SOC Analyst (24/7 Shift) - Public Sector

IBM

Hursley

On-site

GBP 65,000 - 90,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

IBM CIC in the United Kingdom seeks a Technical Consultant specialising in Threat Detection, Response & Intelligence to monitor and respond within a 24x7 SOC environment. You will lead investigations and ensure high-quality security operations across client environments.

You will work with SIEM platforms, coordinate incident response, and contribute to playbooks and continuous improvement efforts for detection capabilities and alert quality across diverse client environments.

Qualifications

  • Proven experience working in a SOC environment (L2 / L3) within a 24x7 operational setting.
  • Strong experience with SIEM platforms, such as Microsoft Sentinel, QRadar, Splunk, Elastic or similar.
  • Incident triage and investigation.
  • Security event analysis.
  • Alert validation and escalation.
  • Understanding of incident response processes and workflows.
  • Exposure to security tooling, such as EDR/XDR platforms, network security technologies, identity and access systems.
  • Ability to interpret logs and identify suspicious behaviour across endpoints, networks and cloud environments.
  • Strong communication skills, with the ability to clearly articulate incidents and risks.
  • Experience working in client-facing or service-based environments.

Responsibilities

  • Monitor, triage, and investigate security alerts and incidents across SIEM platforms.
  • Lead or support incident response activities, including initial investigation and containment coordination.
  • Act as a senior presence on shift, supporting analysts and ensuring SOC operations run smoothly.
  • Drive incident quality, ensuring playbooks and procedures are followed.
  • Produce clear incident reports and handovers; support client interactions when required.
  • Contribute to playbook development and refinement to improve SOC efficiency.
  • Collaborate with detection and engineering teams to improve alert quality and reduce false positives.

Skills

SOC operations
24x7 monitoring
Incident triage
Investigation
SIEM knowledge
Incident response
Playbook development
Threat detection
Communication

Education

Bachelor's Degree

Tools

Microsoft Sentinel
QRadar
Splunk
Elastic

Job description

Introduction

At IBM CIC, we provide technical and industry expertise to a wide range of public and private sector clients in the UK.


A career in IBM CIC means you’ll have the opportunity to work with leading professionals across multiple industries to improve the hybrid cloud and AI journey for the most innovative and valuable companies in the world. You will get the chance to deliver effective solutions, driving meaningful business change for our clients, using some of the latest technology platforms.


Curiosity and a constant quest for knowledge serve as the foundation to success here. You’ll be encouraged and supported to constantly reinvent yourself, focusing on skills in demand in an ever changing market. You’ll be working with diverse teams, coming up with creative solutions which impact a wide network of clients, who may be at their site or one of our CIC or IBM locations. Our culture of evolution centres on long-term career growth and development opportunities in an environment that embraces your unique skills and experience.


Your Role And Responsibilities

As a Technical Consultant specialising in Threat Detection, Response & Intelligence, you will support and lead the monitoring, detection, and initial response to cyber security threats within a 24×7 SOC consulting environment.


You will play a key role in maintaining operational excellence on shift, supporting incident investigation, and ensuring consistent delivery of high-quality security operations across client environments.


Working across SIEM platforms, security tooling, and incident response workflows, you will help ensure threats are identified, triaged, and escalated effectively, while contributing to the continuous improvement of SOC processes and capabilities.


This is a hands‑on operational role with responsibility for incident leadership, team support, and quality assurance, alongside exposure to client environments and senior stakeholders.


