Tier 1 Security Operations Centre Analyst

Tier 1 Security Operations Centre Analyst

Full-Time 53085 - 64881 £ / year (est.) No working from home possible
S

At a Glance

  • Tasks: Monitor security alerts and assist in incident response to protect against cyber threats.
  • Company: Join a dynamic team at a leading Security Operations Centre.
  • Benefits: Competitive salary, shift allowance, and opportunities for professional growth.
  • Other info: Work on-site in Stoke on Trent with excellent career advancement opportunities.
  • Why this job: Kickstart your cybersecurity career with hands-on experience in a collaborative environment.
  • Qualifications: Ideal for graduates or career changers with some relevant experience or lab projects.

The predicted salary is between 53085 - 64881 £ per year.

We are seeking an enthusiastic and driven Tier 1 SOC Analyst to join our 24x7 Security Operations Centre. In this frontline role, you’ll support the detection, triage, and escalation of security incidents, helping to protect our organisation and customers from evolving cyber threats. You'll monitor security alerts, assist with investigations, and contribute to vulnerability management and compliance efforts. This is an excellent opportunity for someone early in their cybersecurity career to gain hands‑on experience, grow their skills, and be part of a collaborative and high-performing security team. This role will be on site in our Stoke on Trent technical hub and will be subject to shift allowance at market rate.

Role Responsibilities

  • Incident Detection & Response: Monitor security events and alerts using SIEM (Security Information and Event Management) and other security tools to identify potential security threats and incidents. Conduct initial triage, analysis, and categorisation of security incidents based on severity and impact. Escalate complex or high-impact incidents to senior SOC analysts or other IT/security teams as required. Assist with containment and remediation efforts, ensuring incident response actions are carried out promptly and effectively. Collaborate on the detection and response to incidents with senior SOC staff and other teams when necessary. Assist in documenting incident timelines, indicators of compromise (IOCs), and response actions taken. Regularly perform compliance checks and IT health check schedules against internal components and against our services. Working on Remedial Action Plans and mitigations on completion of ITHC and vulnerability scanning activity.
  • Threat intelligence and analysis: Stay updated with the latest cybersecurity threats, vulnerabilities, and attack techniques. Analyse network and system logs to identify anomalous behaviour and trends indicating potential cyber threats. Contribute to threat intelligence sharing within the organisation and with external partners.
  • Security Monitoring: Conduct continuous security monitoring of network traffic, endpoints, and critical systems. Help to identify, analyse, and support the mitigation of security weaknesses and vulnerabilities across the infrastructure. Help to ensure that alerts are managed, categorised, and investigated in line with the organisation’s incident management procedures and within SLAs. Contribute to the development and refinement of detection rules and response playbooks. Assist in the deployment and configuration of security tools, ensuring they are properly integrated and functioning.
  • Compliance, Reporting and Documentation: Participate in security audits and assessments, providing evidence of SOC activities and controls. Maintain accurate records of all events handled, including triage notes and escalation details. Support the delivery of incident and vulnerability summaries to the management team and customers as part of Service Reviews or Security Working Groups. Participate in post-incident reviews and help document lessons learned. Assist in ensuring compliance with industry standards, regulations, and internal security policies. Contribute to the preparation of regular reports and metrics on SOC operations and overall security posture.
  • Vulnerability Management: Assist in monitoring and managing vulnerabilities across live service using various vulnerability management tools. Support compliance with patching policies by tracking vulnerability status and helping to coordinate remediation efforts. Providing regular updates on vulnerability status to the wider SOC team and other stakeholders. Contribute to Remedial Action Plans by documenting actions taken and tracking remediation progress. Work with third parties to respond to advisories and directives for critical vulnerabilities in a timely manner.
  • Collaboration and knowledge sharing: Work closely with other Service Operations teams (e.g., Network, Architecture, and Development teams) to identify and resolve security issues. Share insights, threat intelligence, and incident learnings to improve the overall security posture of the organization.
  • Continuous Improvement: Identify and suggest improvements to SOC processes, playbooks, and tools based on hands‑on experience and incident handling. Contribute to the development and documentation of SOC procedures, ensuring they are clear, accurate, and up to date.

Education and Experience Requirements

  • Experience (preferred): 6 months to 2 years of hands‑on experience in a SOC or similar security environment. Graduates or career changers with lab experience, internships, or home lab projects are encouraged to apply.
  • Education: Bachelor’s degree in Computer Science, Information Security, Cyber Security or related field, or equivalent experience desirable.
  • Certifications (preferred): Any SIEM‑specific certification or vendor‑specific training. Relevant cybersecurity certifications such as Certified Cloud Security Professional (CCSP) or other relevant security certifications, BTL1 or others are highly desirable but not essential.
  • Technical Skills: Familiarity with SIEM tools (e.g., LogRhythm, Elastic SIEM, Microsoft Sentinel, or similar). Basic understanding of network protocols, firewalls, intrusion detection/prevention systems (IDS/IPS), and endpoint security. Exposure to or understanding of log analysis and alert triage, vulnerability scanning and patching and incident response. Knowledge of cyber security and compliance frameworks (NIST, ISO 27001, MITRE ATT&CK). Understanding of network protocols, malware analysis, threat intelligence, and vulnerability management. An understanding of and an interest in learning scripting and automation for security operations.
  • Soft Skills: Strong written and verbal communication skills. Analytical thinker with good attention to detail and sound judgement. Able to follow standard operating procedures with discipline and accuracy. Eager to learn, ask questions, and develop professionally. Comfortable working in a fast‑paced team environment and handling multiple alerts. Participate in on‑call or out‑of‑hours technical support where appropriate and supported by senior staff.

Tier 1 Security Operations Centre Analyst employer: Securecloudplus

Join our dynamic team at the Stoke on Trent technical hub, where we prioritise employee growth and development in a collaborative work culture. As a Tier 1 SOC Analyst, you'll gain invaluable hands-on experience in cybersecurity while benefiting from competitive shift allowances and opportunities to advance your skills in a supportive environment dedicated to protecting our organisation and customers from cyber threats.

S

Contact Details:

Securecloudplus Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Tier 1 Security Operations Centre Analyst

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Securecloudplus, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Securecloudplus

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Securecloudplus. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Tier 1 Security Operations Centre Analyst

Incident Detection & Response
SIEM (Security Information and Event Management)
Threat Intelligence Analysis
Security Monitoring
Vulnerability Management
Compliance Checks
Network Protocols

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Securecloudplus insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Securecloudplus that you’re committed to staying ahead in the game.

How to prepare for a job interview at Securecloudplus

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Securecloudplus to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Securecloudplus.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.