At a Glance
- Tasks: Join our team as a SOC Analyst, tackling cyber threats and enhancing security measures daily.
- Company: DXC Technology is a leading IT solutions provider focused on delivering excellence and community.
- Benefits: Enjoy competitive pay, a pension scheme, private health insurance, gym memberships, and more perks.
- Why this job: Be part of a dynamic team, grow your skills, and make a real impact in cybersecurity.
- Qualifications: Experience with SIEM solutions, Kusto Query Language, and a solid understanding of networking concepts required.
- Other info: Must be eligible for high-level UK Security clearance and work onsite in Farnborough.
The predicted salary is between 36000 - 60000 £ per year.
At DXC Technology, delivering excellence for our customers and colleagues is more than just a motto; it is something we strive towards constantly through our work. Every day we deliver mission-critical services in a secure environment whilst promoting our people-first agenda, a real sense of community and a healthy work-life balance. Our consistently positive customer feedback and continuous growth help us cement our place as one of the world's leading IT solutions enterprises.
We have a great opportunity for an experienced SOC Analyst to join the DXC Cyber Threat Analysis Centre (CTAC). In this role, you will be responsible for advancing the initial work conducted by Tier 1 Analysts and providing more in-depth analysis of potential threats to the organization. This role is crucial in the escalated investigation, triage, and response to cyber incidents. The Tier 2 Analyst works closely with senior and junior analysts to ensure a seamless SOC operation and acts as a bridge between foundational and advanced threat detection and response functions.
Due to customer requirements, successful applicants must be eligible for high-level UK Security clearance, SC, and be able to work onsite in Farnborough.
Responsibilities:- Conduct escalated triage and analysis on security events identified by Tier 1 Analysts, determining threat severity and advising on initial response actions.
- Apply expertise in SIEM solutions utilizing Kusto Query Language (KQL) to perform log analysis, event correlation, and thorough documentation of security incidents.
- Identify and escalate critical threats to Tier 3 Analysts with detailed analysis for further action, ensuring rapid response and adherence to service Tier objectives (SLOs).
- Investigate potential security incidents by conducting deeper analysis on correlated events and identifying patterns or anomalies that may indicate suspicious or malicious activity.
- Use OSINT (Open-Source Intelligence) to enrich contextual data and enhance detection capabilities, contributing to a proactive stance on emerging threats.
- Monitor the threat landscape and document findings on evolving threat vectors, sharing relevant insights with CTAC teams to enhance overall situational awareness.
- Follow established incident response playbooks, providing feedback for enhancements and suggesting updates to streamline CTAC processes and improve threat response times.
- Coordinate with Tier 3 Analysts and management to refine detection and response workflows, contributing to continuous SOC maturity.
- Collaborate with Tier 3 Analysts on tuning SIEM and detection tools to reduce false positives and improve alert fidelity, submitting tuning requests and testing configurations when necessary.
- Identify gaps in current detection content and work with Senior Analysts to develop and validate new detection rules and use cases tailored to the organization's threat profile.
- Act as a mentor to Tier 1 Analysts, offering guidance on triage and analysis techniques and facilitating on-the-job training to elevate their technical skills and operational efficiency.
- Assist in training sessions and knowledge-sharing activities, providing feedback on areas for growth and contributing to a supportive learning environment within the SOC.
- Understands advanced networking concepts, including IP addressing, basic network protocols, and how traffic flows within a network.
- Advanced knowledge of Windows and Linux operating environments, including standard commands, file systems, and user authentication mechanisms.
- Competence in using SIEM solutions (e.g., ArcSight, Azure Sentinel) for monitoring and log analysis; some exposure to additional analysis tools such as basic XDR platforms.
- Able to demonstrate proficient knowledge using Kusto Query Language (KQL) to search and filter logs effectively.
- Familiar with open-source intelligence (OSINT) techniques to aid in identifying potential threats and gathering information.
- Able to communicate clearly and efficiently with team members and stakeholders, both internally and externally, under direction from senior analysts.
