience in Python development, specifically contributing to a shared codebase used for automating SOC operations

- Experience with one or more SIEM languages (SPL, KQL, SQL)

- Experience conducting analysis in a data lake environment

- Broad range of practical security knowledge across endpoint, network, identity, application, and cloud infrastructure

- Knowledge of attacker tactics, techniques, and procedures (TTPs) across Windows, Linux, MacOS, AWS/Azure, etc.

- Strong communication skills and experience collaborating with internal and external stakeholders

- Must be able to obtain and hold a UK Security Clearance

**Preferred Qualifications**

- Experience conducting incident response in the Cloud (AWS, Azure, GCP)

- Digital Forensics and/or reverse engineering experience

**Benefits**

Anduril offers a comprehensive, competitive benefits package, including top-tier benefits for full-time employees.

## Skills

### Required
- Python
- SIEM languages (SPL, KQL, SQL)
- security monitoring
- log analysis
- detection engineering
- data lake environment
- cloud infrastructure
- attacker tactics, techniques, and procedures (TTPs)

### Nice to have
- incident response in the Cloud (AWS, Azure, GCP)
- Digital Forensics
- reverse engineering

---

Source: [Apply at job-boards.greenhouse.io](https://job-boards.greenhouse.io/andurilindustries/jobs/5222558007?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
