À propos de ce poste SIOC Analyst chez UBDS Group
At UBDS, we help organisations transform through cloud, cyber security, AI and digital innovation. As our Managed Services capability grows, we're looking for a SIOC Analyst to join our Security and Infrastructure Operations Centre, helping protect and support critical customer environments.
This is a hands-on cyber security role focused on security monitoring, threat detection, incident investigation and response. You'll work across complex cloud and enterprise environments, investigating security events, responding to incidents and supporting Digital Forensics and Incident Response (DFIR) activities.
Our technology landscape is primarily Microsoft and AWS, alongside SIEM and wider security tooling.
Location: Manchester (Office-based)
Working Pattern: Monday to Friday | Rotating shifts between 08:00–20:00 | On-call rota
What You'll Do
You'll:
- Monitor and investigate security alerts, events and suspicious activity across customer environments.
- Triage security alerts and determine severity, impact and appropriate response actions.
- Investigate potential security incidents across endpoints, identities, cloud environments, networks and applications.
- Use SIEM and security tooling to analyse logs, correlate events and identify suspicious behaviour.
- Support incident response activities from initial detection and investigation through to containment, remediation and recovery.
- Perform initial DFIR activities, including evidence collection, log analysis, timeline analysis and investigation of compromised systems or accounts.
- Investigate phishing, malware, suspicious authentication activity, account compromise and other common security threats.
- Support security monitoring and investigation across Microsoft and AWS cloud environments.
- Analyse indicators of compromise and support threat hunting activities.
- Escalate complex or high-severity incidents to senior security specialists and incident response teams.
- Support vulnerability, security and threat management activities where required.
- Document investigations, findings, actions and recommendations clearly.
- Contribute to incident reports and post-incident reviews.
- Help develop and improve security monitoring use cases, detection rules and operational playbooks.
- Identify recurring threats and opportunities to improve detection and response capabilities.
- Work closely with customers, cloud engineers, infrastructure teams and other security specialists during investigations.
- Contribute to continual improvement across the SIOC and wider Managed Services capability.
Skills & Experience
This is not an exhaustive list of requirements. We're looking for someone with experience across several of these areas and an appetite to continue developing their cyber security and incident response capability.
- Experience working within a SOC, SIOC, Cyber Security Operations or similar operational security environment.
- Experience monitoring, triaging and investigating security alerts and incidents.
- Hands-on experience using SIEM or security monitoring platforms.
- Experience investigating security events using logs and telemetry from multiple sources.
- Good understanding of common cyber threats, attack techniques and indicators of compromise.
- Understanding of incident response processes, including identification, containment, remediation and recovery.
- Experience or knowledge of Microsoft security technologies and environments.
- Understanding of Microsoft identity and endpoint security, including Entra ID and Microsoft Defender technologies.
- Experience or understanding of security monitoring within AWS environments.
- Some practical knowledge of DFIR principles and investigation techniques.
- Understanding of endpoint, identity, network and cloud security concepts.
- Ability to analyse technical information and build a clear picture of what has happened during an incident.
- Strong analytical and problem-solving skills with a methodical approach to investigations.
- Ability to prioritise multiple alerts and incidents within a fast-paced operational environment.
- Strong written and verbal communication skills, including the ability to clearly document and communicate security incidents.
DFIR Capability
We're particularly interested in candidates who have some exposure to Digital Forensics and Incident Response or who want to develop further in this area.
Useful experience could include:
- Security incident investigation and evidence gathering.
- Endpoint and host-based investigation.
- Log and event analysis.
- Timeline development and analysis.
- Malware or suspicious file investigation.
- Identity and account compromise investigations.
- Email and phishing investigations.
- Analysis of indicators of compromise.
- Basic forensic acquisition and preservation principles.
- Using EDR, SIEM and cloud telemetry to reconstruct security incidents.
We are not necessarily looking for a dedicated forensic specialist, but you should be comfortable supporting investigations beyond initial alert triage.
Technology Exposure
Experience across some of the following would be beneficial:
- Microsoft Sentinel or comparable SIEM platforms.
- Microsoft Defender XDR.
- Microsoft Defender for Endpoint.
- Microsoft Defender for Cloud.
- Microsoft Entra ID.
- Microsoft 365 security tooling.
- AWS security and logging services.
- Endpoint Detection and Response tooling.
- Vulnerability management platforms.
- Threat intelligence platforms and feeds.
- SOAR and security automation tooling.
- PowerShell, Python or other scripting languages for investigation and automation.
Desirable Qualifications
Relevant certifications are beneficial but not essential, including:
- Microsoft Security Operations Analyst Associate (SC-200).
- Microsoft security or Azure certifications.
- AWS security or cloud certifications.
- CompTIA Security+, CySA+ or equivalent.
- GIAC, SANS or other incident response/forensics training.
- CREST or equivalent cyber security qualifications.
The Opportunity
This role would suit a security analyst who enjoys understanding how incidents happened, not simply closing alerts.
You'll gain exposure to a broad range of customer environments and security technologies, with opportunities to develop deeper skills across security operations, threat detection, incident response and DFIR while working alongside experienced cyber, cloud and infrastructure specialists.
Benefits
Why people choose to grow their careers at UBDS Group
Professionals choose to grow their careers at UBDS Group for its reputation as a dynamic and forward-thinking organisation that is deeply committed to both innovation and employee development. At UBDS Group, employees are given unique opportunities to work on cutting-edge projects across a diverse range of industries, exposing them to new challenges and learning opportunities that are pivotal for professional growth. The Group’s culture emphasises continuous improvement, offering ample training programs, mentorship, and the chance to gain certifications that enhance their skills and marketability.
UBDS Group fosters a collaborative environment where creativity and innovation are encouraged, allowing employees to contribute ideas and solutions that have a tangible impact on the company and its clients. This combination of professional development, a culture of innovation, and the opportunity to make meaningful contributions makes UBDS Group an attractive place for those looking to advance their careers and be at the forefront of technological and operational excellence.
Employee Benefits
- Training – All team members are offered a number of options in terms of personal development, whether it is technical led, business acumen or methodologies. We want you to grow with us and to help us achieve more
- Private medical cover for you and your spouse/partner, offered via Vitality
- Discretionary bonus based on a blend of personal and company performance
- Holiday – You will receive 25 Days holiday, plus 1 day for Birthday and 1 day for your work anniversary in addition to UK bank holidays
- Electric Vehicle leasing with salary sacrifice
- Contributed Pension Scheme
- Death in service cover
About UBDS Group
At UBDS Group our mission is to support entrepreneurs who are setting new standards with technology solutions across cloud services, cybersecurity, data and AI, ensuring that every investment advances our commitment to innovation, making a difference, and creating impactful solutions for organisations and society.
Equal Opportunities
We are an equal opportunities employer and do not discriminate on the grounds of gender, sexual orientation, marital or civil partner status, pregnancy or maternity, gender reassignment, race, colour, nationality, ethnic or national origin, religion or belief, disability or age.