> Markdown version of [/jobs/ext/2920931-graduate-soc-analyst](https://www.wearedevelopers.com/jobs/ext/2920931-graduate-soc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Graduate SOC Analyst - **Company:** CyPro - **Location:** Slough, UK - **Experience:** Starter - **Salary:** £27,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Microsoft Antivirus, JIRA, Microsoft Azure, Cyber Security, Data Files, Intrusion Detection and Prevention, Microsoft Security Essentials, Microsoft Office, Kusto Query Language, Datadog, Microsoft Power Automate, Mitre Att&ck, Cyber Threat Analysis, Infrastructure Automation Frameworks, Information Technology, Microsoft Sentinel, Programming Languages - **Published:** September 15, 2026 - **Apply:** https://www.collegerecruiter.com/job/2879230425-graduate-soc-analyst ## About the Role You must meet all 5 of these minimum requirements, please do not apply if you do not - your application will be rejected. * Education: You must hold a 2:1 degree (ideally in a science, mathematics or technical subject) or have completed an apprenticeship in a relevant subject area (e.g. Cyber Security, Information Security, Computer Science) studied at a UK/US/Australian/New Zealand/Canadian University or college. You must also hold grade BBB at A-Level (or equivalent) or a Merit T-Level in a relevant subject. * Experience: No experience is necessary, but you should be able to clearly articulate what a role in a Cyber Security Operations Centre entails. * IT literacy: highly confident using Microsoft Office 365 with some experience of other Microsoft tools such as Defender or Azure. * Fluent in English: you must be highly proficient with business-level written and spoken English * Location: must be within a reasonable commute of Canary Wharf, London, * Self-Starters - we're not a large FTSE organisation with a procedure for everything. You'll need to operate in an environment with few guardrails and help build things as we grow., * University educated with a degree from a UK/US/Australian/New Zealand/Canadian University, or an apprenticeship in a subject relevant area * A levels (or equivalent) of grade BBB or above, or a Merit T-Level in a relevant subject * An understanding of and ability to articulate what a role in the SOC entails. * Ability to quickly grasp new technical tasks using a range of different tools. * SC-200 certification or willingness to achieve it * Within commuting distance (~1 hour) of Canary Wharf, London Technical Skills * Familiarity with scripting and automation development (you do not need to be fluent in any particular coding language, but you should be able to demonstrate an understanding of how scripting and other tools (such as AI agents) can be used to streamline tasks. * High-level understanding of the Microsoft security stack (e.g. Defender, Sentinel, Purview, etc.) * Familiarity with incident response frameworks and security best practice Soft Skills * Problem-Solving: Identify, troubleshoot and resolve complex security issues. * Attention to Detail: Ensure accurate detection, analysis and documentation. * Analytical Thinking: Comfortable interpreting complex security data. * Communication: Clear and confident communicator, able to translate technical issues for non-technical audiences. * Calm Under Pressure: Maintain composure during incidents and escalate appropriately. * Accountable & Humble: Take ownership and learn from experience. * Curious: Dive into data sets and problems to uncover patterns and root causes. ## Description * This isn't your typical SOC Analyst role where you're pigeonholed into one narrow specialism. At CyPro, you'll have the opportunity to get involved in a wide range of areas including monitoring, incident response, threat intelligence, detection engineering, automation and internal security operations. * You'll play a key role in our Security Operations Centre, delivering 365-day monitoring, detection and response to our growing customer base. You'll contribute to building out our capabilities, improving tooling and processes, and shaping how we operate as the function matures. * As the team grows further, you'll have the flexibility to focus more deeply on the areas that interest you most - whether that's advanced detection engineering, threat intelligence, incident response leadership or platform automation. If you're ambitious and want to help shape something rather than simply follow a process, this is the right environment for you. Core Responsibilities: Client Support & Reporting * Prepare weekly and monthly SOC reports highlighting activity, incidents and trends. * Join governance calls with senior analysts or managers to present SOC insights. * Communicate independently with clients via email, messenger and Teams call to address queries around incidents, detection coverage and service issues. Security Monitoring & Incident Response * Monitor security alerts generated by Microsoft Sentinel, Microsoft Defender, Datadog and Elastic. * Assess severity and impact of alerts, triage and investigate incidents independently. * Execute containment and remediation actions using defined runbooks and playbooks. * Correlate data across platforms to identify anomalies, malicious patterns and attacker behaviour. * Produce detailed incident reports, RCA and after-action reviews for internal and client use. * Maintain accurate incident records in JIRA Service Management. Detection Engineering * Develop and implement new detection rules in Microsoft Sentinel aligned to the MITRE ATT&CK framework. * Draft and optimise KQL queries for detection and threat hunting. * Refine existing detection logic based on false positive analysis and threat evolution. Threat Intelligence & Enrichment * Analyse threat intelligence feeds to identify relevant threats and vulnerabilities. * Review and tag IOCs and TTPs observed in client environments. * Participate in proactive threat hunting sprints to identify risks before they escalate. Internal Security Operations * Support the management of CyPro's internal security environment. * Administer and monitor identity management solutions. * Manage and maintain our MDM platform to ensure secure and compliant device management. * Help ensure our internal security posture reflects the same standards we deliver to clients. Process Improvement & Automation * Design and develop Logic Apps to automate incident response workflows. * Contribute to evolving internal runbooks and knowledge base articles. * Identify gaps in visibility, tooling or processes and propose solutions. Professional Development * Work toward and maintain relevant certifications (e.g. SC-200, AZ-500). * Stay up to date with current threat trends, attacker TTPs and defensive strategies. * Actively participate in ongoing training and capability development. ## Related Videos - [Debugging in the Dark](https://www.wearedevelopers.com/videos/1658-debugging-in-the-dark) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Introduction to TXT](https://www.wearedevelopers.com/videos/30-introduction-to-txt) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Implementing continuous delivery in a data processing pipeline](https://www.wearedevelopers.com/videos/73-implementing-continuous-delivery-in-a-data-processing-pipeline) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk)