SOCAnalyst Location: Home based/Remote – Must be Based in the United Kingdom Salary: Up to £35,000, shift based role with 24/7 coverage Qualifications: Must be eligible for SC Clearance The company An exciting opportunity has arisen at an award-winning Microsoft Partner for a SOC Analyst. The business is a fast … growing, industry-leading managed service and managed service security provider, delivering in to mid and large enterprise clients. This is a fantastic opportunity for a SOCAnalyst to continue their development at an established Microsoft Partner. The business has a keen focus on developing their staff by providing support for training and earning certifications. You will also … role; you must however be based in the UK to be considered. This role will also require eligibility to gain SC Clearance due to government-based customers. About The SOCAnalyst Role As a SOCAnalyst, you will support the SOC Manager, acting as an escalation point and technical SME for stakeholders within More ❯
SOCAnalyst £57000 GBP Hybrid WORKING Location: Glasgow, Scotland - United Kingdom Type: Permanent Senior SOCAnalyst Location: Glasgow (hybrid) Salary: Up to £57,000 + package NOTE: Candidates for this role must be eligible for UK Security Clearance (SC). We are seeking a Senior SOCAnalyst to join a growing … is a hybrid role based in Glasgow, offering the opportunity to take a leading role in incident response and advanced security monitoring within a dynamic environment. As a Senior SOCAnalyst, you will take ownership of escalated incidents from L1 and L2 analysts, leading investigations, performing root cause analysis, and guiding appropriate remediation actions. You will play … a key role in developing SOC use cases, enhancing monitoring capabilities, and ensuring incident response follows best practice standards. This role combines technical depth, client interaction, and leadership, requiring someone who thrives in a fast-moving environment and is comfortable working with both technical and non-technical stakeholders. Key Responsibilities Lead investigations into escalated security incidents, including detailed analysis More ❯
Senior Incident Responder - SOCAnalyst (L3) £71000 GBP Hybrid WORKING Location: Central London, Greater London - United Kingdom Type: Permanent Senior Incident Responder - SOCAnalyst (L3) Location: UK-wide (hybrid/on-site as required) Salary: £71,000 + Bonus Clearance: Must be eligible for SC Clearance Our client is a global consulting and technology … services firm, supporting public and private sector organisations with complex digital and cyber transformation. They are building out their UK Security Practice and are seeking a Senior Incident Responder - SOCAnalyst (L3) to lead investigations, manage escalations, and strengthen cyber resilience for mission-critical environments. The Role As a Senior Incident Responder, you'll be the escalation … point for L1 and L2 SOC Analysts, taking ownership of security incidents from investigation through to containment and remediation. You'll drive root cause analysis, ensure runbooks and playbooks are followed, and directly engage with clients and delivery managers to provide expert guidance on incident handling. This is a hands-on technical leadership role that combines investigation, response, threat More ❯
Cyber SecuritySOCAnalyst – London/Remote Atrium EMEA is looking for an accomplished Cyber SecuritySOCAnalyst to support the Security Incident Response Team. The team is growing, we require a strong individual contributor that will investigate, analyse, and contain security incidents. This is a fully remote role, with the occasional London office … automation (Python, Powershell, Bash, KQL etc) • Financial services sector, a benefit/Shift work NOT required Click Apply now/contact Lianne to be considered for the Cyber SecuritySOCAnalyst – London/Remote role More ❯
Cyber SecuritySOCAnalyst – London/Remote Atrium EMEA is looking for an accomplished Cyber SecuritySOCAnalyst to support the Security Incident Response Team. The team is growing, we require a strong individual contributor that will investigate, analyse, and contain security incidents. This is a fully remote role, with the occasional London office … automation (Python, Powershell, Bash, KQL etc) • Financial services sector, a benefit/Shift work NOT required Click Apply now/contact Lianne to be considered for the Cyber SecuritySOCAnalyst – London/Remote role More ❯
