SOC Analyst

SOC Analyst

Full-Time On-site
T

Incident Response Analyst

We are seeking an experienced Incident Response Analyst to support the detection, triage, investigation, containment and resolution of cyber security incidents across a complex enterprise environment.

Key Responsibilities

  • Monitor and investigate alerts from SIEM, EDR/XDR, identity, email, cloud and network security technologies.
  • Triage incidents, assess severity and business impact, and coordinate containment, eradication and recovery.
  • Investigate phishing, malware, account compromise, data loss, unauthorised access and suspicious network activity.
  • Collect, preserve and analyse endpoint, server, identity, network, email and cloud artefacts.
  • Analyse logs, packet captures, forensic images and security telemetry to establish scope, root cause and attacker activity.
  • Identify IOCs, attacker behaviours, TTPs and map findings to MITRE ATT&CK where appropriate.
  • Develop and execute threat hunts and contribute to detection rule, monitoring and logging improvements.
  • Maintain incident records, investigation timelines, evidence and post-incident reports.
  • Develop and maintain incident response playbooks, procedures and communication processes.
  • Conduct post-incident reviews, root-cause analysis and lessons-learned activities.
  • Provide clear technical and management updates to senior stakeholders.

Essential Skills & Experience

  • Practical experience in cyber security incident response, security monitoring or a SOC environment.
  • Hands-on experience with SIEM and EDR/XDR technologies.
  • Experience investigating Windows and Linux systems, authentication activity, security logs and network traffic.
  • Strong understanding of the incident response lifecycle.
  • Knowledge of MITRE ATT&CK, Cyber Kill Chain and NIST.
  • Good understanding of enterprise networking, IAM, cloud, email and endpoint security.
  • Experience with digital forensics and evidence handling.
  • Strong communication, investigation and analytical skills.

Desirable

  • Banking, financial services or other regulated-sector experience.
  • Microsoft Sentinel, Defender XDR, Defender for Identity or Defender for Cloud.
  • KQL, PowerShell, Python or similar scripting/automation.
  • Threat hunting, malware analysis and detection engineering.
  • Azure and Microsoft 365 investigation experience.
  • EnCase, FTK, Velociraptor, Volatility or Wireshark.
  • Certifications such as GCIH, GCIA, GCFA, GNFA, SC-200, CySA+ or CISSP.

Qualifications

  • Relevant cyber security experience, degree or equivalent practical experience. Knowledge of NIST, CIS Controls and recognised information security standards

#J-18808-Ljbffr

SOC Analyst employer: Tank Recruitment

Join a dynamic technology team in London as a Lead Python Developer, where you will not only enhance your technical skills but also play a pivotal role in shaping the future of software development. Our hybrid working model promotes a healthy work-life balance, while our commitment to employee growth ensures you have ample opportunities for professional development and mentorship. Experience a collaborative culture that values innovation and encourages you to stay hands-on with coding, all within a vibrant city known for its tech advancements.

T

Contact Details:

Tank Recruitment Recruitment Team