Security Operations Analyst (SOC analyst)

Company: JP Morgan Chase
Apply for the Security Operations Analyst (SOC analyst)
Location: London
Job Description:

Overview

In this hands-on Detection and Response role, you will be at the frontline of JPMorganChase’s cyber defense, triaging alerts and driving end-to-end investigations. You will work within the London SOC to sustain 24/7 coverage across regions, collaborating with global teams to improve detections and response. You’ll apply threat hunting, detection engineering, and AI-assisted tooling to raise investigation speed and accuracy. This position offers meaningful work at scale in a fast-paced financial services environment.

Responsibilities

  • Triage and analyze alerts from SIEM, EDR, and other detection tooling based on severity and business impact
  • Investigate security incidents end-to-end from detection to containment, eradication and resolution
  • Proactively hunt threats across endpoints, networks, cloud, and identity telemetry
  • Contribute to detection engineering by tuning rules, use cases, and correlations
  • Utilize AI-assisted tooling to accelerate investigations and improve efficiency
  • Document findings, maintain case records, and produce incident reports and post-incident reviews
  • Collaborate with global SOC teams, threat intel, IR, and engineering to ensure smooth handoffs under follow-the-sun model
  • Contribute to playbooks, runbooks, and SOPs for continuous SOC improvement
  • Stay current with threat landscape, ATT&CK techniques, and industry best practices

Key requirements

  • 2+ years of SOC, incident response, or security analyst experience
  • Solid understanding of security monitoring across SIEM, EDR/XDR, and network tooling
  • Working knowledge of attack techniques, the cyber kill chain, and MITRE ATT&CK
  • Strong networking concepts (TCP/IP, DNS, HTTP/S, proxies, firewalls) and OS internals (Windows, Linux)
  • Experience investigating alerts across endpoint, network, cloud, and identity logs
  • Ability to analyze logs, correlate events, and reconstruct incident timelines
  • Strong written and verbal communication for documentation and updates
  • Ability to work under pressure and participate in weekend rotation approximately every five weeks
  • Clear communication
  • Ability to work under pressure
  • Collaborative mindset
  • SIEM, EDR/XDR, and network security tooling
  • MITRE ATT&CK framework
  • Attack techniques and cyber kill chain knowledge

…

Posted: October 1st, 2026