Cyber Security Analyst

hackajob

Cardiff

On-site

GBP 32,000 - 54,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Up to £3,600 of free shares each year
33 days holiday (including bank) with

Job summary

Admiral Group Plc, in collaboration with hackajob, seeks a L1 SOC Analyst to join its 24/7 global Security Operations Centre. You will monitor, triage, and escalate security alerts across critical systems, collaborating across regions to ensure continuous coverage; this role is remote with occasional office attendance and offers clear handover standards.

Ideal candidates have SOC monitoring experience, knowledge of networking, Windows and Linux, strong attention to detail, and the ability to

Qualifications

  • Demonstrated experience performing SOC monitoring and investigation activities.
  • Understanding of Networking (IP, DNS, HTTP).
  • Knowledge of Windows and Linux operating systems.
  • Strong attention to detail and ability to follow structured processes.
  • Good written and verbal communication skills.

Responsibilities

  • Monitor alerts from SIEM platforms, Endpoint detection tools, Identity and access systems.
  • Validate whether alerts are true or false positives and classify severity.
  • Conduct investigations using available tools and playbooks; identify indicators of compromise.
  • Escalate suspicious or confirmed threats with structured evidence and follow runbooks.
  • Perform structured handovers with clear summaries, actions, risks and timelines.

Skills

SOC monitoring
Investigation
Networking
Windows
Linux
Attention to detail
Communication skills
Structured processes

Tools

SIEM
Endpoint tools
Playbooks

Job description

hackajob is collaborating with Admiral Group Plc to connect them with exceptional professionals for this role.

As a L1 SOC Analyst, you are the first line of defence against cyber threats targeting the organisation.

You will work as part of a 24/7 global Security Operations Centre across three regions, monitoring, triaging, and escalating security alerts affecting critical financial systems, customer data, and user accounts. The role requires seamless collaboration across regions, ensuring continuous security coverage through effective handover.

You will follow structured processes while developing the skills needed to understand how attacks happen and how to investigate them effectively. This role is designed for individuals with a strong interest in cyber security and a willingness to learn quickly in a real-world environment.

Key Responsibilities
Alert Monitoring & Triage
  • Monitor alerts from SIEM platforms, Endpoint detection tools, Identity and access systems.
Perform Initial Triage
  • Validate whether alerts are true or false positives.
  • Classify severity based on defined criteria.
  • Identify potential impact on financial systems or users.
Investigation (Initial Level)
  • Conduct investigations using available tools and playbooks.
  • Login activity and user behaviour, Endpoint activity (processes, files, connections) indicators of compromise and threat actor behaviours.
  • Gather relevant evidence before escalation.
Escalation & Incident Handling
  • Escalate suspicious or confirmed threats to L2 Analysts.
  • Provide clear, structured evidence including what was detected, what has been checked, why it is suspicious/anomalous/malicious.
  • Playbook execution following predefined runbooks and response procedures, perform response actions where appropriate, ensure consistency and accuracy in all actions.
Regional Handover
Perform Structured Handovers At Shift End, Including
  • Clear summary of active incidents and investigations.
  • Outstanding actions, risks, and priorities.
  • Relevant evidence, timelines, and analyst observations.
  • Ensure no loss of context or investigative continuity during handover.
  • Adhere to defined handover standards to maintain operational resilience.
Documentation
  • Maintain accurate and detailed case notes.
  • Log Investigation steps, Findings, Actions taken.
  • Ensure documentation meets audit and regulatory standards.
Continuous Learning
  • Build knowledge of common cyber threats phishing, malware, credential theft etc.
  • Participate in training sessions, simulated attack exercises, knowledge-sharing within the SOC.
Essential
Required Skills & Experience
  • Demonstrated experience performing SOC monitoring and investigation activities.
  • Understanding of Networking (IP, DNS, HTTP).
  • Knowledge of Windows and Linux operating systems.
  • Strong attention to detail.
  • Ability to follow structured processes.
  • Good written and verbal communication skills.
Desirable
  • Hands on experience SIEM or endpoint tools.
  • Cyber labs (e.g., TryHackMe, Hack the Box).
  • Certifications (e.g., CompTIA Security+, SC-200).
  • Basic scripting knowledge (PowerShell, Python).
Location

This role is remote with occasional office attendance.

Admiral: Where You Can

We take pride in being a diverse and inclusive business. It's a place where you can Be You, and show up as you are. We’re committed to fostering a people-first culture where everyone is accepted, supported, and empowered to be brilliant. You can, Grow And Progress at a pace and direction that suits you, Make A Difference for our customers and each other, and Share in Our Future with all colleagues eligible for up to £3,600 of free shares each year after one year of service.

Everyone receives 33 days holiday (including bank holidays) when they join us, increasing the longer you stay with us, up to a maximum of 38 days (including bank holidays). You also have the option to buy or sell up to an additional five days of annual leave.

We’re proud of our people-first culture. In fact, we've been recognised as a Great Place to Work for Women, a Great Place to Work for Wellbeing, and an overall Great Place to Work for over 25 years! We’re fully committed to making sure your progression is not slowed or halted by barriers related to race, gender, age, sexuality or any of the protected characteristics.

Our fantastic benefits make sure our colleagues have a great work-life balance; You can view some of our other key benefits here.

Disability Confident Leader

As a Disability Confident Leader, for candidates with a disability or long-term health condition, that opt into the Disability Confident scheme, we’ll invite a fair and proportionate number of applicants that meet the essential requirements of the role to the first stage of our selection process.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security SOC Analyst (L1)
Cyber Security SOC Analyst (L1)

Wavenet • Batley

On-site
GBP 28,000 - 36,000
Annual Leave 25 days
Private medical coverage
Wellbeing program
+1
Cyber Security Analyst
Cyber Security Analyst

Netcompany Group • Leeds

On-site
GBP 40,000 - 60,000
Private Medical Health care via Vitality
Pension contribution
Life Assurance
+2
L1 SOC Analyst - Telecommuncations
L1 SOC Analyst - Telecommuncations

Hamilton Barnes Associates Limited • West Yorkshire

On-site
GBP 29,000 - 36,000
Career progression into threat hunting
Mentorship from experienced analysts
Support for certifications and ongoing
+2
Cyber Analyst
Cyber Analyst

Admiral Money • Cardiff

On-site
GBP 45,000 - 65,000
Share plan
Holiday entitlement
Disability Confident Leader
Cyber Analyst
Cyber Analyst

Admiral • Cardiff

On-site
GBP 42,000 - 65,000
33 days holiday incl. bank holidays
Up to £3,600 of free shares after one​
Disability Confident Leader scheme
SOC Analyst - Tier 1
SOC Analyst - Tier 1

Methods • Greater London

On-site
GBP 40,000 - 60,000
Flexibility - home working
25 days annual leave
Pension scheme
+2
Cyber Security SOC Analyst – 11626CA2
Cyber Security SOC Analyst – 11626CA2

Proactive.IT Appointments Limited • Bristol

On-site
GBP 40,000 - 45,000
Remote L1 SOC Analyst — 24/7 Threat Monitoring & Triage
Remote L1 SOC Analyst — 24/7 Threat Monitoring & Triage

hackajob • Cardiff

Hybrid
GBP 32,000 - 54,000
Up to £3,600 of free shares each year
33 days holiday (including bank) with
SOC Analyst - SC Cleared
SOC Analyst - SC Cleared

Sanderson Government & Defence • Greater London

Hybrid
GBP 146,000 - 151,000
Security Managed Services Senior Analyst
Security Managed Services Senior Analyst

Accenture UK • Greater London

On-site
GBP 55,000 - 75,000