SOC Analyst

Free-Work UK

Chippenham

On-site

GBP 32,000 - 46,000

Full time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Share scheme (3.5% + 3.5% matching)
Excellent pension
Private healthcare

Job summary

CGI is seeking a Security Operations Centre professional to join the Data and Detection Engineering team in Chippenham. You will help onboard customers, design data ingestion into Elastic, and develop detection logic for SOC triage while expanding exposure to Oracle Cloud and other cloud platforms.

You’ll contribute to day-to-day security monitoring, incident investigation, and continuous improvement while working with experienced cyber professionals in a secure environment.

Qualifications

  • Technical background in cyber security or related discipline.
  • Knowledge of SIEM technologies such as Elastic or Splunk.
  • Understanding of cyber security monitoring, alerts, incident triage or investigation.
  • General IT knowledge including Linux and enterprise platforms.
  • Strong analytical and problem‑solving skills.
  • Strong written and verbal communication skills.
  • Willingness to engage with customers and collaborate in a technical team.
  • Interest in cloud security with Oracle Cloud experience advantageous and exposure to AWS/Azure/Google Cloud beneficial.
  • Existing UK Security Clearance is advantageous; willing to progress to higher clearance if required.

Responsibilities

  • Engineer & Deliver: Design and support security data ingestion pipelines into Elastic for newly onboarded customers.
  • Develop & Detect: Draft detection rules against defined cyber security use cases and create SOC triage guides.
  • Engage & Onboard: Liaise with customers to gather technical information for SOC onboarding.
  • Monitor & Triage: Review security alerts from SIEM and other systems, assess severity and impact.
  • Investigate & Escalate: Support incident investigations and recommend containment or escalation actions.
  • Analyse & Respond: Monitor client environments, investigate alerts and respond to incidents within SLAs.
  • Learn & Improve: Research emerging threats and security practices, sharing knowledge with colleagues.
  • Support & Assure: Assist with investigations, exercises, testing, changes and first-line support.
  • Operate & Automate: Ensure scheduled jobs and automated processes run reliably.

Skills

Cyber security
SIEM
Cloud security
Data ingestion
Detection engineering
Customer engagement

Education

Computer Science
Software Engineering
Cyber Security
Digital Forensics

Tools

Elastic
Splunk
Oracle Cloud
AWS
Azure
Google Cloud

Job description

At CGI, you’ll help strengthen the cyber resilience of critical UK programmes by building the data and detection capabilities that underpin an effective Security Operations Centre. Joining our Space, Defence and Intelligence business, you’ll work with customers and experienced colleagues to onboard secure cloud environments, engineer security data pipelines and develop practical detection content. This is an opportunity to take ownership of meaningful technical work while expanding your skills across Oracle Cloud, Elastic and other major cloud platforms. You’ll have the freedom to explore better ways of detecting threats, with the guidance and support of a collaborative team around you. Whether you’re developing your cyber career or ready for your next challenge, you can make a tangible contribution to protecting important services.

CGI was recognised in the Sunday Times Best Places to Work List 2025 and has been named a UK ‘Best Employer’ by the Financial Times.

We offer a competitive salary, excellent pension, private healthcare, plus a share scheme (3.5% + 3.5% matching) which makes you a CGI Partner not just an employee. We are committed to inclusivity, building a genuinely diverse community of tech talent and inspiring everyone to pursue careers in our sector, including our Armed Forces, and are proud to hold a Gold Award in recognition of our support of the Armed Forces Corporate Covenant. Join us and you’ll be part of an open, friendly community of experts. We’ll train and support you in taking your career wherever you want it to go.

Due to the secure nature of the programme, you will need to hold UK Security Clearance or be eligible to go through this clearance. This role requires full-time onsite working in Chippenham within a restricted working environment. Applicants who already hold Security Clearance are welcomed and will need to be willing and eligible to progress to a higher level of clearance where required. Additional payments are available for full-time onsite working and for working within the restricted environment.

Candidate Profile

In this role, you will join CGI’s Data and Detection Engineering team, supporting the onboarding of new customers into the Security Operations Centre (SOC). You’ll work directly with customers to understand their environments and requirements before helping design how security data is ingested into Elastic. With a primary focus on Oracle Cloud and opportunities to build exposure to AWS, Microsoft Azure and Google Cloud, you’ll develop detection logic and triage guidance that enables the SOC to identify and respond to potential threats effectively.

