Saviynt

Saviynt

Saviynt is the leading cloud identity governance platform providing access governance and intelligence solutions for critical applications on Cloud and Enterprise, ensuring operational efficiency, risk reduction, and simplified identity management.

Internet Software & Services
251-1K
Founded 2010
$170M raised

Description

  • Act as the final technical escalation point for complex security incidents originating from L1 and L2 analysts.
  • Lead investigations into high-severity incidents across AWS, Kubernetes clusters, and hybrid environments.
  • Perform advanced forensic analysis across endpoints, cloud workloads, and network telemetry to determine root cause, impact, and remediation steps.
  • Correlate telemetry from SIEM, EDR, CSPM, and cloud-native sources to identify sophisticated attack chains.
  • Design, develop, and maintain automated response playbooks in the SOAR platform.
  • Build and maintain automation scripts in Python, Go, PowerShell, Bash, and similar languages for alert enrichment, evidence collection, and containment.
  • Integrate security platforms through APIs to support streamlined detection and response workflows.
  • Conduct proactive threat hunting across enterprise and cloud environments using intelligence-driven and hypothesis-based methods.
  • Develop and tune SIEM detections, correlation rules, and EDR queries aligned to MITRE ATT&CK and current threat intelligence.
  • Mentor L1 and L2 analysts and maintain SOC documentation such as SOPs, runbooks, and response playbooks.

Requirements

  • Must have been resident in the UK for a minimum of 5 years immediately prior to application.
  • Must be able to obtain and maintain Security Check (SC) level clearance.
  • Must provide original documentation verifying Right to Work in the UK and British citizenship during the initial interview stage.
  • Bachelor’s degree in Computer Science, Cybersecurity, or a related discipline, or equivalent industry experience.
  • Extensive experience in Security Operations with demonstrable time in a senior analyst, threat hunter, or L3 role.
  • Strong hands-on experience in cloud security monitoring and incident response, with AWS experience essential.
  • Proven scripting and automation capability using Python, Go, PowerShell, Bash, or similar tools.
  • Practical experience with SOAR platforms such as CrowdStrike Fusion SOAR and SIEM technologies such as Splunk, QRadar, Microsoft Sentinel, or CrowdStrike Falcon.
  • Deep understanding of EDR tooling, host and network forensics, and detection engineering practices.
  • Strong working knowledge of the MITRE ATT&CK framework and its application in threat detection and hunting.

Benefits

  • Full-time, permanent remote role based in the United Kingdom.
  • Opportunity to work on modern, intelligence-driven SOC operations using AI, automation, and cloud security tooling.
  • Exposure to challenging, high-impact work supporting government-related security environments.
  • Growth and learning opportunities through technically demanding work.
  • Welcoming and positive work environment.
  • Equal opportunity employer status with consideration for all qualified applicants.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Security Scientist

Figma 1K-5K Internet Software & Services

Figma is hiring a Security Scientist to use security expertise and data analysis to reduce risks, improve detection and response, and strengthen the safety of its products, platform, and IT systems.

Apache Spark Presto Python R Snowflake SQL
2 days, 10 hours ago

Senior TPRM Analyst

EVOCS 1-10 Internet Software & Services

EVOCS is hiring two remote Senior TPRM Analysts to lead complex third-party risk assessments, advise leadership on vendor exposures, and strengthen the company’s technology risk management program.

Cybersecurity Penetration Testing
3 days, 10 hours ago

TPRM Analyst

EVOCS 1-10 Internet Software & Services

EVOCS is hiring four remote TPRM Analysts to execute third-party security assessments, maintain accurate risk records, and drive vendor remediation activities to closure.

Cybersecurity Penetration Testing
3 days, 10 hours ago

Senior Security Assurance Engineer

GitLab 1K-5K Internet Software & Services

GitLab is hiring a Security Compliance professional to operate its technology compliance program across corporate, security, engineering, and third-party systems, unifying controls and evidence for regulatory, contractual, and security assurance needs.

DevSecOps GitLab
4 days, 9 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers