We are seeking a Cyber SOC Specialist to join a security operations team responsible for monitoring, investigating and... Read more
We are seeking a Cyber SOC Specialist to join a security operations team responsible for monitoring, investigating and responding to cyber threats across a complex technology environment. In this role, you will help protect critical systems, applications and data by identifying suspicious activity, assessing security alerts and coordinating timely responses to incidents.
Your responsibilities will include monitoring security information and event management (SIEM) platforms, endpoint detection and response tools, network security solutions and other monitoring technologies. You will triage alerts, investigate potential compromises, analyse logs and security events, and determine the scope and impact of incidents. You will also support containment, eradication and recovery activities, maintain accurate incident records, and escalate significant threats in line with established procedures. Additional duties may include developing and refining detection rules, contributing to threat-hunting activities, preparing operational reports, and helping improve playbooks, processes and security controls.
The successful candidate will have practical experience in a security operations centre, incident response or a related cyber security role. You should have a sound understanding of common attack techniques, vulnerabilities, malware, phishing, identity threats and network security principles, together with experience using SIEM, EDR or comparable security tooling. Familiarity with frameworks such as MITRE ATT&CK, NIST or ISO 27001 is desirable. Strong analytical and problem-solving skills are essential, along with the ability to communicate clearly and work effectively under pressure. Relevant certifications such as Security+, CySA+, GCIH, GCIA or equivalent experience would be advantageous. A willingness to participate in shift-based or on-call support may be required.
Read lessBristol, England, United KingdomPermanent
We are seeking a skilled SOC Analyst Level 2 to support the continuous monitoring, investigation, and response to... Read more
We are seeking a skilled SOC Analyst Level 2 to support the continuous monitoring, investigation, and response to cybersecurity threats across a complex technology environment. The successful candidate will analyse security alerts, identify suspicious activity, assess potential impact, and determine whether incidents require escalation or coordinated response. This role involves working across multiple security tools and data sources, including SIEM, endpoint detection and response, vulnerability management, network monitoring, identity platforms, and threat intelligence feeds.
Key responsibilities include investigating and validating security events, conducting root-cause analysis, correlating indicators across systems, and documenting findings in accordance with established procedures. You will lead or support the response to security incidents, contain threats where appropriate, and provide clear recommendations to relevant technical teams. The role also includes developing and refining detection rules, tuning alert logic to reduce false positives, conducting threat hunting activities, and contributing to playbooks, incident reports, and post-incident reviews. You will work closely with Level 1 analysts, infrastructure and application teams, and other security specialists to improve monitoring coverage and operational effectiveness.
Applicants should have proven experience in a security operations centre or equivalent cyber defence environment, with a strong understanding of incident detection, investigation, and response processes. Experience using SIEM and EDR platforms, analysing Windows and Linux logs, and investigating network, email, identity, and endpoint-based threats is required. Knowledge of common attack techniques, threat intelligence, MITRE ATT&CK, vulnerability management, and security controls will be highly valued. Relevant industry certifications or formal training in cybersecurity are desirable. Strong analytical and communication skills are essential, along with the ability to prioritise competing incidents, produce accurate technical documentation, and participate in an on-call or shift-based support model when required.
Read lessFarnborough, England, United KingdomPermanent
We are seeking a reliable and vigilant Relief Security Operations Centre Operator to support a busy security control... Read more
We are seeking a reliable and vigilant Relief Security Operations Centre Operator to support a busy security control room in Cambridge, CB21. This role is responsible for monitoring site security systems, responding to incidents and maintaining a calm, professional approach in a fast-paced environment. You will work as part of a wider security team, providing operational cover across a range of shifts, including days, nights, weekends and public holidays.
Key responsibilities will include monitoring CCTV, alarms, access control systems and other security technology; receiving and assessing incident reports; contacting relevant emergency services or on-site personnel when required; and accurately recording all activity in daily occurrence logs and electronic reporting systems. You will manage communications professionally, follow agreed escalation procedures, conduct regular system checks and help ensure that all security incidents are handled promptly and appropriately. The role may also involve issuing instructions to mobile officers, coordinating responses, monitoring access and assisting with investigations by reviewing footage or producing incident information.
