NTT DATA
SOC Analyst Level 1
Job Description
Salary: £55,000 - 95,000 per year
Requirements:- Foundational understanding of cybersecurity concepts, including TCP/IP networking, common log sources, and basic attack techniques
- Experience using a SIEM platform such as Splunk, Microsoft Sentinel, or an equivalent tool
- Basic knowledge of Windows, Linux, and macOS
- Strong analytical and problem-solving skills, with the ability to assess alerts, follow investigative processes, and make sound decisions within defined procedures
- Clear written and verbal communication skills for accurate ticketing, escalation, and shift handover
- Ability to work calmly and effectively in a shift-based operational environment, manage workload, and maintain focus during high alert volumes
- Ability to follow procedures, work with minimal supervision, and learn from feedback and operational experience
- Experience or strong interest in cybersecurity or IT operations
- Entry-level or foundation cybersecurity certifications such as CySA+ or SC-200 are desirable
- Experience with Microsoft Azure and/or AWS is desirable
- Proficiency with Microsoft Office tools, particularly Excel and Word
- Eligibility for, or possession of, UK SC Clearance
- Willingness to work in a 24/7 shift-based SOC environment
- Awareness of scripting, query languages, or rule-based detection is advantageous but not required
- Continuously monitor security alerts, logs, and event data across customer and internal environments to identify suspicious or malicious activity
- Triage and analyse alerts, determine whether they indicate potential security or service incidents, and prioritise them according to security incident management policies
- Conduct first-line investigations using SIEM, SOAR, and supporting security tools; validate alerts, gather evidence, and assess initial impact and severity
- Recognise successful or unsuccessful attack attempts and escalate identified indicators of compromise or attack activity to senior analysts or incident responders with clear context
- Support incident containment and remediation by following runbooks and customer guidance, and document actions consistently
- Create and maintain incident tickets, record investigation steps and findings, and produce incident summaries and investigation notes using internal knowledge bases and research
- Contribute findings to post-incident reviews and identify opportunities to improve detection, response, and operational processes
- Apply SOC-provided threat intelligence to alert analysis and investigations
- Follow SOC procedures, documentation standards, and shift-handover processes
- Participate in the 24/7 shift rota and collaborate with other analysts to maintain monitoring coverage
- AI
- AWS
- Azure
- Excel
- Incident Management
- Support
- Linux
- macOS
- Security
- Splunk
- TCP/IP
- Windows
- Cloud
- Network
More:
We are hiring a Level 1 Security Analyst for our UK Sovereign SOC, a frontline, shift-based role in a 24/7 Security Operations Centre. At NTT DATA, we are a global business and technology services, AI, and digital infrastructure leader serving 75% of the Fortune Global 100, with experts in more than 70 countries. We offer tailored benefits supporting physical, emotional, and financial wellbeing, ongoing learning and development, and flexible work options. We are an equal opportunities employer and a Disability Confident Committed Employer, committed to equity, diversity, inclusion, and removing barriers to employment.
last updated 40 week of 2026
Interested in this role?
Submit your application now
How to Apply
About NTT DATA
NTT DATA
Birmingham
IT
Skills & Technologies
Inferred from job description
Salary Insight
£75,000
This role
£45,000
UK median
This salary is 67% above the UK median for Analysts (£45,000/yr).
Based on 2024–2025 UK technology sector benchmarks