Skip to main content
AfterDuty

SOC Level 2 Security Analyst

NTT DATA · Birmingham, West Midlands

Type
Full-time
Posted
Yesterday

Overview

Your incident command and analytical decision-making under pressure translate directly to SOC incident response.

About this role

You will investigate security alerts and events escalated from Level 1 analysts, validating and classifying activity to determine whether it represents a confirmed security incident. This includes performing detailed analysis to understand root cause, scope, impact, and attacker behaviour using SIEM platforms and supporting telemetry.

You will coordinate and support incident response activities in line with defined SOC and customer processes, assisting with containment, eradication, and recovery actions. During high‑severity or customer‑impacting incidents, you will follow major incident procedures and ensure timely, accurate escalation to stakeholders. You will provide technical guidance to L1 analysts during live incidents and help maintain investigation quality under pressure.

You will execute defined SOAR playbooks as part of incident response and provide structured feedback to improve automation, response consistency, and efficiency. You will maintain awareness of SOC performance metrics and service levels, such as MTTD and MTTR, and actively contribute to improving investigation quality and response outcomes.

You will apply threat intelligence to investigations and alert triage, maintaining awareness of emerging threats, vulnerabilities, and attacker techniques. Incident learnings and threat insights will be fed back into detection logic to continuously enhance SOC monitoring capabilities.

You will also contribute to the development and tuning of SOC detection use cases, ensuring alerting remains relevant, effective, and aligned to current threat activity. This includes supporting onboarding of new services, identifying detection gaps, and recommending improvements to tooling, processes, and coverage.

Clear and accurate documentation is a key part of the role. You will maintain investigation records, runbooks, and playbooks, produce post‑incident reports for customers and internal stakeholders, and contribute to operational and service reporting. You will help document and implement improvements to event and incident management processes.

Collaboration is essential. You will work closely with IT, security, and technical teams to resolve incidents and reduce risk, act as a mentor and escalation point for L1 analysts, and support continual service improvement by identifying recurring issues and proposing corrective actions.

You will have hands‑on experience working with SIEM platforms such as Splunk, Microsoft Sentinel, or QRadar, and a strong understanding of incident response workflows and escalation management. You will be comfortable analysing security telemetry, understanding attacker behaviour, and applying log‑ and artefact‑based investigation techniques.

You will demonstrate strong analytical thinking, sound decision‑making, and the ability to remain effective during high‑pressure incidents. Clear, professional communication—both written and verbal—is essential, as is the ability to work independently while following and improving structured operational processes.

  • 2–4 years’ experience in the IT security industry, ideally within a SOC or NOC environment, including experience operating at SOC L1 level
  • Relevant cybersecurity certifications desirable (e.g. GIAC, CySA+, SC‑200)
  • Experience working with cloud platforms such as Microsoft Azure and/or AWS
  • Proficiency with Microsoft Office tools, particularly Excel and Word

Security & Working Requirements

  • Eligibility for, or holding, UK SC Clearance
  • Willingness to work within a 24/7 shift‑based SOC environment, including on‑call duties.

UK Sovereign SOC

Security Analyst (Level 2)

Role Description

The SOC Analyst (L2) plays a critical role in the detection, investigation, and management of security alerts and incidents escalated from SOC Analyst (L1) teams. The position focuses on in‑depth analysis, incident validation, tactical response coordination, and continuous improvement of security monitoring and response capabilities.

Operating within a 24/7 Security Operations Centre, the L2 Analyst serves as a technical escalation point for junior analysts, working closely with internal IT and security teams as well as customers to contain and remediate security incidents. The role contributes directly to improving detection quality, response efficiency, and the overall effectiveness of SOC operations.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Birmingham

Why this fits a police background

  • Intelligence & OSINT
  • Incident command & response
  • Investigative casework
  • Security operations
  • Team & shift leadership

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Senior Infrastructure Operations Engineer

    National Crime Agency · Birmingham

    Full-time

    £57,687 – £70,623Estimated

    Your experience managing sensitive operational IT and digital forensics systems directly supports this role's mission.

    Posted 10 days ago

  • Cyber Security Manager

    The Lanes Group · Birmingham

    Full-time

    Your incident command, threat assessment and digital forensics handling map directly to cyber resilience work.

    Posted 13 days ago

  • Senior Manager - National Cyber Crime Unit Strategy

    National Crime Agency · Birmingham

    Full-time

    £4,379 – £70,179Estimated

    Your strategic command and multi-agency coordination experience from policing directly prepares you for this national cybercrime strategy role.

    Posted 17 days ago

  • Lead Cyber Security Monitoring

    Department for Transport · Birmingham

    Full-time

    Your incident response command, digital forensics experience and evidence discipline transfer directly to cyber security incident management.

    Posted 17 days ago