LT Harper Recruitment Group
Incident Response / SOC Analyst

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Incident Response / SOC Analyst – Security Operations & Incident Response
Location: United Kingdom - Remote
Salary: £70-90,000
Experience: 5-8 years' experience in Cyber Security, with strong Security Operations and Incident Response expertise
About the Role
My client is seeking an experienced IR Analyst / SOC Analyst to join a complex enterprise security environment, with a strong focus on both Security Operations and Incident Response.
This is a highly hands-on operational role, requiring someone with demonstrable experience monitoring, investigating and responding to security threats and incidents across a large and complex environment. The successful candidate will operate at a senior level within the SOC, handling advanced security investigations, supporting and leading incident response activities, and providing technical guidance to other analysts. The role will suit an experienced security professional who combines strong SOC and incident response capabilities with the ability to communicate effectively with technical and non-technical stakeholders.
Key Responsibilities
- Perform advanced security monitoring, triage, investigation and response across a complex enterprise environment.
- Investigate and respond to security alerts, suspicious activity and confirmed cyber security incidents.
- Conduct detailed analysis across endpoint, network, identity, cloud and other relevant security telemetry.
- Take ownership of complex investigations from initial alert through to containment, remediation and recovery.
- Support and lead Incident Response activities for high-severity and complex security incidents.
- Perform advanced incident triage, investigation and scoping to establish root cause, attack vectors, affected systems and potential impact.
- Analyse endpoint, network, identity and cloud evidence during incident investigations.
- Support containment, eradication and recovery activities in collaboration with Incident Response, Cyber Defence and infrastructure teams.
- Provide technical escalation and guidance to Tier 1 and Tier 2 SOC analysts.
- Mentor and support junior and mid-level analysts, helping to develop their investigation and incident response capabilities.
- Contribute to the development and continual improvement of SOC and Incident Response playbooks, procedures and processes.
- Identify opportunities to improve security monitoring, detection, investigation and response capabilities.
- Work closely with Detection Engineering, Threat Intelligence, Incident Response, Cyber Defence and wider security teams.
- Conduct proactive threat hunting and investigations based on emerging threats, intelligence and suspicious activity.
- Support the development and tuning of SIEM, EDR/XDR detections and security monitoring use cases.
- Communicate technical findings, incident impact, risk and recommended actions clearly to technical and non-technical stakeholders.
- Participate in post-incident reviews and ensure lessons learned are incorporated into future SOC and Incident Response processes.
- Help improve the overall maturity, effectiveness and operational resilience of the security operations function.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Essential Experience & Skills
- 5-8 years' experience in Cyber Security, with substantial experience across Security Operations and Incident Response.
- Demonstrable experience working as a Senior SOC Analyst, Incident Responder or equivalent senior operational security role.
- Strong hands-on experience investigating and responding to complex cyber security incidents.
- Experience working within a large enterprise, complex SOC or similarly sophisticated security environment.
- Strong understanding of SOC operations, security monitoring, incident triage, investigation and response methodologies.
- Practical experience supporting or leading Incident Response investigations.
- Experience analysing security events across multiple sources of telemetry, including endpoint, network, identity and cloud environments.
- Experience with containment, eradication and recovery activities during security incidents.
- Experience mentoring or providing technical guidance to other SOC analysts.
- Experience developing and improving SOC and Incident Response processes, playbooks and procedures.
- Ability to collaborate effectively with Detection Engineering, Incident Response, Threat Intelligence and Cyber Defence teams.
- Strong analytical and problem-solving skills.
- Excellent written and verbal communication skills.
- Comfortable working with multiple stakeholders and operating effectively during high-pressure security incidents.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Desirable Experience
Experience across some or all of the following would be advantageous:
- Digital forensics and forensic investigation.
- Endpoint Detection & Response (EDR/XDR).
- SIEM and security analytics platforms.
- Threat hunting.
- Incident response automation and orchestration.
- Security monitoring and detection optimisation.
- MITRE ATT&CK framework.
- Experience contributing to major incident response investigations.
Personal Profile
The successful candidate will be:
- Highly technical and comfortable operating hands-on across both SOC and Incident Response activities.
- Calm, analytical and structured when working under pressure.
- Comfortable taking ownership of complex security investigations and incidents.
- A strong communicator who can engage effectively with technical and senior stakeholders.
- Collaborative, with a genuine interest in mentoring and developing other analysts.
- Proactive in identifying opportunities to improve security monitoring, detection and response capabilities.
- Able to work effectively across SOC, Incident Response, Cyber Defence, Detection Engineering and wider security teams.
- Curious and analytical, with a strong interest in understanding attacker behaviour, emerging threats and improving defensive capabilities.
Key Requirement
This is a primarily hands-on Senior SOC Analyst role with significant Incident Response responsibilities. Candidates should be able to demonstrate recent, practical experience across security monitoring, advanced investigation, incident triage and response.
The successful candidate should be comfortable operating within a SOC environment while also taking a hands-on role in the investigation and management of significant cyber security incidents. Candidates with a purely managerial, governance or compliance-focused background are unlikely to be suitable for the role.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location