East London, London, United Kingdom Hybrid / WFH Options
Atrium (EMEA)
Cyber SecuritySOCAnalyst – London/Remote Atrium EMEA is looking for an accomplished Cyber SecuritySOCAnalyst to support the Security Incident Response Team. The team is growing, we require a strong individual contributor that will investigate, analyse, and contain security incidents. This is a fully remote role, with the occasional London office … automation (Python, Powershell, Bash, KQL etc) • Financial services sector, a benefit/Shift work NOT required Click Apply now/contact Lianne to be considered for the Cyber SecuritySOCAnalyst – London/Remote role More ❯
Cyber SecuritySOCAnalyst – London/Remote Atrium EMEA is looking for an accomplished Cyber SecuritySOCAnalyst to support the Security Incident Response Team. The team is growing, we require a strong individual contributor that will investigate, analyse, and contain security incidents. This is a fully remote role, with the occasional London office … automation (Python, Powershell, Bash, KQL etc) • Financial services sector, a benefit/Shift work NOT required Click Apply now/contact Lianne to be considered for the Cyber SecuritySOCAnalyst – London/Remote role More ❯
City of London, London, United Kingdom Hybrid / WFH Options
Atrium (EMEA)
Cyber SecuritySOCAnalyst – London/Remote Atrium EMEA is looking for an accomplished Cyber SecuritySOCAnalyst to support the Security Incident Response Team. The team is growing, we require a strong individual contributor that will investigate, analyse, and contain security incidents. This is a fully remote role, with the occasional London office … automation (Python, Powershell, Bash, KQL etc) • Financial services sector, a benefit/Shift work NOT required Click Apply now/contact Lianne to be considered for the Cyber SecuritySOCAnalyst – London/Remote role More ❯
Altrincham, Greater Manchester, United Kingdom Hybrid / WFH Options
Atrium (EMEA)
Cyber SecuritySOCAnalyst – London/Remote Atrium EMEA is looking for an accomplished Cyber SecuritySOCAnalyst to support the Security Incident Response Team. The team is growing, we require a strong individual contributor that will investigate, analyse, and contain security incidents. This is a fully remote role, with the occasional London office … automation (Python, Powershell, Bash, KQL etc) • Financial services sector, a benefit/Shift work NOT required Click Apply now/contact Lianne to be considered for the Cyber SecuritySOCAnalyst – London/Remote role More ❯
Bury, Greater Manchester, United Kingdom Hybrid / WFH Options
Atrium (EMEA)
Cyber SecuritySOCAnalyst – London/Remote Atrium EMEA is looking for an accomplished Cyber SecuritySOCAnalyst to support the Security Incident Response Team. The team is growing, we require a strong individual contributor that will investigate, analyse, and contain security incidents. This is a fully remote role, with the occasional London office … automation (Python, Powershell, Bash, KQL etc) • Financial services sector, a benefit/Shift work NOT required Click Apply now/contact Lianne to be considered for the Cyber SecuritySOCAnalyst – London/Remote role More ❯
Leigh, Greater Manchester, United Kingdom Hybrid / WFH Options
Atrium (EMEA)
Cyber SecuritySOCAnalyst – London/Remote Atrium EMEA is looking for an accomplished Cyber SecuritySOCAnalyst to support the Security Incident Response Team. The team is growing, we require a strong individual contributor that will investigate, analyse, and contain security incidents. This is a fully remote role, with the occasional London office … automation (Python, Powershell, Bash, KQL etc) • Financial services sector, a benefit/Shift work NOT required Click Apply now/contact Lianne to be considered for the Cyber SecuritySOCAnalyst – London/Remote role More ❯
Central London / West End, London, United Kingdom Hybrid / WFH Options
Atrium (EMEA)
Cyber SecuritySOCAnalyst – London/Remote Atrium EMEA is looking for an accomplished Cyber SecuritySOCAnalyst to support the Security Incident Response Team. The team is growing, we require a strong individual contributor that will investigate, analyse, and contain security incidents. This is a fully remote role, with the occasional London office … automation (Python, Powershell, Bash, KQL etc) • Financial services sector, a benefit/Shift work NOT required Click Apply now/contact Lianne to be considered for the Cyber SecuritySOCAnalyst – London/Remote role More ❯
