> Markdown version of [/jobs/ext/350855-junior-soc-analyst](https://www.wearedevelopers.com/jobs/ext/350855-junior-soc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Junior SOC Analyst - **Company:** Cypro - **Location:** London, UK - **Experience:** Starter - **Contract:** Permanent contract - **Skills:** Microsoft Word, Microsoft Excel, Microsoft Antivirus, JIRA, Microsoft Azure, Microsoft Outlook, Cyber Security, Data Files, Identity and Access Management, Intrusion Detection and Prevention, Intrusion Detection Systems, Microsoft Office, Kusto Query Language, Security Information and Event Management, Datadog, Microsoft Power Automate, Mitre Att&ck, Cyber Threat Analysis, Infrastructure Automation Frameworks, Information Technology, Cybercrime, Microsoft Sentinel - **Published:** June 22, 2026 - **Apply:** https://www.apply4u.co.uk/jobs/x/39603347/ ## About the Role Minimum RequirementsYou must meet all 4 of these minimum requirements, please do not apply if you do not - your application will be rejected.Experience: 6 months to 1 year of security experience, ideally in an operations capacityIT literacy: highly confident using Microsoft Office 365, especially Outlook (calendar + inbox management), Word, Excel and PowerPointFluent in English: you must be highly proficient with business-level written and spoken EnglishLocation: must be within a reasonable commute of Canary Wharf, London, Who we're looking for:Self-Starters - we're not a large FTSE organisation with a procedure for everything. You'll need to operate in an environment with few guardrails and help build things as we grow.Ambitious & Driven - whether your goal is to lead a team, specialise technically or move into leadership in future, we'll support your development.Always Improving - we're a growing business and want our people to grow with us. What we think you need to be successful:Education & ExperienceUniversity educated with a degree in computer science, information security or equivalent, or an apprenticeship in a relevant areaAt least 6 months to one year of experience in a SOC environment monitoring and responding to incidentsMicrosoft Sentinel and Defender hands-on expertiseSC-200 certification or willingness to achieve itWithin commuting distance (~1 hour) of Canary Wharf, LondonTechnical SkillsStrong KQL skills for threat hunting and incident forensicsExperience with SIEM, IDS/IPS and threat intelligence platformsFamiliarity with incident response frameworks and security best practiceExperience with scripting and automation (e.g. Azure Logic Apps)Soft SkillsProblem-Solving: Identify, troubleshoot and resolve complex security issues.Attention to Detail: Ensure accurate detection, analysis and documentation.Analytical Thinking: Comfortable interpreting complex security data.Communication: Clear and confident communicator, able to translate technical issues for non-technical audiences.Calm Under Pressure: Maintain composure during incidents and escalate appropriately.Accountable & Humble: Take ownership and learn from experience.Curious: Dive into data sets and problems to uncover patterns and root causes. Our Two-stage Hiring Process:Intro Discussion (20 minutes, Remote): An initial chat to learn more about you and the role.Assessment Centre (2 hours, London): A mini project on-site (no prep required), some quick tests, followed by a final interview with the founders and our SOC Manager. ## Description The Role:This isn't your typical SOC Analyst role where you're pigeonholed into one narrow specialism. At CyPro, you'll have the opportunity to get involved in a wide range of areas including monitoring, incident response, threat intelligence, detection engineering, automation and internal security operations.You'll play a key role in our Security Operations Centre, delivering 365-day monitoring, detection and response to our growing customer base. You'll contribute to building out our capabilities, improving tooling and processes, and shaping how we operate as the function matures.As the team grows further, you'll have the flexibility to focus more deeply on the areas that interest you most - whether that's advanced detection engineering, threat intelligence, incident response leadership or platform automation. If you're ambitious and want to help shape something rather than simply follow a process, this is the right environment for you. Core Responsibilities: Security Monitoring & Incident ResponseMonitor security alerts generated by Microsoft Sentinel, Microsoft Defender, Datadog and Elastic.Assess severity and impact of alerts, triage and investigate incidents independently.Execute containment and remediation actions using defined runbooks and playbooks.Correlate data across platforms to identify anomalies, malicious patterns and attacker behaviour.Produce detailed incident reports, RCA and after-action reviews for internal and client use.Maintain accurate incident records in JIRA Service Management.Detection EngineeringDevelop and implement new detection rules in Microsoft Sentinel aligned to the MITRE ATT&CK framework.Draft and optimise KQL queries for detection and threat hunting.Refine existing detection logic based on false positive analysis and threat evolution.Threat Intelligence & EnrichmentAnalyse threat intelligence feeds to identify relevant threats and vulnerabilities.Review and tag IOCs and TTPs observed in client environments.Participate in proactive threat hunting sprints to identify risks before they escalate.Client Support & ReportingPrepare weekly and monthly SOC reports highlighting activity, incidents and trends.Join governance calls with senior analysts or managers to present SOC insights.Respond to client queries regarding investigations, coverage and data flows.Internal Security OperationsSupport the management of CyPro's internal security environment.Administer and monitor identity management solutions.Manage and maintain our MDM platform to ensure secure and compliant device management.Help ensure our internal security posture reflects the same standards we deliver to clients.Process Improvement & AutomationDesign and develop Logic Apps to automate incident response workflows.Contribute to evolving internal runbooks and knowledge base articles.Identify gaps in visibility, tooling or processes and propose solutions.Professional DevelopmentWork toward and maintain relevant certifications (e.g. SC-200, AZ-500).Stay up to date with current threat trends, attacker TTPs and defensive strategies.Actively participate in ongoing training and capability development. ## Related Videos - [Debugging in the Dark](https://www.wearedevelopers.com/videos/1658-debugging-in-the-dark) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Software Engineering Social Connection: Yubo’s lean approach to scaling an 80M-user infrastructure](https://www.wearedevelopers.com/videos/1583-software-engineering-social-connection-yubo-s-lean-approach-to-scaling-an-80m-user-infrastructure) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)