<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
  <channel>
    <title>2nd/3rd Line Security Analyst - Reading - Xact Placements Limited RSS Feed</title>
    <link>https://jobs.co.uk/job/2nd3rd-line-security-analyst-reading-xact-placements-limited--4d35adf8-ef60-4073-be8e-2d562b813a8b</link>
    <description>RSS feed for 2nd/3rd Line Security Analyst - Reading at Xact Placements Limited.</description>
    <language>en-gb</language>
    <lastBuildDate>Tue, 25 Aug 2026 20:51:13 GMT</lastBuildDate>
    <item>
      <title>2nd/3rd Line Security Analyst - Reading - Xact Placements Limited</title>
      <link>https://jobs.co.uk/job/2nd3rd-line-security-analyst-reading-xact-placements-limited--4d35adf8-ef60-4073-be8e-2d562b813a8b</link>
      <guid>https://jobs.co.uk/job/2nd3rd-line-security-analyst-reading-xact-placements-limited--4d35adf8-ef60-4073-be8e-2d562b813a8b</guid>
      <pubDate>Tue, 25 Aug 2026 11:56:09 GMT</pubDate>
      <description>Location: Reading | Salary: 50000.00-50000.00 Annual | Type: Permanent | 2nd / 3rd Line Security Analyst Location: Reading (Hybrid)  Salary: £50,000 - £60,000   Our client is looking for a 2nd/3rd Line Security Analyst to join their Security Operations Centre as a senior technical escalation point. This is a genuinely hands-on role - ideal for someone who wants to keep working close to the tooling and the day-to-day operational workload rather than move straight into a purely managerial or architectural position. You''ll own complex incidents end-to-end, drive detection engineering and automation, and provide senior technical depth across the SOC.  Duties of the Role  Own complex security incidents end-to-end - from alert validation through investigation, containment and closure Act as the senior escalation point when earlier-stage investigations stall, reviewing prior work and coaching the original analyst Investigate identity and cloud-based compromise (e.g. anomalous sign-ins, malicious OAuth consent, mailbox access), including session/token revocation Design, build and test SIEM detection rules mapped to MITRE ATTandCK, and tune out false positives without blanket whitelisting Build automation for SOC processes - enrichment, ticketing, containment -...</description>
      <category>Permanent</category>
    </item>
  </channel>
</rss>