> Markdown version of [/jobs/ext/61738-security-soc-analyst-uk-remote](https://www.wearedevelopers.com/jobs/ext/61738-security-soc-analyst-uk-remote). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security SOC Analyst - UK Remote - **Company:** Employment Hero - **Location:** UK (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cloud Computing Security, Cyber Security, System Configuration, Identity and Access Management, Meter Data Management (Flow Meters), Security Information and Event Management, Systems Integration, Diagnostic Tools, Cyber Threat Analysis, Microsoft InTune, Casper Suite, Gsuite - **Published:** May 29, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=4cd9603060be60fb ## About the Role Do you have experience in SIEM?, * A "Self-Starter" Mentality: You are a high-performer who takes initiative to investigate challenges independently before seeking guidance. You possess the technical aptitude and confidence to step into complex scenarios and deliver outsized impact as you grow into the role. * Technical Passion: You likely run personal labs, participate in CTFs/Hack The Box, or have personal AI projects. * Operational Experience: 2-3 years in a SOC, NOC, or technical Helpdesk environment. * Tooling Knowledge: Familiarity with EDR, SIEM, and Cloud Security. * Ambition: You aren't satisfied with a "passing grade"; you strive for excellence. * Reliability: The ability to own your impact in a fully remote, asynchronous environment. ## Description As our Security SOC Analyst, you'll be working with the wider security team to act as the front line of our security defense. You will be instrumental in protecting our community of 2 million+ users, ensuring our vector to 10 million users remains secure and unimpeded. Your key focus areas will be: * Achieving 24/7 "Follow the Sun" coverage by bridging the gap between our teams. * Maintaining a high-velocity response rate to SOC alerts and internal security queries. * Integrating and improving our "AI Analyst" to automate manual triage. This will include: * Triage & Incident Response: Monitoring SIEM alerts and responding to events in real-time. * Security Service Delivery: Resolving internal security tickets and troubleshooting tools like Netskope, Crowdstrike, and Abnormal Security. * AI Collaboration: Working hand-in-hand with our AI Analyst to improve its accuracy and automation capabilities. * Identity & Access Management: Configuring Google Workspace (IDP/SSO/Conditional Access) and MDMs (Intune, Jamf, Kandji). * Threat Intelligence: Monitoring dark web mentions and compromised credentials. * Vulnerability Support: Performing regular scans and providing remediation guidance., * You will work remotely, with the flexibility to own your time and impact * You will access cutting-edge tools to amplify your work, knowledge and outputs * You'll surround yourself with ambitious, outcome-driven colleagues who challenge you to do the best work of your life * You'll own ESOP (employee share options) in one of the world's fastest-growing tech companies * You'll also have access to a wide range of benefits that includes - a very generous parental leave policy, subsidised egg freezing (so you can make the choice that's right for you, on your terms), a WFH office expense budget, and outstanding learning & development opportunities * Annual Global Gathering - so far we've been to Thailand, Vietnam, Bali, Dubai and are excited to meet in Gold Coast in Australia in September 2026 We're AI-first, so you may meet some of our AI tools early in the process. They help us cut the noise, surface great talent fast and make sure every candidate gets a fair, consistent experience. ## Related Videos - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Better Together: Leveraging Your Observability Tools as a SIEM](https://www.wearedevelopers.com/videos/2118-better-together-leveraging-your-observability-tools-as-a-siem) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Agile work at CARIAD – Creating a customer web application for controlling the vehicle ](https://www.wearedevelopers.com/videos/200-agile-work-at-cariad-creating-a-customer-web-application-for-controlling-the-vehicle) ## Related Articles - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Engineer Salary UK](https://www.wearedevelopers.com/magazine/253-data-engineer-salary-uk) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)