SOC Analyst
SOC Analyst - Level 2 - Leeds - Hybrid
My client is looking for for an experienced SOC Analyst - Level 2 to join their Security Operations Centre and help protect the organisation against evolving cyber threats. You will be responsible for investigating and responding to security alerts and incidents, performing detailed analysis of suspicious activity, and supporting the continuous improvement of our detection and response capabilities. This is a hands-on role suited to an analyst who is comfortable working independently on complex investigations and escalating significant incidents when required.
Key Responsibilities
- Monitor and investigate security alerts generated by SIEM, EDR, NDR and other security technologies.
- Perform Level 2 triage and in-depth investigation of suspected security incidents.
- Analyse security logs, network traffic, endpoint activity and authentication events.
- Identify indicators of compromise (IOCs), attack techniques and potential threat activity.
- Investigate phishing, malware, credential compromise, lateral movement and suspicious authentication incidents.
- Contain and escalate security incidents in accordance with established incident response procedures.
- Perform threat hunting across endpoints, networks and cloud environments.
- Develop and improve SIEM detection rules, correlation logic and investigation playbooks.
- Contribute to vulnerability, threat intelligence and security monitoring activities.
- Support continuous improvement of SOC processes, procedures and automation.
Essential Skills & Experience
- Proven experience working within a SOC or security operations environment.
- Strong understanding of security monitoring, incident detection and incident response.
- Hands-on experience with a SIEM platform such as Microsoft Sentinel, Splunk, QRadar or Elastic.
- Experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike or SentinelOne.
- Strong knowledge of Windows and Linux security events and logging.
- Experience investigating phishing, malware, account compromise and suspicious endpoint activity.
- Ability to analyse logs and correlate events from multiple security and infrastructure sources.
Desirable
- Experience with Microsoft Azure, Microsoft 365 or AWS security monitoring.
- Experience with threat hunting and developing detection use cases.
- Knowledge of PowerShell, Python or another scripting language.
What They Offer
- Competitive salary and benefits package.
- Hybrid/flexible working options.
- Professional development and funded security certifications.
- Exposure to a broad range of security technologies and real-world incidents.
- Supportive and collaborative security team.
- Opportunities to progress towards senior SOC, threat hunting, detection engineering or incident response roles.