L3 SOC Analyst

L3 SOC Analyst

Full-Time On-site
A

Role overview Must-haves:
Microsoft SC-200 certification and eligibility for SC clearance. You'll be the senior escalation point in a Belfast Cyber Security Operations Centre (CSOC). You'll take incidents escalated from Tier 1 and Tier 2 analysts, assess their business impact, and recommend the response and escalation path. You'll triage threat intelligence (IOCs and TTPs) from multiple sources, run threat hunts across the SIEM, and help organisations identify, isolate and contain security issues. You'll also guide and mentor two analysts, without direct line management, and support the rollout and management of IBM QRadar, Microsoft Sentinel, Defender for Endpoint, Defender for Identity and Defender for Cloud. Key responsibilities Handle security incidents escalated by L1 and L2 analysts, carry out business impact analysis and recommend response actions and escalation paths Perform advanced event and incident analysis, including baselining and trend analysis Conduct intelligence-led threat hunting using IOCs and TTPs, investigating suspicious activity through the SIEM Support Major Incident Response from a protective monitoring perspective, helping teams identify, contain and remediate threats Give timely advice on response plans based on incident type and severity Oversee daily SOC checklists: log review, management reporting, alert analysis and escalation follow-up Provide oversight, guidance and mentoring to L2 and L3 analysts, and cover SOC Manager duties when they are absent Oversee a virtual team of L1 and L2 analysts, including objectives, performance reviews, training and shift cover Identify SIEM improvements: use case development, rule creation, tuning and optimisation Help design the onboarding of new systems, including assessing, parsing and onboarding log sources Improve SOC procedures and processes, with SOC Manager approval Produce stakeholder and client reporting and manage client engagement Join the on-call rota to support L1 analysts working out of hours Stay current on cyber security trends and threat intelligence to guide the team's detection capability
Essential requirements Microsoft SC-200 certification (mandatory) Eligible for SC clearance (mandatory) Proven experience at Level 3 SOC Analyst or senior security operations level Strong hands-on experience with Microsoft Sentinel, Microsoft Defender for Endpoint (MDE) and KQL Experience onboarding, configuring, tuning and reporting on SIEM solutions Threat intelligence experience Leadership and mentoring experience Commercial experience in security monitoring and/or penetration testing Solid understanding of operating systems, networking and infrastructure design System administration knowledge across one or more of Windows, Linux or Mac Ability to explain technical issues clearly to non-technical stakeholders at all levels Strong written and verbal communication, and a self-motivated, flexible approach Degree in Computing or a related subject; a Cyber Security master's with relevant experience is also considered
Desirable In-depth Microsoft Sentinel expertise: use case and rule development, workbooks and playbooks, KQL, Logic Apps and SOAR Managing Sentinel as an MSSP, including Azure Lighthouse and multi-customer environments using DevOps Wider Microsoft security experience across Defender for Endpoint, Identity and Cloud Other SIEM platforms, such as IBM QRadar and LogRhythm Certifications such as Network+, Security+, CySA+, CISMP or CISSP
TPBN1_UKTJ

L3 SOC Analyst employer: ANSON MCCADE

Anson McCade is an exceptional employer that prioritises employee well-being and professional growth, offering a flexible remote working environment in the UK. With a strong focus on security and digital transformation, employees benefit from comprehensive training programmes and clear pathways for career advancement, all while contributing to impactful projects alongside talented teams and senior stakeholders.

A

Contact Details:

ANSON MCCADE Recruitment Team