Graduate SOC Analyst

CyPro

Slough

Hybrid

GBP 27,000 - 32,000

Full time

12 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Salary £27,000 + overtime
Holiday 25 days
Flexible working
London office
Training budget
Social events
Start Sep/Oct 2026

Job summary

CyPro is seeking a SOC Analyst to deliver 365-day monitoring, detection and response for our growing client base in the UK. You will work across monitoring, incident response, threat intelligence and automation within a flexible hybrid model in London.

The role offers a starting salary of £27,000 plus overtime, with 25 days holiday and annual training budget. Suitable candidates must be able to commute to Canary Wharf and have strong English skills.

Qualifications

  • You must hold a 2:1 degree (ideally in science, maths or technical subjects) or have completed a relevant apprenticeship in cyber security/IT.
  • BBB at A-Level or Merit T-Level in a relevant subject is required.
  • You should be able to articulate what a SOC entails.

Responsibilities

  • Prepare weekly and monthly SOC reports highlighting activity, incidents and trends.
  • Monitor alerts from Microsoft Defender, Sentinel, Datadog and Elastic.
  • Contain and remediate incidents using runbooks and playbooks.
  • Develop detection rules in Microsoft Sentinel and write KQL queries.
  • Analyse threat intelligence and contribute to threat hunting.

Skills

2:1 degree or relevant apprenticeship
Articulate SOC concepts
Office 365 proficiency
English fluency
Commute to Canary Wharf

Education

2:1 degree or apprenticeship in cyber/tech subject

Tools

Microsoft Defender
Azure
Microsoft Sentinel
Datadog

Job description

Important: you must be UK based – we are unable to provide visa sponsorship, and you must meet all 5 minimum requirements below.

What we’re offering (saves you scrolling straight to the bottom):

  • Salary: £27,000 + overtime
  • Holiday: 25 days paid holiday plus bank holidays (increases by 1 day per year worked up to 30 days)
  • Flexible Working: We love getting the team together in the office, so we typically spend three days per week together in our lovely London office (39 floors up in Canary Wharf ?). The rest of the time, you can work wherever you’re most productive.
  • Working Hours: Monday to Friday 9:00am - 5:30pm with the potential to move to be part of a 24/7 shift rota on promotion.
  • Training: Budget for one certification/course per year
  • Socials: We meet regularly to have a drink, throw some axes
  • Start Date: September/October 2026
Minimum Requirements

You must meet all 5 of these minimum requirements, please do not apply if you do not – your application will be rejected.