- Can communicate simple technical issues to non-technical individuals in a clear and understandable way.
- Able to create concise, structured reports that outline findings from preliminary investigations and daily monitoring activities.
- Able to manage personal workload effectively to ensure timely completion of assigned tasks within the SOC.
- Willing to collaborate with team members, accepting guidance and learning from more experienced analysts.
- Shows initiative in learning new technologies and techniques, leveraging internal resources and training to grow professionally.
- Able to function efficiently during high-pressure situations, following procedures to ensure consistent performance in incident management.
- Competitive compensation
- Pension scheme
- DXC Select - Our comprehensive benefits package (includes private health/medical insurance, gym membership and more)
- Perks at Work (discounts on technology, groceries, travel and more)
- DXC incentives (recognition tools, employee lunches, regular social events etc)
At DXC Technology, we believe strong connections and community are key to our success. Our work model prioritises in-person collaboration while offering flexibility to support wellbeing, productivity, individual work styles, and life circumstances. We are committed to fostering an inclusive environment where everyone can thrive.
Recruitment fraud is a scheme in which fictitious job opportunities are offered to job seekers typically through online services, such as false websites, or through unsolicited emails claiming to be from the company. These emails may request recipients to provide personal information or to make payments as part of their illegitimate recruiting process. DXC does not make offers of employment via social media networks and DXC never asks for any money or payments from applicants at any point in the recruitment process, nor ask a job seeker to purchase IT or other equipment on our behalf.
SOC Analyst employer: VERCIDA
Contact Detail:
VERCIDA Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land SOC Analyst
✨Tip Number 1
Familiarise yourself with Kusto Query Language (KQL) as it's essential for the SOC Analyst role. Practising your skills in log analysis and event correlation using KQL will give you a significant edge during interviews.
✨Tip Number 2
Stay updated on the latest trends in cybersecurity and threat intelligence. Being able to discuss current threats and how they relate to the role will demonstrate your proactive approach and genuine interest in the field.
✨Tip Number 3
Network with professionals in the cybersecurity community, especially those working in SOC environments. Engaging in discussions or attending relevant events can provide insights and potentially lead to referrals.
✨Tip Number 4
Prepare to showcase your problem-solving skills during the interview. Be ready to discuss specific incidents where you've successfully triaged or responded to security events, highlighting your analytical thinking and teamwork.
We think you need these skills to ace SOC Analyst
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience and skills that align with the SOC Analyst role. Emphasise your knowledge of SIEM solutions, Kusto Query Language (KQL), and any experience with incident response.
Craft a Strong Cover Letter: In your cover letter, express your enthusiasm for the position at DXC Technology. Mention specific responsibilities from the job description that excite you and how your background makes you a great fit for the team.
Showcase Relevant Skills: Clearly outline your technical skills related to networking concepts, operating systems, and threat analysis. Use examples from past experiences to demonstrate your ability to handle high-pressure situations and collaborate effectively.
Proofread Your Application: Before submitting, carefully proofread your application materials. Check for spelling and grammatical errors, and ensure that all information is accurate and presented clearly. A polished application reflects your attention to detail.
How to prepare for a job interview at VERCIDA
✨Brush Up on KQL Skills
Since the role requires expertise in Kusto Query Language (KQL), make sure to review your skills. Prepare to demonstrate your ability to perform log analysis and event correlation using KQL during the interview.
✨Understand the Threat Landscape
Familiarise yourself with current cyber threats and trends. Be ready to discuss how you would monitor the threat landscape and document findings, as this shows your proactive approach to security.
✨Showcase Your Incident Response Knowledge
Prepare to talk about your experience with incident response playbooks. Highlight any specific examples where you followed established procedures and contributed to improving response times.
✨Demonstrate Team Collaboration
This role involves working closely with both junior and senior analysts. Be prepared to share examples of how you've collaborated in past roles, mentored others, or contributed to a supportive team environment.