- Company Name
- Certain Advantage
- Job Title
- SOC Threat Detection Analyst
- Job Description
-
**Job Title:** SOC Threat Detection Analyst
**Role Summary:**
Analytical SOC professional responsible for monitoring, triaging, and investigating security events across a 24x7 operational environment. Supports incident response, threat hunting, and security platform maintenance while maintaining a proactive security posture within a defense‑aligned SOC.
**Expectations:**
- Work a 28‑day shift cycle, rotating early (04:00‑12:00), late (12:00‑20:00), and night (20:00‑04:00) shifts, with 28 hours per week.
- Achieve and sustain high‑quality triage, incident resolution, and reporting standards.
- Contribute to continuous improvement of detection capabilities, playbook development, and automation.
**Key Responsibilities:**
- Conduct Tier 1‑2 alert triage and automated monitoring of security tools (SIEM, network packet capture, IDS/IPS).
- Manage SOC email notifications, incident tickets, and remediation workflows.
- Support proactive threat hunting in partnership with CTI and assist IR investigations.
- Maintain security technologies, add/remove URLs from AcceptList/BlockList, and participate in routine security meetings.
- Collaborate with UK SOC members, enterprise IT, and InfoSec teams for broader incident response.
- Aid in project activities for SOC solutions and contribute to maturity and continuous improvement initiatives.
**Required Skills:**
- Experience in cyber security operations, including network, infrastructure, and OS/application awareness.
- Strong understanding of OSI model, networking protocols (DNS, HTTP/S, SSL/TLS, SMTP, FTP/S, LDAP/S).
- Hands‑on with SIEM (e.g., Splunk, QRadar) and network packet capture tools.
- Proficiency with IDS/IPS, threat hunting, defensive cyber‑attack frameworks, and malware analysis.
- Analytical mindset, excellent communication, and collaboration with business & suppliers.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Cyber Security, or related field *or* equivalent professional experience.
- Industry cybersecurity certification (e.g., CompTIA Security+, GIAC, or equivalent) preferred.
---
Stevenage, United kingdom
On site
01-12-2025