← Back to Directory

Senior SOC Analyst – Leeds

BAE Systems · Leeds, UK
Clearance Level
DV
Salary Range
Competitive
Employment Type
FULL TIME
Work Style
onsite

// Role Summary

Join BAE Systems Digital Intelligence as a Senior SOC Analyst in Leeds, playing a crucial role in protecting a major UK CNI organisation by monitoring, investigating, and responding to cyber threats within Azure and AWS cloud environments.

// Key Responsibilities

  • Hands-on shift-based role in a 24/7 SOC operation.
  • Monitor, triage, and investigate security alerts and incidents using SIEM tools.
  • Support incident response and remediation activities.
  • Develop new workflows for SOAR tools and contribute to service improvement.
  • Requires a minimum of SC clearance, with DV clearance readiness.
  • Experience with Splunk, Sentinel, and cloud security (AWS/Azure) is essential.

// Role Specification

About BAE Systems Digital Intelligence

BAE Systems Digital Intelligence is a leading provider of digital, cyber, and intelligence solutions, collaborating across 10 countries to help governments, nation states, armed forces, and businesses leverage digital advantage in challenging environments.

Role Overview

We are seeking a Senior SOC Analyst & Shift Lead to join our dedicated Security Operations Centre (SOC) team in Leeds. This role is critical in supporting the defence of a major UK CNI organisation, safeguarding numerous systems hosted primarily on Azure and AWS cloud platforms. Our SOC aims to be a benchmark of best practice, reflecting the significant threats our protected systems face.

This is a hands-on, shift-based role, operating within a 24/7 environment as part of a four-shift team. You will be responsible for using our Security Incident and Event Management (SIEM) toolsets to detect, investigate, and respond to potential security and service incidents.

Key Responsibilities

  • Prepare and deliver shift handover briefs.
  • Monitor, triage, analyse, and investigate alerts, log data, and network traffic to identify cyber-attacks and security incidents.
  • Categorise suspected incidents according to the Security Incident policy.
  • Identify potential, successful, and unsuccessful intrusion attempts through analysis of event details.
  • Document security incidents by writing high-quality tickets, utilising existing knowledge and independent research.
  • Assist with and conduct permitted remediation activities to mitigate cyber-attacks and secure networks.
  • Produce security incident review reports, including recommendations for security improvements.
  • Understand and apply Threat Intelligence in an operational context.
  • Support incident response for national-scale incidents in a coaching capacity.
  • Collaborate with other BAE Systems teams to enhance services based on customer needs.
  • Develop new workflows for SOAR tools to automate responses to common attack types.
  • Continuously improve the service by reviewing use cases and proposing enhancements in response to evolving threats.

Technical Requirements

  • Basic Python and/or scripting skills.
  • Proficiency with Windows, OS X, and Linux operating systems.
  • Experience using Splunk and Sentinel.
  • Working knowledge of a range of security tooling and technology.
  • Strong understanding of security architecture, particularly networking.
  • Detailed understanding of threat intelligence, threat actors, TTPs, and operationalising threat intelligence.
  • Experience investigating complex network intrusions.
  • Understanding of TCP/IP component layers to identify normal and abnormal traffic.
  • Understanding of AWS and/or Azure cloud services.
  • Experience with Splunk (with ES) and/or Sentinel; content development experience is desirable.

Non-Technical Requirements

  • Client-side consulting experience, including stakeholder engagement and communication of insights.
  • Coaching mindset with a desire to mentor team members.
  • Experience in security process development.
  • Ability to adapt to different cultures and hierarchical structures.
  • Self-starter capable of independent work.
  • Team player adept at working in multi-disciplinary and diverse teams.

Desirable Skills

  • Software engineering experience.
  • Penetration testing skills.

Life at BAE Systems Digital Intelligence

We embrace Hybrid Working, fostering flexibility in when and where we work to enhance work-life balance and well-being. Diversity and inclusion are core to our success, creating an environment where varied perspectives and experiences drive excellence.