> Markdown version of [/jobs/ext/3293072-security-operations-analyst-soc-analyst](https://www.wearedevelopers.com/jobs/ext/3293072-security-operations-analyst-soc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Operations Analyst (SOC analyst) - **Company:** JPMorganChase - **Location:** London, UK - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Artificial Intelligence, Amazon Web Services, Microsoft Azure, Cloud Computing Security, CompTIA Security+, Cyber Security, Linux, Domain Name System (DNS), Hypertext Transfer Protocols (HTTP), Intrusion Detection and Prevention, Network Security, Kusto Query Language, Security Information and Event Management, TCP/IP, Google Cloud, Computer Network Technologies, Mitre Att&ck, Firewalls (Computer Science), Information Technology, Cybercrime, Cyber Warfare, Blue Team (Cyber Security) - **Published:** September 1, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=57292531aa9bd096 ## About the Role This is a hands-on detection and response role at the core of the firm's cyber defense operations. The analyst will primarily triage security alerts and investigate cases end-to-end, while contributing to threat hunting, detection engineering, and the adoption of AI-assisted tooling to improve investigative efficiency and accuracy. The position suits a technically strong practitioner who thrives in a fast-paced, high-stakes environment and is motivated by continuous improvement., * Demonstrable experience in a SOC, incident response, or security analyst role (typically 2+ years). * Solid understanding of security monitoring and investigation across SIEM, EDR/XDR, and network security tooling. * Working knowledge of common attack techniques, the cyber kill chain, and the MITRE ATT&CK framework. * Strong understanding of core networking concepts (TCP/IP, DNS, HTTP/S, proxies, firewalls) and operating system internals (Windows, Linux). * Experience investigating alerts across endpoint, network, cloud, and identity/authentication logs. * Ability to analyze logs, correlate events across multiple data sources, and reconstruct incident timelines. * Strong written and verbal communication skills for clear documentation and stakeholder updates. * Ability to work under pressure, prioritize effectively, and participate in weekend shift rotation (approximately once every five weeks)., * Experience with detection engineering and writing/tuning detection content (e.g., Sigma, YARA, KQL, SPL, or equivalent). * Hands-on threat hunting experience using hypothesis-driven methodologies. * Familiarity with SOAR platforms, scripting/automation, and AI-assisted security tooling. * Experience defending large, complex enterprise or financial-services environments. * Exposure to cloud security monitoring (AWS, Azure, or GCP). * Knowledge of threat intelligence concepts and integration into detection and response workflows. Education and Certifications * Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience. * Industry certifications are advantageous, such as: CompTIA Security+, CompTIA CySA+, GIAC (GCIH, GCIA, GCFA, GDAT), Blue Team Level 1/2 (BTL1/BTL2), CEH, or cloud security certifications (AWS/Azure/GCP security). ## Description The team operates a follow-the-sun model to guarantee continuous global coverage. Analysts work standard weekday business hours, for the most part, with weekend shift coverage required on a rotational basis approximately once every five (5) weeks. This rotation ensures uninterrupted monitoring and response capability across all time zones and handoff points., * Triage and analyze security alerts from SIEM, EDR, and other detection tooling, prioritizing based on severity, risk, and business impact. * Investigate security incidents and cases end-to-end, from initial detection through containment, eradication, and documented resolution. * Conduct proactive threat hunting across endpoints, networks, cloud, and identity telemetry to identify undetected threats and emerging adversary behavior. * Contribute to detection engineering: develop, tune, and refine detection rules, use cases, and correlation logic to reduce false positives and improve coverage. * Leverage AI and automation tooling (e.g., AI-assisted triage, enrichment, and summarization) to accelerate investigations and improve analyst efficiency. * Document findings, maintain accurate case records, and produce clear incident reports and post-incident reviews. * Collaborate with global SOC teams, threat intelligence, incident response, and engineering functions to ensure seamless handoffs under the follow-the-sun model. * Contribute to continuous improvement of SOC playbooks, runbooks, and standard operating procedures. * Stay current with the evolving threat landscape, attacker TTPs (mapped to frameworks such as MITRE ATT&CK), and industry best practices.