4 дня назад
24/7 SOC Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
24/7 SOC Analyst (Cybersecurity): Monitoring, triaging, and investigating security events across diverse customer environments with an accent on SIEM, EDR/XDR analysis, attacker behaviour, and clear incident timelines. Focus on threat hunting, identifying indicators of compromise, escalating complex cases, and improving detection logic, dashboards, and SOC runbooks.
Location: Home-based in the United Kingdom with occasional visits to the office in Basingstoke. The role operates on 12-hour shifts: 2 days, 2 nights, followed by 4 days/nights off. Flexibility is required during major incidents.
Company
provides cybersecurity and digital infrastructure connectivity services to organisations across Europe.
What you will do
- Monitor and triage alerts across SIEM, EDR/XDR, email, and web security platforms.
- Investigate suspicious activity, identify indicators of compromise, and determine escalation requirements.
- Build activity timelines, maintain investigation notes, and escalate complex cases with relevant context.
- Review vulnerability management output and provide basic prioritisation insight.
- Participate in directed threat hunting and test new detection use cases and logic.
- Improve detections, dashboards, and runbooks while communicating clearly with customers and stakeholders.
Requirements
- At least 1 year of SOC experience, or at least 3 years in infrastructure or networking with demonstrable security exposure.
- Experience triaging and investigating security alerts, interpreting logs, and recognising suspicious processes, network connections, logons, and file changes.
- Hands-on experience with at least one major SIEM, EDR, or XDR platform.
- Knowledge of attacker behaviour, TTPs, malware execution chains, MITRE ATT&CK, and core protocols including DNS, HTTP, SMB, and LDAP.
- Operational knowledge of Windows, macOS, and Linux, including event logs, authentication logs, process trees, and command-line tools.
- Familiarity with ticketing tools such as ServiceNow, Salesforce, or JIRA, plus strong analytical, organisational, written communication, and teamwork skills.
Nice to have
- Experience with Microsoft Sentinel, Google SecOps, Defender, CrowdStrike, SentinelOne, or comparable platforms.
- Ability to query using KQL, CQL, S1QL, XQL, or similar languages.
- Awareness of threat intelligence concepts and their use in investigations.
- Coding or scripting experience, with proficiency in at least one language.
- Eligibility for DV clearance is advantageous.
Culture & Benefits
- Structured training, cyber ranges, hands-on exposure to modern SOC technologies, and real investigation experience.
- Career pathways into Threat Intelligence, SOC Engineering, SOC Professional Services, senior SOC roles, and Incident Response.
- Collaborative, agile environment focused on continuous improvement, knowledge sharing, and technical development.
- Competitive salary and commission scheme with industry-leading benefits.
- Supportive team environment with regular team events and opportunities to contribute to departmental improvements.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
4 дня назад
Senior Security Analyst (Cybersecurity)
50 000 - 60 000GBP
CrowdStrike
3 часа назад
Principal Detection Engineer (Cybersecurity)
5 дней назад
Senior Cyber Threat Intelligence Analyst (CTI)
7 дней назад
Information Security Engineer (Cybersecurity)
7 дней назад
Cyber Security Manager (Defence)
7 дней назад