SOC Level 2 Security Analyst

NTT DATA

Birmingham

On-site

GBP 42,000 - 62,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

NTT DATA in the UK is seeking a Security Analyst (Level 2) for the UK Sovereign SOC to detect, investigate, and respond to security alerts and incidents.

You will validate incidents escalated from L1, run deep analyses using SIEMs like Splunk, Sentinel, or QRadar, coordinate containment, and guide L1 analysts during live incidents.

This 24/7 role requires collaboration with IT and security teams, familiarity with threat intel, SOAR playbooks, and documenting lessons learned.

Qualifications

  • Hands-on experience with SIEM platforms and incident response workflows.
  • Ability to analyse telemetry, attacker behaviour and apply log/artifact-based investigations.
  • 2–4 years' experience in the IT security industry, ideally in a SOC/NOC environment.

Responsibilities

  • Investigate security alerts and events escalated from Level 1 analysts, validating and classifying activity.
  • Coordinate and support incident response activities, containment, eradication and recovery actions.
  • Execute defined SOAR playbooks and provide feedback to improve automation and response consistency.
  • Maintain investigation records, runbooks and post-incident reports for customers and internal stakeholders.
  • Collaborate with IT, security and technical teams to resolve incidents and reduce risk.

Skills

SOC L2 experience
Analytical thinking
Clear communication
Independent working

Education

Cybersecurity certifications desirable (GIAC, CySA+, SC-200)

Tools

Splunk
Microsoft Sentinel
QRadar
Azure
AWS
Excel
Word

Job description

The team you';ll be working with:

UK Sovereign SOC

Security Analyst (Level 2)

Role Description

The SOC Analyst (L2) plays a critical role in the detection, investigation, and management of security alerts and incidents escalated from SOC Analyst (L1) teams. The position focuses on in-depth analysis, incident validation, tactical response coordination, and continuous improvement of security monitoring and response capabilities.

Operating within a 24/7 Security Operations Centre, the L2 Analyst serves as a technical escalation point for junior analysts, working closely with internal IT and security teams as well as customers to contain and remediate security incidents. The role contributes directly to improving detection quality, response efficiency, and the overall effectiveness of SOC operations.

What you';ll be doing:

You will investigate security alerts and events escalated from Level 1 analysts, validating and classifying activity to determine whether it represents a confirmed security incident. This includes performing detailed analysis to understand root cause, scope, impact, and attacker behaviour using SIEM platforms and supporting telemetry.

You will coordinate and support incident response activities in line with defined SOC and customer processes, assisting with containment, eradication, and recovery actions. During high-severity or customer-impacting incidents, you will follow major incident procedures and ensure timely, accurate escalation to stakeholders. You will provide technical guidance to L1 analysts during live incidents and help maintain investigation quality under pressure.

You will execute defined SOAR playbooks as part of incident response and provide structured feedback to improve automation, response consistency, and efficiency. You will maintain awareness of SOC performance metrics and service levels, such as MTTD and MTTR, and actively contribute to improving investigation quality and response outcomes.

You will apply threat intelligence to investigations and alert triage, maintaining awareness of emerging threats, vulnerabilities, and attacker techniques. Incident learnings and threat insights will be fed back into detection logic to continuously enhance SOC monitoring capabilities.

You will also contribute to the development and tuning of SOC detection use cases, ensuring alerting remains relevant, effective, and aligned to current threat activity. This includes supporting onboarding of new services, identifying detection gaps, and recommending improvements to tooling, processes, and coverage.

Clear and accurate documentation is a key part of the role. You will maintain investigation records, runbooks, and playbooks, produce post-incident reports for customers and internal stakeholders, and contribute to operational and service reporting. You will help document and implement improvements to event and incident management processes.

Collaboration is essential. You will work closely with IT, security, and technical teams to resolve incidents and reduce risk, act as a mentor and escalation point for L1 analysts, and support continual service improvement by identifying recurring issues and proposing corrective actions.

What experience you';ll bring:

You will have hands-on experience working with SIEM platforms such as Splunk, Microsoft Sentinel, or QRadar, and a strong understanding of incident response workflows and escalation management. You will be comfortable analysing security telemetry, understanding attacker behaviour, and applying log-and artifact-based investigation techniques.

You will demonstrate strong analytical thinking, sound decision-making, and the ability to remain effective during high-pressure incidents. Clear, professional communication - both written and verbal is essential, as is the ability to work independently while following and improving structured operational processes.

  • 2-4 years' experience in the IT security industry, ideally within a SOC or NOC environment, including experience operating at SOC L1 level
  • Relevant cybersecurity certifications desirable (e.g. GIAC, CySA+, SC-200)
  • Experience working with cloud platforms such as Microsoft Azure and/or AWS
  • Proficiency with Microsoft Office tools, particularly Excel and Word

Security & Working Requirements

  • Eligibility for, or holding, UK SC Clearance
  • Willingness to work within a 24/7 shift-based SOC environment, including on-call duties.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior SOC Analyst
Senior SOC Analyst

慨正橡扯 • Greater London

On-site
GBP 50,000 - 70,000
L1 SOC Analyst - Telecommuncations
L1 SOC Analyst - Telecommuncations

Hamilton Barnes Associates Limited • West Yorkshire

On-site
GBP 29,000 - 36,000
Career progression into threat hunting
Mentorship from experienced analysts
Support for certifications and ongoing
+2
L3 SOC Analyst
L3 SOC Analyst

Saviynt • United Kingdom

On-site
GBP 60,000 - 80,000
Senior SOC Analyst
Senior SOC Analyst

Focus Group • Manchester

Hybrid
GBP 60,000 - 90,000
Soc Analyst Level 1
Soc Analyst Level 1

NTT DATA • Birmingham

On-site
GBP 32,000 - 44,000
Flexible work options
Learning & Development
Equal opportunity employer
Level 1 SOC Analyst - MSP
Level 1 SOC Analyst - MSP

Hamilton Barnes Associates Limited • West Yorkshire

On-site
GBP 29,250 - 35,750
Career progression pathways
Hands-on experience with industry-leading security tools
Mentorship from experienced analysts
+2
SOC Analyst - SC Cleared
SOC Analyst - SC Cleared

Sanderson Government & Defence • Greater London

Hybrid
GBP 146,000 - 151,000
Senior SOC Analyst
Senior SOC Analyst

Searchability NS&D • Farnborough

On-site
GBP 42,000 - 70,000
Shift allowance included within the包
Ongoing training and professional dev
Support towards cyber security certs
+1
DIG - Level 1 SOC Cyber Analyst
DIG - Level 1 SOC Cyber Analyst

Morson Human Resources Limited • Hereford

On-site
GBP 42,000 - 64,000
Senior SOC Analyst
Senior SOC Analyst

GCS Recruitment • Greater London

On-site
GBP 90,000 - 120,000