SOC Level 2 Security Analyst

Company: NTT DATA
Apply for the SOC Level 2 Security Analyst
Location: Birmingham
Job Description:

Overview

In this Security Analyst (L2) role, you will deepen analysis, validate incidents, and coordinate containment and recovery within a 24/7 SOC. You act as a technical escalation point for L1 analysts and partner with IT, security teams, and customers to improve detection quality and response efficiency. You will apply threat intel and automate responses to strengthen monitoring, while documenting investigations and contributing to process improvements. This is a hands-on, impact-driven position in a fast-paced security operations environment.

Responsibilities

  • Investigate alerts from Level 1, validate and classify incidents, and determine containment needs
  • Coordinate and support incident response activities per SOC and customer processes
  • Lead or support major incidents with escalation to stakeholders and live guidance to L1 analysts
  • Execute SOAR playbooks and provide feedback to improve automation and consistency
  • Monitor SOC performance metrics (MTTD/MTTR) and drive investigation quality improvements
  • Apply threat intelligence to investigations and incorporate learnings into detections
  • Develop and tune SOC use cases, onboard new services, and close detection gaps
  • Maintain incident records, runbooks, and post-incident reports; contribute to operational reporting
  • Collaborate with IT, security, and technical teams; mentor L1 analysts and drive continual service improvement

Key requirements

  • 2–4 years in IT security, preferably in a SOC/NOC environment
  • Hands-on with SIEM platforms (Splunk, Microsoft Sentinel, QRadar)
  • Strong incident response knowledge and escalation management
  • Analytical thinker with good decision-making under pressure
  • Clear written and verbal communication; able to work independently within structured processes
  • Experience with cloud platforms such as Microsoft Azure and/or AWS
  • Proficiency with Microsoft Office tools (Excel, Word)
  • Relevant cybersecurity certifications desirable (e.g., GIAC, CySA+, SC-200)
  • Eligibility for UK SC Clearance and willingness to work 24/7 shift-based environment
  • Clear, professional communication
  • Ability to perform under pressure
  • Mentoring and escalation support for junior analysts
  • SIEM platforms: Splunk, Microsoft Sentinel, QRadar
  • Incident response workflows and escalation management
  • SOAR playbooks and automation feedback

…

Posted: October 1st, 2026