Stand out for this role — generate a tailored resume and cover letter in about a minute.
Oscar in Stoke-on-Trent is seeking an experienced Tier 2 SOC Analyst to own security incidents, investigations and threat analysis within a 24/7 SOC. You'll move beyond triage to drive detection improvement and incident response, while working with SIEM/EDR tooling and cross-functional teams.
Initially office-based in Stoke-on-Trent, you’ll transition to a 3-on/3-off shift pattern with a shift allowance on top of a £50,000 base salary.
I'm currently working with a high-profile UK security organisation that is looking to add an experienced Tier 2 SOC Analyst to its growing Security Operations function.
This is a great opportunity for someone who has moved beyond purely monitoring and alert triage and wants to take genuine ownership of security incidents, investigations, threat analysis and detection improvement.
The role supports a 24/7 SOC environment protecting highly sensitive UK environments, so you'll be working on meaningful security challenges rather than simply dealing with a high volume of alerts.
£50,000 base salary + shift allowance
Stoke-on-Trent
3 days on / 3 days off
DV cleared environment
You'll initially be office-based in Stoke-on-Trent, getting fully embedded within the team and environment.
Once established, you'll move onto a 3-on / 3-off shift pattern, working shifts. A shift allowance will be paid on top of the £50,000 base salary.
As a Tier 2 analyst, you'll sit above the first line of defence and become a key escalation point for more complex security events.
You'll be involved across areas including:
You'll ideally have 1–5 years' experience within a SOC or security operations environment, with solid hands-on exposure to areas such as:
I'm particularly interested in speaking with analysts who can demonstrate that they've dealt with real security incidents and are comfortable taking ownership rather than simply escalating everything to someone else.
Relevant certifications such as BTL1/BTL2, Security+, CEH, CISSP, CCSP or vendor/SIEM-specific qualifications are beneficial, but practical capability is more important.
Due to the nature of the environment, candidates will need to hold SC and be eligible for DV security clearance.