  • Education: You must hold a 2:1 degree (ideally in a science, mathematics or technical subject) or have completed an apprenticeship in a relevant subject area (e.g. Cyber Security, Information Security, Computer Science) studied at a UK/US/Australian/New Zealand/Canadian University or college. You must also hold grade BBB at A-Level (or equivalent) or a Merit T-Level in a relevant subject.
  • Experience: No experience is necessary, but you should be able to clearly articulate what a role in a Cyber Security Operations Centre entails.
  • IT literacy: highly confident using Microsoft Office 365 with some experience of other Microsoft tools such as Defender or Azure.
  • Fluent in English: you must be highly proficient with business-level written and spoken English
  • Location: must be within a reasonable commute of Canary Wharf, London
About CyPro:
  • We are an innovative cyber security start-up united in a shared mission: to redefine cyber security for small and medium-sized businesses (SMBs).
  • Our Founders – Jonny & Rob – spent most of their early careers delivering cyber security for large enterprises and central government. They saw a clear need for a new approach to cyber security as SMBs became increasingly targeted by cyber criminals.
  • Together, CyPro is already setting new standards, defining innovative solutions and equipping its clients with the cyber security they need to prevent attacks, secure bigger clients and scale to new heights.
  • We are growing quickly, and the next few years promise more of the same. Joining CyPro means becoming an integral part of our mission and joining a team of industry experts embarking on this journey.
The Role:
  • This isn’t your typical SOC Analyst role where you’re pigeonholed into one narrow specialism. At CyPro, you’ll have the opportunity to get involved in a wide range of areas including monitoring, incident response, threat intelligence, detection engineering, automation and internal security operations.
  • You’ll play a key role in our Security Operations Centre, delivering 365-day monitoring, detection and response to our growing customer base. You’ll contribute to building out our capabilities, improving tooling and processes, and shaping how we operate as the function matures.
  • As the team grows further, you’ll have the flexibility to focus more deeply on the areas that interest you most – whether that’s advanced detection engineering, threat intelligence, incident response leadership or platform automation. If you’re ambitious and want to help shape something rather than simply follow a process, this is the right environment for you.
Core Responsibilities:
Client Support & Reporting
  • Prepare weekly and monthly SOC reports highlighting activity, incidents and trends.
  • Join governance calls with senior analysts or managers to present SOC insights.
  • Communicate independently with clients via email, messenger and Teams call to address queries around incidents, detection coverage and service issues.
Security Monitoring & Incident Response
  • Monitor security alerts generated by Microsoft Sentinel, Microsoft Defender, Datadog and Elastic.
  • Assess severity and impact of alerts, triage and investigate incidents independently.
  • Execute containment and remediation actions using defined runbooks and playbooks.
  • Correlate data across platforms to identify anomalies, malicious patterns and attacker behaviour.
  • Produce detailed incident reports, RCA and after-action reviews for internal and client use.
  • Maintain accurate incident records in JIRA Service Management.
Detection Engineering
  • Develop and implement new detection rules in Microsoft Sentinel aligned to the MITRE ATT&CK framework.
  • Draft and optimise KQL queries for detection and threat hunting.
  • Refine existing detection logic based on false positive analysis and threat evolution.
Threat Intelligence & Enrichment
  • Analyse threat intelligence feeds to identify relevant threats and vulnerabilities.
  • Review and tag IOCs and TTPs observed in client environments.
  • Participate in proactive threat hunting sprints to identify risks before they escalated.
Internal Security Operations
  • Support the management of CyPro’s internal security environment.
  • Administer and monitor identity management solutions.
  • Manage and maintain our MDM platform to ensure secure and compliant device management.
  • Help ensure our internal security posture reflects the same standards we deliver to clients.
Process Improvement & Automation
  • Design and develop Logic Apps to automate incident response workflows.
  • Contribute to evolving internal runbooks and knowledge base articles.
  • Identify gaps in visibility, tooling or processes and propose solutions.
Professional Development
  • Work toward and maintain relevant certifications (e.g. SC-200, AZ-500).
  • Stay up to date with current threat trends, attacker TTPs and defensive strategies.
  • Actively participate in ongoing training and capability development.
Who we’re looking for:
  • Self-Starters – we’re not a large FTSE organisation with a procedure for everything. You’ll need to operate in an environment with few guardrails and help build things as we grow.
  • Ambitious & Driven – whether your goal is to lead a team, specialise technically or move into leadership in future, we’ll support your development.
  • Always Improving – we’re a growing business and want our people to grow with us.
  • Innovative – we are constantly evolving to deliver new solutions to our clients. You’ll need to be the kind of person that brings new ideas to the table and follows them through to realisation.
What we think you need to be successful:
Education & Experience
  • University educated with a degree from a UK/US/Australian/New Zealand/Canadian University, or an apprenticeship in a subject relevant area
  • A levels (or equivalent) of grade BBB or above, or a Merit T-Level in a relevant subject
  • An understanding of and ability to articulate what a role in the SOC entails.
  • Ability to quickly grasp new technical tasks using a range of different tools.
  • SC-200 certification or willingness to achieve it
  • Within commuting distance (~1 hour) of Canary Wharf, London
Technical Skills
  • Familiarity with scripting and automation development (you do not need to be fluent in any particular coding language, but you should be able to demonstrate an understanding of how scripting and other tools (such as AI agents) can be used to streamline tasks.
  • High-level understanding of the Microsoft security stack (e.g. Defender, Sentinel, Purview, etc.)
  • Familiarity with incident response frameworks and security best practice
Soft Skills
  • Problem-Solving: Identify, troubleshoot and resolve complex security issues.
  • Attention to Detail: Ensure accurate detection, analysis and documentation.
  • Analytical Thinking: Comfortable interpreting complex security data.
  • Communication: Clear and confident communicator, able to translate technical issues for non-technical audiences.
  • Calm Under Pressure: Maintain composure during incidents and escalated appropriately.
  • Accountable & Humble: Take ownership and learn from experience.
  • Curious: Dive into data sets and problems to uncover patterns and root causes.
Our Three-stage Hiring Process:
  • Video Introduction (5 mins, Remote): You will be invited to send a short video introduction telling us more about your experience and interest in Security Operations
  • Initial Discussion (20 minutes, Remote): An initial chat to learn more about you and the role.
  • Assessment Centre (2 hours, London): A mini project on-site (no prep required), some quick tests, followed by a final interview with the founders and our SOC Manager.
  • Seniority Level
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Graduate SOC Analyst
Graduate SOC Analyst

CyPro • Greater London

Hybrid
GBP 24,000 - 30,000
Salary £27,000 + overtime
25 days holiday + bank holidays
Hybrid in London office
+2
Junior SOC Analyst
Junior SOC Analyst

Artemis Clarke Ltd • United Kingdom

Remote
GBP 25,000 - 28,000
Cyber Security Manager
Cyber Security Manager

Applied Computing • City Of London

On-site
GBP 70,000 - 100,000
SOC Analyst
SOC Analyst

Inforcer • Richmond

Hybrid
GBP 42,000 - 64,000
Steep learning curve
Real impact
Transparent culture
+3
Senior Cyber Analyst
Senior Cyber Analyst

Methods Business and Digital Technology • Greater London

Hybrid
GBP 70,000 - 110,000
Flexible Working
Wellness Programme
Pension
+4
Senior Cyber Analyst
Senior Cyber Analyst

Methods • Greater London

On-site
GBP 90,000 - 130,000
Autonomy to develop
Flexible working
Private medical insurance
+1
Senior SOC Analyst
Senior SOC Analyst

GCS Recruitment • England

On-site
GBP 90,000 - 120,000
Lead Security Analyst
Lead Security Analyst

Made Tech Limited • United Kingdom

On-site
GBP 90,000 - 120,000
Soc Analyst Level 1
Soc Analyst Level 1

NTT DATA • Birmingham

On-site
GBP 32,000 - 44,000
Flexible work options
Learning & Development
Equal opportunity employer
Senior Security Analyst
Senior Security Analyst

Made Tech Limited • United Kingdom

On-site
GBP 60,000 - 80,000
Sponsorship for recognized cyber certifications
Support for achieving SC clearance