You can’t protect what you can’t see, which is why at Zensec, risk identification is fundamental to cyber strategy. We believe that the best approach to cyber risk management is to take action before an attack takes place – that’s why we’ve developed our own platforms to simplify data and give our clients greater visibility over their digital estate. By encompassing the people, systems and processes required to maintain a robust security posture, we act as an extension of our clients’ teams to mitigate cyber risks. Founded by cyber defence experts as an integral function within the successful Zenzero organisation, Zensec is a leader in cyber incident response and security managed services, with a range of customers in both private and public sectors.
We're on a mission to make technology genuinely work for mid-market businesses, covering managed IT, cyber security, cloud, and AI solutions that actually move the needle. The demand is growing, and so are we.
About the Role
A 24/7 Security Operations Centre (SOC) Analyst is a cybersecurity professional responsible for monitoring and defending organisations against potential security threats. They play a critical role in identifying, analysing, and responding to security incidents to ensure the confidentiality, integrity, and availability of sensitive data and systems. 24/7 SOC Analysts work closely with other cybersecurity team members to maintain a strong security posture and prevent or mitigate potential cyber-attacks.
Education: Bachelor's degree in Computer Science, Cybersecurity, or related technical field, or equivalent experience
Experience: This is an entry level SOC role however having experience in cybersecurity, network security, or information security and MSP experience is preferential.
Certifications: One or more of the following certifications preferred: CompTIA Security+, SANS GIAC certifications, Certified Information Systems Security Professional (CISSP), Certified SOC Analyst (CSA)
Skills:
- Strong understanding of network protocols and security concepts
- Knowledge of threat detection and incident response methodologies
- Familiarity with common attack vectors and mitigation techniques
- Understanding of Windows operating systems
- Experience with endpoint protection platforms
- Good documentation and communication skills
- Ability to work in a fast-paced environment and handle multiple priorities
- Problem-solving skills and analytical thinking
- Experience with cloud security (AWS, Azure, GCP) is a plus
- Knowledge of scripting languages (Python, PowerShell) for automation
- Monitor and analyse security alerts from various security tools and technologies
- Perform initial triage and investigation of security incidents
- Document and track security incidents through to resolution
- Perform threat hunting activities to proactively identify potential security threats
- Maintain and tune security monitoring tools to reduce false positives
- Develop and maintain security playbooks and response procedures
- Provide regular reporting on security incidents and trends
- Collaborate with other IT teams to remediate security issues
- Stay current with emerging threats and attack techniques
- Participate in on-call rotation for after-hours incident response
Operational Effectiveness
Alert Response Time: Average time to acknowledge and begin analysis of security alerts (Target: <10 minutes for critical, <20 minutes for high priority)
Incident Resolution Time: Average time to resolve or escalate security incidents (Target: <90 minutes for critical, <4 hours for high priority)
False Positive Rate: Percentage reduction in false positives through tuning (Target: 10% reduction quarter-over-quarter)
Detection Coverage: Percentage of client environments with comprehensive security monitoring (Target: >95%)
SEIM Rule Effectiveness: Percentage of alerts that lead to true positive detections (Target: >40%) Technical Excellence
SEIM Content Development: Number of new detection rules or use cases developed per quarter (Target: ≥3)
Playbook Development: Number of new or updated incident response playbooks (Target: ≥2 per quarter)
Tool Optimisation: Measurable improvements in security tool performance (Target: Quarterly optimization of at least one key system)
Technical Documentation: Quality and completeness of technical documentation (Target: >95% compliance with documentation standards)
Incident Management
Incident Handling Accuracy: Percentage of incidents correctly categorized and managed (Target: >95%)
Root Cause Analysis: Percentage of significant incidents with completed RCA (Target: 100%)
Mean Time to Detect (MTTD): Average time to detect security incidents (Target: Continuous improvement trend)
Mean Time to Respond (MTTR): Average time to initiate response to security incidents (Target: Continuous improvement trend)
Threat Intelligence and Hunting
Proactive Threat Detection: Number of threats identified through proactive hunting (Target: ≥2 per month)
Threat Intelligence Implementation: Number of threat intelligence feeds incorporated into security monitoring (Target: Review and update quarterly)
Zero-Day Vulnerability Coverage: Response time to implement detections for new critical vulnerabilities (Target: <24 hours for critical vulnerabilities)
Team Contribution
On-Call Responsiveness: Response time and effectiveness during on-call rotations (Target: <15 minutes response, positive feedback)
Knowledge Transfer: Regular contributions to team knowledge base and documentation (Target: ≥2 significant contributions per month)
Cross-Team Collaboration: Effective collaboration with other IT teams on security remediation (Target: Positive feedback from team leaders)
Client Satisfaction: Feedback on security incident handling and communication (Target: >90% positive ratings)
Professional Development
Certification Progress: Advancement toward required security certifications (Target: One new certification or significant progress annually)
Continuous Learning: Completion of assigned training and self-directed learning (Target: ≥20 hours per quarter)
Industry Awareness: Demonstrated knowledge of emerging threats and technologies (Target: Regular sharing of relevant threat intelligence)