Security Operations Center Analyst L2

Communicate Technology

Leeds

On-site

GBP 35,000 - 52,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Communicate SOC is seeking an experienced L2 SOC Analyst to join our MSSP security operations centre. You will help protect client environments through threat detection, incident investigation, and ongoing monitoring improvements.

You will act as an escalation point for Tier 1 analysts, investigate complex events and support the development of detection capabilities across multiple customer environments, with an on-call rota as part of a Monday–Friday shift.

Qualifications

  • Experience working in a SOC, MSSP, MDR, or cyber security operations environment.
  • Experience investigating and responding to incidents across endpoint, network, cloud, and identity platforms.
  • Strong understanding of security operations, incident response, and threat detection methodologies.
  • Hands-on with SIEM platforms such as CrowdStrike, Microsoft Sentinel, Splunk, QRadar, or similar.
  • Expertise with EDR/XDR technologies, including Microsoft Defender XDR and CrowdStrike.
  • Good working knowledge of Windows, Active Directory, Microsoft 365, networking, and authentication technologies.
  • Certifications such as SC-200, Security+, CySA+, AZ-500 or equivalent are desirable.

Responsibilities

  • Investigate security alarms end-to-end and validate escalations from Tier 1 analysts.
  • Analyse logs, alerts, and threat intelligence to determine the scope, impact, and root cause of security incidents.
  • Correlate events across multiple security technologies to identify malicious activity and IOC indicators.
  • Act as a technical escalation point, providing guidance to junior analysts.
  • Document investigations and remediation actions within case management systems.

Job description

Communicate SOC is seeking an experienced and proactive L2 SOC Analyst to join our growing Managed Security Services team. Working within our Security Operations Centre (SOC), you will play a key role in protecting client environments through threat detection, incident investigation, response activities, and the continual improvement of security monitoring capabilities.

As an L2 Analyst, you will act as an escalation point for Tier 1 analysts, investigating complex security events, engaging with incident response activities, and supporting the development of detection capabilities across multiple customer environments. This role offers exposure to a broad range of security technologies and opportunities to further develop your technical expertise within a fast-paced MSSP environment.

This role operates in a staggered shift between Monday-Friday 0830—1730 and all team members are required to participate in an on-call rota to support continuous monitoring and incident response.

Key Responsibilities
Security Monitoring & Investigation
  • Investigate security alarms end-to-end and validate escalations from Tier 1 analysts.
  • Analyse logs, alerts, and threat intelligence to determine the scope, impact, and root cause of security incidents.
  • Correlate events across multiple security technologies to identify malicious activity, attack patterns, and indicators of compromise (IOCs).
  • Act as a technical escalation point, providing guidance and support to junior analysts.
  • Document investigations, findings, and remediation actions within case management systems.
  • Ensure incidents are prioritised and managed in line with customer requirements and service levels.
  • Conduct detailed investigations and support response activities for security incidents, including phishing, malware, credential compromise, and other cyber threats, ensuring timely and effective remediation.
  • Coordinate and execute containment, eradication, and recovery activities in line with approved response procedures, including actions such as endpoint isolation, account containment, and IOC blocking.
  • Provide clear updates and technical summaries to internal teams and customer stakeholders.
  • Produce incident reports and contribute to post-incident reviews and lessons learned activities.
SOC Development
  • Develop and tune detection rules, use cases, and alert logic to improve detection quality and reduce false positives.
  • Create and maintain operational documentation, including playbooks, runbooks, and knowledge articles.
  • Contribute to improvements across SIEM, EDR/XDR, SOAR, and related security technologies.
  • Identify gaps in monitoring coverage and recommend enhancements to SOC processes and tooling.
  • Support customer onboarding activities, ensuring monitoring and response requirements are implemented effectively.
Professional Development
  • Maintain awareness of emerging threats, vulnerabilities, and attack techniques.
  • Contribute to knowledge sharing and support the development of Tier 1 analysts.
  • Participate in training, certifications, technical exercises, and threat hunting activities.
  • Support a culture of continuous improvement across the SOC.
Skills & Requirements
  • Experience working within a SOC, MSSP, MDR, or cyber security operations environment.
  • Experience investigating and responding to security incidents across endpoint, network, cloud, and identity platforms.
  • Strong understanding of security operations, incident response, and threat detection methodologies.
  • Hands-on experience with SIEM platforms such as CrowdStike NGS, Microsoft Sentinel, Splunk, QRadar, or similar.
  • Expertise with EDR/XDR technologies, including Microsoft Defender XDR and CrowdStrike.
  • Good working knowledge of Windows, Active Directory, Microsoft 365, networking, and authentication technologies.
  • Ability to analyse security events, correlate data from multiple sources, and make risk-based decisions.
  • Strong analytical, problem-solving, and communication skills.
  • Experience creating technical documentation and maintaining accurate incident records.
  • Relevant certifications such as SC-200, Security+, CySA+, AZ-500, or equivalent experience are desirable.

This role is ideal for an established Tier 1 analyst looking to progress into a more investigative and technically focused role, or an existing Tier 2 analyst seeking broader exposure within a managed security services environment.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Operations Center Analyst L1
Security Operations Center Analyst L1

Communicate Technology • Leeds

On-site
GBP 30,000 - 42,000
SOC Analyst L2: Threat Detection & Incident Response
SOC Analyst L2: Threat Detection & Incident Response

Communicate Technology • Leeds

On-site
GBP 35,000 - 52,000
L1 SOC Analyst - Telecommuncations
L1 SOC Analyst - Telecommuncations

Hamilton Barnes Associates Limited • West Yorkshire

On-site
GBP 29,000 - 36,000
Career progression into threat hunting
Mentorship from experienced analysts
Support for certifications and ongoing
+2
Senior SOC Analyst
Senior SOC Analyst

GCS Recruitment • England

On-site
GBP 90,000 - 120,000
Security Analyst
Security Analyst

Talion Cyber Security • Wakefield

On-site
GBP 32,000 - 52,000
Level 1 SOC Analyst - MSP
Level 1 SOC Analyst - MSP

Hamilton Barnes Associates Limited • West Yorkshire

On-site
GBP 29,250 - 35,750
Career progression pathways
Hands-on experience with industry-leading security tools
Mentorship from experienced analysts
+2
Senior SOC Analyst
Senior SOC Analyst

慨正橡扯 • Greater London

On-site
GBP 50,000 - 70,000
L3 SOC Analyst
L3 SOC Analyst

Saviynt • United Kingdom

On-site
GBP 60,000 - 80,000
Security Operations Center Analyst (L1)
Security Operations Center Analyst (L1)

SecurityHQ Ltd. • Greater London

Hybrid
GBP 32,000 - 45,000
2nd/3rd Line Security Analyst
2nd/3rd Line Security Analyst

Xact Placements Limited • Reading

Hybrid
GBP 50,000 - 60,000
Hybrid work arrangement
Competitive salary