Bolton, Greater Manchester, United Kingdom Hybrid / WFH Options
Atrium (EMEA)
Cyber SecuritySOCAnalyst – London/Remote Atrium EMEA is looking for an accomplished Cyber SecuritySOCAnalyst to support the Security Incident Response Team. The team is growing, we require a strong individual contributor that will investigate, analyse, and contain security incidents. This is a fully remote role, with the occasional London office … automation (Python, Powershell, Bash, KQL etc) • Financial services sector, a benefit/Shift work NOT required Click Apply now/contact Lianne to be considered for the Cyber SecuritySOCAnalyst – London/Remote role More ❯
Leeds, West Yorkshire, United Kingdom Hybrid / WFH Options
Atrium (EMEA)
Cyber SecuritySOCAnalyst – London/Remote Atrium EMEA is looking for an accomplished Cyber SecuritySOCAnalyst to support the Security Incident Response Team. The team is growing, we require a strong individual contributor that will investigate, analyse, and contain security incidents. This is a fully remote role, with the occasional London office … automation (Python, Powershell, Bash, KQL etc) • Financial services sector, a benefit/Shift work NOT required Click Apply now/contact Lianne to be considered for the Cyber SecuritySOCAnalyst – London/Remote role More ❯
London, South East, England, United Kingdom Hybrid / WFH Options
Atrium Workforce Solutions Ltd
Cyber SecuritySOCAnalyst – London/Remote Atrium EMEA is looking for an accomplished Cyber SecuritySOCAnalyst to support the Security Incident Response Team. The team is growing, we require a strong individual contributor that will investigate, analyse, and contain security incidents. This is a fully remote role, with the occasional London office … automation (Python, Powershell, Bash, KQL etc) • Financial services sector, a benefit/Shift work NOT required Click Apply now/contact Lianne to be considered for the Cyber SecuritySOCAnalyst – London/Remote role More ❯
london (city of london), south east england, united kingdom Hybrid / WFH Options
Atrium (EMEA)
Cyber SecuritySOCAnalyst – London/Remote Atrium EMEA is looking for an accomplished Cyber SecuritySOCAnalyst to support the Security Incident Response Team. The team is growing, we require a strong individual contributor that will investigate, analyse, and contain security incidents. This is a fully remote role, with the occasional London office … automation (Python, Powershell, Bash, KQL etc) • Financial services sector, a benefit/Shift work NOT required Click Apply now/contact Lianne to be considered for the Cyber SecuritySOCAnalyst – London/Remote role More ❯
london (west end), south east england, united kingdom Hybrid / WFH Options
Atrium (EMEA)
Cyber SecuritySOCAnalyst – London/Remote Atrium EMEA is looking for an accomplished Cyber SecuritySOCAnalyst to support the Security Incident Response Team. The team is growing, we require a strong individual contributor that will investigate, analyse, and contain security incidents. This is a fully remote role, with the occasional London office … automation (Python, Powershell, Bash, KQL etc) • Financial services sector, a benefit/Shift work NOT required Click Apply now/contact Lianne to be considered for the Cyber SecuritySOCAnalyst – London/Remote role More ❯
Ashton-Under-Lyne, Greater Manchester, United Kingdom Hybrid / WFH Options
Atrium (EMEA)
Cyber SecuritySOCAnalyst – London/Remote Atrium EMEA is looking for an accomplished Cyber SecuritySOCAnalyst to support the Security Incident Response Team. The team is growing, we require a strong individual contributor that will investigate, analyse, and contain security incidents. This is a fully remote role, with the occasional London office … automation (Python, Powershell, Bash, KQL etc) • Financial services sector, a benefit/Shift work NOT required Click Apply now/contact Lianne to be considered for the Cyber SecuritySOCAnalyst – London/Remote role More ❯
Hampshire, South East, United Kingdom Hybrid / WFH Options
Experis
