SOC Analyst L2

2 weeks ago


Birmingham, Birmingham, United Kingdom NTT DATA Full time

We're a business with a global reach that empowers local teams, and we undertake hugely exciting work that is genuinely changing the world. Our advanced portfolio of consulting, applications, business process, cloud, and infrastructure services will allow you to achieve great things by working with brilliant colleagues, and clients, on exciting projects.

Our inclusive work environment prioritises mutual respect, accountability, and continuous learning for all our people. This approach fosters collaboration, well-being, growth, and agility, leading to a more diverse, innovative, and competitive organisation. We are also proud to share that we have a range of Inclusion Networks such as: the Women's Business Network, Cultural and Ethnicity Network, LGBTQ+ & Allies Network, Neurodiversity Network and the Parent Network.

For more information on Diversity, Equity and Inclusion please click here: Creating Inclusion Together at NTT DATA UK | NTT DATA

What you will be doing;

  • The primary function of the SOC Analyst (L2) is to analyse any incidents escalated by the SOC Analyst (L1) and undertake the detailed investigation of the Security Event. The Security Analyst (L2) shall determine whether the security event will be classified as an incident. They will be coordinating with the customer IT and Security team for resolution of the Security Incident.

MainDuties

  • Security Monitoring: & Investigation:
  • Monitoring SIEM tools to assure high a level of security operations delivery function
  • Oversee and enhance security monitoring systems to detect and analyse potential security incidents.
  • Conduct real-time analysis of security events and incident and escalate as necessary
  • Support other teams on investigations into incidents, determining the root cause and impact.
  • Document findings and lessons learned to improve incident response procedures.
  • Ensure runbooks are followed and are fit for purpose
  • Incident Response:
  • Lead and coordinate incident response activities to effectively contain, eradicate, and recover from security incidents.
  • Develop and maintain incident response plans, ensuring they align with industry best practices.
  • Escalation management in the event of a security incident
  • Follow major incident process
  • Threat Intelligence:
  • Stay abreast of the latest cybersecurity threats and vulnerabilities, integrating threat intelligence into security monitoring processes.
  • Contribute to the development of threat intelligence feeds to enhance proactive threat detection.
  • Security Tool Management:
  • Manage and optimise SIEM tools, ensuring they are properly configured and updated to maximize effectiveness.
  • Own the development and implementation of SOC Use Cases
  • Evaluate new security technologies and recommend enhancements to the security infrastructure.
  • Collaboration:
  • Collaborate with cross-functional teams, including IT, legal, and management, to address security incidents and implement preventive measures.
  • Provide expertise and guidance to other analysts.
  • Working with the Technical Teams to ensure all new and changed services are monitored accordingly
  • Documentation:
  • Maintain accurate and up-to-date documentation of security procedures, incident response plans, and analysis reports.
  • Create post-incident reports for management and stakeholders.
  • Support the creation of monthly reporting packs as per contractual requirements.
  • Create and document robust event and incident management processes, Runbooks & Playbooks
  • Other responsibilities:
  • Involvement in scoping and standing up new solutions for new opportunities
  • Assisting Pre-Sales team with requirements on new opportunities
  • Demonstrations of SOC tools to clients
  • Continual Service Improvement - Recommendations for change to address incidents or persistent events.

What you will bring;

  • This role will be based on-site in Birminham, we need canddiates that are able to work in a job that involves 24/7 operations, this will probably be inshift patterns of 4 days on, 4 days off.
  • Must be able to obtain SC Clearance or already hold SC clearance.
  • Must have a good understanding on Incident Response approaches
  • Must have knowledge and hands-on knowledge of Microsoft Sentinel (or any SIEM tool).
  • Strong verbal and written English communication.
  • Strong interpersonal and presentation skills.
  • Strong analytical skills

  • Must have good understanding on network traffic flows and able to understand normal and suspicious activities.

  • Must have good understanding of Vulnerability Scanning and management as well as Ethical Hacking (Penetration Testing)
  • Ability to learn forensic techniques
  • Ability to reverse engineer attacks to understand what actions took place.
  • Knowledge of ITIL disciplines such as Incident, Problem and Change Management.
  • Ability to work with minimal levels of supervision.
  • Willingness to work in a job that involves 24/7 operations or on-call.

Education Requirements & Experience

  • Minimum of 3 to 5 years of experience in the IT security industry, preferably working in a SOC/NOC environment.
  • Preferably holds Cyber Security Certification e.g. GIAC, ISC2, SC-200

  • Experience with Cloud platforms (AWS and/or Microsoft Azure)

  • Excellent knowledge of Microsoft Office products, especially Excel and Word

Reports to

  • Security Director – NTT DATA UK Security Practice
  • Client Delivery Director – NTT DATA UK Managed Services

We offer a range of tailored benefits that support your physical, emotional, and financial wellbeing. Our Learning and Development team ensure that there are continuous growth and development opportunities for our people. We also offer the opportunity to have flexible work options.

