SOC Analyst - Tier 2/3, 24/7 Threat Detection & Response

SOC Analyst - Tier 2/3, 24/7 Threat Detection & Response

Full-Time 45000 - 60000 £ / year (est.) No working from home possible
3004 Avanade UK Limited Company

At a Glance

  • Tasks: Investigate security incidents and escalate threats while ensuring top-notch documentation.
  • Company: Join Microsoft’s innovative Security Operations Centre in Newcastle.
  • Benefits: Enjoy competitive pay, flexible shifts, and opportunities for professional growth.
  • Other info: Dynamic work environment with mentorship and career advancement opportunities.
  • Why this job: Be part of a cutting-edge team protecting against cyber threats 24/7.
  • Qualifications: Experience in security analysis and strong analytical skills required.

The predicted salary is between 45000 - 60000 £ per year.

Overview

Microsoft Security Operations Centre (SOC) Analyst – T2 & T3 (Security Clearance Required). Preferred Location: Newcastle.

The SOC Analyst Team operates as a next‑generation, intelligence‑led Security Operations function, delivering 24×7 security monitoring and response. All SOC analysts participate in a 24×7 shift model to ensure uninterrupted service coverage, while contributing to detection improvement, automation feedback, and service optimisation when operational demand allows.

Tier 2 – SOC Analyst (Role Purpose)

Tier 2 SOC Analysts represent the primary human analysis function, responsible for investigating escalated alerts and incidents that require human judgement, contextual understanding, and analytical depth.

Key Responsibilities

  • Perform deep investigation of escalated alerts and incidents from automated Tier 1 workflows.
  • Validate threats, scope impact, and determine severity using contextual analysis.
  • Investigate across multiple data sources, including SIEM, EDR / XDR, identity and authentication telemetry, cloud and SaaS platforms.
  • Coordinate and execute response actions in line with defined playbooks, client‑specific requirements, and incident response procedures.
  • Maintain clear, high‑quality investigation documentation and handover notes.

Operational Expectations

  • Operate as part of a 24×7 shift rota.
  • Maintain accountability for investigation accuracy and quality.
  • Escalate complex or ambiguous cases to Tier 3 appropriately.
  • Provide structured feedback into detection tuning, alert quality improvements, automation optimisation, and continuous improvement.

Tier 2 – Contributions

When operational demand allows, Tier 2 analysts are expected to contribute insight time to platform improvement activities, supporting the Platform Automation Lead through:

  • Identification of repeatable investigation patterns.
  • Feedback on automation opportunities.
  • Playbook refinement and improvement; detection logic tuning recommendations.

Tier 3 – Senior SOC Analyst / Incident Specialist

Tier 3 analysts provide advanced security expertise and escalation handling, focusing on complex, high‑risk, or ambiguous security incidents and ensuring consistent investigation quality across the SOC.

Key Responsibilities

  • Handle escalations involving high‑impact or business‑critical incidents, advanced or evasive attacker techniques, and ambiguous or novel threat behaviour.
  • Conduct advanced threat analysis, including attacker behaviour and intent assessment, cross‑incident correlation, and campaign/intrusion analysis.
  • Provide oversight and quality assurance of Tier 2 investigations.
  • Lead complex incident response coordination where required.

Leadership & Mentorship

  • Participate in 24×7 escalation coverage, via on‑call or senior shift roles.
  • Act as a technical mentor to Tier 2 analysts.
  • Support analyst development through coaching and investigative guidance.
  • Set investigation and response quality standards across the SOC.

Platform & Automation Feedback

Like Tier 2, Tier 3 analysts provide structured feedback into platform and automation initiatives, working with the Platform Automation Lead to:

  • Improve detection fidelity.
  • Reduce repeat incident patterns.
  • Increase automation coverage over time.
  • Ensure complex incidents inform long‑term service improvement.

#J-18808-Ljbffr

SOC Analyst - Tier 2/3, 24/7 Threat Detection & Response employer: 3004 Avanade UK Limited Company

Avanade is an exceptional employer, offering a dynamic work culture that prioritises collaboration and innovation within the Health & Public Sector. Employees benefit from extensive growth opportunities through strategic partnerships with Accenture, allowing for impactful contributions to digital transformation initiatives. With a strong commitment to diversity and inclusion, Avanade fosters a sense of belonging, making it an ideal workplace for those passionate about leveraging Microsoft technologies to drive meaningful change.

3004 Avanade UK Limited Company

Contact Details:

3004 Avanade UK Limited Company Recruitment Team

We think you need these skills to ace SOC Analyst - Tier 2/3, 24/7 Threat Detection & Response

Security Monitoring
Incident Response
Threat Analysis
Contextual Analysis
SIEM
EDR/XDR
Cloud Security