You’ll also contribute to day-to-day security monitoring and incident investigation, taking responsibility for assessing alerts, understanding their potential impact and escalating where appropriate. Working alongside experienced cyber professionals, you’ll have opportunities to develop new approaches, broaden your technical knowledge and build practical experience across cloud security, SIEM and threat detection.

  • Engineer & Deliver: Design and support security data ingestion pipelines into Elastic for newly onboarded customers.
  • Develop & Detect: Draft detection rules against defined cyber security use cases and create clear SOC triage guides.
  • Engage & Onboard: Liaise directly with customers to gather the technical information required for successful SOC onboarding.
  • Monitor & Triage: Review security alerts from SIEM, intrusion detection, log monitoring and other security systems, assessing severity and potential impact.
  • Investigate & Escalate: Support security incident investigations and recommend appropriate containment, eradication or escalation actions.
  • Analyse & Respond: Monitor client environments, investigate alerts and respond to real or suspected cyber security incidents within agreed timescales.
  • Learn & Improve: Research emerging threats, technologies and security practices, sharing knowledge with colleagues and contributing to continuous improvement.
  • Support & Assure: Assist with security investigations, exercises, testing, change activities and first-line technical support.
  • Operate & Automate: Help ensure scheduled security jobs and automated processes operate correctly and reliably.
Required Qualifications To Be Successful In This Role

You’ll have a technical foundation in cyber security, computing, software engineering, digital forensics or a related discipline, combined with an interest in developing hands‑on expertise in security monitoring and detection engineering. You don’t need to know every technology from day one: we’re looking for technical aptitude, curiosity and sound judgement, together with the communication skills to work effectively with customers and colleagues in a secure environment.

  • A technical background or relevant qualification, such as Computer Science, Software Engineering, Cyber Security or Digital Forensics.
  • Knowledge or practical experience of SIEM technologies such as Elastic or Splunk.
  • An understanding of cyber security monitoring, alerts, incident triage or investigation.
  • A general understanding of IT technologies and operating environments, including Linux and/or other enterprise platforms.
  • Strong analytical and problem-solving skills with the ability to assess information and determine when escalation is required.
  • Strong written and verbal communication skills.
  • The confidence to engage directly with customers and collaborate effectively within a technical team.
  • An interest in cloud security, with Oracle Cloud experience advantageous and exposure to AWS, Azure or Google Cloud beneficial.
  • Existing UK Security Clearance is advantageous; you must be willing and eligible to progress to a higher level of clearance where required.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Analyst
SOC Analyst

Onyx-Conseil • Chippenham

Hybrid
GBP 55,000 - 75,000
Excellent pension
Private healthcare
Share scheme
Cloud Engineers
Cloud Engineers

CGI Group Inc. • Bagstone

On-site
GBP 60,000 - 90,000
Private healthcare
Pension scheme
CGI share scheme
DevSecOps Engineer
DevSecOps Engineer

CGI Group Inc. • Bagstone

On-site
GBP 90,000 - 130,000
Cyber Security Consultant
Cyber Security Consultant

Onyx-Conseil • Manchester

Hybrid
GBP 60,000 - 90,000
competitive salary
excellent pension
private healthcare
+1
SOC Detection Engineer - Cloud Security & Threat Detection
SOC Detection Engineer - Cloud Security & Threat Detection

Free-Work UK • Chippenham

On-site
GBP 32,000 - 46,000
Share scheme (3.5% + 3.5% matching)
Excellent pension
Private healthcare
Graduate SOC Analyst
Graduate SOC Analyst

CyPro • Greater London

Hybrid
GBP 40,000 - 65,000
Holiday: 25 days paid holiday plus 9/7
Flexible Working: three days in London
Working Hours: 9:00–17:30, potential 7
+3
Lead Security Analyst
Lead Security Analyst

Made Tech Limited • United Kingdom

On-site
GBP 90,000 - 120,000
Security Operations Analyst - Threat Detection & Cloud Data
Security Operations Analyst - Threat Detection & Cloud Data

Onyx-Conseil • Chippenham

Hybrid
GBP 55,000 - 75,000
Excellent pension
Private healthcare
Share scheme
Java Developer
Java Developer

CGI Group Inc. • Leeds

Hybrid
GBP 70,000 - 100,000
Cyber Security Engineer
Cyber Security Engineer

Advantage Resourcing UK Ltd • Stevenage

On-site
GBP 174,000 - 180,000