Senior SOC Analyst - Leeds

BAE Systems Digital Intelligence

Leeds

Hybrid

GBP 45,000 - 60,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

£5,000 referral bonus
Hybrid Working

Job summary

BAE Systems Digital Intelligence in Leeds operates a 24/7 Security Operations Centre, delivering monitoring, detection and response services for a major UK CNI client. The role is 24/7 shift-based, requiring DV clearance and collaboration across multiple locations, including UK and customer sites.

You will utilise SIEM tools to detect, investigate and respond to cyber threats. Hybrid working is supported to balance on-site presence in Leeds with remote collaboration.

Qualifications

  • Experience in security operations and SOC processes.
  • Ability to work in 24/7 shift rotation with DV clearance.
  • Strong analytical and investigative skills.
  • Experience with cloud platforms (AWS/Azure).

Responsibilities

  • Monitor, triage, analyse and investigate alerts and logs.
  • Categorise incidents per policy and document findings.
  • Write security incident tickets with quality reporting.
  • Assist remediation and coordinate with customers.
  • Produce incident review reports and improvement recommendations.
  • Develop workflows for automation into SOAR and improve use cases.

Skills

Python scripting
Splunk
Sentinel
Security architecture
Threat intelligence
AWS/Azure cloud
Incident investigation

Tools

Splunk (ES)
Sentinel
SOAR tools

Job description

Location(s): UK, Europe & Africa : UK : Leeds BAE Systems Digital Intelligence is home to 4,500 digital, cyber and intelligence experts. We work collaboratively across 10 countries to collect, connect and understand complex data, so that governments, nation states, armed forces and commercial businesses can unlock digital advantage in the most demanding environments.

Location(s): UK, Europe & Africa : UK : Leeds BAE Systems Digital Intelligence is home to 4,500 digital, cyber and intelligence experts. We work collaboratively across 10 countries to collect, connect and understand complex data, so that governments, nation states, armed forces and commercial businesses can unlock digital advantage in the most demanding environments.

Job Title: Senior SOC Analyst
Requisition ID: 123212
Location: Leeds
Grade: GG09-GG10
Referral Bonus: £5,000
SOC Senior Analyst & Shift Lead
Role description

BAE Systems have been contracted to undertake the day to day operation of (and incremental improvement of) a dedicated Security Operations Centre (SOC) to support the defence of a major UK CNI organisation. The networks protected are predominantly hosted in Azure and AWS cloud platforms, with many hundred systems within these environments that must be protected. The customer is committed to development of this improved SOC to be a benchmark of best practice and excellence in reflection of the significant threat that the protected systems are subject to.

The SOC will be staffed by a blend of customer and BAE Systems staff, based in multiple locations, but with the day to day operations based from our Leeds office (due to the need for customer network access available at this location).

The SOC Analyst roles are ‘hands‑on’ shift based roles, working as part of a 24/7 operation with four shift teams working in a standard rotation. They are responsible for utilising the SOC’s Security Incident and Event Management (SIEM) toolsets to detect and investigate potential Security and Service Incidents occurring within the monitored networks.

These roles require a minimum of SC clearance and be prepared to undergo DV clearance.

Initial requirements are for a blend of 6 month and 12 month roles, which may be extended in future subject to other programme variables that will be clarified during delivery. Position is expected to work from company offices on a full time basis.