Key Responsibilities


  • Monitor, triage, and investigate security alerts and incidents across a range of SIEM and security platforms

  • Lead or support incident response activities, including:

  • Initial investigation

  • Containment coordination

  • Escalation to relevant teams

  • Act as a senior presence on shift, supporting Tier 1/2 analysts and ensuring smooth SOC operations

  • Drive incident quality and consistency, ensuring playbooks and procedures are followed

  • Support major incident initiation and coordination, including communication across technical and non-technical stakeholders

  • Analyse security events and identify

  • Patterns

  • Threat behaviours

  • Opportunities for improvement

  • Contribute to playbook development and refinement, improving SOC efficiency and response capability

  • Work with detection and engineering teams to

  • Improve alert quality

  • Reduce false positives

  • Support operational effectiveness

  • Produce clear and structured incident reports and handovers

  • Participate in shift handovers, retrospectives, and continuous improvement activities

  • Support client interactions where required, providing updates and operational insights


Preferred Education

Bachelor's Degree


Required Technical And Professional Expertise


  • Proven experience working in a SOC environment (L2 / L3 level) within a 24×7 operational setting

  • Strong experience with SIEM platforms, such as

  • Microsoft Sentinel, QRadar, Splunk, Elastic or similar

  • Practical experience in

  • Incident triage and investigation

  • Security event analysis

  • Alert validation and escalation

  • Understanding of:

  • Incident response processes and workflows

  • Threat detection methodologies

  • Exposure to security tooling, such as

  • EDR/XDR platforms

  • Network security technologies

  • Identity and access systems

  • Ability to interpret logs and identify suspicious behaviour across:

  • Endpoints

  • Networks

  • Cloud environments

  • Strong communication skills, with the ability to clearly articulate incidents and risks

  • Experience working in client-facing or service-based environments


This role is subject to pre-employment screening in line with the UK Government’s Baseline Personnel Security Standard (BPSS). An additional range of Personal Security Controls referred to as National Security Vetting (NVS) may apply, this could include meeting the eligibility requirements for The Security Check (SC) or Developed Vetting (DV).


Preferred Technical And Professional Experience


  • Experience as an Analyst and/or acting as a shift lead or senior escalation point within a SOC

  • Exposure to threat hunting or detection improvement activities

  • Experience working with

  • MITRE ATT&CK

  • Threat intelligence integration

  • Familiarity with SOAR platforms and automated response workflows

  • Relevant certifications such as:

  • SC-200

  • GCIH / GIAC

  • Vendor SIEM certifications

  • Experience working in regulated or public sector environments

  • Understanding of SOC performance metrics and continuous improvement approaches

  • Active UK Security Clearance

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Engineer - UK Public Sector
SOC Engineer - UK Public Sector

IBM • Hursley

On-site
GBP 70,000 - 100,000
Flexible working
Private medical + pension
SOC Solution Engineer
SOC Solution Engineer

Anson McCade • England

Hybrid
GBP 70,000 - 85,000
25 days annual leave + public holidays
Private healthcare, dental, wellbeing support
Contributory pension scheme
+1
Level 1 SOC Analyst - MSP
Level 1 SOC Analyst - MSP

Hamilton Barnes Associates Limited • West Yorkshire

On-site
GBP 29,250 - 35,750
Career progression pathways
Hands-on experience with industry-leading security tools
Mentorship from experienced analysts
+2
Cyber Security Analyst
Cyber Security Analyst

Digital Waffle • Greater London

On-site
GBP 42,000 - 70,000
On-Call Allowance
Benefits
Security Analyst
Security Analyst

Talion Cyber Security • Wakefield

On-site
GBP 32,000 - 52,000
Senior SOC Analyst
Senior SOC Analyst

GCS Recruitment • England

On-site
GBP 90,000 - 120,000
SOC Engineer - UK Public Sector
SOC Engineer - UK Public Sector

IBM • Abbots Worthy

On-site
GBP 65,000 - 95,000
Flexible working
Private medical
Dental & optical cover
+2
SOC Analyst - SC Cleared
SOC Analyst - SC Cleared

Sanderson Government & Defence • Greater London

Hybrid
GBP 146,000 - 151,000
SOC Shift Lead (Cyber)
SOC Shift Lead (Cyber)

Searchability • Hemel Hempstead

On-site
GBP 70,000 - 86,000
Security Operations Analyst
Security Operations Analyst

SiXworks an IBM company • Farnborough

On-site
GBP 40,000 - 60,000