SOC Analyst
Role details
Job location
Tech stack
Job description
This role sits within the Detect & Respond sub-team of the Group Security Operations Centre, under the Cyber Security tower in Security & Resilience. Working with the team you will be analysing and responding to security events as they surface, making initial judgements as to possible severity, seeking support and guidance where needed, and escalating or developing mitigation recommendations to help defend our systems and data. Your role will often require close collaboration with other parts of the business to help identify, enable, and drive the right investigation steps and response actions[INS: . :INS] The GSOC defends the whole of Nationwide and Virgin Money's estate, both Member-facing and support capabilities, requiring engagement and communication with both technical and non-technical teams across the business. You'll help mature our internal processes, developing or defining appropriate detection, response and containment capabilities as well as contributing to the GSOC Strategy. You will help shape our future technology direction, suggesting and assisting with innovative ways to combat contemporary cyber threats so we remain fit to find and confront malicious activity. What you'll be doing
- You'll be handling cyber security alerts from triage through to closure, making and evidencing high quality decisions and escalating where appropriate
- There will be opportunities to play a supporting role in Incident Response activities to enable the prompt identification, investigation and mitigation of threats, acting across various roles and responsibilities to achieve cyber risk reduction in cloud, hybrid and on-premises environments
- You'll be expected to identify potential service improvements to enable GSOC Detect & Respond to operate more effectively and efficiently, providing feedback and taking ownership to deliver improvement activities where appropriate
- Supporting BAU operational demands, including process/playbook development, use case review, and the collection and production of Management Information
- This role will require you to work closely with other teams across S&R, TOCs and COO to drive positive security outcomes, As a Disability Confident Leader, we're committed to removing any obstacles to inclusion. If you need any reasonable adjustments or support making your application, contact our Talent Acquisition team careers@virginmoney.com Please note: If we receive a high volume of eligible applications, we may need to prioritise candidates whose skills and experience most closely align with the role, while still ensuring fair and equitable consideration for all applicants. Now the legal bit We're in the process of bringing Virgin Money and Nationwide together which, subject to Court approval, will happen on 2 April 2026. You can find out more about what this means at https://uk.virginmoney.com/nationwide-transfer. If you're successful in securing a role with us, your employment will move automatically to Nationwide when this transfer goes ahead. Although some of our roles allow you to be based anywhere in the UK, we'll need you to confirm you have the right to work in the UK. If you're successful in securing a role with us, there are some checks you need to complete before starting. These include credit and criminal record checks and three years' worth of satisfactory references. If the role is part of the Senior Manager Regime and Certification Regime, it requires enhanced pre-employment checks - we'll ask for six years of regulatory references, and once in the role, you'll be subject to periodic employment checks.
Requirements
-
Experience of working within a Cyber Security (e.g., SOC, Cyber Incident Response, Penetration Testing) or IT (e.g. Service Disk, Sysadmin) role
-
A problem-solving mindset, with the ability to use structured and analytical approaches
-
Demonstrable knowledge of basic IT concepts, including but not limited to Networking, Hardware, Operating Systems & Cloud Computing
-
Working knowledge of core Cyber Security concepts and tooling, and the ability to apply this understanding to investigations
-
The ability to build good working relationships with both technical and business stakeholders, gaining their respect and trust based on your knowledge and professionalism
-
The ability and desire to quickly learn new technologies It's a bonus if you have but not essential
-
CompTIA Security+ (or equivalent Defensive Security certification)
-
CompTIA Network+ (or equivalent Networking certification)
-
Certified Ethical Hacker (or equivalent Offensive Security certification)
-
MS SC-200 (or equivalent Security Tooling certification)