SOC Analyst: Threat Hunting & 24/7 Incident Response

SOC Analyst: Threat Hunting & 24/7 Incident Response

Full-Time 40000 - 50000 £ / year (est.) No working from home possible
Avanade

At a Glance

  • Tasks: Investigate security incidents and validate threats using advanced analytical skills.
  • Company: Join Microsoft’s cutting-edge Security Operations Centre in Newcastle.
  • Benefits: Enjoy competitive pay, flexible shifts, and opportunities for professional growth.
  • Other info: Be part of a dynamic team with 24/7 support and mentorship opportunities.
  • Why this job: Make a real difference in cybersecurity while working with innovative technologies.
  • Qualifications: Experience in security analysis and strong problem-solving abilities required.

The predicted salary is between 40000 - 50000 £ per year.

  • Microsoft Security Operations Centre (SOC) Analyst – T2 & T3
  • Security Clearance Required
  • Preferred Location - Newcastle

Job Description

The SOC Analyst Team operates as a next‑generation, intelligence‑led Security Operations function, designed to deliver high‑quality, scalable 24×7 security monitoring and response.

All SOC analysts participate in a 24×7 shift model, ensuring uninterrupted service coverage, while also contributing to detection improvement, automation feedback, and service optimisation when operational demand allows.

Tier 2 – SOC Analyst

Technology Primary – Microsoft Sentinel & Service Now.

Role Purpose

Tier 2 SOC Analysts represent the primary human analysis function, responsible for investigating escalated alerts and incidents that require human judgement, contextual understanding, and analytical depth.

Key Responsibilities

  • Perform deep investigation of escalated alerts and incidents from automated Tier 1 workflows
  • Validate threats, scope impact, and determine severity using contextual analysis

• Investigate across multiple data sources, including

  • SIEM
  • EDR / XDR
  • Identity and authentication telemetry
  • Cloud and Saa S platforms

• Coordinate and execute response actions in line with

  • Defined playbooks
  • Client‑specific requirements
  • Incident response procedures
  • Maintain clear, high‑quality investigation documentation and handover notes
  • Operational Expectations
  • Operate as part of a 24×7 shift rota
  • Maintain accountability for investigation accuracy and quality
  • Escalate complex or ambiguous cases to Tier 3 appropriately

• Provide structured feedback into

  • Detection tuning
  • Alert quality improvements
  • Automation optimisation
  • Continuous Improvement Contributions
  • Identification of repeatable investigation patterns
  • Feedback on automation opportunities
  • Playbook refinement and improvement
  • Detection logic tuning recommendations
  • Tier 3 – Senior SOC Analyst / Incident Specialist
  • Role Purpose

Tier 3 analysts provide advanced security expertise and escalation handling, focusing on complex, high‑risk, or ambiguous security incidents and ensuring consistent investigation quality across the SOC.

Key Responsibilities

• Handle escalations involving

  • High‑impact or business‑critical incidents
  • Advanced or evasive attacker techniques
  • Ambiguous or novel threat behaviour

• Conduct advanced threat analysis, including

  • Attacker behaviour and intent assessment
  • Cross‑incident correlation
  • Campaign and intrusion analysis
  • Provide oversight and quality assurance of Tier 2 investigations
  • Lead complex incident response coordination where required
  • Leadership & Mentorship
  • Participate in 24×7 escalation coverage, via on‑call or senior shift roles
  • Act as a technical mentor to Tier 2 analysts
  • Support analyst development through coaching and investigative guidance
  • Set investigation and response quality standards across the SOC
  • Platform & Automation Feedback
  • Improve detection fidelity
  • Reduce repeat incident patterns
  • Increase automation coverage over time
  • Ensure complex incidents inform long‑term service improvement
  • #J-18808-Ljbffr

SOC Analyst: Threat Hunting & 24/7 Incident Response employer: Avanade

Avanade is an excellent employer for those seeking to thrive in the dynamic field of cloud architecture. With a strong emphasis on innovation and client satisfaction, employees benefit from structured learning opportunities and a collaborative work culture that fosters personal development. Located in Greater London, Avanade offers a vibrant environment where skilled professionals can lead impactful projects and grow their careers in a diverse and supportive setting.

Avanade

Contact Details:

Avanade Recruitment Team

We think you need these skills to ace SOC Analyst: Threat Hunting & 24/7 Incident Response

Microsoft Sentinel
Service Now
SIEM
EDR / XDR
Incident Response Procedures
Contextual Analysis
Threat Validation