You can find more information about NTT DATA UK & Ireland here:

We are an equal opportunities employer. We believe in the fair treatment of all our employees and commit to promoting equity and diversity in our employment practices. We are also a proud Disability Confident Committed Employer - we are committed to creating a diverse and inclusive workforce. We actively collaborate with individuals who have disabilities and long-term health conditions which have an effect on their ability to do normal daily activities, ensuring that barriers are eliminated when it comes to employment opportunities. In line with our commitment, we guarantee an interview to applicants who declare to us, during the application process, that they have a disability and meet the minimum requirements for the role. If you require any reasonable adjustments during the recruitment process, please let us know. Join us in building a truly diverse and empowered team.

SOC Analyst (L2)

We are currently recruiting for a Senior Associate level Managed Detection and Response SOC Analyst Level 2 to join our growing Security Operations Centre business.

This role will be based on-site in Birminham, we need canddiates that are able to work in a job that involves 24/7 operations, this will probably be inshift patterns of 4 days on, 4 days off.

About Us

NTT DATA is one of the world's largest Global Security services providers with over 7500 Security SMEs and Integration partner to many of the worlds most recognised Security Technology providers. We strive to hire exceptional, innovative, and passionate individuals who want to grow with us. In a constantly changing world, we work together with our people, clients and communities to enable them to fulfil their potential to do great things. We believe that by bringing everyone together, we can solve problems using innovative technology that can create a world that is sustainable and secure.

This is a great opportunity for you to play a pivotal role in helping to shape our client's transformation journeys.


  • SOC Analyst

    1 day ago


    Birmingham, Birmingham, United Kingdom Hamilton Barnes 🌳 Full time

    SOC Analyst – Managed Security Service Provider (MSSP)We're partnering with a well-established Managed Security Service Provider that has been protecting organisations worldwide since 2004. Originally founded as a SIEM specialist, the business evolved into managed security services over a decade ago to meet growing client demand. With a highly agile team...


  • Birmingham, Birmingham, United Kingdom NTT DATA Full time

    We're a business with a global reach that empowers local teams, and we undertake hugely exciting work that is genuinely changing the world. Our advanced portfolio of consulting, applications, business process, cloud, and infrastructure services will allow you to achieve great things by working with brilliant colleagues, and clients, on exciting projects.Our...


  • Birmingham, Birmingham, United Kingdom La Fosse Full time

    I'm currently partnering with a global organization who are on the lookout for a Cyber Security Analyst to join their established team to contribute to their maturity journey. It's a wide spanning role where you'll gain experience across the full spectrum of cyber security and perfect for someone with a genuine thirst for knowledge.The org have a really...


  • Birmingham, Birmingham, United Kingdom Spait Infotech Private Limited Full time

    Job Title: Information Security Analyst (Full-Time, Permanent)Location: Remote within the United KingdomExperience Level: 0–12 yearsEligibility: Must have the right to work in the UK(Valid Visa) No sponsorship providedAbout the RoleWe are looking for a proactive and detail-oriented Information Security Analyst to join our growing security team. This role...


  • Birmingham, Birmingham, United Kingdom National Crime Agency (NCA) Full time

    BirminghamJob SummaryThis is an exciting opportunity to join the NCA's Cyber Security team. We are currently looking to recruit a SOC Analyst within our Integrated Protective Security command.The Cyber Security Team leads the strategic response to cyber risks, cybersecurity function, oversees audit, building internal and external alliances with diverse...


  • Birmingham, Birmingham, United Kingdom Ntt Data Full time

    The team you';ll be working with:Security Operations ManagerAbout UsNTT DATA is one of the world's largest global security services providers, with over 7,500 security SMEs. We work with leading security technology vendors and pride ourselves on delivering innovative and effective solutions. Our people, clients, and communities are at the core of what we do....

  • Threat Analyst

    1 day ago


    Birmingham, Birmingham, United Kingdom NTT DATA Full time

    We're a business with a global reach that empowers local teams, and we undertake hugely exciting work that is genuinely changing the world. Our advanced portfolio of consulting, applications, business process, cloud, and infrastructure services will allow you to achieve great things by working with brilliant colleagues, and clients, on exciting projects.Our...


  • Birmingham, Birmingham, United Kingdom Focus Group Full time

    Cyber Essentials AnalystFocus Group | Managed Security ServicesLocation{{:}} Hybrid from Shoreham, Exeter, Birmingham, Manchester or CarlisleTravel{{:}} Occasional visits to UK customers requiredSalary{{:}} £35,000 to £37,500 + BenefitsHelp UK businesses achieve security certification that mattersWe're looking for a technically-capable, customer-focused...


  • Birmingham, Birmingham, United Kingdom National Crime Agency Full time

    DetailsReference number434490Salary£36,057This position attracts a Recruitment and Retention Allowance (RRA) of £1000 (Per Annum) available as an addition to the advertised salary.The role attracts a shift payment premium of 30% of your base salaryA Civil Service Pension with an employer contribution of 28.97%GBPJob gradeExecutive OfficerNCA Grade 5/Police...


  • Birmingham, Birmingham, United Kingdom LRQA Full time

    Job ID:43125Location:Birmingham : 1 Trinity Park : BiPosition Category:Information TechnologyPosition Type:Employee RegularRole PurposeWe're looking for a Senior Test Engineer to lead quality engineering across LRQA's Cyber Digital products. Embedding quality early, automating intelligently, and assuring every release meets the highest standards of...