> Markdown version of [/jobs/ext/1260137-soc-analyst](https://www.wearedevelopers.com/jobs/ext/1260137-soc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SOC Analyst - **Company:** Infrashift Solutions Limited - **Location:** Birmingham, UK (Remote available) - **Salary:** £35,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Application Programming Interfaces (APIs), JIRA, Automation of Tests, Microsoft Azure, Cyber Security, Windows PowerShell, Kusto Query Language, Zero Trust Network Access, Runbook, EndPointSecurity, Data Logging, Microsoft InTune, Patch Management, Microsoft Sentinel, ManageEngine - **Published:** July 14, 2026 - **Apply:** https://www.totaljobs.com/job/soc-analyst/infrashift-solutions-limited-job107682400 ## About the Role * Hands-on experience in a SOC / security analyst role. * Strong working knowledge of Microsoft Sentinel and Defender XDR. * Experience administering Microsoft 365 premium licensing (Business Premium / E5) and the associated security workloads. * Hands-on with ManageEngine Endpoint Central for UEM and patch management. * Proficient in KQL for hunting and detection. * Practical incident response experience across the full lifecycle. * Working knowledge of Jira / Jira Service Management for ticketing and workflow (required). * Strong documentation discipline - logging all changes and maintaining runbooks and operational records. * Understanding of Microsoft 365 / Azure security, identity, and Zero Trust principles. * Clear written and verbal communication for customer-facing work., * SC-200 (Security Operations Analyst); AZ-500 advantageous. * Detection-as-code / automation experience (Graph Security API, PowerShell). * MSP or multi-tenant experience. ## Description Own day-to-day security operations across our customer base - monitoring, triage, investigation and response - and help mature our SOC and MDR delivery as we scale., * Monitor and triage alerts across Microsoft Sentinel and Defender XDR for all managed customers. * Investigate and respond to security incidents; drive containment, eradication and recovery in line with our incident process and SLAs. * Run threat hunting and proactive detection using KQL across Sentinel and the Defender portals. * Execute and improve SOC runbooks, including Microsoft Graph Security API automation. * Manage vulnerability posture: Defender for Endpoint findings, Secure Score, and remediation tracking with customers. * Support endpoint hardening and patch compliance via Intune and ManageEngine Endpoint Central. * Maintain thorough documentation: log all changes and keep SOC runbooks and operational records accurate and current. * Produce clear customer-facing security reporting and contribute to service reviews. * Handle security tickets through Jira Service Management to agreed SLAs. * Feed detections, tuning and lessons learned back into our detection engineering and runbooks., * Meet alert-triage and incident-response SLAs across all managed tenants (=95% within target response times). * Zero critical vulnerabilities or security findings left untracked beyond agreed remediation windows. * Maintain complete, current documentation - all changes logged and runbooks kept up to date. * Deliver at least two detection-rule or runbook improvements per quarter. * Maintain or improve each managed customer's Microsoft Secure Score against its baseline. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Build Delightful Mobile Experiences with Kotlin, Realm, and Atlas Device Sync](https://www.wearedevelopers.com/videos/694-build-delightful-mobile-experiences-with-kotlin-realm-and-atlas-device-sync) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)