A fantastic MSP based in the West End are currently looking for a Tier 1 Cyber Security SOC Support Analyst to join our expanding UK based Service Desk team. The ideal candidate would be someone that is already in a similar role and has minimum of 1-year experience. You must have a years experience working for an MSP and managing corporate clients. Fantastic Benefits Hours : 7.5 hours a day on a fortnightly shift pattern (8am to 4.30pm or 9am to 5.30pm or 9.30am to 6pm) Holidays : 20 days per year, plus bank holidays. After 3 years continuous service, an extra day annual leave up to 25 days. Benefits : Competitive Package Offered - Gym membership, Vitality at Work Business rewards & benefits, Cycle to Work scheme, quarterly team nights out/events, monthly games night with pizzasand breakfast on Wednesdays! As a Tier 1 SOC Support Analyst, you will be primarily responsible for monitoring systems and making the initial response to any flags or alerts that come in via support tickets or telephone tickets. One of the key responsibilities is also to review and categorise potential threats in order of priorityand dismiss any false alarms, whilst also gathering information and escalating the most urgent threats to Escalations Management Team. Essential Experience Preference given to candidates with MSP background Minimum 1 years proven experience in a Tier 1 Cyber Security SOC Support Analyst role Working knowledge of Microsoft Defender XDR and Microsoft Sentinel SIEM technologies Working knowledge of Microsoft Defender suite including Endpoint Detection and Response Understanding of key Microsoft 365 Cloud Technologies from a threat landscape perspective Essential Certification/Working towards SC-200 Microsoft Certified: Security Operations Analyst Associate OR SC-900 Microsoft Certified: Security Compliance and Identity Fundamentals Personal Skills Highly Motivated Can do attitude Attention to detail Excellent communication Proven client service skills Ability to work under pressure Willingness to work flexibly as required Good telephone etiquette Main Tasks and Responsibilities Provide triage and first line of defence for all cyber security incidents within the organisation and as part of our Managed Security Service Take ownership and provide remedial actions to ensure that Cyber Security Threats are mitigated as per Playbooks provided by the Cyber Security Team or escalate incidents to Escalations Management Team for further information/support Manage technical and stakeholder incident reporting via concise communications Manage client communication channels during an active incident Liaise with third party service suppliers where necessary, logging tickets and act as a central point of contact for active incident Provide operational support to wider Cyber Security Team on security incidents Provide a professional and customer-focused service through the life cycle of each ticket; manage customer expectations by keeping customer informed of progress. If you'd like to be part of this dynamic team please email me your CV ASAP!
May 25, 2026
Full time
A fantastic MSP based in the West End are currently looking for a Tier 1 Cyber Security SOC Support Analyst to join our expanding UK based Service Desk team. The ideal candidate would be someone that is already in a similar role and has minimum of 1-year experience. You must have a years experience working for an MSP and managing corporate clients. Fantastic Benefits Hours : 7.5 hours a day on a fortnightly shift pattern (8am to 4.30pm or 9am to 5.30pm or 9.30am to 6pm) Holidays : 20 days per year, plus bank holidays. After 3 years continuous service, an extra day annual leave up to 25 days. Benefits : Competitive Package Offered - Gym membership, Vitality at Work Business rewards & benefits, Cycle to Work scheme, quarterly team nights out/events, monthly games night with pizzasand breakfast on Wednesdays! As a Tier 1 SOC Support Analyst, you will be primarily responsible for monitoring systems and making the initial response to any flags or alerts that come in via support tickets or telephone tickets. One of the key responsibilities is also to review and categorise potential threats in order of priorityand dismiss any false alarms, whilst also gathering information and escalating the most urgent threats to Escalations Management Team. Essential Experience Preference given to candidates with MSP background Minimum 1 years proven experience in a Tier 1 Cyber Security SOC Support Analyst role Working knowledge of Microsoft Defender XDR and Microsoft Sentinel SIEM technologies Working knowledge of Microsoft Defender suite including Endpoint Detection and Response Understanding of key Microsoft 365 Cloud Technologies from a threat landscape perspective Essential Certification/Working towards SC-200 Microsoft Certified: Security Operations Analyst Associate OR SC-900 Microsoft Certified: Security Compliance and Identity Fundamentals Personal Skills Highly Motivated Can do attitude Attention to detail Excellent communication Proven client service skills Ability to work under pressure Willingness to work flexibly as required Good telephone etiquette Main Tasks and Responsibilities Provide triage and first line of defence for all cyber security incidents within the organisation and as part of our Managed Security Service Take ownership and provide remedial actions to ensure that Cyber Security Threats are mitigated as per Playbooks provided by the Cyber Security Team or escalate incidents to Escalations Management Team for further information/support Manage technical and stakeholder incident reporting via concise communications Manage client communication channels during an active incident Liaise with third party service suppliers where necessary, logging tickets and act as a central point of contact for active incident Provide operational support to wider Cyber Security Team on security incidents Provide a professional and customer-focused service through the life cycle of each ticket; manage customer expectations by keeping customer informed of progress. If you'd like to be part of this dynamic team please email me your CV ASAP!
A fantastic MSP based in the West End are currently looking for a Tier 1 Cyber Security SOC Support Analyst to join our expanding UK based Service Desk team. The ideal candidate would be someone that is already in a similar role and has minimum of 1-year experience. You must have a years experience working for an MSP and managing corporate clients. Fantastic Benefits Hours : 7.5 hours a day on a fortnightly shift pattern (8am to 4.30pm or 9am to 5.30pm or 9.30am to 6pm) Holidays : 20 days per year, plus bank holidays. After 3 years continuous service, an extra day annual leave up to 25 days. Benefits : Competitive Package Offered - Gym membership, Vitality at Work Business rewards & benefits, Cycle to Work scheme, quarterly team nights out/events, monthly games night with pizzasand breakfast on Wednesdays! As a Tier 1 SOC Support Analyst, you will be primarily responsible for monitoring systems and making the initial response to any flags or alerts that come in via support tickets or telephone tickets. One of the key responsibilities is also to review and categorise potential threats in order of priorityand dismiss any false alarms, whilst also gathering information and escalating the most urgent threats to Escalations Management Team. Essential Experience Preference given to candidates with MSP background Minimum 1 years proven experience in a Tier 1 Cyber Security SOC Support Analyst role Working knowledge of Microsoft Defender XDR and Microsoft Sentinel SIEM technologies Working knowledge of Microsoft Defender suite including Endpoint Detection and Response Understanding of key Microsoft 365 Cloud Technologies from a threat landscape perspective Essential Certification/Working towards SC-200 Microsoft Certified: Security Operations Analyst Associate OR SC-900 Microsoft Certified: Security Compliance and Identity Fundamentals Personal Skills Highly Motivated Can do attitude Attention to detail Excellent communication Proven client service skills Ability to work under pressure Willingness to work flexibly as required Good telephone etiquette Main Tasks and Responsibilities Provide triage and first line of defence for all cyber security incidents within the organisation and as part of our Managed Security Service Take ownership and provide remedial actions to ensure that Cyber Security Threats are mitigated as per Playbooks provided by the Cyber Security Team or escalate incidents to Escalations Management Team for further information/support Manage technical and stakeholder incident reporting via concise communications Manage client communication channels during an active incident Liaise with third party service suppliers where necessary, logging tickets and act as a central point of contact for active incident Provide operational support to wider Cyber Security Team on security incidents Provide a professional and customer-focused service through the life cycle of each ticket; manage customer expectations by keeping customer informed of progress. If you'd like to be part of this dynamic team please email me your CV ASAP!
