Senior SOC Analyst

Network IT Recruitment
Milton Keynes, UK
2 days ago
Apply on www.totaljobs.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
£156,000.0
Working hours
Shift work

Tech stack

Business Analytics Applications Cyber Security Intrusion Detection and Prevention Log Analysis Cloud Services Security Information and Event Management Mitre Att&ck Cyber Threat Analysis Microsoft Sentinel

Job description

  • Monitor the organisation’s technology estate to identify cyber security events, suspicious activity and indicators of compromise using approved monitoring platforms and analytical tools.
  • Independently investigate security alerts and complex cyber security events, determining their significance, potential impact and appropriate course of actions.
  • Correlate information from multiple data sources to establish attack timelines, identify affected systems and support the assessment of cyber security incidents.
  • Analyse indicators of compromise, attacker techniques and available threat intelligence to determine the nature and severity of security events.
  • Escalate indicators confirmed or suspected cyber security incidents to the Lead SOC Analyst or Incident Responder team in accordance with established operational procedures.
  • Support Incident Responders by providing accurate analytical findings, supporting evidence, timelines and technical information throughout incident investigations.
  • Contribute to the continual improvement of monitoring capability by identifying opportunities to improve alert quality, investigation processes, monitoring coverage and detection effectiveness.
  • Validate new monitoring content, detection rules and operational procedures before deployment into the live SOC environment.
  • Assist in the onboarding of new systems, cloud services and application into SOC monitoring by validating operational visibility and monitoring effectiveness.
  • Maintain accurate investigations records, ensuring all analytical activities are fully documented in accordance with organisational procedures.
  • Share knowledge, provide technical guidance and support the development of Practitioner SOC Analysts through coaching and day-to-day mentoring.
  • Contribute to operational reviews, lessons identified and post-incident activities, recommending improvements to monitoring capability and operational processes.
  • Maintain awareness of emerging cyber threats, attacker techniques and monitoring technologies to support continual professional development and improved operational effectiveness

Requirements

  • The Senior SOC Analyst should demonstrable knowledge and skills in the areas: Cyber security operations, Forensics, Incident management, incident investigation and response, Information risk assessment and risk management, Intrusion detection analysis, Protective security, Secure operations management, Threat intelligence and threat assessment
  • Experience working within a SOC or comparable cyber security operations environment.
  • Experience investigating cyber security alerts and security events using enterprise monitoring techniques.
  • Good knowledge of SIEM platforms, security monitoring tools and log analysis techniques.
  • Understanding of cyber attack methodologies, indicators or compromise, threat intelligence and common attacker techniques.
  • Experience analysing information from multiple technical sources to investigate cyber security events.
  • Experience supporting cyber incident response activities.
  • Strong analytical and problem-solving skills with the ability to made sound technical judgements.
  • Good written and verbal communication skills with the ability to produce accurate technical reports and investigation findings.
  • Ability to work effectively within a shift-based 24/7 environment.
  • Professional certifications such as Microsoft SC-200, CompTIA CySA+, GIAC, GCIA or equivalent

Desirable:

  • Experience using Microsoft Sentinel, LogRhythm, or equivalent enterprise SIEM platforms.
  • Experience developing monitoring improvements, detection tuning, or operational process development.
  • Experience supporting Incident Responder activities during major cyber security incidents.
  • Experience contributing to the development of monitoring use cases and detection improvements.
  • Applied knowledge of MITRE ATT&CK or equivalent adversary behaviour frameworks.

Benefits & conditions

12 Hour shifts (7am-7pm & 7pm-7am) 7 Days & 7 Nights over a 4-week pattern 6 month contract initially Buckinghamshire

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.totaljobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2026 Europe

11:18 min

Addressing audience questions on security and microservice architectures

Reinhard Kugler · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

3:48 min

Leveraging multi-agent systems for autonomous software testing

Ondřej Gróf Ondřej Gróf · World Congress 2026 Europe

Videos

See all

Related articles

See all