Skip to content

Open nowPosted 9 hours ago

SIOC Analyst

Workable (global search)107,962 open roles

Where
Manchester, England, United Kingdom
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSIOC AnalystWorkable (global search) · Manchester, England, United Kingdom
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 3 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.5%3 days
  3. 8.1%7 days
  4. 15.1%14 days
  5. 33.9%30 days
This job: posted 9 hours ago

Workable (global search) median: 3 days open

The posting

At UBDS, we help organisations transform through cloud, cyber security, AI and digital innovation. As our Managed Services capability grows, we're looking for a SIOC Analyst to join our Security and Infrastructure Operations Centre, helping protect and support critical customer environments.

This is a hands-on cyber security role focused on security monitoring, threat detection, incident investigation and response. You'll work across complex cloud and enterprise environments, investigating security events, responding to incidents and supporting Digital Forensics and Incident Response (DFIR) activities.

Our technology landscape is primarily Microsoft and AWS, alongside SIEM and wider security tooling.

Location: Manchester (Office-based) Working Pattern: Monday to Friday | Rotating shifts between 08:00–20:00 | On-call rota

What You'll Do

You'll:

  • Monitor and investigate security alerts, events and suspicious activity across customer environments.
  • Triage security alerts and determine severity, impact and appropriate response actions.
  • Investigate potential security incidents across endpoints, identities, cloud environments, networks and applications.
  • Use SIEM and security tooling to analyse logs, correlate events and identify suspicious behaviour.
  • Support incident response activities from initial detection and investigation through to containment, remediation and recovery.
  • Perform initial DFIR activities, including evidence collection, log analysis, timeline analysis and investigation of compromised systems or accounts.
  • Investigate phishing, malware, suspicious authentication activity, account compromise and other common security threats.
  • Support security monitoring and investigation across Microsoft and AWS cloud environments.
  • Analyse indicators of compromise and support threat hunting activities.
  • Escalate complex or high-severity incidents to senior security specialists and incident response teams.
  • Support vulnerability, security and threat management activities where required.
  • Document investigations, findings, actions and recommendations clearly.
  • Contribute to incident reports and post-incident reviews.
  • Help develop and improve security monitoring use cases, detection rules and operational playbooks.
  • Identify recurring threats and opportunities to improve detection and response capabilities.
  • Work closely with customers, cloud engineers, infrastructure teams and other security specialists during investigations.
  • Contribute to continual improvement across the SIOC and wider Managed Services capability.

Skills & Experience

This is not an exhaustive list of requirements. We're looking for someone with experience across several of these areas and an appetite to continue developing their cyber security and incident response capability.

  • Experience working within a SOC, SIOC, Cyber Security Operations or similar operational security environment.
  • Experience monitoring, triaging and investigating security alerts and incidents.
  • Hands-on experience using SIEM or security monitoring platforms.
  • Experience investigating security events using logs and telemetry from multiple sources.
  • Good understanding of common cyber threats, attack techniques and indicators of compromise.
  • Understanding of incident response processes, including identification, containment, remediation and recovery.
  • Experience or knowledge of Microsoft security technologies and environments.
  • Understanding of Microsoft identity and endpoint security, including Entra ID and Microsoft Defender technologies.
  • Experience or understanding of security monitoring within AWS environments.
  • Some practical knowledge of DFIR principles and investigation techniques.
  • Understanding of endpoint, identity, network and cloud security concepts.
  • Ability to analyse technical information and build a clear picture of what has happened during an incident.
  • Strong analytical and problem-solving skills with a methodical approach to investigations.
  • Ability to prioritise multiple alerts and incidents within a fast-paced operational environment.
  • Strong written and verbal communication skills, including the ability to clearly document and communicate security incidents.

DFIR Capability

We're particularly interested in candidates who have some exposure to Digital Forensics and Incident Response or who want to develop further in this area.

Useful experience could include:

  • Security incident investigation and evidence gathering.
  • Endpoint and host-based investigation.
  • Log and event analysis.
  • Timeline development and analysis.
  • Malware or suspicious file investigation.
  • Identity and account compromise investigations.
  • Email and phishing investigations.
  • Analysis of indicators of compromise.
  • Basic forensic acquisition and preservation principles.
  • Using EDR, SIEM and cloud telemetry to reconstruct security incidents.

We are not necessarily looking for a dedicated forensic specialist, but you should be comfortable supporting investigations beyond initial alert triage.

Technology Exposure

Experience across some of the following would be beneficial:

  • Microsoft Sentinel or comparable SIEM platforms.
  • Microsoft Defender XDR.
  • Microsoft Defender for Endpoint.
  • Microsoft Defender for Cloud.
  • Microsoft Entra ID.
  • Microsoft 365 security tooling.
  • AWS security and logging services.
  • Endpoint Detection and Response tooling.
  • Vulnerability management platforms.
  • Threat intelligence platforms and feeds.
  • SOAR and security automation tooling.
  • PowerShell, Python or other scripting languages for investigation and automation.

Desirable Qualifications

Relevant certifications are beneficial but not essential, including:

  • Microsoft Security Operations Analyst Associate (SC-200).
  • Microsoft security or Azure certifications.
  • AWS security or cloud certifications.
  • CompTIA Security+, CySA+ or equivalent.
  • GIAC, SANS or other incident response/forensics training.
  • CREST or equivalent cyber security qualifications.

The Opportunity

This role would suit a security analyst who enjoys understanding how incidents happened, not simply closing alerts.

You'll gain exposure to a broad range of customer environments and security technologies, with opportunities to develop deeper skills across security operations, threat detection, incident response and DFIR while working alongside experienced cyber, cloud and infrastructure specialists.

Benefits

Why people choose to grow their careers at UBDS Group

Professionals choose to grow their careers at UBDS Group for its reputation as a dynamic and forward-thinking organisation that is deeply committed to both innovation and employee development. At UBDS Group, employees are given unique opportunities to work on cutting-edge projects across a diverse range of industries, exposing them to new challenges and learning opportunities that are pivotal for professional growth. The Group’s culture emphasises continuous improvement, offering ample training programs, mentorship, and the chance to gain certifications that enhance their skills and marketability.

UBDS Group fosters a collaborative environment where creativity and innovation are encouraged, allowing employees to contribute ideas and solutions that have a tangible impact on the company and its clients. This combination of professional development, a culture of innovation, and the opportunity to make meaningful contributions makes UBDS Group an attractive place for those looking to advance their careers and be at the forefront of technological and operational excellence.

Employee Benefits

  • Training – All team members are offered a number of options in terms of personal development, whether it is technical led, business acumen or methodologies. We want you to grow with us and to help us achieve more
  • Private medical cover for you and your spouse/partner, offered via Vitality
  • Discretionary bonus based on a blend of personal and company performance
  • Holiday – You will receive 25 Days holiday, plus 1 day for Birthday and 1 day for your work anniversary in addition to UK bank holidays
  • Electric Vehicle leasing with salary sacrifice
  • Contributed Pension Scheme
  • Death in service cover

About UBDS Group

At UBDS Group our mission is to support entrepreneurs who are setting new standards with technology solutions across cloud services, cybersecurity, data and AI, ensuring that every investment advances our commitment to innovation, making a difference, and creating impactful solutions for organisations and society.

Equal Opportunities

We are an equal opportunities employer and do not discriminate on the grounds of gender, sexual orientation, marital or civil partner status, pregnancy or maternity, gender reassignment, race, colour, nationality, ethnic or national origin, religion or belief, disability or age.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.