
SOC Analyst Level 1 Skelmersdale, England
Job description
SOC Analyst Level 1
The National Management Centre (NMC) will provide visibility and control of information risks for Policing. It will support the 24x7x365 nature of the police operations, providing a threat detection and response capability for digital services before, during and after cyber-attacks, enabling stakeholders to understand and proactively manage risk across the technology estate at both the national and force level
- Security incidents carry financial cost and can impact our brand and reputation. Proactively preventing, detecting, and responding to incidents allows NMC to reduce risk for PDS.
- Any large organisation needs a centralised facility responsible for every aspect of Security, hardening the business posture from attack.
- This role places real value in finding and adapting ways to protect and support PDS.
- Identification of critical services within forces where loss would negatively impact police operations.
- Awareness of the cyber risks to critical services by continually assessing the threat landscape and informing stakeholders.
- Detecting when, where and how attacks take place.
- Reporting cyber risks to service, executive and operational stakeholders for mitigation decisions.
- Limiting the impact of known cyber risks by engaging forces in pre-incident planning and preparatory activities.
- As a member of the NMC Protective Monitoring team you will respond to immediate security threats on NMC Monitored networks.
- Responsible for working as part of a wider 24x7 Security Operation Center (SOC) environment
- The NMC Protective Monitoring team’s goal is to detect, analyse, investigate and respond to cybersecurity alerts using a combination of cutting-edge technology and a strong set of processes.
- The NMC Protective Monitoring staff work within the NMC, typically with incident response teams to ensure security issues are addressed quickly upon discovery.
- Monitor, analyse and defend against malicious or unusual activity that could be indicative of a security incident or compromise.
- Initial Triage of alerts – evaluation & detection
- Confirmation of false positive
- Incident data gathering and feedback on any gaps and issues in respect to SIEM Platform Content or tuning opportunities
- Reflect incident severity based on analysis
- Escalate potential incidents to customer or L2/CIMT Team as appropriate
- Regular Performance conversation with BT people manager
- Utilising the My Performance approach and coaching conversations to challenge and develop yourself and others.
- Knowledge of various security methodologies and processes
- Knowledgeable in business strategy and the drivers of organisational performance.
- Knowledge of commonly deployed Cyber Security tools and products
- Knowledge of common Internet protocols and applications
- Knowledge and hands on experience of IP networks and their key components
- Proficient in the use of SIEM technology, in terms of handling alerts, analysis of the data within the alert and rationale on whether escalation or closure is required.
- A genuine enthusiasm and drive to work within Cyber Security
- Motivated and ambitious to work on your own initiative without needing direction
- Strong attention to detail
- Ability to multi-task, prioritise, and manage time effectively
What's in it for you - the benefits
- Discounted BT Broadband, TV & mobile packages and BT products
- On target Bonus
- BT 10% pension contribution
- Professional development and paid for industry certifications/qualifications
- Flexible benefits/rewards including dental insurance, healthcare, gym memberships etc.
- Well-being support for you and your family
- 3 days paid volunteering a year
