Level 3 SOC Analyst

Capita resourcing
Belfast, UK
14 days ago
Apply on uk.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Macintosh Computers Software System Penetration Testing Cloud Computing Cyber Security Information Systems Linux DevOps Microsoft Software Open Source Technology Parsing Kusto Query Language
+8 more
Security Information and Event Management Manual Data Entry Microsoft Power Automate QRadar Cyber Threat Analysis Azure Security Center SC Clearance Microsoft Sentinel

Job description

As an experienced Senior Cyber Security Operations Analyst, you will be responsible for handing security incidents received/escalated from the CSOC Analyst (Tier 1 or Tier 2) and perform a business impact analysis on the security incident.

You will leverage a deep understanding of information security technologies, you will aid in triaging threat intelligence from multiple sources and add contextual information to the security incident, perform additional analysis and based on the business impact will recommend the response actions and escalation path.

You will be guided by Threat Intelligence which is actionable information (e.g. IOCs/TTPs), conduct threat hunting activities; leveraging and analyzing sources of information as available through the SIEM, in addition identify and investigate potential suspicious activity as well as helping organizations identify, isolate and contain security issues.

You will support the initial implementation and management of security related technologies, including (but not limited to) IBM QRadar, Microsoft Sentinel, MDE, MDI and Defender for Cloud.

Successful candidate must hold - SC-200 Certification

Successful candidate must be eligible for SC clearance, * Oversee completion of day-to-day checklist(s), including log review, management report scheduling & running, alert analysis, and escalation follow up

  • Remain current on cyber security trends and intelligence (open source and commercial) in order to guide the security analysis & identification capabilities of the CSOC team
  • Provide oversight, guidance and mentoring to L2 & L3 analysts, and fulfil SOC Manager responsibilities in the absence of the SOC Manager
  • Oversee a number of analysts as part of a virtual team of L1 and L2 analysts, including objectives setting, performance management / reviews, training & development, and BAU activities including shift cover etc.
  • Perform advanced event and incident analysis, including baseline establishment and trend analysis.
  • Support on-call arrangements as part of a Rota, to support L1 Analysts working out of hours
  • Support Major Incident Response activity, from a Protective Monitoring perspective, including supporting teams in identification, containment, and remediation of security related threat.
  • Provide timely advice and guidance on the response action plans for events and incidents based on incident type and severity.
  • Identify, create and implement improvements to procedures and processes, with the SOC Manager’s approval.
  • Identify opportunities for SOC and client SIEM platform configuration improvements, use case development, monitoring rule creation, tuning & optimization.
  • Stakeholder and Client Reporting, and engagement
  • Assist in architectural design to facilitate the onboarding of new information systems, including the assessment, parsing, onboarding of log sources, and use case and rule development., We prioritise our customers by delivering effective cyber security monitoring, incident response, and expert guidance that protects their services and supports their success. Fearless Innovation We embrace continuous improvement by identifying new threats, enhancing detection capabilities, and driving innovative security solutions that strengthen our services. Achieve Together We collaborate across teams, share knowledge, and support one another to deliver outstanding security outcomes and achieve our collective goals. Everyone is Valued We foster an inclusive and supportive environment where every colleague is respected, empowered to develop, and encouraged to contribute their unique perspectives.

Join Capita - Where Innovation Meets Opportunity, We are committed to building a workforce that reflects the diversity of the communities we serve. As part of our strategic goals, we are focused on accelerating gender and ethnic representation in leadership roles. We warmly encourage applications from women and individuals from Black, Asian, and other ethnic minority backgrounds. We’re an equal opportunity and Disability Confident employer, which means we recruit and develop people based on their merit and passion. We’re committed to providing an inclusive, barrier-free recruitment process and working environment for everyone. If you need the job description or application form in an alternative format (such as large print or audio), or if you’d like to discuss other changes or support you might need going forward, please email reasonableadjustments@capita.com and we’ll get back to you. For more information about equal opportunities and process adjustments, please visit the Capita Careers website.

Requirements

  • Level 3 SOC Analyst / Senior Cyber Security and security operations experience
  • Experience of onboarding, tuning, reporting and configuring SIEM solutions
  • Experience of threat intelligence
  • Leadership and mentoring experience and skills
  • Understanding of low-level concepts including operating systems and networking
  • Commercial experience in Penetration Testing and / or Security Monitoring
  • Understanding of networking and infrastructure design
  • Knowledge/experience of one or more System administration (Linux, Windows, Mac)
  • Self-motivated individual with flexible approach to working.
  • Excellent interpersonal skills with the ability to explain technical problems to non-technical business stakeholders at all levels.
  • Strong written and oral communication skills
  • Active or ability to obtain SC clearance, IT Certifications, including Network+, Security+ Protective Monitoring / SOC Certifications, including CySA+ Cyber Security Certifications, including CISMP, CISSP Experience with various Microsoft Technologies, including Microsoft Defender for Endpoint, Identity and Cloud Experience with SIEM platforms, including IBM QRadar, Microsoft Sentinel and LogRhythm In-depth experience with Microsoft Sentinel, including use case and rule development, workbook / playbook creation, KQL & Logic Apps / SOAR Experience in managing Microsoft Sentinel as an MSSP, including Lighthouse, and management and multi-customer environments using DevOps

Benefits & conditions

Pulled from the full job description

  • Company pension
  • Paid volunteer time
  • Cycle to work scheme, * Competitive salary
  • 23 days’ holiday, rising to 27 (pro rata) - plus the option to buy more after qualifying period
  • ️ Paid volunteering day with a charity of your choice
  • Generous family leave policies - including 15 weeks’ fully paid maternity, adoption, and shared parental leave
  • ️ Cycle2Work scheme, pension, life assurance, and more

Customer first, always Fearless innovation Achieve together

Everyone is valued

About the company

At Capita, we live by our values: Customer First, Always; Fearless Innovation; Achieve Together; Everyone is Valued. These guide how we work, collaborate, and deliver exceptional results.

Job title, Capita is a dynamic leader in consulting and digital services, helping some of the UK’s most recognised organisations transform and thrive. We use cutting-edge technology and fearless innovation to create smarter, more efficient solutions that make a real difference. Our work spans diverse sectors-government, healthcare, education, and finance-offering you the chance to contribute to projects that impact millions of lives. At Capita, you’ll be part of a collaborative, forward-thinking team that values creativity, growth, and inclusion.

We’re committed to your development and success, providing opportunities to learn, progress, and shape better outcomes for customers and communities. If you’re ready to make an impact and grow your career, Capita is the place for you. Check out our website www.capita.com

What’s in it for you?

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on uk.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all