24 x 7 Security Analyst

Nettitude Group

Birmingham

On-site

GBP 50,000 - 80,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Nettitude Group in Birmingham is seeking a vigilant SOC Monitoring Analyst to join our 24x7 team, using SIEM, EDR, and threat intelligence to triage events and advise on risk.

You will produce detailed incident reports, tune alerts, and collaborate on advancing monitoring capabilities, including malware analysis and cross‑team projects.

The role demands strong communication with customers and stakeholders, and a proactive approach to threat hunting and response.

Qualifications

  • Experience with Microsoft Sentinel and Defender in an enterprise environment.
  • Knowledge of SIEM/EDR technologies, with focus on Sentinel to deliver detection, investigation and response.
  • Ability to operate in a complex, high-performing service environment using Microsoft security tools.
  • Experience conducting security investigations using large datasets and KQL.
  • Solid understanding of enterprise IT infrastructure (Windows/Linux) and networking.

Responsibilities

  • Operate as part of the 24x7 SOC Monitor Team, providing proactive defensive monitoring to clients.
  • Generate detailed, informative incident reports with recommendations, mitigations, and remediations.
  • Respond to, and action all alerts and customer requests within agreed SLAs.
  • Maintain awareness of the latest Defensive Monitoring technologies and trends.
  • Maintain an up-to-date understanding of current threats and trends in cyber crime.
  • Produce high quality management and operational reports within SLAs.
  • Constantly tune and improve alerts, playbooks, and automations.
  • Maintain regular written and verbal communication with customers, suppliers, and internally as required.

Skills

Communication skills
Customer-facing
Analytical thinking
Mentoring junior staff

Tools

Microsoft Sentinel
Microsoft Defender
KQL
Windows OS
Linux OS
CrowdStrike CCFA
SC-200
SC-100

Job description

Select how often (in days) to receive an alert: Create Alert

Working as a key member of our SOC 24x7 shift team, you will use your expertise to detect and respond to a multitude of threats of differing capability and sophistication. You will use SIEM, EDR, Network Monitoring, bespoke tooling and Threat Intelligence solutions to triage suspicious events, provide context and an assessment of risk/threat to customers to enable efficient response and continuously monitor customer environments; yet it doesn’t stop there.

Not only will you be expected to assess threats using all information sources available to you, but you’ll also get involved in projects that enhance the capability of our services and ensure we are providing cutting‑edge detection & response services to our clients. This includes threat hunting, supporting the implementation of new cutting‑edge technology, malware analysis, recommending detections and getting involved in strategic cross‑team projects as part of your wider role within our award‑winning Security Operations Centre.

We’re a high‑trust, close‑knit team that doesn’t operate under the traditional SOC tiers, so the passion and drive to get involved, make a difference and use your eye for detail to spot patterns and support both our security mission and that of our customers is essential.

Key Role Responsibilities

The following list is indicative of the overall expectations of the role (not exhaustive):

Operate as part of the 24x7 SOC Monitor Team, providing proactive defensive monitoring to clients of all shapes, sizes and industries.

Generate detailed, informative, and actionable incident reports from your investigations with applicable recommendations, mitigations, and remediations.

Respond to, and action all alerts and customer requests within agreed SLAs.

Maintain an awareness of the latest Defensive Monitoring technologies and trends.

Maintain an up‑to‑date understanding of current threats and trends in cyber crime.

Produce high quality management and operational reports within agreed SLAs.

Constantly strive to tune and improve alerts, playbooks, and automations.

Maintain regular written and verbal communication with customers, suppliers, and internally as required.

Technical/Professional/Qualifications/Requirements

The following list of requirements are pre‑requisites for the role:

Experience with Microsoft Sentinel and Microsoft Defender (Defender for Endpoint, Defender for Identity, Defender for Cloud Apps), including deployment, configuration, and day‑to‑day operational management within an enterprise environment.

Knowledge of SIEM and EDR/EPP technologies, with a particular focus on leveraging Microsoft Sentinel and Defender to deliver threat detection, investigation, and response capabilities.

Proven ability to operate within a complex, high‑performing service management enterprise environment, using Microsoft’s security tools to enhance visibility, resilience, and incident response effectiveness.

Experience in conducting security investigations using large datasets, with knowledge of Kusto Query Language (KQL) to develop custom Sentinel queries and analytics rules.

Solid understanding of enterprise IT infrastructure, including Windows and Linux operating systems, networking, and third‑party security tools — and how these integrate with the Microsoft security ecosystem.

Experience of analysing complex security data within Sentinel and Defender portals, identifying patterns, prioritising threats, and presenting actionable recommendations.

An understanding of attack vectors, MITRE ATT&CK framework, and adversary behaviours, with the ability to distinguish between normal and abnormal activity.

Excellent communication skills, with experience in customer‑facing roles and the ability to clearly convey technical findings and security risk to both technical and non‑technical stakeholders, using Microsoft dashboards and reporting tools.

Microsoft certifications such as SC-200 and SC-100

Crowdstrike certifications such as CCFA, CCSA

Python, PowerShell, and RegEx skills

Key Performance Indicators

Key Performance Indicators (KPIs) are goals that must be achieved in order to demonstrate satisfactory or above performance for this job role. KPIs will be monitored on an on‑going basis throughout each year and will be explored in further depth as part of the performance management process.

Triage and action all security alerts and customer requests within established SLAs

Maintain documentation of processes, investigations, and use‑cases

Complete all management reporting, projects, and any other assigned work

Develop the Security Engineering technology stack through upgrades and automation.

Mentor junior members of staff and develop their technical understanding.

Adhere to Analyst Best Practice, Core Competencies, Compliance and Process/Procedure Standards

Adhere to LRQA Policies and Procedures, as detailed in the HR ‘UK Employee Handbook’ and ‘Policies & Procedures’ sections of the LRQA Intranet

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

24 x 7 Security Analyst
24 x 7 Security Analyst

LRQA Group Limited 2021 • Birmingham

On-site
GBP 45,000 - 65,000
Head of Security Operations Technology · London, Dubai · Hybrid
Head of Security Operations Technology · London, Dubai · Hybrid

Sokin • Greater London

On-site
GBP 120,000 - 180,000
Level 1 SOC Analyst - MSP
Level 1 SOC Analyst - MSP

Hamilton Barnes Associates Limited • West Yorkshire

On-site
GBP 29,250 - 35,750
Career progression pathways
Hands-on experience with industry-leading security tools
Mentorship from experienced analysts
+2
SOC Analyst (24/7 Shift) - Public Sector
SOC Analyst (24/7 Shift) - Public Sector

IBM • Hursley

On-site
GBP 65,000 - 90,000
3rd Line Security Analyst
3rd Line Security Analyst

Xact Placements Limited • Reading

On-site
GBP 51,000 - 69,000
2nd/3rd Line Security Analyst
2nd/3rd Line Security Analyst

Xact Placements Limited • Reading

On-site
GBP 50,000 - 60,000
Hybrid work arrangement
Competitive salary
Security Analyst
Security Analyst

Talion Cyber Security • Wakefield

On-site
GBP 32,000 - 52,000
SOC Team Lead
SOC Team Lead

Jobtailor • Greater London

On-site
GBP 90,000 - 120,000
Head of Security Operations
Head of Security Operations

Sokin • Harrow

On-site
GBP 120,000 - 170,000
Security Operations Center Analyst L1
Security Operations Center Analyst L1

Communicate Technology • Leeds

On-site
GBP 30,000 - 42,000