Tier 2 SOC Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
| Tier 2 SOC Analyst | ÂŁ40,000-ÂŁ50,000 DOE | London (Hybrid) |
Are you passionate about cyber security and enjoy investigating complex security incidents?
Weâre partnering with a growing cyber security organisation that is looking to strengthen its Security Operations capability with the addition of a Tier 2 SOC Analyst.
This is an opportunity to join a collaborative cyber security team responsible for monitoring, investigating and responding to security threats across complex client environments.
Youâll play a key role in identifying potential security incidents, conducting detailed investigations and supporting the response to emerging threats. The role offers exposure to a wide range of technologies, security tools and client environments, with the opportunity to develop your technical expertise within a fast-paced SOC environment.
What youâll be doing:
As a Tier 2 SOC Analyst, youâll take ownership of more complex security alerts and incidents, including:
- Investigating and analysing escalated security alerts from Tier 1 analysts
- Conducting detailed incident investigations to determine scope, impact and root cause
- Monitoring and analysing activity across SIEM, EDR and other security platforms
- Identifying indicators of compromise, suspicious activity and emerging threats
- Supporting incident response and containment activities
- Performing threat hunting activities to proactively identify potential security risks
- Escalating significant or complex incidents where appropriate
- Working closely with Tier 1 and Tier 3 analysts, incident responders and other technical teams
- Tuning and improving detection rules and use cases to reduce false positives and improve threat detection
- Analysing logs and security events from endpoints, networks, cloud environments and other infrastructure
- Producing clear investigation reports and documenting incidents, findings and recommendations
- Maintaining awareness of the latest cyber threats, vulnerabilities and attacker techniques
- Contributing to the ongoing development and improvement of SOC processes and capabilities
Requirements
Weâre interested in speaking with candidates who can demonstrate:
- Previous experience working within a Security Operations Centre (SOC), cyber security operations or incident response environment
- Experience investigating and responding to complex security alerts and incidents
- Strong knowledge of SIEM platforms and security event analysis
- Experience with endpoint detection and response (EDR) technologies
- A good understanding of incident response processes and methodologies
- Knowledge of common attack techniques, tactics and procedures, including the MITRE ATT&CK framework
- Experience analysing logs across endpoint, network, cloud or identity environments
- An understanding of threat intelligence and indicators of compromise
- Strong analytical and problem-solving skills
- Excellent written and verbal communication skills
- The ability to clearly communicate technical findings to both technical and non-technical stakeholders
Experience with technologies such as Microsoft Sentinel, Splunk, Microsoft Defender, CrowdStrike or similar security platforms would be highly beneficial.
About the company
Youâll be joining a growing organisation that places a strong emphasis on collaboration, technical development and delivering effective cyber security outcomes.
Working as part of an experienced Security Operations team, youâll have the opportunity to investigate real-world security threats, work with a broad range of technologies and develop your career across incident response, threat hunting and advanced security operations.
The role is based in London on a hybrid working basis, with some flexibility depending on operational and client requirements.
If youâre looking for an opportunity to take the next step in your SOC career and work on challenging cyber security incidents, weâd be pleased to hear from you.
Oscar Associates (UK) Limited is acting as an Employment Agency in relation to this vacancy.
To understand more about what we do with your data please review our privacy policy in the privacy section of the Oscar website. Reference: 57301847
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role â technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
9 Ways to Make Money Hacking
Dev Digest 191: Malware interviews, EU â¤ď¸ Open Source and Skilled Agents
Best Companies to work for in London: Top 25 Companies in 2023