> Markdown version of [/jobs/ext/2801091-graduate-soc-analyst](https://www.wearedevelopers.com/jobs/ext/2801091-graduate-soc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Graduate SOC Analyst - **Company:** CyPro - **Location:** London, UK - **Experience:** Starter - **Contract:** Permanent contract - **Skills:** Microsoft Antivirus, JIRA, Microsoft Azure, Cyber Security, Intrusion Detection and Prevention, Microsoft Office, Kusto Query Language, Datadog, Mitre Att&ck, Cyber Threat Analysis, Infrastructure Automation Frameworks, Information Technology, Microsoft Sentinel - **Published:** September 9, 2026 - **Apply:** https://www.collegerecruiter.com/job/2842870371-graduate-soc-analyst ## About the Role * Education: You must hold a 2:1 degree (ideally in a science, mathematics or technical subject) or have completed an apprenticeship in a relevant subject area (e.g. Cyber Security, Information Security, Computer Science) studied at a UK/US/Australian/New Zealand/Canadian University or college. You must also hold grade BBB at A-Level (or equivalent) or a Merit T-Level in a relevant subject. * Experience: No experience is necessary, but you should be able to clearly articulate what a role in a Cyber Security Operations Centre entails. * IT literacy: highly confident using Microsoft Office 365 with some experience of other Microsoft tools such as Defender or Azure. * Fluent in English: you must be highly proficient with business-level written and spoken English * Location: must be within a reasonable commute of Canary Wharf, London ## Description * This isn't your typical SOC Analyst role where you're pigeonholed into one narrow specialism. At CyPro, you'll have the opportunity to get involved in a wide range of areas including monitoring, incident response, threat intelligence, detection engineering, automation and internal security operations. * You'll play a key role in our Security Operations Centre, delivering 365-day monitoring, detection and response to our growing customer base. You'll contribute to building out our capabilities, improving tooling and processes, and shaping how we operate as the function matures. * As the team grows further, you'll have the flexibility to focus more deeply on the areas that interest you most - whether that's advanced detection engineering, threat intelligence, incident response leadership or platform automation. If you're ambitious and want to help shape something rather than simply follow a process, this is the right environment for you., * Prepare weekly and monthly SOC reports highlighting activity, incidents and trends. * Join governance calls with senior analysts or managers to present SOC insights. * Communicate independently with clients via email, messenger and Teams call to address queries around incidents, detection coverage and service issues. Security Monitoring & Incident Response * Monitor security alerts generated by Microsoft Sentinel, Microsoft Defender, Datadog and Elastic. * Assess severity and impact of alerts, triage and investigate incidents independently. * Execute containment and remediation actions using defined runbooks and playbooks. * Correlate data across platforms to identify anomalies, malicious patterns and attacker behaviour. * Produce detailed incident reports, RCA and after-action reviews for internal and client use. * Maintain accurate incident records in JIRA Service Management. Detection Engineering * Develop and implement new detection rules in Microsoft Sentinel aligned to the MITRE ATT&CK framework. * Draft and optimise KQL queries for detection and threat hunting. * Refine existing detection logic based on false positive analysis and threat evolution. * Analyse threat intelligence feeds to identify relevant threats and vulnerabilities. * Review and tag IOCs and TTPs observed in client environments. * Participate in proactive threat hunting sprints to identify risks before they elevate. ## Related Videos - [Debugging in the Dark](https://www.wearedevelopers.com/videos/1658-debugging-in-the-dark) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Software Engineering Social Connection: Yubo’s lean approach to scaling an 80M-user infrastructure](https://www.wearedevelopers.com/videos/1583-software-engineering-social-connection-yubo-s-lean-approach-to-scaling-an-80m-user-infrastructure) ## Related Articles - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london)