Anson McCade
L3 SOC Analyst

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Role overview
Must-haves: Microsoft SC-200 certification and eligibility for SC clearance.
You'll be the senior escalation point in a Belfast Cyber Security Operations Centre (CSOC). You'll take incidents escalated from Tier 1 and Tier 2 analysts, assess their business impact, and recommend the response and escalation path.
You'll triage threat intelligence (IOCs and TTPs) from multiple sources, run threat hunts across the SIEM, and help organisations identify, isolate and contain security issues. You'll also guide and mentor two analysts, without direct line management, and support the rollout and management of IBM QRadar, Microsoft Sentinel, Defender for Endpoint, Defender for Identity and Defender for Cloud.
Key responsibilities
- Handle security incidents escalated by L1 and L2 analysts, carry out business impact analysis and recommend response actions and escalation paths
- Perform advanced event and incident analysis, including baselining and trend analysis
- Conduct intelligence-led threat hunting using IOCs and TTPs, investigating suspicious activity through the SIEM
- Support Major Incident Response from a protective monitoring perspective, helping teams identify, contain and remediate threats
- Give timely advice on response plans based on incident type and severity
- Oversee daily SOC checklists: log review, management reporting, alert analysis and escalation follow-up
- Provide oversight, guidance and mentoring to L2 and L3 analysts, and cover SOC Manager duties when they are absent
- Oversee a virtual team of L1 and L2 analysts, including objectives, performance reviews, training and shift cover
- Identify SIEM improvements: use case development, rule creation, tuning and optimisation
- Help design the onboarding of new systems, including assessing, parsing and onboarding log sources
- Improve SOC procedures and processes, with SOC Manager approval
- Produce stakeholder and client reporting and manage client engagement
- Join the on-call rota to support L1 analysts working out of hours
- Stay current on cyber security trends and threat intelligence to guide the team's detection capability
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Essential requirements
- Microsoft SC-200 certification (mandatory)
- Eligible for SC clearance (mandatory)
- Proven experience at Level 3 SOC Analyst or senior security operations level
- Strong hands-on experience with Microsoft Sentinel, Microsoft Defender for Endpoint (MDE) and KQL
- Experience onboarding, configuring, tuning and reporting on SIEM solutions
- Threat intelligence experience
- Leadership and mentoring experience
- Commercial experience in security monitoring and/or penetration testing
- Solid understanding of operating systems, networking and infrastructure design
- System administration knowledge across one or more of Windows, Linux or Mac
- Ability to explain technical issues clearly to non-technical stakeholders at all levels
- Strong written and verbal communication, and a self-motivated, flexible approach
- Degree in Computing or a related subject; a Cyber Security master's with relevant experience is also considered


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Desirable
- In-depth Microsoft Sentinel expertise: use case and rule development, workbooks and playbooks, KQL, Logic Apps and SOAR
- Managing Sentinel as an MSSP, including Azure Lighthouse and multi-customer environments using DevOps
- Wider Microsoft security experience across Defender for Endpoint, Identity and Cloud
- Other SIEM platforms, such as IBM QRadar and LogRhythm
- Certifications such as Network+, Security+, CySA+, CISMP or CISSP
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London