HimalayasHimalayas logo
SaviyntSA

L3 SOC Analyst

Saviynt is a leading provider of cloud-native identity and governance platform solutions, empowering enterprises to secure their digital transformation, safeguard critical assets, and meet regulatory compliance.

Saviynt

Employee count: 1001-5000

United Kingdom only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

Location: United Kingdom
Type: Full-time, permanent
Due to the nature of the UK Government projects this role supports, this position is classified as a Reserved Post. In accordance with the Civil Service Nationality Rules, paragraph 1 of Schedule 23 and paragraph 5 of Schedule 22 of the Equality Act 2010, we can only accept applications from persons with UK residency (at least five years).
Successful candidates must undergo National Security Vetting (NSV). This role requires Security Check SC level clearance as a minimum. Any offer of employment is strictly conditional upon the candidate successfully obtaining and maintaining this clearance.
To meet the vetting criteria, you will be required to have been resident in the UK for a minimum of 5 years immediately prior to your application. Failure to obtain clearance or a lapse in residency history may result in the withdrawal of the employment offer, and you will not be entitled to any compensation from Saviynt as a result.
In line with the Immigration, Asylum and Nationality Act 2006, all shortlisted candidates will be required to provide original documentation verifying their Right to Work in the UK and their British Citizenship during the initial interview stage. We conduct thorough Baseline Personnel Security Standard (BPSS) checks as a precursor to all higher-level clearances.

Role Overview:

We are establishing a modern Security Operations Centre designed to deliver proactive, intelligence-driven security outcomes. Moving beyond traditional reactive monitoring, our SOC emphasises AI, automation, detection engineering, and deep cloud security visibility to identify and neutralise sophisticated threats at scale.
The L3 SOC Analyst will act as the senior technical escalation point within the SOC, leading complex investigations, driving automation initiatives, and mentoring junior analysts. This role requires strong hands-on expertise across cloud security, threat hunting, incident response, and orchestration technologies.

WHAT YOU WILL DO:

  • Incident Response & Technical Escalation
  • Act as the final escalation point for complex incidents originating from L1/L2 analysis.
  • Lead investigations into high-severity security events, including those impacting AWS, Azure, Kubernetes clusters and hybrid environments.
  • Perform advanced forensic analysis across endpoints, cloud workloads, and network telemetry to determine root cause, impact, and remediation actions.
  • Correlate telemetry from SIEM, EDR, CSPM, and cloud-native sources to identify sophisticated attack chains.
  • Security Automation & SOAR Engineering
  • Design, develop, and maintain automated response playbooks within the SOAR platform to improve response efficiency.
  • Build and maintain automation scripts (Python, go, etc.) for alert enrichment, evidence collection, and containment.
  • Integrate security platforms via APIs to enable streamlined, automated detection and response workflows.
  • Identify opportunities to reduce Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) through automation and process optimisation.
  • Threat Hunting & Detection Engineering
  • Conduct proactive threat hunting across enterprise and cloud environments using intelligence-driven and hypothesis-based methodologies.
  • Serve as an SME for cloud security monitoring leveraging tools such as AWS GuardDuty, CloudTrail, CrowdStrike, and Proofpoint.
  • Develop and tune SIEM detections, correlation rules, and EDR queries aligned to MITRE ATT&CK tactics and emerging threat intelligence.
  • Mentorship & Continuous Improvement
  • Provide technical mentoring and guidance to L1/L2 analysts to strengthen SOC capability.
  • Maintain and enhance SOC documentation including SOPs, runbooks, and response playbooks.
  • Analyse incident trends and operational metrics to recommend improvements in detection coverage, automation effectiveness, and security posture.

WHAT YOU BRING:

  • Bachelor’s degree in Computer Science, Cybersecurity, or related discipline (or equivalent industry experience).
  • Extensive experience in Security Operations with demonstrable time in a senior analyst, threat hunter, or L3 role.
  • Strong hands-on experience in cloud security monitoring and incident response across AWS, Azure, or GCP.
  • Proven scripting and automation capability using Python, Go, PowerShell,Bash,etc.
  • Practical experience with SOAR platforms (e.g., CrowdStrike Fusion SOAR) and SIEM technologies (e.g., CrowdStrike Falcon, Splunk, QRadar, Microsoft Sentinel).
  • Deep understanding of EDR tooling, host/network forensics, and detection engineering practices.
  • Strong working knowledge of the MITRE ATT&CK framework and its application in threat detection and hunting.

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Education

Bachelor degree

Experience accepted in place of education

Location requirements

Hiring timezones

United Kingdom +/- 0 hours

About Saviynt

Learn more about Saviynt and their company culture.

View company profile

Saviynt is a provider of intelligent identity and access governance solutions. The company empowers enterprises to secure their digital transformation, safeguard critical assets, and meet regulatory compliance. Saviynt's platform, the Identity Cloud, is designed to provide visibility, control, and intelligence to identity management. It offers a converged approach to identity security that is agile, cloud-based, and scalable to manage and mitigate risk across diverse IT landscapes, including multi-cloud, hybrid, and on-premises environments. The company aims to simplify the complexity of identity security by providing deep visibility and seamless integration across all IT environments.

Founded in 2010, Saviynt has established itself as a leader in the identity management market. The company's solutions address key areas of identity governance, cloud privileged access management (CPAM), and identity analytics and intelligence, helping organizations embrace Zero Trust principles. Saviynt's services are applicable to various sectors, including energy, government, financial services, higher education, healthcare, manufacturing, and retail. The company focuses on modernizing legacy identity governance and administration (IGA) systems and managing multi-cloud environments. Saviynt emphasizes innovation, customer focus, accountability, collaboration, and integrity as its core values. The company is committed to delivering advanced identity solutions that facilitate digital transformation by leading the market in security, ease of use, and organizational impact. Saviynt's mission is to provide intelligent, cloud-first identity governance and access management solutions that enable organizations to achieve Zero-Trust security.

Employee benefits

Learn about the employee benefits and perks provided at Saviynt.

View benefits

Competitive Pay

Saviynt offers competitive compensation packages.

Great Benefits

Saviynt provides a comprehensive benefits package.

Flexible Time Off

Saviynt offers flexible time off to its employees.

Food, Drink & Snacks

Saviynt provides food, drinks, and snacks in the office.

View Saviynt's employee benefits
Claim this profileSaviynt logoSA

Saviynt

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

50 remote jobs at Saviynt

Explore the variety of open remote roles at Saviynt, offering flexible work options across multiple disciplines and skill levels.

View all jobs at Saviynt

Remote companies like Saviynt

Find your next opportunity by exploring profiles of companies that are similar to Saviynt. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan