Skip to main content
AfterDuty

SOC Analyst L1 (Analyst I - Information Security)

UST · Leeds, West Yorkshire

Type
Full-time
Posted
11 days ago

Overview

Your experience with digital evidence handling and investigative reporting maps directly onto SOC triage and incident documentation.

About this role

Role Description

Job Title: SOC Analyst L1

Mode of Hiring: Permanent

Working Model: Hybrid

Department: Cybersecurity / SOC

Reports to: SOC Team Lead

Job Summary

We are looking for a motivated SOC Analyst L1 to join our SOC. The role focuses on monitoring security s, performing initial triage, and escalating potential incidents to higher-level analysts.

Key Responsibilities

  • Monitor security tools (SIEM, EDR, IDS/IPS) for s and suspicious activity
  • Perform initial triage and classification of security events
  • Escalate confirmed or high-risk incidents to SOC L2/L3
  • Follow incident response playbooks and procedures
  • Document incidents, actions taken, and findings
  • Assist in basic threat hunting and log analysis
  • Maintain awareness of common threats and attack techniques

Requirements

  • Basic knowledge of networking (TCP/IP, DNS, HTTP)
  • Understanding of cybersecurity fundamentals (malware, phishing, brute force, etc.)

Familiarity with SIEM and EDR tools (e.g., Splunk, Sentinel, Defender and CrowdStrike) is a plus

  • Strong analytical and problem-solving skills

Good written and verbal communication skills in english

  • Ability to work in shifts 24/7.

Nice to Have (is not a mandatory)

  • Certifications such as CompTIA Security+, Network+, or similar
  • Basic scripting knowledge (Python, PowerShell)
  • Internship or prior experience in IT or security

Skills

siem,incident response,log analysis,network security,

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Leeds

Why this fits a police background — match score 70/100

  • Incident command & response

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Full-time

    Your incident management and digital forensic investigation experience from policing transfers directly to cyber incident response.

    Posted 14 days ago

  • Lead Cyber Security Monitoring

    Driver and Vehicle Standards Agency (DVSA) · Leeds

    Full-time

    Your experience in digital forensics, evidence handling, and incident command from policing maps directly to this SOC lead role.

    Posted 16 days ago

  • Operational and Cyber Resilience Lead

    Financial Conduct Authority · Leeds

    Full-time

    Your incident command and contingency planning experience directly applies to assessing firms' operational resilience and cyber incident response.

    Posted 23 days ago

  • Full-time

    £47,389 – £56,535Estimated

    This role involves managing infrastructure, network security, and cyber security services, including firewalls, endpoint security, and SOC operations. Your policing experience in incident response, risk assessment, and secure handling of sensitive information directly applies to maintaining a resilient IT environment. While the position requires specific technical leadership in IT, your background in command, crisis management, and operational security gives you a strong foundation for overseeing security technologies and teams.

    Posted 24 days ago