> Markdown version of [/jobs/ext/105350-cyber-security-analyst](https://www.wearedevelopers.com/jobs/ext/105350-cyber-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Analyst - **Company:** Admiral - **Location:** UK (Remote available) - **Experience:** Experienced - **Salary:** £43,200.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, CompTIA Security+, Cyber Security, Customer Data Management, Domain Name System (DNS), Python (Programming Language), Windows PowerShell, Phishing, Security Information and Event Management, EndPointSecurity, Scripting, Cybercrime, User Accounts - **Published:** May 30, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=a38c01aaa2038ad4 ## About the Role Do you have experience in Windows?, * 2 years minimum experience as a Cyber Security Analyst * Hands on experience with SIEM or endpoint tools * An understanding of Networking (IP, DNS, HTTP) * Operating systems (Windows fundamentals) * Strong attention to detail * Ability to follow structured processes * Good written and verbal communication skills Desirable * Cyber labs experience (e.g., TryHackMe, Hack The Box) * Entry-level certifications (e.g., CompTIA Security+, SC-200) * Basic scripting knowledge (PowerShell, Python) ## Description As a SOC Analyst, you are the first line of defence against cyber threats targeting Admiral Insurance. You will work as part of a 24/7 global Security Operations Centre across three regions, monitoring, triaging, and escalating security alerts affecting critical financial systems, customer data, and user accounts. The role requires seamless collaboration across regions, ensuring continuous security coverage through effective handover. You will follow structured processes while developing the skills needed to understand how attacks happen and how to investigate them effectively. This role is designed for individuals with a strong interest in cyber security and a willingness to learn quickly in a real-world environment., Alert Monitoring & Triage * Monitor alerts from SIEM platforms, Endpoint detection tools, Identity and access systems. Perform initial triage * Validate whether alerts are true or false positives * Classify severity based on defined criteria * Identify potential impact on financial systems or users Investigation * Conduct investigations using available tools and playbooks * Login activity and user behaviour, Endpoint activity (processes, files, connections) indicators of compromise and threat actor behaviours * Gather relevant evidence before escalation Escalation & Incident Handling * Escalate suspicious or confirmed threats to L2 Analysts * Provide clear, structured evidence including what was detected, what has been checked, why it is suspicious/anomalous/malicious * Playbook execution following predefined runbooks and response procedures, perform response actions where appropriate, ensure consistency and accuracy in all actions Regional Handover Perform structured handovers at shift end, including: * Clear summary of active incidents and investigations * Outstanding actions, risks, and priorities * Relevant evidence, timelines, and analyst observations * Ensure no loss of context or investigative continuity during handover * Adhere to defined handover standards to maintain operational resilience Documentation and Continuous Learning * Maintain accurate and detailed case notes * Log Investigation steps, Findings, Actions taken * Ensure documentation meets audit and regulatory standards * Build knowledge of common cyber threats phishing, malware, credential theft etc * Participate in training sessions, simulated attack exercises, knowledge-sharing within the SOC ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) ## Related Articles - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Data Engineer Salary UK](https://www.wearedevelopers.com/magazine/253-data-engineer-salary-uk)