> Markdown version of [/jobs/ext/2688280-soc-analysts-l2-and-l3-sc-and-dv-cleared](https://www.wearedevelopers.com/jobs/ext/2688280-soc-analysts-l2-and-l3-sc-and-dv-cleared). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SOC Analysts - L2 and L3 (SC and DV-Cleared) - **Company:** Pigment Consulting - **Location:** Manchester, UK - **Salary:** £14,560.0 - £49,920.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Phishing, Security Information and Event Management, Mitre Att&ck, Malware, Cybercrime, 3-tier Architectures - **Published:** September 3, 2026 - **Apply:** https://www.careerboard.com/pt/en/find-jobs-in-United-Kingdom/-6C9F8861D0DB2129D8/ ## About the Role * Proven experience within a SOC, security monitoring or incident response environment. * Strong SIEM and security event investigation experience. * Experience with EDR/XDR technologies. * Good understanding of cyber attack techniques and MITRE ATT&CK. * Experience investigating common security incidents and threats. * For Tier 3, the ability to lead complex investigations and provide technical direction Due to the sensitive nature of our work, our consultants must have an active SC or DV Clearance, and be able to work fully on-site in Manchester when on shift. At Pigment, working together collaboratively to form a cohesive and blended team is at the heart of what we do. We therefore are seeking consultants who natural embody this, who are naturally cooperative and happy to work closely with others, empowering the wider team through knowledge transfer and teamwork. If you are passionate about making a difference to the public sector while leveraging your SOC expertise, then we would love to hear from you! Please apply promptly and one of our team will be in touch to discuss. ## Description Tier 2 SOC Analyst You will be responsible for investigating and responding to security incidents escalated from Tier 1, including: * Detailed investigation of SIEM, EDR, network and authentication alerts. * Threat hunting and identification of indicators of compromise. * Investigation of phishing, malware, credential compromise and suspicious activity. * Supporting containment, eradication and recovery. * Developing and improving detection rules and playbooks. * Producing high-quality incident documentation and reports. * Supporting and mentoring Tier 1 analysts. Tier 3 SOC Analyst As a Tier 3 Analyst, you'll provide advanced technical investigation and act as a senior escalation point for complex incidents. Responsibilities include: * Leading complex and high-severity security investigations. * Advanced threat hunting and incident response. * Malware, endpoint, network and forensic investigation. * Developing advanced detections and response capabilities. * Root-cause analysis and post-incident investigation. * Supporting major incident response. * Working closely with security engineering and infrastructure teams. * Providing technical guidance and mentoring to Tier 1 and Tier 2 SOC analysts. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 196: AI Killed DevOps, LLM Political Bias & AI Security](https://www.wearedevelopers.com/magazine/659-dev-digest-196-ai-killed-devops-llm-political-bias-ai-security)