ROLE TITLE: SOCAnalyst - SC Cleared LOCATION: flexible (can be predominantly remote) The ideal candidate must have active SC clearance We are actively looking to secure an SOCAnalyst to join Experis. Experis Consultancy is a Global entity with a well-established team with over 1000 consultants on assignment across 20 clients globally. Our … approach is a very personal one, with both our clients and our own employees. We are passionate about training, technology and career development. Skills required: Microsoft Certified: SecurityOperationsAnalyst Associate Certification (SC200) is a mandatory requirement for role fulfilment Experience working with SIEM technologies and security tooling An understanding of IT Infrastructure and Networking An understanding of … in a close team and independently The ability to be adaptable to a high pace changeable workload An interest in security and threat management Nice to have skills A SOCAnalyst will be responsible for providing Protective Monitoring Services across a range of Secure Customers. They will be responsible for the day to day monitoring using various More ❯
Reading, Berkshire, South East, United Kingdom Hybrid / WFH Options
Stott & May Professional Search Limited
SOCAnalyst Location: Reading (Hybrid - 3 days onsite per week) Contract Type: Contract (Inside IR35) Duration: 6 Months Day Rate: £382.50 per day Inside IR35 The Role We are seeking an experienced SOC Level 2 Analyst to join our SecurityOperations Center, supporting threat detection, investigation, and response across enterprise systems. You'll work … processes, and maintain accurate incident documentation. Collaborate with IT and security teams to strengthen overall detection and response capability. Essential Skills & Experience 6-8 years in cybersecurity, with strong SOC or incident response experience. Proficient in SIEM (Splunk, ArcSight) and EDR (Defender, CrowdStrike, Carbon Black). Strong knowledge of digital forensics, malware analysis, and threat hunting. Skilled across Windows … Linux, and cloud environments. Familiar with frameworks such as MITRE ATT&CK, NIST, and ISO 27001. Scripting experience (Python, PowerShell) beneficial. Preferred Certifications SOC-related (CySA+, Blue Team L1, GCIH, GCIA, GCFA). CISSP or equivalent desirable. Additional Information Fast-paced environment; occasional out-of-hours work may be required. More ❯
ROLE TITLE: SOCAnalyst LOCATION: flexible (can be mostly remote, must be based in UK) CLEARANCE: SC cleared, or eligible for SC clearance Salary: £35k - £41k The ideal candidate will have active SC Clearance or be eligible to undergo SC Clearance. We are actively looking to secure an SOCAnalyst to join Experis. Experis … approach is a very personal one, with both our clients and our own employees. We are passionate about training, technology and career development. Key accountabilities of the role A SOCAnalyst will be responsible for providing Protective Monitoring Services across a range of Secure Customers. They will be responsible for the day to day monitoring using various … Trend reporting Rule tuning and continual service improvement The role involves working alongside other team members including SOC engineers and Service Managers. Skills required: Microsoft Certified: SecurityOperationsAnalyst Associate Certification (SC200) is a mandatory requirement for role fulfilment Experience working with SIEM technologies and security tooling An understanding of IT Infrastructure and Networking An understanding of More ❯
Huntsville, Alabama, United States Hybrid / WFH Options
Gridiron IT Solutions
Senior SOCAnalyst Location: Huntsville, AL Work Type: Onsite Remote Work: No Job Description Respond to and resolve cybersecurity incidents and proactively prevent reoccurrence of these incidents. Apply leading-edge principles, theories, and concepts. Contribute to the development of new principles and concepts. Work on unusually complex problems and provide highly innovative solutions. Operate with substantial latitude … company and technical competencies. Qualifications 8+ years of experience supporting Information Technology or Intelligence Operations Experience supporting a Computer Incident Response Team, Cyber Network Operations, or SecurityOperations Center (SOC) operations for a large and complex enterprise Experience with Intelligence Driven Defense, Cyber Kill Chain methodology, or MITRE ATT&CK framework Knowledge of industry-accepted standards for incident response … actions and best practices for SOCoperations Knowledge of security operation tools, including SIMs or DCAP analysis Knowledge of intrusion set tactics, techniques, and procedures Top Secret clearance Bachelor's degree Additional Qualifications Experience with Microsoft Sentinel Experience with Splunk TS/SCI clearance GIAC Continuous Monitoring (GMON) Certification GIAC Certified Incident Handler (GCIH) Certification GIAC Certified Forensic AnalystMore ❯
