Security Operations Analyst: Threat Detection & Response

Graphic Packaging International

United Kingdom

On-site

GBP 40,000 - 70,000

Full time

4 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Graphic Packaging International seeks a Cyber Security Analyst to monitor, detect, investigate, and respond to cybersecurity threats. As part of the SOC team, you’ll protect enterprise systems, networks, and data through continuous monitoring, threat analysis, and proactive security operations.

Collaborate with security engineers, IT operations, and stakeholders to identify cyber risks and maintain a strong security posture. Requires 2+ years in SOC and considerable SIEM experience.

Qualifications

  • Bachelor's degree or equivalent practical experience in cyber security or related field.
  • 2+ years in a SOC, cyber defense, or incident response role.
  • Strong understanding of security principles, attack methods and threat actors.
  • Experience with SIEMs such as Microsoft Sentinel, Splunk, QRadar or ArcSight.
  • Knowledge of Windows/Linux/cloud networks, and incident investigation.

Responsibilities

  • Monitor security alerts and events from SIEMs, EDR/XDR, firewalls and cloud security tools.
  • Triage and analyze security events for legitimacy, impact and severity.
  • Investigate IOCsmalicious behavior and correlate events to identify threats.
  • Escalate incidents using established procedures and participate in IR activities.
  • Document findings and maintain incident records; support containment and recovery.

Skills

Analytical thinking
Collaboration and teamwork
Problem-solving
Calm under pressure
Strong communication

Education

Bachelor's degree in Cyber Security, Computer Science, IT, or related field
Equivalent practical experience

Tools

Microsoft Sentinel
Splunk
QRadar
ArcSight
EDR/XDR platforms

Job description

The Cyber Security Analyst is responsible for monitoring, detecting, investigating, and responding to cybersecurity threats and security incidents within the organization's environment. As a member of the SOC team, this role focuses on protecting enterprise systems, networks, applications, and data through continuous monitoring, threat analysis, incident response, and proactive security operations.

The successful candidate will work closely with security engineers, threat intelligence teams, IT operations, and business stakeholders to identify and mitigate cyber risks while maintaining a strong security posture.

Key Responsibilities

Security Monitoring & Detection

  • Monitor security alerts and events from SIEM, EDR/XDR, firewalls, IDS/IPS, cloud security platforms, email security gateways, and other security tools.
  • Perform triage and analysis of security events to determine legitimacy, impact, and severity.
  • Investigate suspicious activities, indicators of compromise (IOCs), and potential malicious behavior.
  • Correlate security events across multiple technologies to identify attack patterns and emerging threats.
  • Escalate incidents based on established procedures and severity classifications.
  • Participate in cybersecurity incident response activities.
  • Investigate phishing attacks, malware infections, unauthorized access attempts, credential compromise, data exfiltration, and insider threats.
  • Collect, preserve, and analyze security evidence.
  • Document findings and maintain detailed incident records.
  • Support incident containment, eradication, recovery, and post-incident reviews.

Knowledge, Skills and Experience

  • Bachelor's degree in Cyber Security, Computer Science, Information Technology, or related field, or equivalent practical experience.
  • 2+ years of experience in a Security Operations Center (SOC), cyber defense, security monitoring, or incident response role.
  • Strong understanding of cybersecurity principles, attack methodologies, and threat actor tactics.
  • Experience using SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, ArcSight, or similar.
  • Experience investigating security incidents across Windows, Linux, cloud, and network environments.
  • Knowledge of network protocols including TCP/IP, DNS, HTTP/S, SMTP, and VPN technologies.
  • Familiarity with endpoint security and EDR/XDR solutions.
  • Strong analytical and problem-solving skills.
  • Ability to work in a fast-paced operational environment.
  • CompTIA Security+
  • Certified Information Systems Security Professional (CISSP)
  • Certified Ethical Hacker (CEH)
  • Certified Information Security Manager (CISM)
  • GIAC Certifications
  • Microsoft Security Certifications (SC-200, SC-300, SC-100)
  • Global Industrial Cyber Security Professional (GICSP)
  • Risk awareness and commercial judgement
  • Analytical thinking
  • Collaboration and teamwork
  • Ability to remain calm under pressure
  • Strong organisational skills
  • Commitment to safety, quality, and operational excellence

Success Measures

  • Reduction of false positives.
  • Documentation & knowledge management.
  • Effective protection of manufacturing and business-critical systems.
  • Improvement in overall cyber security maturity across IT and OT environments.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Analyst
Cyber Security Analyst

Graphic Packaging International • United Kingdom

On-site
GBP 40,000 - 70,000
Cyber Security Operations Specialist
Cyber Security Operations Specialist

Tank Recruitment • Bath

On-site
GBP 55,000 - 85,000
Security Operations Vice President
Security Operations Vice President

JPMorgan Chase & Co. • Greater London

On-site
GBP 90,000 - 120,000
Security Operations Vice President
Security Operations Vice President

JP Morgan • Greater London

On-site
GBP 70,000 - 110,000
Cyber security Operation Manager
Cyber security Operation Manager

Agratas – A Tata Enterprise • Bridgwater

On-site
GBP 55,000 - 75,000
Security Operations Center Analyst
Security Operations Center Analyst

Anson McCade • Greater London

On-site
GBP 50,000 - 70,000
Tier 1 Security Operations Centre Analyst
Tier 1 Security Operations Centre Analyst

Securecloudplus • Stoke-on-Trent

On-site
GBP 25,000 - 36,000
Shift allowance
Cyber Security Operations Analyst
Cyber Security Operations Analyst

Caraffi • Reading

On-site
GBP 55,000 - 75,000
Cyber Security Analyst
Cyber Security Analyst

Synapri • Greater London

Hybrid
GBP 50,000 - 70,000
Cyber Security Analyst
Cyber Security Analyst

Novia Financial plc • Bath

On-site
GBP 55,000 - 75,000