Senior SOC Analyst
Network IT Recruitment
Milton Keynes, UK
2 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.totaljobs.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
£156,000.0
Working hours
Shift work
Job source
Tech stack
Business Analytics Applications
Cyber Security
Intrusion Detection and Prevention
Log Analysis
Cloud Services
Security Information and Event Management
Mitre Att&ck
Cyber Threat Analysis
Microsoft Sentinel
Job description
- Monitor the organisation’s technology estate to identify cyber security events, suspicious activity and indicators of compromise using approved monitoring platforms and analytical tools.
- Independently investigate security alerts and complex cyber security events, determining their significance, potential impact and appropriate course of actions.
- Correlate information from multiple data sources to establish attack timelines, identify affected systems and support the assessment of cyber security incidents.
- Analyse indicators of compromise, attacker techniques and available threat intelligence to determine the nature and severity of security events.
- Escalate indicators confirmed or suspected cyber security incidents to the Lead SOC Analyst or Incident Responder team in accordance with established operational procedures.
- Support Incident Responders by providing accurate analytical findings, supporting evidence, timelines and technical information throughout incident investigations.
- Contribute to the continual improvement of monitoring capability by identifying opportunities to improve alert quality, investigation processes, monitoring coverage and detection effectiveness.
- Validate new monitoring content, detection rules and operational procedures before deployment into the live SOC environment.
- Assist in the onboarding of new systems, cloud services and application into SOC monitoring by validating operational visibility and monitoring effectiveness.
- Maintain accurate investigations records, ensuring all analytical activities are fully documented in accordance with organisational procedures.
- Share knowledge, provide technical guidance and support the development of Practitioner SOC Analysts through coaching and day-to-day mentoring.
- Contribute to operational reviews, lessons identified and post-incident activities, recommending improvements to monitoring capability and operational processes.
- Maintain awareness of emerging cyber threats, attacker techniques and monitoring technologies to support continual professional development and improved operational effectiveness
Requirements
- The Senior SOC Analyst should demonstrable knowledge and skills in the areas: Cyber security operations, Forensics, Incident management, incident investigation and response, Information risk assessment and risk management, Intrusion detection analysis, Protective security, Secure operations management, Threat intelligence and threat assessment
- Experience working within a SOC or comparable cyber security operations environment.
- Experience investigating cyber security alerts and security events using enterprise monitoring techniques.
- Good knowledge of SIEM platforms, security monitoring tools and log analysis techniques.
- Understanding of cyber attack methodologies, indicators or compromise, threat intelligence and common attacker techniques.
- Experience analysing information from multiple technical sources to investigate cyber security events.
- Experience supporting cyber incident response activities.
- Strong analytical and problem-solving skills with the ability to made sound technical judgements.
- Good written and verbal communication skills with the ability to produce accurate technical reports and investigation findings.
- Ability to work effectively within a shift-based 24/7 environment.
- Professional certifications such as Microsoft SC-200, CompTIA CySA+, GIAC, GCIA or equivalent
Desirable:
- Experience using Microsoft Sentinel, LogRhythm, or equivalent enterprise SIEM platforms.
- Experience developing monitoring improvements, detection tuning, or operational process development.
- Experience supporting Incident Responder activities during major cyber security incidents.
- Experience contributing to the development of monitoring use cases and detection improvements.
- Applied knowledge of MITRE ATT&CK or equivalent adversary behaviour frameworks.
Benefits & conditions
12 Hour shifts (7am-7pm & 7pm-7am) 7 Days & 7 Nights over a 4-week pattern 6 month contract initially Buckinghamshire
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.totaljobs.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
EM
Eli McGarvie
about 3 years ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
over 2 years ago
EM
Eli McGarvie
IT Salaries in UK
about 3 years ago
LM
Luis Minvielle
Is Software Engineering Over-Saturated?
over 2 years ago
EM
Eli McGarvie
Software Engineer Salary London
over 3 years ago
LM
Luis Minvielle
The Most Popular IT Jobs on the Market
over 2 years ago