SOC Analyst
UK Government - Department for Business and Trade · London, ENG, GB
Apply directly on UK Government - Department for Business and Trade’s careers site — no account needed.
About the role
Details
Reference number
Salary
Your salary will be determined by your skills and capability as assessed at interview
Job grade
Contract type
Business area
Type of role
Knowledge and Information Management
Security
Working pattern
Number of jobs available
Contents
- Location
- About the job
- Benefits
- Things you need to know
- Apply and further information
Location
About the job
Job summary
The Department for Business and Trade (DBT) has a clear mission - to grow the economy. Our role is to help businesses invest, grow and export to create jobs and opportunities right across the country. We do this in three ways.
Firstly, we help to build a strong, competitive business environment, where consumers are protected and companies rewarded for treating their employees properly.
Secondly, we open international markets and ensure resilient supply chains. This can be through Free Trade Agreements, trade facilitation and multilateral agreements.
Finally, we work in partnership with businesses every day, providing advance, finance and deal-making support to those looking to start up, invest, export and grow.
The Digital, Data and Technology (DDaT) directorate develops and operates tools and services to support us in this mission. The team have been nominated four times in a row for Best Public Sector Employer at the Women in Tech awards and won the award in 2025!
Job description
We are looking for a capable and motivated SOC Analyst to join the Cyber Incident Detection and Response team and help strengthen our cyber defence capabilities.
In this role, you will play a key part in protecting the departments systems and data. You will monitor, triage and investigate security alerts, identifying genuine threats and ensuring incidents are accurately assessed, documented and escalated where appropriate. You will also support incident response activities, working closely with Senior Analysts and wider technical teams to deliver effective and coordinated responses.
Alongside operational responsibilities, you will have dedicated time to focus on proactive work. This includes contributing to the improvement of detection rules, refining alerts, supporting threat hunting, and helping to develop repeatable processes and playbooks.
At this level, we are looking for someone who is curious, collaborative and able to use sound judgement in a fast-paced environment. You will manage your workload effectively, communicate clearly with a range of stakeholders, and take ownership of your work while contributing positively to the team.
We are committed to your development, offering protected learning time, access to training platforms, and opportunities to attend external courses and industry events such as SANS.
Main responsibilities
You will:
- Triage, investigate, and resolve security alerts and incidents in line with established processes, ensuring a timely and effective response.
- Contribute to the development and refinement of incident response procedures, playbooks, and documentation.
- Support the continuous improvement of logging, monitoring, and alerting capabilities to enhance threat visibility.
- Provide support and advice to stakeholders and colleagues.
- Maintain awareness of emerging threats, vulnerabilities, and trends to support effective detection and response.
- Use time away from live operations to develop key SOC capabilities, including alert refinement, dashboard creation, and engagement across the wider Cyber team.
Person specification
It is essential that you have:
- Hands-on experience working in a professional Security Operations Centre (SOC), including direct involvement in responding to security alerts using a SIEM, conducting triage, and supporting incident investigations. (Lead Criteria)
- Demonstrable operational experience managing cyber security incidents from initial triage through to resolution. (Lead Criteria)
- Demonstrable experience investigating security events within cloud platforms (e.g. AWS, Azure).
- Demonstrable experience contributing to proactive security activities, such as threat hunting or developing detection rules.
- Experience analysing security data using a query language (e.g. KQL, SQL, SPL). Familiarity with KQL (Kusto Query Language) is particularly desirable.
- Effective verbal and written communication skills, including the ability to collate and present information clearly and accurately.
It is desirable that you have:
- Relevant or working towards cyber security certifications or qualifications.
Behaviours
We'll assess you against these behaviours during the selection process:
- Making Effective Decisions
- Working Together
Technical skills
We'll assess you against these technical skills during the selection process:
- Intrusion Detection and Analysis
- Threat Understanding
- Cyber Security Operations
- Threat intelligence and threat assessment
- Forensics
Benefits
- Learning and development tailored to your role
- An environment with flexible working options
- A culture encouraging inclusion and diversity
- A Civil Service pension with an employer contribution of 28.97%
Things you need to know
Artificial intelligence
Selection process details
As part of the application process you will be asked to upload a two-page CV and complete a 750 word personal statement outlining how you meet the essential skills and experience listed above. You can use bullet points and subheadings if you prefer.
