SOC Analyst

ITC Secure
London, UK
25 days ago
Apply on uk.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Shift work
Job source

Tech stack

Data Analysis Software System Penetration Testing CompTIA Security+ Cyber Security Information Management Intrusion Detection and Prevention Network Security Software Vulnerability Management EndPointSecurity Mitre Att&ck Microsoft Sentinel Tools for Reporting
+1 more
Vulnerability Analysis

Job description

Job Purpose: As a member of a team of Security Analysts and Network and Security Engineers within ITC’s Security Operations Centre (SOC) you will provide security analysis of customer security events, monitor and investigate incidents in customer environments with a focus on security event management, vulnerability management, behavioural analytics and MDR for a portfolio of blue-chip and mid-market customers.

Key Interfaces: Operation Centre Team Leads, Customer Security teams, Head of SOC, Service Delivery Managers, Project Engineers, SOC Analysts, Network Security Engineers and Vendors.

The Role will Involve:

  • Analysis and investigation of alerts arising from Security Event and Information Management tools
  • Analysis, investigation and refinement of alerts and reports arising from Network Behaviour Analytics tools
  • Vulnerability Scanning and reporting. Prioritising and tracking remediation of vulnerabilities
  • Utilising Intrusion Prevention solutions to monitor and alert on potential breaches
  • Using packet-capture tools, analyse packet flows and utilise network-based User Behaviour Analytics to understand breaches and track propagation of malware
  • Using Threat Intelligence Services to identify potential new threats and develop new mitigations
  • Working with customer security teams to detect, contain and eradicate threats
  • Understanding of security assessment and penetration testing tools
  • Undertaking other duties from time to time as required

Requirements

  • COMPTIA Security+ (essential)
  • Microsoft SC-200 (desirable)
  • Microsoft AZ-500 / SC-500(desirable)
  • Experience across two or more cybersecurity domains (essential)
  • Security Monitoring & Threat Detection Platforms (e.g., Microsoft Sentinel)
  • Endpoint Detection, Response & Managed Security Services (EDR/XDR/MDR)
  • Network Detection & Behaviour Analytics (e.g., Darktrace, IronNet)
  • Vulnerability Management & Remediation
  • Exposure working with a previous managed security provider or within an MSSP environment (desirable)
  • The ability to communicate fluently and confidently to a high standard in both written and verbal English (essential)
  • Experience using ITSM tools (desirable)
  • Knowledge and understanding of MITRE ATT&CK Framework (desirable)
  • Has a passion for learning to better themselves and their department
  • Has the desire to translate their skills into ways that can improve the function of the Operations Centre
  • Enjoys research into emerging threats in the security landscape and identifying and analysing real-world threats
  • Works collaboratively, shares information, improves documentation and trains colleagues

Working Hours: Our SOC operates 24/7/365. This role follows a dedicated shift pattern (12 hours shifts, 7-7).

Benefits & conditions

Pulled from the full job description

  • Annual leave
  • Company pension
  • Private medical insurance
  • Cycle to work scheme
  • Enhanced maternity leave
  • Enhanced paternity leave, * 24 shifts annual leave.
  • Pension scheme.
  • Private health insurance.
  • Enhanced maternity and paternity leave.
  • Death-in-service life cover.
  • Shopping discounts.
  • Cycle to work scheme.
  • Season ticket/gym loans.
  • Online wellbeing centre.
  • And more!

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on uk.indeed.com
Prepare application

Good distractions

Talks and stories from around this role β€” technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman Β· World Congress 2022

1:48 min

Automating exploratory data analysis within training pipelines

Dora Petrella Β· World Congress 2023

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber Β· World Congress 2026 Europe

1:23 min

Understanding the complexity of cybersecurity domains

Jennifer Reif Β· LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger Β· LIVE

1:36 min

Performing exploratory data analysis to uncover underlying patterns

Julian Joseph Β· LIVE

Videos

See all

Related articles

See all