SOC Analyst
NCC Group is hiring an SOC Analyst for a remote role open to applicants in United Kingdom. Level rates it ; you can apply on Level.
AI in this role
Level 2 SOC Analyst responsible for monitoring global systems, analyzing security alerts, and handling incident response.
Today, it is an unavoidable fact that your business-critical infrastructure and systems are at risk of attack. The key to good security is a clear understanding of what is most critical to the business. When you do not have enough internal resources, time, or skills to monitor and manage your IT environment 24/7, NCC Group can help, freeing up your skilled employees to focus on value-add activities.
NCC Group provides a range of managed and hosted services delivered from our Global Security Operations Centre (SOC), which operates 24/7, 365 days a year. Our team of over 100 accredited security experts is available around the clock, dealing daily with over 200 million log events and providing support for thousands of network devices.
NCC Group’s MXDR Team provides world-class Extended Detection and Response (XDR) services, detecting, responding to, and mitigating cyber-attacks on our customers' networks in our Security Operations Centres. We use a plethora of detection tools such as the Microsoft Security Stack, Splunk, EDR, IDS & IPS tools, and many more, all integrated with NCC Group's Unified Cyber Platform (UCP).
The MXDR Team is looking for L2 SOC Analysts with a passion for security to join the team, helping customers get the most out of our services and protect their networks. This is an opportunity to join a technically advanced and talented team and help NCC Group build and deliver world-class services to our customers.
This role is ideal for a seasoned SOC Analyst with experience in cybersecurity looking to broaden their scope of cyber skills with a strong focus on detection and response to cyber incidents.
Key Responsibilities
- Monitor global systems for potential threats, vulnerabilities, and indicators of compromise.
- Perform in-depth analysis of security alerts utilising both NCC Group's UCP and explore further using the underlying detection platform where necessary.
- Provide incident remediation and prevention documentation and recommendations to customers based on defined procedures and analyst experience.
- Document and adhere to processes related to security monitoring procedures.
- Provide customer service that always exceeds our customers’ expectations.
- Initiate escalation procedures to counteract potential threats, vulnerabilities, and threat actors.
- Compile and review service-focused reports.
- Act as an escalation point for junior team members, aiding and mentoring where necessary.
- Contribute to the continuous improvement of SOC procedures and documentation.
- Perform other SOC duties as assigned.
Skills, Knowledge & Expertise
Core Technical Skills & Experience- Practical experience with security and networking tools such as Microsoft XDR (Sentinel, Defender) and Splunk Enterprise/Cloud/Enterprise Security
- Strong understanding of network protocols, endpoint detection, and digital forensics
- In‑depth knowledge of Windows and Linux operating systems
- Hands‑on experience analysing common security incidents and supporting endpoint security
- Ability to remain calm and effective during high‑pressure and sensitive security situations
Not mandatory, but a strong advantage if held or equivalent knowledge demonstrated.
- Microsoft: SC‑200, AZ‑500, AZ‑900, MS‑500
- Splunk: Certified User, Power User, Advanced Power User, Enterprise Security Administrator
- CrowdStrike: CCFR, CCFH
- CREST: CPSA, CRIA, CMRE, CNIA, CHIA
- CompTIA: Security+, Network+, CySA+
- Cisco: CCNA
- SANS: GCIA, GCIH, GSEC
- Other relevant certifications
How we rate this
SOC Analyst at NCC Group rates 0 out of 100 for how much of the daily work is AI. That makes it Little AI (AI Level 1 of 4). The level is about AI in the job, not seniority.
Little AI. AI is not part of the work.
- ●●●● Builds AI80 to 100
- ●●●○ Works on AI60 to 79
- ●●○○ Uses AI40 to 59
- ●○○○ Little AI0 to 39
Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.
Prepare for this job
A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.
Skills and AI tools this role asks for
Questions you could be asked
- Tell me about a project where cybersecurity was part of your work. What did you do?
- Tell me about a project where incident response was part of your work. What did you do?
- Tell me about a project where threat monitoring was part of your work. What did you do?
- Tell me about a project where soc was part of your work. What did you do?
- Walk me through how you've used Splunk in your day-to-day work.
Adapt your resume
- List these exact terms on your resume: Cybersecurity, Incident Response, Threat Monitoring, Soc, and Splunk. An applicant tracking system matches the wording, not the idea.
- Attach one line of real, concrete experience to at least one of them. A tool named with nothing behind it rarely survives a human read.
Want an expert to read your CV for this job?
Free. Send your CV and the role you want next. We reply by email within 2 to 4 business days.
Get new remote cybersecurity jobs by email
One email a week with the new remote cybersecurity jobs, each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.
Free. One email a week. Unsubscribe in one click.
Similar roles
Other roles that involve little AI, at other companies.
What kind of AI work fits you?
Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.
Find my next step