Posted on: 07/09/2026
Core Responsibilities :
Incident Response & Investigation :
- Perform triage, investigation, containment, and remediation activities for complex and high-severity cybersecurity incidents.
- Act as a senior technical escalation point during incident handling, providing guidance and direction to analysts as required.
- Participate in incident bridges, contributing clear technical updates and investigative findings.
- Conduct forensic data collection and analysis across endpoints, network, cloud, and identity sources.
- Produce accurate and well-structured incident timelines, investigation notes, and post-incident summaries.
- Support post-incident reviews by contributing technical insights and lessons learned.
Detection & Threat Monitoring :
- Review and investigate alerts generated from SIEM, EDR, cloud security, and identity platforms.
- Support the tuning and refinement of detection rules to improve alert quality and reduce false positives.
- Conduct threat-hunting activities under defined hypotheses, using available telemetry and analytical techniques.
- Identify gaps in visibility or logging and raise these with senior analysts or engineering teams.
SOC Tooling & Automation Support :
- Use SOC tooling effectively to support investigations and response activities.
- Contribute ideas and feedback to improve SOC workflows, automation and playbooks.
- Assist with the validation and testing of changes to SOC tools and automated response processes.
- Highlight tooling issues or limitations that impact investigation effectiveness.
Governance, Process & Assurance Support :
- Support internal and external audit activities by providing investigation evidence and technical input when requested.
- Follow established SOC procedures and ensure investigations are documented accurately and consistently.
- Contribute to the maintenance of SOC documentation, playbooks and operational procedures.
- Participate in lessons-learned activities and contribute suggestions for process improvement.
Team & Stakeholder Interaction :
- Provide informal guidance and support to junior analysts during investigations, helping to improve analysis quality.
- Share technical knowledge and investigative techniques with peers through day-to-day collaboration.
- Communicate technical findings clearly to SOC leads and relevant stakeholders during incidents.
- Work collaboratively with Legal, Risk, Privacy, Crisis Management and Global SOC teams when required.
Operational Support :
- Support daily SOC monitoring activities during periods of increased workload or incident activity.
- Assist with escalation handling for complex alerts or investigations.
- Maintain a high standard of investigative quality and professional conduct during operational activity.
Required Skills & Experience :
- Experience working in a SOC, incident response or cybersecurity investigation role.
- Strong understanding of common attack techniques, threat actor behaviours, and investigative methodologies.
- Ability to analyse security alerts and logs across SIEM, EDR, cloud, identity and network security tools.
- Experience with scripting or automation (e.g. Python, PowerShell) is advantageous.
- Familiarity with frameworks such as MITRE ATT&CK, NIST CSF, or equivalent.
- Strong written and verbal communication skills, with the ability to explain technical findings clearly.
- Ability to work effectively under pressure during incident scenarios.
Preferred Qualifications :
- Relevant industry certifications such as CompTIA CySA+ or Microsoft Certified : Security Operations Analyst Associate (SC-200).
- Hands-on experience with EDR, SOAR, or forensic tooling.
- Experience participating in threat-hunting activities or security exercises.
- Exposure to tabletop or incident-response simulations.
- Certifications or demonstrated expertise in Microsoft security technologies related to Sentinel, Purview, or Microsoft Defender suites (e.g., Microsoft Certified : Information Protection Administrator Associate (SC-400), Microsoft Certified : Azure Security Engineer Associate (AZ-500)).
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1669306