Responsibilities
  • Ensure that the shift handover brief is prepared and delivered to the incoming shift
  • Monitor, triage, analyse and investigate alerts, log data and network traffic using the Protective Monitoring platform and Internet resources to identify cyber‑attacks / security incidents.
  • Categorise all suspected incidents in line with the Security Incident policy
  • Recognise potential, successful and unsuccessful intrusion attempts and compromises through reviews and further analysis of relevant event detail and incident summary information.
  • Write up high quality security incident tickets using a combination of existing knowledge resources and independent research.
  • Assist with remediation activities and conduct permitted remediation (or support customer stakeholders) to inhibit cyber‑attacks, clean up IT systems and secure networks against repeat attacks.
  • Produce security incident review reports to present information about the security incident and provide security improvement recommendations based on the security incident review.
  • Understand Threat Intelligence and its use in an operational environment
  • Support incident response to national scale incidents in a coaching capacity
  • Work with other teams within BAE to improve services on the basis of customer needs.
  • Produce new workflows for automation into SOAR tools for common attack types.
  • Continually improve the service and review use cases and propose changes and enhancements in line with the changing threat.
Requirements
Technical
  • Basic Python and/or scripting skills, Windows, OS X, and Linux
  • Experience using Splunk and Sentinal
  • Working with a range of security tooling/technology
  • Strong understanding of security architecture, in particular networking
  • Detailed understanding of threat intelligence and threat actors, TTPs and operationalising threat intelligence.
  • Experience in investigating complex network intrusions (by state-sponsored groups or targeted ransomware attacks).
  • Understand TCP/IP component layers to identify normal and abnormal traffic
  • Understanding of AWS &/or Azure cloud services
  • Experience of Splunk (with ES) &/or Sentinel, content development experience desirable
Non-technical
  • Client side consulting, including stakeholder engagement and the ability to communicate insights and concepts to others (including briefing skills and report writing)
  • Coaching mindset – Mentor team.
  • Security process development
  • Able to understand and adapt to different cultures and hierarchical structures.
  • Self-starter and capable of independent working
  • Team player and adept at working in multi-disciplinary and diverse teams
Desirable
  • Software engineering experience
  • Penetration testing skills
Life at BAE Systems Digital Intelligence

We are embracing Hybrid Working. This means you and your colleagues may be working in different locations, such as from home, another BAE Systems office or client site, some or all of the time, and work might be going on at different times of the day.

By embracing technology, we can interact, collaborate and create together, even when we’re working remotely from one another. Hybrid Working allows for increased flexibility in when and where we work, helping us to balance our work and personal life more effectively, and enhance well-being.

Diversity and inclusion are integral to the success of BAE Systems Digital Intelligence. We are proud to have an organisational culture where employees with varying perspectives, skills, life experiences and backgrounds – the best and brightest minds – can work together to achieve excellence and realise individual and organisational potential.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior SOC Analyst – Leeds
Senior SOC Analyst – Leeds

BAE Systems • Leeds

Hybrid
GBP 65,000 - 90,000
£5,000 referral bonus
Senior SOC Analyst – Manchester
Senior SOC Analyst – Manchester

BAE Systems • Manchester

Hybrid
GBP 70,000 - 100,000
Hybrid working
Referral bonus £5,000
Senior SOC Analyst - Manchester
Senior SOC Analyst - Manchester

BAE Systems Digital Intelligence • Manchester

Hybrid
GBP 60,000 - 90,000
£5,000 referral bonus
Hybrid working
Senior SOC Analyst & Shift Lead — Hybrid (Leeds)
Senior SOC Analyst & Shift Lead — Hybrid (Leeds)

BAE Systems • Leeds

Hybrid
GBP 65,000 - 90,000
£5,000 referral bonus
SOC Analyst - SC Cleared
SOC Analyst - SC Cleared

Sanderson Government & Defence • Greater London

Hybrid
GBP 146,000 - 151,000
NSL – Operational Cyber Software Engineer
NSL – Operational Cyber Software Engineer

Cyber UK • Greater London

Hybrid
GBP 45,000 - 75,000
Dedicated training budget
Flexible working hours
Private medical and dental insurance
+4
Senior SOC Analyst
Senior SOC Analyst

Searchability • Farnborough

On-site
GBP 63,000 - 77,000
Shift allowance
Training & certifications support
Opportunity to work on high profile UK
+1
Senior SOC Analyst & Shift Lead - Hybrid
Senior SOC Analyst & Shift Lead - Hybrid

BAE Systems Digital Intelligence • Manchester

Hybrid
GBP 60,000 - 90,000
£5,000 referral bonus
Hybrid working
SOC Shift Lead
SOC Shift Lead

Sopra Steria • Hemel Hempstead, Farnborough

On-site
GBP 39,000 - 65,000
25 days annual leave
Health cash plan
Life assurance
+1
Senior SOC Analyst
Senior SOC Analyst

Searchability NS&D • Farnborough

On-site
GBP 42,000 - 70,000
Shift allowance included within the包
Ongoing training and professional dev
Support towards cyber security certs
+1