Level 3 SOC Analyst

Capita

Belfast City District

On-site

GBP 65,000 - 90,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Hybrid – 2 days in Belfast office
Competitive salary
25 days holiday + 2 days pro rata
Volunteer day
Family leave policies
Cycle to work
Pension
Life Assurance

Job summary

Capita is seeking an experienced Level 3 SOC Analyst to join a hybrid Belfast team. The role involves handling security incidents escalated from Tier 1/2, triaging threat intelligence, and guiding response actions based on business impact.

You will manage SIEM platforms (IBM QRadar, Microsoft Sentinel, MDE/MDI, Defender for Cloud) and mentor junior analysts, while contributing to Major Incident Response and architectural onboarding of new systems.

Qualifications

  • Level 3 SOC Analyst / Senior Cyber Security and security operations experience.
  • Experience of onboarding, tuning, reporting and configuring SIEM solutions
  • Experience of threat intelligence
  • Leadership and mentoring experience and skills
  • Understanding of low-level concepts including operating systems and networking
  • Commercial experience in Penetration Testing and / or Security Monitoring
  • Understanding of networking and infrastructure design
  • Knowledge/experience of one or more System administration (Linux, Windows, Mac)
  • Self‑motivated individual with flexible approach to working.
  • Excellent interpersonal skills with the ability to explain technical problems to non‑technical business stakeholders at all levels.
  • Active or ability to obtain SC clearance

Responsibilities

  • Oversee completion of day-to-day checklist(s), including log review, management report scheduling & running, alert analysis, and escalation follow up
  • Remain current on cyber security trends and intelligence to guide the security analysis & identification capabilities of the CSOC team
  • Provide oversight, guidance and mentoring to L2 & L3 analysts, and fulfil SOC Manager responsibilities in the absence of the SOC Manager
  • Oversee a number of analysts as part of a virtual team of L1 and L2 analysts, including objectives setting, performance management / reviews, training & development, and BAU activities including shift cover
  • Perform advanced event and incident analysis, including baseline establishment and trend analysis
  • Support on-call arrangements as part of a Rota, to support L1 Analysts working out of hours
  • Support Major Incident Response activity, from a Protective Monitoring perspective, including supporting teams in identification, containment, and remediation of security related threat
  • Provide timely advice and guidance on the response action plans for events and incidents based on incident type and severity
  • Identify, create and implement improvements to procedures and processes, with the SOC Manager’s approval
  • Identify opportunities for SOC and client SIEM platform configuration improvements, use case development, monitoring rule creation, tuning & optimization
  • Stakeholder and Client Reporting, and engagement
  • Assist in architectural design to facilitate the onboarding of new information systems, including the assessment, parsing, onboarding of log sources, and use case and rule development

Skills

SOC Analyst experience
Leadership & mentoring
Threat intelligence
SIEM knowledge
Analytical thinking

Tools

IBM QRadar
Microsoft Sentinel
MDE
MDI
Defender for Cloud

Job description

Level 3 SOC Analyst Hybrid – with 2 days in our Belfast office – HillView House

As an experienced Senior Cyber Security Operations Analyst, you will be responsible for handing security incidents received/escalated from the CSOC Analyst (Tier 1 or Tier 2) and perform a business impact analysis on the security incident. You will leverage a deep understanding of information security technologies, you will aid in triaging threat intelligence from multiple sources and add contextual information to the security incident, perform additional analysis and based on the business impact will recommend the response actions and escalation path. You will be guided by Threat Intelligence which is actionable information (e.g. IOCs/TTPs), conduct threat hunting activities; leveraging and analyzing sources of information as available through the SIEM, in addition identify and investigate potential suspicious activity as well as helping organizations identify, isolate and contain security issues. You will support the initial implementation and management of security related technologies, including (but not limited to) IBM QRadar, Microsoft Sentinel, MDE, MDI and Defender for Cloud. Successful candidate must hold - SC-200 Certification Successful candidate must be eligible for SC clearance

Company Values

Customer First, Always; Fearless Innovation; Achieve Together; Everyone is Valued.