Sift will be from week commencing 03.08.2026
Interviews will be from week commencing 24.08.2026
Please note these dates are indicative and may be subject to change.
If there is a high volume of applications, we will sift looking at the first two Lead Criteria only. Hands-on experience working in a professional Security Operations Centre (SOC), including direct involvement in responding to security alerts using a SIEM, conducting triage, and supporting incident investigations. (Lead Criteria) and Demonstrable operational experience managing cyber security incidents from initial triage through to resolution.
You may then be progressed to full sift or straight to interview.
At the interview stage for this role, you will be asked to demonstrate relevant Technical Skills and Behaviours from the Success Profiles framework, which are listed above. These are role specific and in line with the DDaT Capability Framework .
Offers will be made in merit order based on location preferences. If you pass the bar at interview but are not the highest scoring you will be held on a 12-month reserve list in case a role becomes available. If you are judged a near miss at interview, you may be offered a post at the grade below the one you applied for.
This role requires SC clearance. DBTs requirement for SC clearance is to have been present in the UK for at least 3 of the last 5 years. Failure to meet this requirement will result in your application being rejected and your offer will be withdrawn.
Checks will also be made against:
- departmental or company records (personnel files, staff reports, sick leave reports and security records)
- UK criminal records covering both spent and unspent criminal records
- your credit and financial history with a credit reference agency
- security services record
- location details
More about us
This role can only be worked from within the UK, not overseas. If you are based in London, you will receive London weighting. DBT employees are contracted to work in a hybrid pattern, spending 2-3 days a week (pro rata) in the office. Travel to your primary office location will not be paid for by DBT, but costs for travel to an office which is not your main location will be covered.
You can find out more about our office locations, how we calculate salaries, our diversity statement and reasonable adjustments, the Recruitment Principles, the Civil Service code and our complaints procedure on our website.
The Department will not consider sponsoring a visa or issuing a Certificate of Sponsorship. We are unable to offer advice on any Visa and Immigration cases.
Find out more about life at DBT, our benefits and meet the team by watching our video or reading our blog!
Feedback will only be provided if you attend an interview or assessment.
Security
See our vetting charter .
Nationality requirements
This job is broadly open to the following groups:
- UK nationals
- nationals of the Republic of Ireland
- nationals of Commonwealth countries who have the right to work in the UK
- nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities with settled or pre-settled status under the European Union Settlement Scheme (EUSS)
- nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities who have made a valid application for settled or pre-settled status under the European Union Settlement Scheme (EUSS)
- individuals with limited leave to remain or indefinite leave to remain who were eligible to apply for EUSS on or before 31 December 2020
- Turkish nationals, and certain family members of Turkish nationals, who have accrued the right to work in the Civil Service
Working for the Civil Service
We recruit by merit on the basis of fair and open competition, as outlined in the Civil Service Commission's recruitment principles .
Diversity and Inclusion
Apply and further information
Contact point for applicants
Job contact :
- Name : DDaT Recruitment
- Email : Ddat.recruitment@businessandtrade.gov.uk
Recruitment team
- Email : Ddat.recruitment@businessandtrade.gov.uk
Further information
Description sourced from the public Indeed listing — this role isn't indexed from the company's career page yet.
Never be applicant #200 again
Every job here is indexed straight from company career pages — often hours after it opens, before it reaches the big boards. Create a free account and get your best matches in a twice-daily digest.
- Your best matches, twice a day
- No duplicates, no ghost jobs, no recruiter spam
- Every job free to browse — pay only when you apply
Free account — no card required
93 150 live jobs · 17 788 companies tracked · 5 740 added today