Applicants should have previous experience in a security, control room, monitoring or customer-focused operational environment, although full training may be provided for candidates who demonstrate the right skills and attitude. A valid security licence appropriate to control room duties is desirable, along with experience using CCTV, radio communication and computer-based reporting systems. You must have strong attention to detail, clear written and verbal communication skills, good IT ability and the confidence to make sound decisions under pressure. Flexibility, reliability and a professional approach are essential, as is the ability to maintain confidentiality and follow procedures consistently. Successful candidates will be required to complete relevant screening and background checks before appointment.
Read lessCambridge, England, United KingdomPermanent
We are seeking an Associate SOC Analyst to join a security operations team responsible for monitoring, investigating, and... Read more
We are seeking an Associate SOC Analyst to join a security operations team responsible for monitoring, investigating, and responding to potential cyber threats. In this role, you will support the day-to-day operation of a security operations centre, helping to protect systems, networks, applications, and data across a varied technology environment. This is an excellent opportunity for someone beginning a career in cybersecurity and looking to develop practical experience in threat detection and incident response.
Your responsibilities will include monitoring security alerts from SIEM, endpoint detection and response, email security, firewall, and other monitoring platforms; triaging and investigating suspicious activity; and escalating confirmed or complex incidents in line with documented procedures. You will help maintain accurate incident records, gather and analyse relevant evidence, contribute to incident reports, and support containment and remediation activities. The role will also involve reviewing threat intelligence, identifying recurring trends, assisting with vulnerability and security monitoring activities, and recommending improvements to detection rules, playbooks, and operational processes. You may participate in shift-based coverage, including occasional evenings, nights, weekends, or public holidays.
Applicants should have a genuine interest in cybersecurity and a foundational understanding of networking, operating systems, common attack techniques, and information security principles. Familiarity with SIEM tools, security alerts, log analysis, phishing investigations, ticketing systems, or cloud security concepts would be advantageous. Relevant study, certifications, laboratory projects, or practical experience in a helpdesk, IT, networking, or security environment will be considered. Strong analytical and problem-solving skills are essential, along with clear written and verbal communication, careful attention to detail, and the ability to prioritise work in a fast-paced environment. You should be willing to learn, follow established procedures, handle sensitive information responsibly, and work collaboratively while maintaining a calm and methodical approach during incidents.
Read lessManchester, England, United KingdomContract
We are seeking a SOC Analyst to join a security operations team responsible for monitoring, investigating, and responding... Read more
We are seeking a SOC Analyst to join a security operations team responsible for monitoring, investigating, and responding to cyber threats across a diverse technology environment. In this role, you will analyse alerts from security information and event management (SIEM) platforms, endpoint detection and response tools, firewalls, intrusion detection systems, and other security technologies. You will assess potential incidents, distinguish genuine threats from false positives, and take appropriate action in line with documented procedures and service-level requirements.
Key responsibilities include conducting triage and investigation of security alerts, identifying indicators of compromise, supporting containment and remediation activities, and escalating significant incidents to senior analysts or incident response specialists. You will maintain accurate case records, produce clear investigation reports, and contribute to post-incident reviews. The role will also involve threat hunting, reviewing log and network activity, improving detection rules, maintaining operational playbooks, and helping identify opportunities to strengthen monitoring and response capabilities. You may participate in shift-based coverage, including evenings, nights, weekends, or on-call support, depending on operational needs.
The successful candidate will have practical experience in a security operations, incident response, threat monitoring, or related cybersecurity role. You should understand common attack techniques, network protocols, operating systems, authentication technologies, malware behaviours, and the principles of vulnerability management. Experience with SIEM, EDR, ticketing, case management, and threat intelligence platforms is highly desirable, as is the ability to analyse logs and use scripting or query languages to investigate events. Relevant professional certifications or formal training in cybersecurity would be advantageous. We are looking for a methodical and curious individual with strong analytical, written, and verbal communication skills, who can remain calm under pressure, work effectively within a team, and demonstrate a commitment to continuous learning and secure working practices.
Read lessRichmond, England, United KingdomPermanent
We are seeking a Senior Lead Security Operations Analyst to provide technical leadership across security monitoring, incident response,... Read more
We are seeking a Senior Lead Security Operations Analyst to provide technical leadership across security monitoring, incident response, threat detection and operational resilience. You will guide a team of analysts, coordinate the effective operation of security monitoring capabilities, and help ensure that cyber threats are identified, investigated and contained promptly. Working closely with technology, risk and business stakeholders, you will provide clear advice on security events, emerging threats and appropriate remediation activities.