What You’ll Be Doing:
  • Oversee completion of day-to-day checklist(s), including log review, management report scheduling & running, alert analysis, and escalation follow up
  • Remain current on cyber security trends and intelligence (open source and commercial) in order to guide the security analysis & identification capabilities of the CSOC team
  • Provide oversight, guidance and mentoring to L2 & L3 analysts, and fulfil SOC Manager responsibilities in the absence of the SOC Manager
  • Oversee a number of analysts as part of a virtual team of L1 and L2 analysts, including objectives setting, performance management / reviews, training & development, and BAU activities including shift cover etc.
  • Perform advanced event and incident analysis, including baseline establishment and trend analysis.
  • Support on-call arrangements as part of a Rota, to support L1 Analysts working out of hours
  • Support Major Incident Response activity, from a Protective Monitoring perspective, including supporting teams in identification, containment, and remediation of security related threat.
  • Provide timely advice and guidance on the response action plans for events and incidents based on incident type and severity.
  • Identify, create and implement improvements to procedures and processes, with the SOC Manager’s approval.
  • Identify opportunities for SOC and client SIEM platform configuration improvements, use case development, monitoring rule creation, tuning & optimization.
  • Stakeholder and Client Reporting, and engagement
  • Assist in architectural design to facilitate the onboarding of new information systems, including the assessment, parsing, onboarding of log sources, and use case and rule development.
What we’re looking for:
  • Level 3 SOC Analyst / Senior Cyber Security and security operations experience
  • Experience of onboarding, tuning, reporting and configuring SIEM solutions
  • Experience of threat intelligence
  • Leadership and mentoring experience and skills
  • Understanding of low-level concepts including operating systems and networking
  • Commercial experience in Penetration Testing and / or Security Monitoring
  • Understanding of networking and infrastructure design
  • Knowledge/experience of one or more System administration (Linux, Windows, Mac)
  • Self‑motivated individual with flexible approach to working.
  • Excellent interpersonal skills with the ability to explain technical problems to non‑technical business stakeholders at all levels.
  • Strong written and oral communication skills
  • Active or ability to obtain SC clearance
Preferred Qualifications & Experience:
  • IT Certifications, including Network+, Security+ Protective Monitoring / SOC Certifications, including CySA+ Cyber Security Certifications, including CISMP, CISSP
  • Experience with various Microsoft Technologies, including Microsoft Defender for Endpoint, Identity and Cloud Experience with SIEM platforms, including IBM QRadar, Microsoft Sentinel and LogRhythm
  • In-depth experience with Microsoft Sentinel, including use case and rule development, workbook / playbook creation, KQL & Logic Apps / SOAR
  • Experience in managing Microsoft Sentinel as an MSSP, including Lighthouse, and management and multi-customer environments using DevOps
How this aligns to our Values

Customer First, Always: We prioritise our customers by delivering effective cyber security monitoring, incident response, and expert guidance that protects their services and supports their success.

Fearless Innovation: We embrace continuous improvement by identifying new threats, enhancing detection capabilities, and driving innovative security solutions that strengthen our services.

Achieve Together: We collaborate across teams, share knowledge, and support one another to deliver outstanding security outcomes and achieve our collective goals.

Everyone is Valued: We foster an inclusive and supportive environment where every colleague is respected, empowered to develop, and encouraged to contribute their unique perspectives.

Join Capita – Where Innovation Meets Opportunity

Capita is a dynamic leader in consulting and digital services, helping some of the UK’s most recognised organisations transform and thrive. We use cutting‑edge technology and fearless innovation to create smarter, more efficient solutions that make a real difference. Our work spans diverse sectors—government, healthcare, education, and finance—offering you the chance to contribute to projects that impact millions of lives. At Capita, you’ll be part of a collaborative, forward‑thinking team that values creativity, growth, and inclusion. We’re committed to your development and success, providing opportunities to learn, progress, and shape better outcomes for customers and communities.