May 24, 2026
Full time
A fantastic MSP based in the West End are currently looking for a Tier 1 Cyber Security SOC Support Analyst to join our expanding UK based Service Desk team. The ideal candidate would be someone that is already in a similar role and has minimum of 1-year experience. You must have a years experience working for an MSP and managing corporate clients. Fantastic Benefits Hours : 7.5 hours a day on a fortnightly shift pattern (8am to 4.30pm or 9am to 5.30pm or 9.30am to 6pm) Holidays : 20 days per year, plus bank holidays. After 3 years continuous service, an extra day annual leave up to 25 days. Benefits : Competitive Package Offered - Gym membership, Vitality at Work Business rewards & benefits, Cycle to Work scheme, quarterly team nights out/events, monthly games night with pizzasand breakfast on Wednesdays! As a Tier 1 SOC Support Analyst, you will be primarily responsible for monitoring systems and making the initial response to any flags or alerts that come in via support tickets or telephone tickets. One of the key responsibilities is also to review and categorise potential threats in order of priorityand dismiss any false alarms, whilst also gathering information and escalating the most urgent threats to Escalations Management Team. Essential Experience Preference given to candidates with MSP background Minimum 1 years proven experience in a Tier 1 Cyber Security SOC Support Analyst role Working knowledge of Microsoft Defender XDR and Microsoft Sentinel SIEM technologies Working knowledge of Microsoft Defender suite including Endpoint Detection and Response Understanding of key Microsoft 365 Cloud Technologies from a threat landscape perspective Essential Certification/Working towards SC-200 Microsoft Certified: Security Operations Analyst Associate OR SC-900 Microsoft Certified: Security Compliance and Identity Fundamentals Personal Skills Highly Motivated Can do attitude Attention to detail Excellent communication Proven client service skills Ability to work under pressure Willingness to work flexibly as required Good telephone etiquette Main Tasks and Responsibilities Provide triage and first line of defence for all cyber security incidents within the organisation and as part of our Managed Security Service Take ownership and provide remedial actions to ensure that Cyber Security Threats are mitigated as per Playbooks provided by the Cyber Security Team or escalate incidents to Escalations Management Team for further information/support Manage technical and stakeholder incident reporting via concise communications Manage client communication channels during an active incident Liaise with third party service suppliers where necessary, logging tickets and act as a central point of contact for active incident Provide operational support to wider Cyber Security Team on security incidents Provide a professional and customer-focused service through the life cycle of each ticket; manage customer expectations by keeping customer informed of progress. If you'd like to be part of this dynamic team please email me your CV ASAP!
SOC Analyst Daily Rate: Inside IR35 Location: Sheffield Job Type: Hybrid (2-3 days on-site) Join our Cyber Defence Centre (CDC) as a SOC Analyst. This is a crucial hands-on operational role within Security Operations, focused on incident detection, investigation, and response. You will play a pivotal role in ensuring effective monitoring, triage, and response to security events, while also driving continuous improvement and detection engineering initiatives. Day-to-day of the role: Incident Detection & Response: Investigate and respond to security incidents and alerts escalated from Tier 1 / Tier 2 SOC. Perform in-depth analysis and triage of security events, identifying threats and determining impact. Support high-severity incident response as required, working closely with Incident Responders. Operational Monitoring: Manage and resolve security tickets within agreed SLAs. Review alerts from multiple security tools and platforms. Ensure accurate documentation and tracking of incidents within ServiceNow. Detection Engineering: Contribute to detection engineering activities on a rotational basis. Develop and tune detection rules to improve alert quality and reduce false positives. Write and optimise queries (e.g., KQL) across SIEM platforms. Collaboration & Support: Work closely with internal teams and third-party providers to investigate and resolve incidents. Support MSSP interactions and escalations where required. Participate in incident bridge calls during major incidents. Continuous Improvement: Identify lessons learned from incidents and contribute to improving processes and controls. Provide feedback on detection gaps and opportunities for enhancement. Focus on delivering value from incidents, not just ticket closure. Required Skills & Qualifications: Core Experience: Proven experience working within a SOC environment (Tier 2 / Tier 3 preferred). Strong background in incident investigation and response. Experience handling escalated alerts and security tickets. Technical Skills: Experience with SIEM platforms (e.g., Microsoft Sentinel). Experience with EDR/XDR tools (e.g., CrowdStrike). ServiceNow or similar ITSM/SecOps platforms. Ability to write and optimise KQL queries (essential). Knowledge of scripting/query languages (e.g., Falcon Query Language) is advantageous. Analytical Capability: Strong investigative and problem-solving skills. Ability to correlate data across multiple sources. Understanding of common attack techniques and threat vectors. Soft Skills: Strong communication and collaboration skills. Ability to work effectively in a fast-paced operational environment. Proactive mindset with focus on continuous improvement and quality outcomes. To apply for this SOC Analyst position, please submit your CV and a member of the Talent Team will be in touch.
