Junior SOC Analyst – Leeds – National Security West
// Role Summary
Join BAE Systems Digital Intelligence as a Junior SOC Analyst in Leeds to protect a major UK CNI organisation's critical cloud infrastructure. You will monitor, analyse, and respond to cyber threats, contributing to a best-in-class Security Operations Centre.
// Key Responsibilities
- Monitor, triage, analyse, and investigate security alerts and network traffic.
- Identify and categorise cyber-attacks and security incidents.
- Assist with incident remediation and provide recommendations for security improvements.
- Utilise Splunk and Sentinel for security monitoring.
- Requires existing SC clearance and willingness to undergo DV clearance.
// Role Specification
About BAE Systems Digital Intelligence
BAE Systems Digital Intelligence is a leading force of 4,500 digital, cyber, and intelligence experts, collaborating across 10 countries. We specialise in collecting, connecting, and understanding complex data to empower governments, nation states, armed forces, and commercial businesses to achieve digital advantage in challenging environments.
About the Role
We are seeking a Junior SOC Analyst to join our dedicated Security Operations Centre (SOC) team in Leeds. This role is crucial for the day-to-day operation and enhancement of a SOC supporting the defence of a major UK CNI organisation. The protected networks are primarily hosted in Azure and AWS cloud platforms, housing hundreds of systems that require robust security measures. The customer is committed to making this SOC a benchmark of best practice and excellence, reflecting the significant threats these systems face.
The SOC will be staffed by a mix of customer and BAE Systems personnel, with primary operations based in our Leeds office to facilitate essential customer network access.
Responsibilities
- Monitor, triage, analyse, and investigate alerts, log data, and network traffic using the Protective Monitoring platform and internet resources to identify cyber-attacks and security incidents.
- Categorise all suspected incidents in line with the Security Incident policy.
- Recognise potential, successful, and unsuccessful intrusion attempts and compromises through detailed review and analysis of event information.
- Document high-quality security incident tickets, leveraging existing knowledge resources and independent research.
- Assist with remediation activities, including supporting customer stakeholders, to inhibit cyber-attacks, clean up IT systems, and secure networks against repeat attacks.
- Produce security incident review reports, presenting incident information and providing security improvement recommendations.
- Understand Threat Intelligence and its application in an operational environment.
- Support incident response for national-scale incidents in a coaching capacity.
- Collaborate with other BAE Systems teams to improve services based on customer needs.
Requirements
Technical Skills:
- Basic Python and/or scripting skills.
- Proficiency with Windows, OS X, and Linux operating systems.
- Experience using Splunk and Sentinel.
- Familiarity with a range of security tooling/technology.
- Strong understanding of security architecture, particularly networking.
- Detailed understanding of threat intelligence and threat actors, TTPs (Tactics, Techniques, and Procedures), and operationalising threat intelligence.
- Experience in investigating complex network intrusions, including those by state-sponsored groups or targeted ransomware attacks.
- Understanding of TCP/IP component layers to identify normal and abnormal traffic.
- Understanding of AWS and/or Azure cloud services.
- Experience of Splunk (with ES) and/or Sentinel; content development experience is desirable.
Non-Technical Skills:
- Client-side consulting experience, including stakeholder engagement and the ability to communicate insights and concepts effectively to others (including briefing and report writing skills).
- Experience in security process development.
- Ability to understand and adapt to different cultures and hierarchical structures.
- Self-starter capable of independent working.
Desirable Skills:
- Software engineering experience.
- Penetration testing skills.
Life at BAE Systems Digital Intelligence
We embrace Hybrid Working, allowing flexibility in when and where you work to better balance work and personal life. Diversity and inclusion are fundamental to our success, fostering an environment where varied perspectives, skills, and backgrounds contribute to excellence.