Your responsibilities will include leading the analysis and response to complex security incidents, reviewing alerts and investigations, and improving processes across the security operations function. You will oversee the development and tuning of detection use cases, correlation rules, dashboards and automated response workflows within SIEM, SOAR, EDR and related security platforms. You will also contribute to threat hunting, vulnerability investigations, forensic analysis and post-incident reviews, ensuring that lessons learned are translated into measurable improvements. The role will involve producing accurate management reports, maintaining operational documentation, supporting audit requirements and helping to define and track security performance metrics.
Applicants should have substantial experience in a security operations, incident response or cyber defence environment, including experience leading or mentoring analysts. Strong practical knowledge of SIEM technologies, endpoint protection, network security monitoring, threat intelligence and incident management is essential. You should be confident analysing complex technical data, identifying attack patterns and communicating risks to both technical and non-technical audiences. Experience with security frameworks such as MITRE ATT&CK, NIST or ISO 27001, along with relevant professional certifications, would be advantageous. The successful candidate will demonstrate sound judgement, excellent organisation, a collaborative leadership style and the ability to remain calm and decisive during high-priority incidents.
Read lessCardiff, Wales, United KingdomPermanent
An experienced SOC Manager is sought to lead and develop a high-performing Security Operations Centre within a managed... Read more
An experienced SOC Manager is sought to lead and develop a high-performing Security Operations Centre within a managed security services environment. This hybrid role will oversee the delivery of 24/7 security monitoring, detection, investigation and response services for multiple customers, ensuring consistently high standards of operational performance, service quality and client satisfaction. The successful candidate will provide clear direction to SOC analysts, incident responders and technical specialists, while fostering a culture of collaboration, accountability and continuous improvement.
Responsibilities will include managing day-to-day SOC operations, workforce planning, shift coverage, escalation procedures and incident response coordination. You will establish and monitor service-level objectives, operational metrics and key performance indicators, producing regular reports for senior stakeholders and customers. The role will also involve developing and maintaining operational processes, playbooks and runbooks; supporting the implementation and optimisation of SIEM, SOAR, EDR and other security technologies; and ensuring effective threat detection, triage, containment and remediation. You will act as a senior escalation point for complex security incidents and contribute to customer onboarding, service reviews, audits and the continual enhancement of MSSP offerings.
Applicants should have substantial experience managing a SOC, CSIRT or comparable security operations function, ideally within an MSSP or other customer-facing security services environment. Strong knowledge of security monitoring, incident response, threat intelligence, vulnerability management and common security frameworks is essential. Experience with SIEM and automation platforms, security metrics, ITIL-aligned service management and regulatory or compliance requirements would be advantageous. The role requires proven leadership and people-management skills, excellent communication with both technical and non-technical audiences, and the ability to prioritise effectively in a fast-paced environment. Relevant professional certifications such as CISSP, CISM, GIAC or equivalent are desirable. A flexible approach to hybrid working and participation in an out-of-hours escalation rota may be required.
Read lessBirmingham, England, United KingdomPermanent
We are seeking a vigilant and analytical SOC Analyst to join a security operations function responsible for monitoring,... Read more
We are seeking a vigilant and analytical SOC Analyst to join a security operations function responsible for monitoring, investigating, and responding to cyber threats across a varied technology environment. In this role, you will review alerts from security information and event management (SIEM) platforms, endpoint detection and response tools, network monitoring systems, and other security technologies. You will assess suspicious activity, identify potential incidents, perform initial triage, and escalate confirmed or complex threats in line with established procedures.
Your responsibilities will include analysing logs and indicators of compromise, investigating phishing reports, malware detections, unauthorised access attempts, and other security events. You will support incident response activities by gathering evidence, documenting timelines, maintaining accurate case records, and recommending containment or remediation actions. The role will also involve monitoring threat intelligence, tuning detection rules, identifying recurring attack patterns, and contributing to vulnerability and risk assessments. You will prepare clear incident reports and operational metrics, participate in shift handovers, and help ensure security monitoring remains effective and aligned with business requirements.
