> Markdown version of [/jobs/ext/3327416-soc-analyst](https://www.wearedevelopers.com/jobs/ext/3327416-soc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SOC Analyst - **Company:** Inforcer - **Location:** Richmond, UK - **Salary:** £44,793.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Audit Trail, User Authentication, Cyber Security, Log Analysis, OAuth, Kusto Query Language, Security Information and Event Management, Mitre Att&ck, Cyber Threat Analysis - **Published:** September 5, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5871671741 ## About the Role * Hands-on alert triage experience in a SOC, MSP, MSSP or internal security team. * Working KQL, you can query sign-in, audit and hunting data to answer a question unaided. * Strong Microsoft 365 and Entra ID security knowledge: authentication flows, conditional access, OAuth and app consent, mailbox and delegation permissions, and the audit trail behind each. * Practical understanding of MITRE ATT&CK and identity-led attack techniques against Microsoft 365. * Sound judgement on when evidence supports a conclusion, and the confidence to say when it does not. * Clear, concise written English for a technical audience, under time pressure ## Description We are seeking a SOC Analyst to play a critical role in monitoring, investigating, and responding to security threats across our environment. There are two key parts to the role. Firstly, you will act as the front line of our security operations; reviewing alerts, identifying suspicious activity, and conducting hands-on investigations using our SIEM, EDR, and threat intelligence tools. This is an operational role with real ownership, ideal for someone who thrives in a fast-paced environment, enjoys digging into logs, and can bring clarity to complex behaviours across our network, endpoints, and cloud platforms. As part of this, you will take part in regular out-of-hours work, which is a natural component of a 24/7 security operation and compensated as overtime. Secondly, you will help strengthen our detection and response capabilities by improving playbooks, enhancing alert quality, and contributing insights that increase our overall readiness. As our environment grows, you'll play a pivotal role in reducing noise, closing detection gaps, and ensuring incidents are handled quickly, consistently, and with high quality. Your work will directly support our ability to remain secure, resilient, and able to operate without interruption. What you'll be doing * Monitor our In-house Custom tooling for real-time alerts and suspicious activity. * Triage, investigate, and document security incidents following established playbooks. * Perform In-depth log analysis across our customer estate * Escalate incidents as needed and collaborate with internal teams * Support containment and remediation efforts * Contribute to improving detection content by identifying gaps, false positives, and tuning opportunities. * Participate in threat hunting exercises and proactive investigations into anomalous behaviour. * Assist with onboarding and operationalizing new security tools and processes. * Stay current with emerging threats, attack techniques, and security best practices. ## Related Videos - [ The attacker's footprint](https://www.wearedevelopers.com/videos/375-the-attacker-s-footprint) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [No Keys for the Robot: GitOps as the Control Plane for Autonomous Agents](https://www.wearedevelopers.com/videos/100095-no-keys-for-the-robot-gitops-as-the-control-plane-for-autonomous-agents) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)