> Markdown version of [/jobs/ext/1392779-soc-analyst](https://www.wearedevelopers.com/jobs/ext/1392779-soc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SOC Analyst - **Company:** Department for Business and Trade - **Location:** London, UK - **Salary:** £35,367.0 - £41,494.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Data Analysis, Microsoft Azure, Cyber Security, Query Languages, Intrusion Detection and Prevention, Kusto Query Language, Security Information and Event Management, SQL Databases, Data Logging, Cyber Threat Analysis, SC Clearance, Cybercrime - **Published:** July 23, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=942c19104548a68d ## About the Role * Hands-on experience working in a professional Security Operations Centre (SOC), including direct involvement in responding to security alerts using a SIEM, conducting triage, and supporting incident investigations. (Lead Criteria) * Demonstrable operational experience managing cyber security incidents from initial triage through to resolution. (Lead Criteria) * Demonstrable experience investigating security events within cloud platforms (e.g. AWS, Azure). * Demonstrable experience contributing to proactive security activities, such as threat hunting or developing detection rules. * Experience analysing security data using a query language (e.g. KQL, SQL, SPL). Familiarity with KQL (Kusto Query Language) is particularly desirable. * Effective verbal and written communication skills, including the ability to collate and present information clearly and accurately. It is desirable that you have: * Relevant or working towards cyber security certifications or qualifications., * Making Effective Decisions * Working Together Technical skills We'll assess you against these technical skills during the selection process: * Intrusion Detection and Analysis * Threat Understanding * Cyber Security Operations * Threat intelligence and threat assessment * Forensics, This vacancy is using Success Profiles , and will assess your Behaviours, Experience and Technical skills., If there is a high volume of applications, we will sift looking at the first two Lead Criteria only. Hands-on experience working in a professional Security Operations Centre (SOC), including direct involvement in responding to security alerts using a SIEM, conducting triage, and supporting incident investigations. (Lead Criteria) and Demonstrable operational experience managing cyber security incidents from initial triage through to resolution. You may then be progressed to full sift or straight to interview. At the interview stage for this role, you will be asked to demonstrate relevant Technical Skills and Behaviours from the Success Profiles framework, which are listed above. These are role specific and in line with the DDaT Capability Framework . Offers will be made in merit order based on location preferences. If you pass the bar at interview but are not the highest scoring you will be held on a 12-month reserve list in case a role becomes available. If you are judged a near miss at interview, you may be offered a post at the grade below the one you applied for. This role requires SC clearance. DBT’s requirement for SC clearance is to have been present in the UK for at least 3 of the last 5 years. Failure to meet this requirement will result in your application being rejected and your offer will be withdrawn. ## Description The Department for Business and Trade (DBT) has a clear mission - to grow the economy. Our role is to help businesses invest, grow and export to create jobs and opportunities right across the country. We do this in three ways. Firstly, we help to build a strong, competitive business environment, where consumers are protected and companies rewarded for treating their employees properly. Secondly, we open international markets and ensure resilient supply chains. This can be through Free Trade Agreements, trade facilitation and multilateral agreements. Finally, we work in partnership with businesses every day, providing advance, finance and deal-making support to those looking to start up, invest, export and grow. The Digital, Data and Technology (DDaT) directorate develops and operates tools and services to support us in this mission. The team have been nominated four times in a row for ‘Best Public Sector Employer’ at the Women in Tech awards and won the award in 2025!, We are looking for a capable and motivated SOC Analyst to join the Cyber Incident Detection and Response team and help strengthen our cyber defence capabilities. In this role, you will play a key part in protecting the department’s systems and data. You will monitor, triage and investigate security alerts, identifying genuine threats and ensuring incidents are accurately assessed, documented and escalated where appropriate. You will also support incident response activities, working closely with Senior Analysts and wider technical teams to deliver effective and coordinated responses. Alongside operational responsibilities, you will have dedicated time to focus on proactive work. This includes contributing to the improvement of detection rules, refining alerts, supporting threat hunting, and helping to develop repeatable processes and playbooks. At this level, we are looking for someone who is curious, collaborative and able to use sound judgement in a fast-paced environment. You will manage your workload effectively, communicate clearly with a range of stakeholders, and take ownership of your work while contributing positively to the team. We are committed to your development, offering protected learning time, access to training platforms, and opportunities to attend external courses and industry events such as SANS. Main responsibilities You will: * Triage, investigate, and resolve security alerts and incidents in line with established processes, ensuring a timely and effective response. * Contribute to the development and refinement of incident response procedures, playbooks, and documentation. * Support the continuous improvement of logging, monitoring, and alerting capabilities to enhance threat visibility. * Provide support and advice to stakeholders and colleagues. * Maintain awareness of emerging threats, vulnerabilities, and trends to support effective detection and response. * Use time away from live operations to develop key SOC capabilities, including alert refinement, dashboard creation, and engagement across the wider Cyber team., * departmental or company records (personnel files, staff reports, sick leave reports and security records) * UK criminal records covering both spent and unspent criminal records * your credit and financial history with a credit reference agency * security services record * location details, * UK nationals * nationals of the Republic of Ireland * nationals of Commonwealth countries who have the right to work in the UK * nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities with settled or pre-settled status under the European Union Settlement Scheme (EUSS) * nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities who have made a valid application for settled or pre-settled status under the European Union Settlement Scheme (EUSS) * individuals with limited leave to remain or indefinite leave to remain who were eligible to apply for EUSS on or before 31 December 2020 * Turkish nationals, and certain family members of Turkish nationals, who have accrued the right to work in the Civil Service ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Build Delightful Mobile Experiences with Kotlin, Realm, and Atlas Device Sync](https://www.wearedevelopers.com/videos/694-build-delightful-mobile-experiences-with-kotlin-realm-and-atlas-device-sync) ## Related Articles - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Data Engineer Salary UK](https://www.wearedevelopers.com/magazine/253-data-engineer-salary-uk) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [UK Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/326-uk-business-culture-and-etiquette)