| Duties & Responsibilities | Overview |
| Monitoring events | Monitoring for events across multiple security technologies, including intruder detection systems (IDS), Intruder prevention systems (IPS), Firewalls, End Point Security Solutions and vulnerability management solutions. |
| Responding to security events | Receiving and acting on calls, emails, alerts, etc. relating to security events and possible security incidents. Including responding to incidents where a detailed understanding of the monitored estate is required and is beyond the capabilities of the SOC Analyst. |
| Content development | Assisting in content development and analytics. Taking threat intelligence and tuning the SOC services to best protect the Agency’s vulnerabilities. |
| Assisting engineers | Assisting in engineering tasks in support of the continuous availability of SOC services. |
| Complete scheduling and reporting | Complete SOC scheduled tasks and ensure reported events and incidents are appropriately progressed. |
| Risk and compliance | Assisting as with Security, Risk, Compliance and Service reporting. |
| Categorising events | Work alongside colleagues from personnel and physical security to assess events and categorise them appropriately. |
| Administration | Maintenance of SOC documentation, processes, and procedures. |
| Provide expert advice on IT security | Provide expertise, guidance and advice in IT Security related matters, including maintaining up to date knowledge of network, application and communications security solutions, as well as emerging technologies. |
| Responding to Incidents | Responding to incidents where a detailed understanding of the monitored estate is required and is beyond the capabilities of the SOC Analyst. |
| Identifying threats | Liaise with trusted partners to provide accurate threat identification. Recommend suitable mitigation measures and report the situation to the shift lead. |
| Reduce risk to data loss | Collaboration with other Security Teams (Cyber Defence, IA, Operational, Physical and Personnel) and adjacent commands to support the overall aim of lowing risk to data loss. |
| Deputising to support delivery | Support of senior management in the delivery of an effective and efficient departmental service, deputising where appropriate. The Senior Analyst leads the shift team during the absences of the Lead Analyst, reporting into the SOC Manager. |
| Building effective working relationships and collaboration | Develop and build internal and external partnerships working collaboratively to foster good relations, including working with other government departments to further the SOC capabilities. |
| Leading the team | The Senior Analyst leads the shift team during the absences of the Lead Analyst, reporting into the SOC Manager. |