Skip to main content
AfterDuty

Associate SOC Analyst

NCC Group · Manchester, Greater Manchester

Type
Full-time
Posted
17 days ago

Overview

Your policing background gives you a disciplined approach to documenting incidents and preserving evidence, which is central to the analyst's duty of recording initial findings and actions. You are used to assessing threat severity and initiating escalations under pressure, and your clear written and verbal communication helps when updating both technical and non-technical stakeholders. The role demands foundational IT and security tooling knowledge, so typical ex-officers would need retraining, but the procedural and investigative mindset transfers well.

About this role

Description

The R1 Analyst plays a vital role in the Security Operations Centre (SOC), contributing to the organisation's overall cybersecurity posture by actively participating in the monitoring, analysis, and response to security incidents and events. With a focus on continuous learning and collaboration, the R1 Analyst supports the SOC team in identifying, assessing, and mitigating potential security threats and vulnerabilities. Through the application of foundational technical skills and a strong dedication to detail-oriented analysis, the R1 Analyst assists in safeguarding the organisation's critical systems, data, and assets from cyber risks. By working closely with senior analysts and leveraging emerging technologies, the R1 Analyst helps maintain a vigilant and proactive defense against evolving cyber threats, enabling the organisation to operate securely and with confidence.

Key Accountabilities

  • Monitor health and security alerts and events from various sources including security information and event management (SIEM) systems, intrusion detection/prevention systems (IDS/IPS), and other monitoring tools.
  • Conduct initial triage of security incidents to assess their severity and potential impact on the organization.
  • Document and maintain incident details, including initial findings, actions taken, and any relevant evidence.
  • Communicate findings and recommendations clearly and concisely to technical and non-technical audiences.
  • Initiate escalation procedure to counteract potential threats, vulnerabilities and threat actors both internally and externally.
  • Collaborate with other SOC team members, IT staff, and relevant stakeholders to effectively respond to security incidents.
  • Provide customer service that exceeds our customers’ expectations at all times.
  • Contribute to the creation and maintenance of security documentation, including incident response playbooks, standard operating procedures, and knowledge base articles.
  • Document and conform to processes related to security monitoring procedures.
  • Compilation and review of service focused reporting.
  • Perform other duties as assigned.

Skills and Behaviors

Skills:*

  • Basic understanding of networking protocols, operating systems, and security technologies.
  • Familiarity with security tools such as SIEM, IDS/IPS, antivirus, and vulnerability scanning tools.
  • Ability to interpret and analyse security logs and events generated by various systems.
  • Flexibility to quickly learn and adapt to new security tools, technologies, and processes.
  • Strong analytical and problem-solving skills.
  • Good communication skills, both written and verbal.*

Benefits

  • Flexible Working: Balance your work and personal life with our flexible working options.
  • Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave.
  • Medicash & Critical Illness Scheme
  • Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme.
  • Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities.
  • Green Car Scheme: Drive green and save money with our eco-friendly car scheme.
  • *Cycle Schem*e: Stay fit and healthy with our cycle-to-work scheme.
  • Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet.
  • Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.

About NCC Group**

We assess, develop and manage cyber threats across our increasingly connected society. We advise global technology, manufacturers, financial institutions, critical national infrastructure providers, retailers and governments on the best way to keep businesses, software and personal data safe.

With our knowledge, experience and global footprint, we are best placed to help businesses identify, assess, mitigate & respond to the risks they face.

We are passionate about making the Internet safer and revolutionising the way in which organisations think about cyber security.

Headquartered in Manchester, UK, with over 35 offices across the world, NCC Group employs more than 2,000 people and is a trusted advisor to 15,000 clients worldwide.

We review every application received and will get in touch if your skills and experience match what we’re looking for. If you don’t hear back from us within 10 days, please don’t be too disappointed – we may keep your CV on our database for any future vacancies and we would encourage you to keep an eye on our career opportunities as there may be other suitable roles.

If you do not want us to retain your details, you can utilise the Manage Your Data tool provided by Pinpoint or contact us directly at: global.ta@nccgroup.com. All personal data is held in accordance with the NCC Group Privacy Notice.

We are committed to diversity and flexibility in the workplace. If you require any reasonable adjustments to support you during the application process, please tell us at any stage.

Please note that this role involves mandatory pre-employment background checks due to the nature of the work NCC Group does. To apply, you must be willing and able to undergo the vetting process.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Manchester

Why this fits a police background

  • Incident command & response
  • Security operations

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Incident Response Analyst

    AXA UK · Manchester

    Full-time

    Your incident command experience and evidence handling skills transfer directly to cyber incident response and digital forensics.

    Posted 7 days ago

  • Full-time

    Your risk assessment and compliance experience from policing transfers directly to governance and risk management.

    Posted 10 days ago

  • Cyber Incident Responder

    CYFOR · Manchester

    Full-time

    £40,000 – £50,000Estimated

    Your experience investigating digital evidence and managing incidents in policing gives you a strong foundation for this role, particularly in forensic acquisition, log analysis, and producing evidential reports. The requirement for clear client communication and structured investigation aligns with your interview and case-file skills, though you would need to build specific technical knowledge of cloud environments and EDR tools.

    Posted 16 days ago

  • Full-time

    Your experience managing operational risk and leading incident reviews translates directly into shaping security culture and resilience.

    Posted 2 days ago