What’s in it for you?
  • Hybrid – 2 days office location Belfast HillView House
  • Competitive salary
  • 23 days’ holiday, rising to 27 (pro rata) – plus the option to buy more after qualifying period
  • Paid volunteering day with a charity of your choice
  • Generous family leave policies – including 15 weeks’ fully paid maternity, adoption, and shared parental leave
  • Cycle2Work scheme, pension, life assurance, and more
Equal Opportunities

We are committed to building a workforce that reflects the diversity of the communities we serve.

As part of our strategic goals, we are focused on accelerating gender and ethnic representation in leadership roles.

We warmly encourage applications from women and individuals from Black, Asian, and other ethnic minority backgrounds.

We’re an equal opportunity and Disability Confident employer, which means we recruit and develop people based on their merit and passion.

We’re committed to providing an inclusive, barrier‑free recruitment process and working environment for everyone.

If you need the job description or application form in an alternative format (such as large print or audio), or if you’d like to discuss other changes or support you might need going forward, please email reasonableadjustments@capita.com and we’ll get back to you.

For more information about equal opportunities and process adjustments, please visit the Capita Careers website.

Location and Contract
  • Location: Belfast , United Kingdom
  • Time Type: Full time
  • Contract Type: Permanent
About Capita

Capita is an AI‑enabled business services partner. We work with organisations across the public and private sectors, helping them deliver better, more efficient services. Every day, millions of people rely on services we support across central and local government and regulated industries. We combine technology, data and AI with the expertise and judgement of our people to help clients solve complex challenges and deliver better outcomes for the people and communities they serve.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Level 3 SOC Analyst
Level 3 SOC Analyst

Capita plc • Belfast City District

Hybrid
GBP 60,000 - 90,000
Hybrid work pattern
Competitive salary
23 days holiday (pro rata)
+3
Senior SOC Analyst - Manchester
Senior SOC Analyst - Manchester

BAE Systems Digital Intelligence • Manchester

Hybrid
GBP 60,000 - 90,000
£5,000 referral bonus
Hybrid working
Major Incident Manager
Major Incident Manager

Capita • Newtownabbey

On-site
GBP 60,000 - 85,000
On call allowance
23 days holiday
Volunteer day
+4
Senior SOC Analyst – Manchester
Senior SOC Analyst – Manchester

BAE Systems • Manchester

Hybrid
GBP 70,000 - 100,000
Hybrid working
Referral bonus £5,000
Senior SOC Analyst (24/7 Shift) - Public Sector
Senior SOC Analyst (24/7 Shift) - Public Sector

IBM • Hursley

Hybrid
GBP 65,000 - 90,000
Flexible working styles
Sabbatical programs
Maternity returners scheme
+2
Security Command Centre - Onsite and On Shift (Security Incident Management Analyst)
Security Command Centre - Onsite and On Shift (Security Incident Management Analyst)

Capgemini • Inverness

Hybrid
GBP 40,000 - 60,000
Flexible working
Wellbeing programs
SOC Analyst - SC Cleared
SOC Analyst - SC Cleared

Sanderson Government & Defence • Greater London

Hybrid
GBP 146,000 - 151,000
Senior SOC Analyst: Threat Hunting & SIEM Lead (Hybrid Belfast)
Senior SOC Analyst: Threat Hunting & SIEM Lead (Hybrid Belfast)

Capita plc • Belfast City District

Hybrid
GBP 60,000 - 90,000
Hybrid work pattern
Competitive salary
23 days holiday (pro rata)
+3
Senior SOC Analyst - Hybrid (Belfast)
Senior SOC Analyst - Hybrid (Belfast)

Capita • Belfast City District

Hybrid
GBP 65,000 - 90,000
Hybrid – 2 days in Belfast office
Competitive salary
25 days holiday + 2 days pro rata
+5
Cyber Security SOC Analyst – 11626CA2
Cyber Security SOC Analyst – 11626CA2

Proactive.IT Appointments Limited • Bristol

On-site
GBP 40,000 - 45,000