About this role
(Security Clearance Required)
Preferred Location - Newcastle
Job Description
The SOC Analyst Team operates as a next‑generation, intelligence‑led Security Operations function, designed to deliver high‑quality, scalable 24×7 security monitoring and response.
All SOC analysts participate in a 24×7 shift model, ensuring uninterrupted service coverage, while also contributing to detection improvement, automation feedback, and service optimisation when operational demand allows.
Tier 2 – SOC Analyst
Technology Primary – Microsoft Sentinel & Service Now.
Role Purpose
Tier 2 SOC Analysts represent the primary human analysis function, responsible for investigating escalated alerts and incidents that require human judgement, contextual understanding, and analytical depth.
Key Responsibilities
- Perform deep investigation of escalated alerts and incidents from automated Tier 1 workflows
- Validate threats, scope impact, and determine severity using contextual analysis
- Investigate across multiple data sources, including:
- SIEM
- EDR / XDR
- Identity and authentication telemetry
- Cloud and SaaS platforms
- Coordinate and execute response actions in line with:
- Defined playbooks
- Client‑specific requirements
- Incident response procedures
- Maintain clear, high‑quality investigation documentation and handover notes
Operational Expectations
- Operate as part of a 24×7 shift rota
- Maintain accountability for investigation accuracy and quality
- Escalate complex or ambiguous cases to Tier 3 appropriately
- Provide structured feedback into:
- Detection tuning
- Alert quality improvements
- Automation optimisation
Continuous Improvement Contributions
When Operational Demand Allows, Tier 2 Analysts Are Expected To Contribute Insight Time To Platform Improvement Activities, Supporting The Platform Automation Lead Through
- Identification of repeatable investigation patterns
- Feedback on automation opportunities
- Playbook refinement and improvement
- Detection logic tuning recommendations
Qualifications
Tier 3 – Senior SOC Analyst / Incident Specialist
Role Purpose
Tier 3 analysts provide advanced security expertise and escalation handling, focusing on complex, high‑risk, or ambiguous security incidents and ensuring consistent investigation quality across the SOC.
Key Responsibilities
- Handle escalations involving:
- High‑impact or business‑critical incidents
- Advanced or evasive attacker techniques
- Ambiguous or novel threat behaviour
- Conduct advanced threat analysis, including:
- Attacker behaviour and intent assessment
- Cross‑incident correlation
- Campaign and intrusion analysis
- Provide oversight and quality assurance of Tier 2 investigations
- Lead complex incident response coordination where required
Leadership & Mentorship
- Participate in 24×7 escalation coverage, via on‑call or senior shift roles
- Act as a technical mentor to Tier 2 analysts
- Support analyst development through coaching and investigative guidance
- Set investigation and response quality standards across the SOC
Platform & Automation Feedback
Like Tier 2, Tier 3 Analysts Are Expected To Provide Structured Feedback Into Platform And Automation Initiatives, Working Indirectly With The Platform Automation Lead To
- Improve detection fidelity
- Reduce repeat incident patterns
- Increase automation coverage over time
- Ensure complex incidents inform long‑term service improvement
About security roles for ex-police
Security management, operations and consultancy roles. Years of operational policing — command, incident response, public order — translate directly into corporate security, and employers in this sector actively rate police experience.
See all security jobs in London →Why this fits a police background
- Police experience explicitly valued
- Incident command & response
- Investigative casework
- Security operations
- Training & coaching delivery
What security roles pay ex-police
Advertised UK ranges, editorial estimates reviewed July 2026
| Security officer (SIA) | £24,000–£29,000 |
| Security supervisor / team leader | £28,000–£34,000 |
| Site / security manager | £38,000–£52,000 |
| Regional / operations security manager | £50,000–£65,000 |