May 23, 2026
Contractor
SOC Analyst Daily Rate: Inside IR35 Location: Sheffield Job Type: Hybrid (2-3 days on-site) Join our Cyber Defence Centre (CDC) as a SOC Analyst. This is a crucial hands-on operational role within Security Operations, focused on incident detection, investigation, and response. You will play a pivotal role in ensuring effective monitoring, triage, and response to security events, while also driving continuous improvement and detection engineering initiatives. Day-to-day of the role: Incident Detection & Response: Investigate and respond to security incidents and alerts escalated from Tier 1 / Tier 2 SOC. Perform in-depth analysis and triage of security events, identifying threats and determining impact. Support high-severity incident response as required, working closely with Incident Responders. Operational Monitoring: Manage and resolve security tickets within agreed SLAs. Review alerts from multiple security tools and platforms. Ensure accurate documentation and tracking of incidents within ServiceNow. Detection Engineering: Contribute to detection engineering activities on a rotational basis. Develop and tune detection rules to improve alert quality and reduce false positives. Write and optimise queries (e.g., KQL) across SIEM platforms. Collaboration & Support: Work closely with internal teams and third-party providers to investigate and resolve incidents. Support MSSP interactions and escalations where required. Participate in incident bridge calls during major incidents. Continuous Improvement: Identify lessons learned from incidents and contribute to improving processes and controls. Provide feedback on detection gaps and opportunities for enhancement. Focus on delivering value from incidents, not just ticket closure. Required Skills & Qualifications: Core Experience: Proven experience working within a SOC environment (Tier 2 / Tier 3 preferred). Strong background in incident investigation and response. Experience handling escalated alerts and security tickets. Technical Skills: Experience with SIEM platforms (e.g., Microsoft Sentinel). Experience with EDR/XDR tools (e.g., CrowdStrike). ServiceNow or similar ITSM/SecOps platforms. Ability to write and optimise KQL queries (essential). Knowledge of scripting/query languages (e.g., Falcon Query Language) is advantageous. Analytical Capability: Strong investigative and problem-solving skills. Ability to correlate data across multiple sources. Understanding of common attack techniques and threat vectors. Soft Skills: Strong communication and collaboration skills. Ability to work effectively in a fast-paced operational environment. Proactive mindset with focus on continuous improvement and quality outcomes. To apply for this SOC Analyst position, please submit your CV and a member of the Talent Team will be in touch.
Role: DV-Cleared Cyber Security Analyst / SOC Analyst Salary/Rate: £540-640 per day inside IR35 Location: on site Corsham 5x pw Contract Duration: contract until April 2027 We are currently looking for a Cyber Security Analyst / SOC Analyst for our government client. This Cyber Security Analyst / SOC Analyst role is based fully on site, 5 days per week in Corsham, over 13-hour shifts spanning days and nights, including weekends, 4 on 5 off, then 5 on 4 off. There is no further flexibility with the on-site requirement or office location. Security Clearance: Developed Vetting (DV Clearance) + sole UK national + Sensitive Post Check (which can take 3 months) The contract for this Cyber Security Analyst / SOC Analyst position is until April 2027, with potential to extend, operating inside IR35. This role is inside IR35 - Due to the service of the role, it will now be based on an Umbrella solution. Essential Skills / Experience required: Industry standard SOC Security qualifications (SANS, ISC2, etc.) Proven Tier 2/3 SOC Analyst experience (2 years+) Perform triage of security events ; determine scope, priority and impact, and make recommendations that enable expeditious remediation. Demonstratable experience working with SIEM technology and SIEM engineering (including tool configuration) i.e. ArcSight within an enterprise SOC. Experience in creation of use-cases, analytics and playbooks . An understanding of cloud Conduct real-time management of security incidents from detection to resolution. Technical Knowledge within anti-virus, networking, vulnerability management, encryption, Microsoft technologies, Linux. Knowledge of Information Security standards , legislation and practices, including GDPR & Data Protection Act 2018. Experience in dealing with a wide range of Information Security matters and operating in an ITIL based environment. Strong problem-solving ability, with flexibility to think creatively and adapt to and implement rapidly changing systems and services. Incident management experience and an ability to quickly tailor responses to deal with fast-moving situations. Highly desirable: Degree level qualification; preferably in technical, engineering or computing subject. Lead experience but would take a Tier 2 Analyst. Defence experience Role / Responsibilities: Responsible for supporting information security delivery work, including the development and implementation of Information Security Policies, Standards, processes and guidance. Responsibility for the security of Digital infrastructure by proactively analysing security threats/challenges/risks to the environment, including conducting penetration testing and compliance reviews monitoring of Information Security and information management to ensure compliance including reviewing and monitoring system and network logs for malicious activity or unacceptable use. If you are interested in the above role, please click Apply Now and send a CV for quick review. As a member of the Disability Confident Scheme, Circle and our Client guarantees to interview all candidates who have a disability and who meet all the essential criteria for the vacancy. In cases where we have a high volume of candidates who have a disability who meet all the essential criteria, we will interview the best candidates from within that group. Our client is proud to support the Armed Forces Covenant and as such, they guarantee to interview all veterans, spouses / partners of military personnel who meet all the essential criteria for the vacancy. In cases where they have a high volume of ex-military candidates / military spouses, partners, who meet all of the essential criteria, they will interview the best candidates from within that group. If you qualify, please notify us on igs at circlerecruitment dot com. We will be in touch to discuss your suitability and arrange your guaranteed interview. Should you require reasonable adjustments at any point during the recruitment process, if there is a better way for us to communicate, please do let us know. Circle Recruitment is acting as an Employment Agency in relation to this vacancy. Earn yourself a referral bonus if you refer somebody else who fills the role! We also offer an iPad if you refer a new client to us and we recruit for them. Follow us on Facebook - Circle Recruitment , Twitter and LinkedIn - Circle Recruitment.
