SOC Analyst

Tank Recruitment

Greater London

On-site

GBP 60,000 - 90,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Tank Recruitment is seeking an experienced Incident Response Analyst to support detection, triage, investigation, containment and resolution of cyber security incidents across a complex enterprise environment. You will work across Windows and Linux systems, investigate alerts, develop response playbooks and provide updates to senior stakeholders.

The role requires hands-on experience with SIEM and EDR/XDR, knowledge of MITRE ATT&CK, NIST frameworks, and a proactive approach to threat hunting and

Qualifications

  • Practical experience in cyber security incident response or SOC environments.
  • Hands-on with SIEM and EDR/XDR technologies.
  • Experience investigating Windows and Linux systems, authentication activity, security logs and network traffic.
  • Strong understanding of the incident response lifecycle.
  • Knowledge of MITRE ATT&CK, Cyber Kill Chain and NIST.

Responsibilities

  • Monitor and investigate alerts from SIEM, EDR/XDR, identity, email, cloud and network security technologies.
  • Triage incidents, assess severity and business impact, and coordinate containment, eradication and recovery.
  • Investigate phishing, malware, account compromise, data loss, unauthorised access and suspicious network activity.
  • Collect, preserve and analyse endpoint, server, identity, network, email and cloud artefacts.
  • Analyse logs, packet captures, forensic images and security telemetry to establish scope, root cause and attacker activity.
  • Identify IOCs, attacker behaviours, TTPs and map findings to MITRE ATT&CK where appropriate.
  • Develop and execute threat hunts and contribute to detection rule, monitoring and logging improvements.
  • Maintain incident records, investigation timelines, evidence and post-incident reports.
  • Develop and maintain incident response playbooks, procedures and communication processes.
  • Conduct post-incident reviews, root-cause analysis and lessons-learned activities.
  • Provide clear technical and management updates to senior stakeholders.

Skills

Incident response
Security monitoring
SOC operations
SIEM
EDR/XDR
Windows security
Linux security
MITRE ATT&CK
NIST
Communication
Analytical

Education

Bachelor's degree in cybersecurity

Tools

Microsoft Sentinel
Defender XDR
PowerShell
Python
KQL
Wireshark
EnCase

Job description

Incident Response Analyst

We are seeking an experienced Incident Response Analyst to support the detection, triage, investigation, containment and resolution of cyber security incidents across a complex enterprise environment.

Key Responsibilities
  • Monitor and investigate alerts from SIEM, EDR/XDR, identity, email, cloud and network security technologies.
  • Triage incidents, assess severity and business impact, and coordinate containment, eradication and recovery.
  • Investigate phishing, malware, account compromise, data loss, unauthorised access and suspicious network activity.
  • Collect, preserve and analyse endpoint, server, identity, network, email and cloud artefacts.
  • Analyse logs, packet captures, forensic images and security telemetry to establish scope, root cause and attacker activity.
  • Identify IOCs, attacker behaviours, TTPs and map findings to MITRE ATT&CK where appropriate.
  • Develop and execute threat hunts and contribute to detection rule, monitoring and logging improvements.
  • Maintain incident records, investigation timelines, evidence and post-incident reports.
  • Develop and maintain incident response playbooks, procedures and communication processes.
  • Conduct post-incident reviews, root-cause analysis and lessons-learned activities.
  • Provide clear technical and management updates to senior stakeholders.
Essential Skills & Experience
  • Practical experience in cyber security incident response, security monitoring or a SOC environment.
  • Hands-on experience with SIEM and EDR/XDR technologies.
  • Experience investigating Windows and Linux systems, authentication activity, security logs and network traffic.
  • Strong understanding of the incident response lifecycle.
  • Knowledge of MITRE ATT&CK, Cyber Kill Chain and NIST.
  • Good understanding of enterprise networking, IAM, cloud, email and endpoint security.
  • Experience with digital forensics and evidence handling.
  • Strong communication, investigation and analytical skills.
Desirable
  • Banking, financial services or other regulated-sector experience.
  • Microsoft Sentinel, Defender XDR, Defender for Identity or Defender for Cloud.
  • KQL, PowerShell, Python or similar scripting/automation.
  • Threat hunting, malware analysis and detection engineering.
  • Azure and Microsoft 365 investigation experience.
  • EnCase, FTK, Velociraptor, Volatility or Wireshark.
  • Certifications such as GCIH, GCIA, GCFA, GNFA, SC-200, CySA+ or CISSP.
Qualifications
  • Relevant cyber security experience, degree or equivalent practical experience. Knowledge of NIST, CIS Controls and recognised information security standards
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior SOC Analyst
Senior SOC Analyst

Network IT • Milton Keynes

On-site
GBP 83,000 - 124,000
Incident Response Analyst
Incident Response Analyst

Hamilton Barnes ? • United Kingdom

Remote
GBP 45,000 - 55,000
SOC Analyst (24/7 Shift) - Public Sector
SOC Analyst (24/7 Shift) - Public Sector

IBM • Hursley

On-site
GBP 65,000 - 90,000
Security Analyst
Security Analyst

Talion Cyber Security • Wakefield

On-site
GBP 32,000 - 52,000
2nd/3rd Line Security Analyst
2nd/3rd Line Security Analyst

Xact Placements Limited • Reading

On-site
GBP 50,000 - 60,000
Hybrid work arrangement
Competitive salary
SOC / Cyber Threat Detection Analyst – SANS/GIAC
SOC / Cyber Threat Detection Analyst – SANS/GIAC

Cyber UK • Wokingham

On-site
GBP 45,000 - 70,000
Excellent benefits and training
Cyber Security Analyst
Cyber Security Analyst

Synapri • Greater London

On-site
GBP 50,000 - 70,000
Senior Incident Response Analyst (VP)
Senior Incident Response Analyst (VP)

Bonhill Partners Ltd • Greater London

On-site
GBP 120,000 - 180,000
Security Operations Center Analyst L1
Security Operations Center Analyst L1

Communicate Technology • Leeds

On-site
GBP 30,000 - 42,000
Incident Response Analyst - Technology Vendor
Incident Response Analyst - Technology Vendor

Hamilton Barnes • United Kingdom

Remote
GBP 45,000 - 55,000
Fully remote work
Ongoing training
Career progression
+1