> Markdown version of [/jobs/ext/1418499-soc-analyst](https://www.wearedevelopers.com/jobs/ext/1418499-soc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SOC analyst - **Company:** CGI Group Inc. - **Location:** London, UK - **Contract:** Permanent contract - **Skills:** Cyber Security, Hypertext Transfer Protocols (HTTP), Internet Protocol, Local Area Networks, Lightweight Directory Access Protocols (LDAP), Simple Mail Transfer Protocols, Networking Basics, ArcSight SIEM Tool, Phishing, Security Information and Event Management, TCP/IP, Wide Area Networks, File Transfer Protocol (FTP), Mitre Att&ck, QRadar, Malware, Cybercrime, Splunk, Security Orchestration, Automation & Response - **Published:** July 24, 2026 - **Apply:** https://www.free-work.com/en-gb/tech-it/job-mission/other/soc-analysts-dv-security-clearance ## About the Role Be willing to learn how to resolve technical issues. . Demonstrate an interest in Cyber Security. . Be detail orientated and show the ability to take a structured approach to procedures and working instructions. . Have an aptitude for understanding and analysing data for troubleshooting purposes. . Strong written communication, critical thinking, and analysis skills. . Understanding of key security concepts and attack types such as phishing, malware, vulnerabilities, Cyber Kill Chain, and attack stages. . Understanding of networking principles including TCP/IP, WANs, LANs, and commonly used Internet protocols such as SMTP, HTTP, FTP, POP, LDAP . An analytical mindset, capable of digesting a wide range of information and making practical judgements based on available data and context. . A desire to keep learning with a curious and creative mindset. . Knowledge of Security Tooling (ArcSight, Splunk, MS Sentinel, FortiSIEM, SwimLane, QRadar LogPoint) #LI-JS2 ## Description The SOC Analyst will be joining an established SOC Team of eight years. The SOC analyst will be the first to respond to cyber security incidents. They will be required to report on cyber threats and will work as part of an expanding security team, working alongside security managers and cybersecurity engineers. . The SOC utilise both tried and tested tooling and state of the art technologies and methods to ensure we provide the best level of service and protection to our prestigious list of clients. Our client base covers a wide range of verticals from Government and CNI. Security Clearance Required. Due to the nature of the work and the security clearance required we can only accept UK Nationals with single nationality Candidate profile The role will require someone with an analytical mindset and a keen eye for detail to investigate alerts, piece together information to build a bigger picture and provide suitable remediation steps for customers. Monitoring our SIEM (Security Incident and Event Management) and SOAR (Security Orchestration, Automation and Response) tools to detect suspicious events and abnormal activities. . Triaging events through validating suspicious events and incidents by use of dedicated tools. . Ability to escalate with effective reporting to level 3 SOC Analyst or Seniors Stakeholders. . Documenting and managing incident cases to utilise information for stakeholder engagement to provide insight and intelligent recommendations. . Providing incident management through effective monitoring, reporting and technical guidance for successful resolution. . Production of the monthly security reports. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Getting under the skin: The Social Engineering techniques](https://www.wearedevelopers.com/videos/38-getting-under-the-skin-the-social-engineering-techniques) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [Debunking the Top 10 Myths about Web 3](https://www.wearedevelopers.com/videos/634-debunking-the-top-10-myths-about-web-3) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk)