Security Operations Centre (SOC) Analyst
Insight
Sheffield, United Kingdom
2 days ago
Role details
Contract type
Permanent contract Employment type
Full-time (> 32 hours) Working hours
Regular working hours Languages
English Experience level
Intermediate Compensation
£ 40KJob location
Sheffield, United Kingdom
Tech stack
Artificial Intelligence
Computer Security
Security Information and Event Management
Web Traffics
Large Language Models
Software Security
Mitre Att&ck
QRadar
Microsoft Sentinel
Cortex XSOAR Platform
Splunk
Vulnerability Analysis
Job description
Monitor, detect, and respond to security events related to Claude Code usage, with focus on AI-specific threats.
- Analyze SIEM dashboards/alerts for anomalies such as unusual prompt volumes, DLP triggers, and authentication failures.
- Investigate and triage security events; escalate confirmed incidents as necessary.
- Develop and refine SIEM detection rules for AI/LLM threat scenarios, including prompt injection and data exfiltration.
- Conduct daily review of audit logs and generate weekly security metrics reports.
- Participate in incident response exercises, especially those involving AI-specific scenarios.
- Maintain and update SOC runbooks for Claude Code incident response procedures.
- Collaborate with cybersecurity teams to ensure best practices in AI security monitoring and incident handling.
- Utilize tools such as Splunk, Microsoft Sentinel, or IBM QRadar for security monitoring.
- Leverage strong analytical and investigation skills to identify and mitigate security risks.
Requirements
Apply knowledge of MITRE ATT&CK framework, API security, and web traffic analysis.
- Preferred: Experience with AI/LLM technologies, prompt-based attack vectors, SOAR platforms (e.g., Palo Alto XSOAR, Splunk SOAR), and Security+ or equivalent certification.
- Target candidates with 3+ years' experience in SOC or security monitoring roles, ideally with enterprise or BFSI sector exposure.