
L1 SOC Engineer
Charterhouse
- Peterborough
- Permanent
- Full-time
- Monitor SIEM, EDR, and SOAR platforms for security alerts, ensuring timely detection and escalation.
- Conduct initial triage of security events and incidents, escalating to L2/L3 teams when required.
- Assist with running vulnerability scans and interpreting results.
- Support incident response activities and document investigation findings.
- Perform packet-capture analysis and support network traffic investigations.
- Use threat intelligence sources to aid in investigations.
- Maintain accurate shift logs and participate in daily SOC briefings.
- Be part of an on-call rotation for after-hours support, when required.
- Contribute to SOC knowledge base and process improvements.
- Triaging and escalating security alerts within agreed SLAs
- Maintaining high accuracy in incident documentation and reporting
- Contributing to effective knowledge-sharing with SOC colleagues
- Supporting continuous improvement of SOC processes and playbooks
- Exposure to real-world security incidents and threat actors
- Hands-on experience with leading security technologies and tools
- Opportunity to gain further certifications and professional development
- Career progression to L2 SOC Analyst, or Security Engineer roles
- Working in a hybrid environment with flexibility and collaboration
- Microsoft Security configuration knowledge – Defender for Endpoint/Email/Sentinel
- SIEM tool operations – Detection and response to security events (Rapid7, QRadar, LogRhythm, or similar)
- EDR operations – Detection and response using SentinelOne, Microsoft Defender for Endpoint, or similar
- Knowledge of vulnerability scanning tools (Rapid7 iVM, Qualys, or similar)
- Understanding of SOAR platforms
- Experience with packet-capture tools and analysis of packet flows
- Familiarity with Behaviour Analytics platforms
- Exposure to using Threat Intelligence in investigations
- Strong understanding of network technologies and how cybersecurity risks affect them
- Relevant certifications such as CompTIA Security+, Network+, CySA+, or equivalent
- Triaging and escalating security alerts within agreed SLAs
- Maintaining high accuracy in incident documentation and reporting
- Contributing to effective knowledge-sharing with SOC colleagues
- Supporting continuous improvement of SOC processes and playbooks
- Exposure to real-world security incidents and threat actors
- Hands-on experience with leading security technologies and tools
- Opportunity to gain further certifications and professional development
- Career progression to L2 SOC Analyst, or Security Engineer roles
- Working in a hybrid environment with flexibility and collaboration
We are sorry but this recruiter does not accept applications from abroad.