Birmingham, England, United Kingdom Hybrid / WFH Options
Anson McCade
SOCAnalyst (L3) - Senior Incident Responder Location: Birmingham (Hybrid) Salary: Up to £70,000 (depending on experience) + bonus NOTE: Candidates for this role must be eligible for UK Security Clearance (SC). We’re looking for a hands-on L3 Senior Incident Responder who can lead on complex security investigations, manage high-severity incidents, and bring … real expertise in Splunk and wider SIEM technologies. This is a critical role within the SOC, where you’ll be the escalation point for L1 and L2 analysts and take ownership of incident containment, remediation, and post-incident review. What you’ll do: Act as the L3 escalation point , leading investigations into complex incidents escalated by L1/L2 … to security events. Perform detailed forensic analysis, root cause analysis, and malware investigation. Lead incident response activities end-to-end, ensuring containment, eradication, and recovery. Develop, refine, and own SOC use cases, runbooks, and playbooks to drive continual service improvement. Liaise directly with clients, providing clear guidance and recommendations. Mentor and support junior SOC analysts, ensuring best practice More ❯
Crawley, Sussex, United Kingdom Hybrid / WFH Options
Morson Talent
Incident Response (CSIRT)/SOC Level 3 Analyst Location: Crawley (Hybrid) Department: Information Systems Type: Contract Full-time Outside IR35 About the Role My client is seeking an experienced Incident Response (CSIRT)/SecurityOperationsCentre (SOC) Level 3 Analyst to join their Information Systems directorate, based in Crawley. In this critical role, you … escalated and high-severity cyber incidents, ensuring rapid containment and recovery. Conduct advanced threat hunting across IT and OT environments to identify and eliminate hidden threats. Develop and enhance SOC policies, playbooks, and incident response processes to align with industry best practices. Collaborate with the Managed Security Service Provider (MSSP) and internal teams to ensure complete log source integration … simulation exercises and continuous improvement initiatives to enhance resilience. Contribute to security audits and compliance efforts (e.g. ISO 27001, NCSC CAF, GDPR). Mentor Level 1 and Level 2 SOC Analysts, helping to build team capability and knowledge. About You You'll bring a combination of technical expertise, analytical acumen, and a collaborative approach to problem-solving. Essential Qualifications More ❯
Crawley, West Sussex, South East, United Kingdom Hybrid / WFH Options
Morson Talent
Incident Response (CSIRT)/SOC Level 3 Analyst Location: Crawley (Hybrid) Department: Information Systems Type: Contract | Full-time Outside IR35 About the Role My client is seeking an experienced Incident Response (CSIRT)/SecurityOperationsCentre (SOC) Level 3 Analyst to join their Information Systems directorate, based in Crawley. In this critical role, you … escalated and high-severity cyber incidents, ensuring rapid containment and recovery. Conduct advanced threat hunting across IT and OT environments to identify and eliminate hidden threats. Develop and enhance SOC policies, playbooks, and incident response processes to align with industry best practices. Collaborate with the Managed Security Service Provider (MSSP) and internal teams to ensure complete log source integration … simulation exercises and continuous improvement initiatives to enhance resilience. Contribute to security audits and compliance efforts (e.g. ISO 27001, NCSC CAF, GDPR). Mentor Level 1 and Level 2 SOC Analysts, helping to build team capability and knowledge. About You You'll bring a combination of technical expertise, analytical acumen, and a collaborative approach to problem-solving. Essential Qualifications More ❯