SOC Analyst
Monitor, investigate and escalate security events using SIEM, endpoint and cloud telemetry within authorised defensive-security operations.
Job description
The SOC Analyst will triage alerts, investigate suspicious activity and maintain evidence and escalation quality across defensive-security operations.
Key responsibilities
- Monitor and triage security alerts from SIEM, EDR and cloud platforms.
- Investigate events using logs, identity and endpoint evidence.
- Escalate incidents using defined severity and response procedures.
- Maintain investigation notes, indicators and case evidence.
- Contribute to detection tuning and playbook improvement.
Qualifications
- 3–5 years of SOC, security-operations or cyber-monitoring experience.
- Practical SIEM and log-analysis experience.
- Good understanding of identity, endpoint, network and cloud security concepts.
Preferred qualifications
- Microsoft Sentinel, Splunk or Defender experience.
- Incident-response or threat-hunting exposure.
- Relevant security certification or equivalent experience.
Benefits & employment terms
- Compensation, leave, pension and any role-specific benefits are confirmed during the recruitment process and stated in the written offer.
- Any client-site, travel, security-screening or right-to-work requirements are confirmed before appointment.
Nature of working style
- Work is organised around defined delivery outcomes, documented responsibilities, peer review and clear escalation paths.
- Hybrid or client-site attendance varies by engagement and is confirmed before assignment.
Location
London-based with UK client-site collaboration where required.
