SOC Analyst

Sopra Steria Limited
Farnborough, United Kingdom
5 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Shift work
Languages
English
Compensation
£ 58K

Job location

Farnborough, United Kingdom

Tech stack

Antivirus Softwares
Bash
C++
Client Server Models
CompTIA Security+
Computer Security
Computer Programming
Relational Databases
Perl
Hypertext Transfer Protocols (HTTP)
Internet Protocol
Virtual Private Networks (VPN)
Python
Local Area Networks
Lightweight Directory Access Protocols (LDAP)
Simple Mail Transfer Protocols
Powershell
Security Information and Event Management
TCP/IP
Wide Area Networks
Web Applications
Enterprise Data Management
Scripting (Bash/Python/Go/Ruby)
File Transfer Protocol (FTP)
Mitre Att&ck
QRadar
Firewalls (Computer Science)
Microsoft Sentinel
Splunk

Job description

We're expanding our Security Operations Centre in Farnborough and looking for sharp, collaborative L2 SOC Analysts to protect enterprise-scale environments across the Defence sector. You'll investigate real threats, tune detections, and make measurable impact-using Microsoft Sentinel, Splunk, and MISP.

Your work fuels national security. Your growth fuels our mission.

Role based on site in our Farnborough office and is shift work. 2 x 6am to 6pm, 2 x 6pm to 6am, 4 days off.

You do need to be eligible for DV Clearance for this role, and cannot start until your clearance is through.

What you'll be doing:

  • Monitor, analyse security alerts and events, conduct initial investigations, and determine the appropriate response.
  • Raise complex incidents to Senior Analysts.
  • Manage SOC Incident queues.
  • Support the maintenance of monitored asset baselines of the customer environments.
  • Prepare reports for managed clients to both technical and non-technical audiences,
  • Collaborate on improving detection rules and use cases aligned with Mitre Att&ck and threat-informed defense.
  • Participate in a team effort to guarantee that corporate data and technology platform components are shielded from known threats.
  • Collaborate with team members to maintain and update security incident documentation, including incident reports, analysis findings, and recommended mitigation strategies.
  • Aid the development and use of threat intelligence throughout the service.
  • Ability to work shifts from our office in Farnborough.

Requirements

  • Experience demonstrated in Security Operations Centre.
  • Experience using Microsoft Sentinel and Splunk.
  • Knowledge and experience with Mitre Att&ck Framework.
  • Basic knowledge of client-server applications, multi-tier web applications, relational databases, firewalls, VPNs, and enterprise AntiVirus products.
  • Understanding of networking principles including TCP/IP, WANs, LANs and commonly used Internet protocols such as SMTP, HTTP, FTP, POP, LDAP.
  • Entry level cyber security certification (e.g. CompTIA Security+, CEH, CPSA).
  • CREST Practitioner Intrusion Analyst/Blue Teams Level 1 or other SOC related certifications.
  • Completed an academic module in cyber security or a related subject

It would be great if you had:

  • Programming and scripting such as Python, Perl, Bash, PowerShell, C++.
  • CREST Practitioner Intrusion Analyst/Blue Teams Level 1 or other SOC related certifications.
  • Experience with SIEM technologies, namely Sentinel and Splunk, with some experience with QRadar.

About the company

Sopra Steria's Aerospace, Defence and Security business designs, develops and deploys digital solutions to Central Government clients. The work we do makes a real difference to the client's goal of National Security, and we operate in a unique and privileged environment. We are given time for professional development activities, and we coach and mentor our colleagues, sharing knowledge and learning from each other. We foster a culture in which employees feel valued and supported and have pride in their work for the customer, delivering outstanding rates of customer satisfaction in the UK's most complex safety- and security-critical markets.

Apply for this position