May 19, 2026
Contractor
Role: DV-Cleared Cyber Security Analyst / SOC Analyst Salary/Rate: £540-640 per day inside IR35 Location: on site Corsham 5x pw Contract Duration: contract until April 2027 We are currently looking for a Cyber Security Analyst / SOC Analyst for our government client. This Cyber Security Analyst / SOC Analyst role is based fully on site, 5 days per week in Corsham, over 13-hour shifts spanning days and nights, including weekends, 4 on 5 off, then 5 on 4 off. There is no further flexibility with the on-site requirement or office location. Security Clearance: Developed Vetting (DV Clearance) + sole UK national + Sensitive Post Check (which can take 3 months) The contract for this Cyber Security Analyst / SOC Analyst position is until April 2027, with potential to extend, operating inside IR35. This role is inside IR35 - Due to the service of the role, it will now be based on an Umbrella solution. Essential Skills / Experience required: Industry standard SOC Security qualifications (SANS, ISC2, etc.) Proven Tier 2/3 SOC Analyst experience (2 years+) Perform triage of security events ; determine scope, priority and impact, and make recommendations that enable expeditious remediation. Demonstratable experience working with SIEM technology and SIEM engineering (including tool configuration) i.e. ArcSight within an enterprise SOC. Experience in creation of use-cases, analytics and playbooks . An understanding of cloud Conduct real-time management of security incidents from detection to resolution. Technical Knowledge within anti-virus, networking, vulnerability management, encryption, Microsoft technologies, Linux. Knowledge of Information Security standards , legislation and practices, including GDPR & Data Protection Act 2018. Experience in dealing with a wide range of Information Security matters and operating in an ITIL based environment. Strong problem-solving ability, with flexibility to think creatively and adapt to and implement rapidly changing systems and services. Incident management experience and an ability to quickly tailor responses to deal with fast-moving situations. Highly desirable: Degree level qualification; preferably in technical, engineering or computing subject. Lead experience but would take a Tier 2 Analyst. Defence experience Role / Responsibilities: Responsible for supporting information security delivery work, including the development and implementation of Information Security Policies, Standards, processes and guidance. Responsibility for the security of Digital infrastructure by proactively analysing security threats/challenges/risks to the environment, including conducting penetration testing and compliance reviews monitoring of Information Security and information management to ensure compliance including reviewing and monitoring system and network logs for malicious activity or unacceptable use. If you are interested in the above role, please click Apply Now and send a CV for quick review. As a member of the Disability Confident Scheme, Circle and our Client guarantees to interview all candidates who have a disability and who meet all the essential criteria for the vacancy. In cases where we have a high volume of candidates who have a disability who meet all the essential criteria, we will interview the best candidates from within that group. Our client is proud to support the Armed Forces Covenant and as such, they guarantee to interview all veterans, spouses / partners of military personnel who meet all the essential criteria for the vacancy. In cases where they have a high volume of ex-military candidates / military spouses, partners, who meet all of the essential criteria, they will interview the best candidates from within that group. If you qualify, please notify us on igs at circlerecruitment dot com. We will be in touch to discuss your suitability and arrange your guaranteed interview. Should you require reasonable adjustments at any point during the recruitment process, if there is a better way for us to communicate, please do let us know. Circle Recruitment is acting as an Employment Agency in relation to this vacancy. Earn yourself a referral bonus if you refer somebody else who fills the role! We also offer an iPad if you refer a new client to us and we recruit for them. Follow us on Facebook - Circle Recruitment , Twitter and LinkedIn - Circle Recruitment.
