24/7 SOC Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Location: Home-based with occasional visits to the office in Basingstoke, United Kingdom. The role follows 12-hour shifts covering two days, two nights, and four days/nights off. Eligibility for UK SC security clearance requires living in the UK for five consecutive years; DV clearance eligibility is advantageous. Planned start date: January 2027.
Company
provides secure and connected digital infrastructure services and operates a 24/7 Security Operations Centre for customers across Europe.
What you will do
- Monitor and triage alerts across SIEM, EDR/XDR, email, and web security platforms.
- Investigate suspicious activity, identify indicators of compromise, and determine whether escalation is required.
- Build activity timelines, maintain investigation notes, and escalate complex cases with appropriate context.
- Follow SOC runbooks and participate in shift handovers across a 24/7 operating model.
- Take part in directed threat hunting and review vulnerability management output.
- Improve detections, dashboards, runbooks, use cases, and detection logic.
Requirements
- At least one year of SOC experience, or at least three years in infrastructure or networking roles with demonstrable security exposure.
- Experience triaging and investigating security alerts and interpreting logs from multiple sources.
- Understanding of attacker behaviours, TTPs, malware execution chains, indicators of compromise, and MITRE ATT&CK.
- Hands-on experience with at least one major SIEM, EDR, or XDR platform.
- Knowledge of Windows, macOS, Linux, Windows and authentication logs, process trees, command-line tools, and DNS, HTTP, SMB, and LDAP.
- Eligibility for UK SC security clearance, including five consecutive years of residence in the UK.
Nice to have
- Experience with Microsoft Sentinel, Google SecOps, Defender, CrowdStrike, or SentinelOne.
- Ability to query using KQL, CQL, S1QL, XQL, or similar languages.
- Awareness of threat intelligence concepts and their application to investigations.
- Coding or scripting experience, with proficiency in at least one language.
- Eligibility for DV security clearance.
Culture & Benefits
- Structured training, cyber ranges, hands-on exposure to modern SOC technologies, and real investigation experience.
- Career pathways into Threat Intelligence, SOC Engineering, SOC Professional Services, senior SOC roles, and Incident Response.
- Collaborative, agile environment with continuous improvement, knowledge-sharing sessions, and regular team events.
- Competitive salary, commission scheme, and industry-leading benefits.
- Flexibility is required during major incidents.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →