Associate SOC Analyst

  • NCC Group
  • Cheltenham, Gloucestershire
  • 18/07/2026
Full time Information Technology Telecommunications

Job Description

Associate SOC Analyst

Department: Cyber Services and Capabilities

Employment Type: Full Time

Location: GBR Cheltenham Jessop House

Description

An Associate Security Analyst will be the first line of defence in the Event Monitoring Centre, responsible for the initial triage of security alerts, basic vulnerability analysis and data loss prevention. The primary role is to monitor, analyse, and assess incoming alerts, identifying potential security incidents based on established criteria. Confirmed or suspicious threats are escalated to R2 analysts, senior analysts or the shift lead for further investigation and response. The role requires strong analytical skills, attention to detail and the ability to follow escalation protocols to ensure swift and effective incident management. Ideal candidates have a foundational understanding of cybersecurity principles, experience with SIEM tools and a commitment to continuous learning in a fast paced security environment.

As the initial contact for alert triage, the analyst's expertise directly supports analytic development by suggesting customer tuning rules to ensure the efficient running of the SOC. The role requires strong analytical skills, technical proficiency and a commitment to continuous learning in a dynamic security environment.

Key Responsibilities Threat Detection and Monitoring
  • Monitor the ITSM platform for new alerts, schemas and tickets
  • Monitor SIEM logs, IDS logs and managed intelligence sources
  • Identify potential threats, vulnerabilities and indicators of compromise
  • Initiate escalation procedures to counteract potential threats and vulnerabilities
Incident Remediation and Documentation
  • Escalate to R2 analysts, team lead or senior analyst when clarification or further review is required
  • Provide incident remediation and prevention recommendations to customers using established procedures and analyst experience
  • Document and adhere to security monitoring processes
  • Suggest process and procedure improvements based on working requirements to streamline processes
Customer Service and Escalation
  • Deliver exceptional customer service by exceeding customer expectations
  • Serve as the initial point of contact for alerts and schemas triaged
  • Contribute to the creation and maintenance of security documentation, including incident response playbooks, standard operating procedures and knowledge base articles
Reporting and Continuous Improvement
  • Compile and review service focused reports for effective communication
  • Contribute to the creation and maintenance of security documentation, including incident response playbooks, standard operating procedures and knowledge base articles
  • Be open to mentoring from senior analysts
Threat Analysis and Collaboration
  • Provide practical insights to the analysis of common security incidents
  • Maintain working relationships with the analytic development and security engineering teams
  • Collaborate with shift partners to provide a high quality of service
General Duties
  • Perform additional assigned duties as required
  • Show flexibility to learn and adapt quickly to new security tools, technologies and processes
  • Process data schema review and data loss prevention alerts
  • Apply strong analytical and problem solving skills
  • Communicate effectively, both written and verbally
  • Work collaboratively as part of a team
  • Keep up to date with latest emerging threats and APT groups
  • Receive mentorship from senior analysts
Skills, Knowledge & Expertise Minimum Requirements

Network, Cloud and OS Knowledge:

  • Understanding of common network protocols and tools
  • Understanding of Linux operating systems
  • Understanding of content delivery networks
  • Understanding of the CIA triad and its interaction with security
  • Understanding of cloud technologies - AWS, GCP, OCI

Customer Interaction:

  • Experience documenting both high level and technical customer facing information
  • Confidence providing critical/sensitive information accurately
  • Contacting key stakeholders during major incidents

Incident Analysis and Response:

  • Awareness of the MITRE ATT&CK framework
  • Experience performing in depth analysis of security alerts
  • Assess customer impact through investigation and work with senior analysts for resolution
  • Basic understanding of Personal Identifiable Information
  • Initiate escalation procedures for potential threats
  • Interpret threat priority against the cyber kill chain
  • Provide appropriate mitigation and remediation steps
Desirable Requirements

Tooling:

  • Hands on experience with SIEM platforms, preferably Splunk
  • Knowledge of cloud products and log events such as AWS, OCI, GCP
  • Knowledge of cloud vulnerability tools such as Wiz

Desirable Certifications:

  • CompTIA Security+
  • CompTIA Network+
  • Security Blue Team Level One
  • AWS Cloud Practitioner
  • MAD20 ATT&CK Fundamentals
Job Benefits
  • Flexible Working: Balance your work and personal life with our flexible working options
  • Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave
  • Medicash & Critical Illness Scheme
  • Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme
  • Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities
  • Green Car Scheme: Drive green and save money with our eco friendly car scheme
  • Cycle Scheme: Stay fit and healthy with our cycle to work scheme
  • Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet
  • Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments