About the Role
The Sec Ops Analyst will be responsible for hands-on security monitoring and assurance across Microsoft, AWS, and Databricks environments. This role involves investigating alerts and incidents, closing monitoring gaps, and maintaining ISO/IEC 27001:2022 controls with audit-ready evidence, including managing security assurance questionnaires.
Responsibilities
- Monitor, correlate, and triage security alerts and activity across Microsoft 365, Azure, Entra ID, AWS, Databricks, endpoints, and network services using native tools and the central SIEM.
- Act as the primary internal contact for the managed SOC, owning incidents, escalations, and follow-up through to resolution within agreed service levels.
- Close monitoring gaps by improving detection use cases, alert logic, playbooks, and escalation criteria.
- Own the evidence cycle for ISO/IEC 27001:2022 controls, mapping, collecting, and maintaining audit-ready evidence, and resolving gaps with control owners.
- Support internal, certification, and surveillance audits, tracking findings and corrective actions to closure.
- Monitor privileged access and authentication activity, review vulnerability findings, and use Microsoft Purview to manage data protection and DLP risk.
- Complete customer and third-party security assurance questionnaires with accurate, evidence-backed responses.
- Run phishing simulations and security-awareness activity, and report on incidents, vulnerabilities, and control evidence to technical and non-technical stakeholders.
Requirements
- Hands-on SecOps experience using SIEM, EDR/XDR, and cloud/identity telemetry, ideally with a managed SOC.
- Practical Microsoft security experience (Sentinel, Defender, Entra ID, Purview) and exposure to AWS; Databricks familiarity is a plus.
- Demonstrable ISO/IEC 27001:2022 experience, including collecting and presenting control evidence, resolving gaps, and supporting audits.
- Experience completing client security assurance questionnaires.
- Strong analytical and stakeholder-management skills.
- Comfortable managing multiple incidents and audit requests simultaneously.
Skills
- SIEM
- EDR/XDR
- Cloud telemetry
- Identity telemetry
- Microsoft security (Sentinel, Defender, Entra ID, Purview)
- AWS
- Databricks
- ISO/IEC 27001:2022
- Security assurance questionnaires
- Analytical skills
- Stakeholder management
- Cyber Essentials Plus
- GRC platforms
- Evidence management platforms
- ISO 27001 Lead Implementer
- SC-200
- Security+
Location
- Hybrid
Work Type
- Hybrid
- Flexible working
Experience Level
- SecOps experience
About the Company
- Unity Advisory is a modern advisory business built for today's CFO.
- It combines deep expertise with an AI-native operating model designed to deliver better evidence, faster execution, and stronger client outcomes.
- Unity delivers advisory through a model that is free from audit conflict.
Equal Opportunity
- Unity Advisory is committed to providing an inclusive and accessible recruitment process.
- In line with the Equality Act 2010, we will accommodate any suitable candidate requiring assistance to attend or conduct an interview.
- Please let us know if you need any adjustments when scheduling your interview or in your cover letter.
