Overview
In this role, you will monitor and triage security alerts as part of a 24/7 SOC, validating events and supporting incident response. You’ll work with SIEM and SOAR tools to investigate potential incidents, escalate with clear context, and document actions in incident records. You will contribute to post‑incident reviews and apply threat intelligence to improve detection and response. This is a hands‑on, process‑driven position within a global security operations team that values disciplined execution and collaboration.
Pay / Benefits
- flexible work options
- Learning and Development opportunities
- tailored benefits
- wellbeing support
- diversity and inclusion commitment
Responsibilities
- Continuously monitor security alerts, logs, and event data across customer and internal environments to identify suspicious activity
- Triage and analyse alerts to determine security or service incidents and prioritise per security policies
- Conduct first‑line investigations using SIEM, SOAR, and supporting tools; gather evidence and assess impact and severity
- Escalate indicators of compromise or attack activity with clear context to senior analysts or incident responders
- Support containment and remediation following runbooks and customer guidance; document actions consistently
- Create and maintain incident tickets; record investigation steps and produce clear incident summaries
- Contribute to post‑incident reviews and share findings to improve detection, response, or processes
- Apply threat intelligence to support alert analysis and investigations
- Follow SOC procedures, documentation standards, and shift handover processes; maintain continuous coverage across shifts
- Participate in a 24/7 shift rota and collaborate with others to ensure monitoring continuity
Key requirements
- Foundational understanding of cyber security concepts ( networking, logs, basic attack techniques)
- Experience with SIEM platforms such as Splunk or Microsoft Sentinel; basic OS knowledge (Windows, Linux, macOS)
- Strong analytical and problem‑solving skills; ability to follow investigative processes and make decisions within procedures
- Clear written and verbal communication; accurate ticketing and escalation; effective shift handover
- Ability to work calmly in a 24/7 shift‑based operational environment; ability to learn from feedback
- Awareness of scripting, query languages, or rule‑based detection is advantageous but not required
- Eligibility for UK SC Clearance and willingness to work in a 24/7 SOC environment
- Entry‑level cyber security certifications desirable (CySA+, SC‑200)
- Experience with cloud platforms such as Azure and/or AWS desirable
- Proficiency with Microsoft Office tools (Excel, Word)
- attention to detail
- analytical mindset
- clear communication
- SIEM (Splunk, Microsoft Sentinel)
- SOAR platforms
- basic networking (TCP/IP)
…