Role: Cyber Security Analyst (SOC Analyst) Location: Corsham - 100% on-site Day Rate: Up to £640 Contract Length: Until 26th April 2027, with potential for extension IR35: In scope Why this could interest you Rare chance to work in a high-impact, mission-critical Defence environment. Long-term stability to 2027, with possibility of extension depending on funding. Tier 2/3 level work - genuinely complex incidents, not just first-line alert handling. Key responsibilities Tier 2/3 SOC analysis in an enterprise environment. Perform triage of security events - determine scope, priority and impact, and recommend rapid remediation actions. Conduct real-time management of security incidents from detection through to resolution. Work with SIEM technologies and SIEM engineering, including tool configuration (e.g. ArcSight). Create and maintain use cases, analytics and playbooks. Contribute to security monitoring across on-prem and cloud technologies. Shift pattern & working conditions 13-hour shifts - days and nights, including some weekends. 4 on 5 off, then 5 on 4 off - averaging a standard 37-hour week. Fully on-site in Corsham. Essential requirements Strongly preffeed to have Active DV Clearance (Developed Vetting) and eligibility for Sensitive Post Check. Industry-standard SOC security qualifications (e.g. SANS, ISC2). Proven Tier 2/3 SOC Analyst experience (2+ years). Hands-on experience with SIEM technologies and engineering (ideally including ArcSight). Experience creating SOC use cases, analytics and playbooks. Desirable Degree in a technical, engineering or computing discipline. Defence / MOD experience. Previous lead-level SOC experience (though an experienced Tier 2 Analyst would also be considered).
May 13, 2026
Contractor
Role: Cyber Security Analyst (SOC Analyst) Location: Corsham - 100% on-site Day Rate: Up to £640 Contract Length: Until 26th April 2027, with potential for extension IR35: In scope Why this could interest you Rare chance to work in a high-impact, mission-critical Defence environment. Long-term stability to 2027, with possibility of extension depending on funding. Tier 2/3 level work - genuinely complex incidents, not just first-line alert handling. Key responsibilities Tier 2/3 SOC analysis in an enterprise environment. Perform triage of security events - determine scope, priority and impact, and recommend rapid remediation actions. Conduct real-time management of security incidents from detection through to resolution. Work with SIEM technologies and SIEM engineering, including tool configuration (e.g. ArcSight). Create and maintain use cases, analytics and playbooks. Contribute to security monitoring across on-prem and cloud technologies. Shift pattern & working conditions 13-hour shifts - days and nights, including some weekends. 4 on 5 off, then 5 on 4 off - averaging a standard 37-hour week. Fully on-site in Corsham. Essential requirements Strongly preffeed to have Active DV Clearance (Developed Vetting) and eligibility for Sensitive Post Check. Industry-standard SOC security qualifications (e.g. SANS, ISC2). Proven Tier 2/3 SOC Analyst experience (2+ years). Hands-on experience with SIEM technologies and engineering (ideally including ArcSight). Experience creating SOC use cases, analytics and playbooks. Desirable Degree in a technical, engineering or computing discipline. Defence / MOD experience. Previous lead-level SOC experience (though an experienced Tier 2 Analyst would also be considered).
