About this role
Salary: £55,000 - 95,000 per year
Requirements: Foundational understanding of cybersecurity concepts, including TCP/IP networking, common log sources, and basic attack techniquesExperience using a SIEM platform such as Splunk, Microsoft Sentinel, or an equivalent toolBasic knowledge of Windows, Linux, and macOSStrong analytical and problem-solving skills, with the ability to assess alerts, follow investigative processes, and make sound decisions within defined proceduresClear written and verbal communication skills for accurate ticketing, escalation, and shift handoverAbility to work calmly and effectively in a shift-based operational environment, manage workload, and maintain focus during high alert volumesAbility to follow procedures, work with minimal supervision, and learn from feedback and operational experienceExperience or strong interest in cybersecurity or IT operationsEntry-level or foundation cybersecurity certifications such as CySA+ or SC-200 are desirableExperience with Microsoft Azure and/or AWS is desirableProficiency with Microsoft Office tools, particularly Excel and WordEligibility for, or possession of, UK SC ClearanceWillingness to work in a 24/7 shift-based SOC environmentAwareness of scripting, query languages, or rule-based detection is advantageous but not required Responsibilities: Continuously monitor security alerts, logs, and event data across customer and internal environments to identify suspicious or malicious activityTriage and analyse alerts, determine whether they indicate potential security or service incidents, and prioritise them according to security incident management policiesConduct first-line investigations using SIEM, SOAR, and supporting security tools; validate alerts, gather evidence, and assess initial impact and severityRecognise successful or unsuccessful attack attempts and escalate identified indicators of compromise or attack activity to senior analysts or incident responders with clear contextSupport incident containment and remediation by following runbooks and customer guidance, and document actions consistentlyCreate and maintain incident tickets, record investigation steps and findings, and produce incident summaries and investigation notes using internal knowledge bases and researchContribute findings to post-incident reviews and identify opportunities to improve detection, response, and operational processesApply SOC-provided threat intelligence to alert analysis and investigationsFollow SOC procedures, documentation standards, and shift-handover processesParticipate in the 24/7 shift rota and collaborate with other analysts to maintain monitoring coverage Technologies: AIAWSAzureExcelIncident ManagementSupportLinuxmacOSSecuritySplunkTCP/IPWindowsCloudNetwork More:
We are hiring a Level 1 Security Analyst for our UK Sovereign SOC, a frontline, shift-based role in a 24/7 Security Operations Centre. At NTT DATA, we are a global business and technology services, AI, and digital infrastructure leader serving 75% of the Fortune Global 100, with experts in more than 70 countries. We offer tailored benefits supporting physical, emotional, and financial wellbeing, ongoing learning and development, and flexible work options. We are an equal opportunities employer and a Disability Confident Committed Employer, committed to equity, diversity, inclusion, and removing barriers to employment.
last updated 40 week of 2026