Protect critical infrastructure, investigate advanced cyber threats, and help shape the future of enterprise cybersecurity.


Job Summary

The SOC Analyst for the Information Security Management Systems Business Unit provides advanced cybersecurity expertise within the Security Operations Centre (SOC). The role leads investigations and containment of complex threats, conducts proactive threat hunting, performs deep forensic analysis, and enhances detection and response capabilities. They act as the final escalation point for high-severity incidents and provide strategic insight to improve clients’ security posture.


Key Responsibilities

🛡 Advanced Incident Response

  • Lead the investigation and containment of high-severity cybersecurity incidents.
  • Perform deep forensic analysis on compromised systems, endpoints, and networks.
  • Coordinate response activities during ransomware, phishing, insider threat, or Advanced Persistent Threat (APT) incidents.
  • Conduct root cause analysis and recommend remediation actions.

🎯 Threat Hunting

  • Proactively search for hidden threats that bypass traditional security controls.
  • Analyse attacker tactics, techniques, and procedures (TTPs) using frameworks such as MITRE ATT&CK.
  • Develop hypotheses and conduct threat hunting exercises across SIEM, EDR, firewall, and cloud environments.

📊 SIEM & Detection Engineering

  • Create, tune, and optimise SIEM use cases, correlation rules, and alerts.
  • Reduce false positives and improve detection accuracy.
  • Develop advanced detection logic for emerging threats.
  • Integrate threat intelligence feeds into monitoring platforms.

🔍 Malware & Threat Analysis

  • Analyse malicious files, scripts, URLs, and suspicious behaviour.
  • Reverse engineer malware where required.
  • Identify Indicators of Compromise (IOCs) and Indicators of Attack (IOAs).
  • Produce technical threat intelligence reports for clients.

📡 Security Monitoring Oversight

  • Provide technical oversight and escalation support to Tier 1 and Tier 2 analysts.
  • Validate escalated incidents and determine severity and impact.
  • Ensure continuous monitoring coverage for critical infrastructure and systems.

🌐 Threat Intelligence Integration

  • Monitor global threat trends, vulnerabilities, and exploit activity.
  • Correlate internal security events with external threat intelligence.
  • Advise clients on emerging cyber risks affecting the industry or region.

📝 Incident Documentation & Reporting

  • Produce detailed incident reports and post-incident reviews.
  • Document lessons learned and recommend security improvements.
  • Provide executive summaries for client management and stakeholders.

🤖 Automation & Process Improvement

  • Develop automated response playbooks and workflows.
  • Improve SOC operational procedures and incident handling processes.
  • Support SOAR integration and orchestration initiatives.

🛡 Vulnerability & Risk Support

  • Assist with prioritising critical vulnerabilities based on exploitability and business impact.
  • Support remediation validation and exposure analysis.

👥 Mentorship & Leadership

  • Mentor Tier 1 and Tier 2 SOC Analysts and conduct team planning in line with client requirements.
  • Conduct technical knowledge sharing and simulation exercises.
  • Contribute to SOC maturity and capability development.
  • Compile and present service reports for all SOC clients in line with client SLAs.

Qualifications & Skills

Education & QualificationsExperience
Bachelor’s Degree in Information Security, IT or related field8–10 years in IT Security, Network Engineering and 24/7 SNOC/SOC environments
CCNP / CCIE (Security or Enterprise)Hands-on experience with enterprise security and monitoring platforms
CISSP / CISMNetwork engineering background advantageous
ISO 27001 Lead Implementer / AuditorEnterprise SOC operations
CEH / GIACVendor certifications advantageous

Technical Skills

  • SIEM Platforms
  • ISO 27001
  • NIST Framework
  • SOC / NOC Tools
  • TCP/IP Networking
  • Routing Protocols
  • VLANs
  • VPN Technologies
  • Firewall Administration
  • IDS / IPS
  • EDR / XDR
  • Incident Management
  • Network Access Control (NAC)
  • Threat Intelligence
  • Vulnerability Management
  • Penetration Testing
  • PCI-DSS
  • ISO Compliance
  • CIS Controls
  • Security Metrics & Reporting
  • Audit Readiness
  • Staff Scheduling
  • Training Plans
  • Cyber Hygiene Programmes
  • AI / ML Analytics
  • Zero Trust Architecture
  • Process Automation

Key Competencies

✔ Exceptional organisational skills

✔ Strong leadership and mentoring abilities

✔ Excellent written communication

✔ Strong verbal communication skills

✔ Attention to detail

✔ Ability to manage multiple priorities

✔ Client-focused approach


Key Performance Areas

✔ Security Strategy Execution and Technical Leadership

✔ Security & Network Operations Management

✔ Infrastructure Monitoring & Network Oversight

✔ Governance, Reporting, Compliance & Audit Readiness


Why Join Us?

Join a team dedicated to protecting critical infrastructure through cutting-edge cybersecurity technologies and industry best practices. Work alongside experienced professionals in a collaborative environment that values innovation, continuous improvement, and technical excellence.


Apply for this Position

If you meet the above requirements and are passionate about cybersecurity, we’d like to hear from you.

Complete the application form below and upload your latest CV.

Apply for this position

Allowed Type(s): .pdf, .doc, .docx