Skip to main content

SOC Analyst

Job Description

Location: Corsham / Remote
Job Type: Permanent
Clearance: SC

CND are looking for a further SOC Analyst resource to support our consultancy in the development and delivery of a new cloud monitoring service within a secure environment. In this role you will be working to not only carry out protective monitoring of critical applications but also onboarding further log sources into the SOC to ensure coverage of the assets. The work is conducted over multiple cloud environments, namely AWS and Azure, and you will need to be confident in challenging the behaviour of the platform and onsite teams where necessary.

Job Details

Experience in the following areas will be beneficial:

  • Exposure to working with Splunk
  • Trend Deep Security Manager
  • Knowledge of AWS Cloud native tools e.g. Cloudwatch, Cloudtrail, GuardDuty, SecurityHub.
  • Experience using Azure Cloud native tools e.g. Azure monitor, security centre
  • Knowledge of Mitre ATT&CK
  • Previous use of Rapid7 Vulnerability Assessment tool
  • Understanding of JSP 440 guidance
  • Has previously worked with MODCert Security Reporting

Key Responsibilities:

  • Work with the wider team to develop an Application SOC capability
  • Provide monitoring with Splunk, Trend, Rapid7 and a variety of cloud native tooling
  • Offer the benefit of experience and proactive ideas for improving the SOC
  • Respond to active incidents and provide remediation
  • Working with the AWS and Cloud environment
  • Threat detection and analysis
  • Development of new security monitoring use case
  • Basic Malware Analysis – Static and Dynamic analysis
  • Responding to alerts within the SIEM tool
  • Working with Customers to configure host IDS / IPS policies.
  • Ensuring customer SLA’s are met in relation to incident response and remediation.
  • Troubleshooting monitoring system issues.
  • Reviewing Customer reports to ensure quality and accuracy

Essential Skills:

  • Security Clearance
  • Experience working with multiple SIEM tools but ideally with Splunk
  • Application and Infrastructure monitoring experience essential
  • Ideally have some knowledge of public cloud systems
  • Experience working with MOD in the past and affecting change in that environment
  • Experience with using different SIEM Tools
  • Intrusion Detection & Prevention (IDP) – Firepower
  • Experience working with network analysis tools

Apply Now

Apply for a Job Vacancy
See a role that suits you? Want to join our team or work with one of our clients? Apply now!
Your Application
Select file...

Point of Contact

If you have any questions about this role, please get in touch with Matt at This email address is being protected from spambots. You need JavaScript enabled to view it.