Ready for your next move in cyber security? Join our fast-growing Security Operations Centre, where you'll help defend multiple organisations across a wide range of industries - from critical infrastructure to complex enterprise environments. As part of our SOC team, you'll play a key role in strengthening and maturing our services, helping deliver smart, efficient and high-impact security outcomes for our clients. You won't just monitor alerts. You'll investigate, enhance detection capability, influence processes and help shape how we defend modern environments. You'll gain exposure to real-world threats, diverse technology stacks and large-scale operations - giving you the kind of hands-on experience that accelerates careers. If you're curious, analytical and enjoy solving problems that genuinely matter, this could be your next challenge. Our team operates a 24/7 SOC. This role involves working day and night shifts. Office based in Hemel Hempstead. You must be eligible for SC Clearance. What you'll be doing: Monitoring and analysing security alerts and events, conducting initial investigations responding. Escalating complex incidents to Senior Analysts for deeper analysis and resolution. Managing SOC incident queues. Maintaining and improving asset baselines across customer environments. Producing clear, insightful reports for both technical and non-technical audiences. Enhancing detection rules and use cases aligned to MITRE ATT&CK and threat-informed defence. What you'll bring: Hands-on experience with Microsoft Sentinel and Splunk. Knowledge of the MITRE ATT&CK framework. Understanding of client-server and multi-tier applications, databases, firewalls, VPNs and endpoint security. Solid networking fundamentals (TCP/IP, LAN/WAN, HTTP, SMTP, FTP, LDAP, etc.). Strong analytical thinking and structured problem-solving. An entry-level cyber security certification (e.g. Security+, CEH, CPSA) or similar. It would be great if you had: ? Scripting or programming skills (Python, PowerShell, Bash, Perl, C++). Broader SIEM experience (e.g. QRadar). Additional SOC or CREST certifications. If you're interested in this role but not sure if your skills and experience are exactly what we're looking for, please do apply, we'd love to hear from you! Employment Type: Full-time, Permanent. Location: Hemel Hempstead. Security Clearance Level: SC. Internal Recruiter: Jane. Salary: £42,000 to £58,000. Benefits: 25 days annual leave with the choice to buy additional days, health cash plan, life assurance and pension. Shift allowance. Sopra Steria: Our Aerospace, Defence and Security business designs, develops and deploys digital solutions to Central Government clients. The work we do makes a real difference to the client's goal of National Security, and we operate in a unique and privileged environment. We are given time for professional development activities, and we coach and mentor our colleagues, sharing knowledge and learning from each other. We foster a culture in which employees feel valued and supported and have pride in their work for the customer, delivering outstanding rates of customer satisfaction in the UK's most complex safety- and security-critical markets.
May 03, 2026
Full time
Ready for your next move in cyber security? Join our fast-growing Security Operations Centre, where you'll help defend multiple organisations across a wide range of industries - from critical infrastructure to complex enterprise environments. As part of our SOC team, you'll play a key role in strengthening and maturing our services, helping deliver smart, efficient and high-impact security outcomes for our clients. You won't just monitor alerts. You'll investigate, enhance detection capability, influence processes and help shape how we defend modern environments. You'll gain exposure to real-world threats, diverse technology stacks and large-scale operations - giving you the kind of hands-on experience that accelerates careers. If you're curious, analytical and enjoy solving problems that genuinely matter, this could be your next challenge. Our team operates a 24/7 SOC. This role involves working day and night shifts. Office based in Hemel Hempstead. You must be eligible for SC Clearance. What you'll be doing: Monitoring and analysing security alerts and events, conducting initial investigations responding. Escalating complex incidents to Senior Analysts for deeper analysis and resolution. Managing SOC incident queues. Maintaining and improving asset baselines across customer environments. Producing clear, insightful reports for both technical and non-technical audiences. Enhancing detection rules and use cases aligned to MITRE ATT&CK and threat-informed defence. What you'll bring: Hands-on experience with Microsoft Sentinel and Splunk. Knowledge of the MITRE ATT&CK framework. Understanding of client-server and multi-tier applications, databases, firewalls, VPNs and endpoint security. Solid networking fundamentals (TCP/IP, LAN/WAN, HTTP, SMTP, FTP, LDAP, etc.). Strong analytical thinking and structured problem-solving. An entry-level cyber security certification (e.g. Security+, CEH, CPSA) or similar. It would be great if you had: ? Scripting or programming skills (Python, PowerShell, Bash, Perl, C++). Broader SIEM experience (e.g. QRadar). Additional SOC or CREST certifications. If you're interested in this role but not sure if your skills and experience are exactly what we're looking for, please do apply, we'd love to hear from you! Employment Type: Full-time, Permanent. Location: Hemel Hempstead. Security Clearance Level: SC. Internal Recruiter: Jane. Salary: £42,000 to £58,000. Benefits: 25 days annual leave with the choice to buy additional days, health cash plan, life assurance and pension. Shift allowance. Sopra Steria: Our Aerospace, Defence and Security business designs, develops and deploys digital solutions to Central Government clients. The work we do makes a real difference to the client's goal of National Security, and we operate in a unique and privileged environment. We are given time for professional development activities, and we coach and mentor our colleagues, sharing knowledge and learning from each other. We foster a culture in which employees feel valued and supported and have pride in their work for the customer, delivering outstanding rates of customer satisfaction in the UK's most complex safety- and security-critical markets.