Your career compass awaits
Create a free account to unlock
- ✓ See how you match this role
- ✓ AI resume tailored to this specific job
- ✓ Inside Track Companion — find your insider contact
- ✓ Skills gap analysis and upskill plan
- ✓ Interview prep kit for this role
- ✓ Relocation concierge — salary, tax, cost of living
Free — no credit card required
AstraZeneca
✓ Verified SponsorConfirm Application
Are you applying to ?
We'll track this in your dashboard as Applied.
SOC Analyst L1
ICT
Company shared salary
NA
Market rate
20,000 GBP–35,000 GBP/mo (240,000 GBP–420,000 GBP/yr)
Based on similar roles (title + domain + location).
About the Company
Are you ready to harness AI-driven security operations to outpace evolving threats and protect breakthroughs that change patients' lives This role places you at the center of our mission to secure the data, platforms and people that power discovery and delivery. You will help safeguard critical science and business operations through precision triage, rapid response and disciplined execution.
Responsibilities
- ● ls, embraces agentic workflows and values evidence-led decision making. Here, you will use Microsoft Sentinel, Microsoft Defender and Security Copilot to accelerate investigations while ensuring human judgment stays in control. Can you picture yourself validating AI analysis at speed, orchestrating response across global teams and turning insights into resilient defenses that scale
- ● Accountabilities:
- ● AI-Enabled Triage and Investigation: Validate AI-generated analysis, distinguish true positives from false positives and investigate alerts using Microsoft Sentinel, Microsoft Defender and SIEM platforms to drive timely, high-quality decisions.
- ● Incident Response Execution: Follow predefined runbooks/playbooks to handle standard alerts such as phishing, malware and login anomalies; escalate complex cases and initiate response actions aligned to zero-trust and privacy requirements.
- ● Security Copilot Governance: Manage human approval points for high-impact actions; critically evaluate Copilot-generated summaries, KQL queries and recommendations; craft structured prompts and reusable investigation instructions to improve accuracy and repeatability.
- ● Evidence and Forensics Support: Perform basic to intermediate malware analysis; analyze packet captures and network traffic; reconstruct timelines, scope incidents, identify affected entities and collect evidence to support root-cause analysis.
- ● SIEM Monitoring and Continuous Improvement: Monitor SIEM tools (e.g., Microsoft Sentinel, Splunk), ensure alerts are tracked and closed, maintain detailed activity logs and incident tickets, and contribute to refining detection logic and automation workflows.
- ● Shift Operations and Handover Excellence: Operate within a 24x7 SOC model, maintain meticulous shift handover notes and ensure seamless transitions so no alerts or incidents are missed.
- ● Stakeholder Communication: Communicate clearly with technical and business stakeholders, providing concise updates, actionable recommendations and post-incident insights that reduce risk and strengthen trust. Essential Skills/Experience:
- ● -7 years cybersecurity; strong cloud security, zero trust, and data privacy in regulated environments.
- ● Strong expertise in SIEM technologies (Microsoft Sentinel, Splunk, QRadar).
- ● Hands-on experience with Microsoft Defender XDR, CrowdStrike, Sentinel One, or similar EDR tools.
- ● Knowledge of Azure, AWS, and GCP security monitoring.
- ● Understanding of attack techniques, malware behaviour, and threat actor tactics.
- ● Ability to analyze packet captures and network traffic.
- ● Knowledge of SOAR platforms and automation workflows.
- ● Participate in shift-based 24x7 SOC operations.
- ● Practical experience using Microsoft Security Copilot to summarise incidents, correlate alerts, analyse entities, generate investigation hypotheses, create KQL queries, interpret threat intelligence and recommend response actions.
- ● Ability to critically evaluate Copilot-generated summaries, queries, recommendations, classifications and response actions.
- ● Ability to create structured prompts and reusable investigation instructions.
⚡ Full Resume Sandbox Canvas