Skip to main content
AfterDuty

Microsoft Security Operations Centre (SOC) Analyst – T2 & T3

Avanade · London, Greater London

Type
Full-time
Posted
16 days ago

Overview

Your experience with incident response and analytical judgement from policing transfers to cyber investigations.

About this role

(Security Clearance Required)

Preferred Location - Newcastle

Job Description

The SOC Analyst Team operates as a next‑generation, intelligence‑led Security Operations function, designed to deliver high‑quality, scalable 24×7 security monitoring and response.

All SOC analysts participate in a 24×7 shift model, ensuring uninterrupted service coverage, while also contributing to detection improvement, automation feedback, and service optimisation when operational demand allows.

Tier 2 – SOC Analyst

Technology Primary – Microsoft Sentinel & Service Now.

Role Purpose

Tier 2 SOC Analysts represent the primary human analysis function, responsible for investigating escalated alerts and incidents that require human judgement, contextual understanding, and analytical depth.

Key Responsibilities

  • Perform deep investigation of escalated alerts and incidents from automated Tier 1 workflows
  • Validate threats, scope impact, and determine severity using contextual analysis
  • Investigate across multiple data sources, including:
  • SIEM
  • EDR / XDR
  • Identity and authentication telemetry
  • Cloud and SaaS platforms
  • Coordinate and execute response actions in line with:
  • Defined playbooks
  • Client‑specific requirements
  • Incident response procedures
  • Maintain clear, high‑quality investigation documentation and handover notes

Operational Expectations

  • Operate as part of a 24×7 shift rota
  • Maintain accountability for investigation accuracy and quality
  • Escalate complex or ambiguous cases to Tier 3 appropriately
  • Provide structured feedback into:
  • Detection tuning
  • Alert quality improvements
  • Automation optimisation

Continuous Improvement Contributions

When Operational Demand Allows, Tier 2 Analysts Are Expected To Contribute Insight Time To Platform Improvement Activities, Supporting The Platform Automation Lead Through

  • Identification of repeatable investigation patterns
  • Feedback on automation opportunities
  • Playbook refinement and improvement
  • Detection logic tuning recommendations

Qualifications

Tier 3 – Senior SOC Analyst / Incident Specialist

Role Purpose

Tier 3 analysts provide advanced security expertise and escalation handling, focusing on complex, high‑risk, or ambiguous security incidents and ensuring consistent investigation quality across the SOC.

Key Responsibilities

  • Handle escalations involving:
  • High‑impact or business‑critical incidents
  • Advanced or evasive attacker techniques
  • Ambiguous or novel threat behaviour
  • Conduct advanced threat analysis, including:
  • Attacker behaviour and intent assessment
  • Cross‑incident correlation
  • Campaign and intrusion analysis
  • Provide oversight and quality assurance of Tier 2 investigations
  • Lead complex incident response coordination where required

Leadership & Mentorship

  • Participate in 24×7 escalation coverage, via on‑call or senior shift roles
  • Act as a technical mentor to Tier 2 analysts
  • Support analyst development through coaching and investigative guidance
  • Set investigation and response quality standards across the SOC

Platform & Automation Feedback

Like Tier 2, Tier 3 Analysts Are Expected To Provide Structured Feedback Into Platform And Automation Initiatives, Working Indirectly With The Platform Automation Lead To

  • Improve detection fidelity
  • Reduce repeat incident patterns
  • Increase automation coverage over time
  • Ensure complex incidents inform long‑term service improvement

About security roles for ex-police

Security management, operations and consultancy roles. Years of operational policing — command, incident response, public order — translate directly into corporate security, and employers in this sector actively rate police experience.

See all security jobs in London

Why this fits a police background

  • Police experience explicitly valued
  • Incident command & response
  • Investigative casework
  • Security operations
  • Training & coaching delivery

What security roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Security officer (SIA)£24,000–£29,000
Security supervisor / team leader£28,000–£34,000
Site / security manager£38,000–£52,000
Regional / operations security manager£50,000–£65,000
Full security salary guide →

More security jobs for ex-police

  • Full-time

    £45,000 – £50,000Estimated

    Your incident command, team leadership and risk-assessment experience from policing directly transfer to corporate security management.

    Posted Yesterday

  • Full-time

    Your patrol, alarm response and incident command experience from policing transfer directly to securing a high-end residential site.

    Posted Yesterday

  • Security Manager

    MadiganGill · London

    Full-time

    Your experience managing incident response, access control and team supervision on high-pressure sites is directly transferable.

    Posted 2 days ago

  • Security Officer

    ISS Facility Services · London

    Full-time

    Your operational security, incident response and public-facing vigilance from policing transfer directly to this guarding role.

    Posted 2 days ago