The successful candidate will have practical experience in a security operations, incident response, cyber defence, or related role, together with a sound understanding of networking, operating systems, authentication methods, and common attack techniques. Experience with SIEM, EDR, ticketing, vulnerability management, or cloud security platforms is highly desirable. Familiarity with frameworks such as MITRE ATT&CK, NIST, or ISO 27001 would be advantageous. Strong investigative, written, and verbal communication skills are essential, as is the ability to prioritise effectively in a fast-paced environment. Relevant certifications such as Security+, CySA+, GCIH, or equivalent practical experience are welcomed. A commitment to continuous learning, careful attention to detail, and a professional approach to handling sensitive information are required.
Read lessLondon, England, United KingdomPermanent
We are seeking a Security Operations Analyst to support the monitoring, investigation and improvement of an organisation’s cyber... Read more
We are seeking a Security Operations Analyst to support the monitoring, investigation and improvement of an organisation’s cyber security operations. Working as part of a collaborative security team, you will help protect systems, networks, applications and data by identifying potential threats, assessing risk and coordinating timely responses to security incidents.
Key responsibilities will include monitoring security alerts and events using SIEM, endpoint detection and response, vulnerability management and other security tools; investigating suspicious activity, phishing reports, malware alerts and unauthorised access attempts; and maintaining accurate incident records, investigation notes and follow-up actions. You will assist with incident response activities, including triage, containment, eradication and recovery, escalating significant issues in line with established procedures. The role will also involve analysing logs and threat intelligence, supporting vulnerability assessments, contributing to security reporting and metrics, and helping to improve detection rules, playbooks, processes and operational controls. You may also support security awareness activities, audit requests and the review of technical findings with relevant stakeholders.
Applicants should have experience in a security operations, incident response, service desk, infrastructure or related technical environment, together with a practical understanding of common cyber threats, attack techniques and defensive measures. Familiarity with SIEM platforms, endpoint security solutions, vulnerability scanners, firewalls, identity systems and cloud environments is desirable. Knowledge of frameworks and practices such as NIST, MITRE ATT&CK, ISO 27001 or ITIL would be advantageous. Strong analytical and problem-solving skills are essential, along with the ability to communicate technical information clearly to both technical and non-technical audiences. You should be organised, dependable and comfortable working under pressure, including participation in an out-of-hours or on-call rota where required. Relevant industry certifications or a willingness to pursue professional development will be welcomed.
Read lessTewkesbury, England, United KingdomPermanent
We are seeking a Security Operations Centre Analyst to support the monitoring, detection and response activities of a... Read more
We are seeking a Security Operations Centre Analyst to support the monitoring, detection and response activities of a busy cyber security function. In this role, you will monitor security alerts and events across enterprise networks, systems, applications and cloud environments, using security information and event management (SIEM), endpoint detection and response (EDR) and other security tools. You will assess alerts, identify potential threats, investigate suspicious activity and take appropriate action in line with documented procedures and escalation routes.
Your responsibilities will include triaging and documenting incidents, analysing logs and indicators of compromise, supporting containment and remediation activities, and escalating complex or high-risk events to senior analysts and incident response specialists. You will contribute to incident reports, maintain accurate case records and help identify recurring issues or opportunities to improve detection rules and operational processes. The role will also involve vulnerability and threat intelligence monitoring, assisting with security investigations, participating in shift handovers and supporting continuous improvement of SOC playbooks, procedures and knowledge articles.
The successful candidate will have practical experience in a security operations, incident response, network monitoring or technical support environment, together with a good understanding of cyber security principles, common attack techniques and security controls. Familiarity with SIEM platforms, EDR tools, firewalls, intrusion detection systems, authentication technologies and cloud security services is desirable. You should be analytical, methodical and able to prioritise effectively when managing multiple alerts. Strong written and verbal communication skills are essential, as is the ability to explain technical findings clearly to both technical and non-technical audiences. Relevant industry certifications or formal qualifications in cyber security, information technology or a related discipline would be advantageous. The role may require participation in a rota covering evenings, nights, weekends or public holidays.
Read lessGlasgow, Scotland, United KingdomPermanent
All your saved jobs are no longer available or you've already applied.
for the following search criteria