About Unity Advisory
Unity Advisory is a modern advisory business built for today's CFO. It combines deep expertise with an AI-native operating model designed to deliver better evidence, faster execution and stronger client outcomes.
Through direct access to the expertise needed to solve complex challenges and a pace of delivery that enables organisations to seize opportunities, Unity delivers advisory as it should be, through a model that is free from audit conflict.
The Role
The Sec Ops Analyst owns hands-on security monitoring and assurance across our Microsoft, AWS and Databricks environments. Working closely with our managed SOC, you'll investigate alerts and incidents, close monitoring gaps, and keep our ISO/IEC 27001:2022 controls backed by complete, audit-ready evidence — including running customer and client security-assurance questionnaires on the business's behalf.
Responsibilities
- Monitor, correlate and triage security alerts and activity across Microsoft 365, Azure, Entra ID, AWS, Databricks, endpoints and network services, using native tools and the central SIEM.
- Act as the primary internal contact for the managed SOC, owning incidents, escalations and follow-up through to resolution within agreed service levels.
- Close monitoring gaps by improving detection use cases, alert logic, playbooks and escalation criteria.
- Own the evidence cycle for ISO/IEC 27001:2022 controls — mapping, collecting and maintaining audit-ready evidence, and resolving gaps with control owners.
- Support internal, certification and surveillance audits, tracking findings and corrective actions to closure.
- Monitor privileged access and authentication activity, review vulnerability findings, and use Microsoft Purview to manage data protection and DLP risk.
- Complete customer and third-party security assurance questionnaires with accurate, evidence-backed responses.
- Run phishing simulations and security-awareness activity, and report on incidents, vulnerabilities and control evidence to technical and non-technical stakeholders.
Qualifications
- Hands-on SecOps experience using SIEM, EDR/XDR and cloud/identity telemetry, ideally with a managed SOC.
- Practical Microsoft security experience (Sentinel, Defender, Entra ID, Purview) and exposure to AWS; Databricks familiarity a plus.
- Demonstrable ISO/IEC 27001:2022 experience — collecting and presenting control evidence, resolving gaps, supporting audits.
- Experience completing client security assurance questionnaires.
- Strong analytical and stakeholder-management skills, comfortable managing multiple incidents and audit requests at once.
- Desirable: Cyber Essentials Plus exposure, GRC/evidence-management platforms, and certifications such as ISO 27001 Lead Implementer, SC-200 or Security+.
Work Environment
A truly hybrid and flexible working environment, at the forefront of AI-driven advisory. You'll have real input into how security operations are run and evidenced from day one.
Additional Information
At Unity Advisory, we are committed to providing an inclusive and accessible recruitment process. In line with the Equality Act 2010, we will accommodate any suitable candidate requiring assistance to attend or conduct an interview. Please let us know if you need any adjustments when scheduling your interview or in your cover letter.
PLEASE NOTE: We do not accept unsolicited CVs from third-party agencies.