This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
BAE Systems are seeking a Level 1 SOC Cyber Analyst to join the TMCT security team within the FCAS DI function. This role will act as the first internal responder to cybersecurity alerts generated by our outsourced Security Operations Centre (SOC).
Job Responsibility:
Review and assess alerts escalated by the outsourced SOC, validating accuracy and determining potential impact
Perform first-line analysis using tools such as SIEM platforms, device logs and firewall logs
Work directly with end users and asset owners to gather additional information and guide immediate containment actions such as asset isolation or password resets
Escalate confirmed or high-severity incidents to Level 2 SOC analysts or internal response teams with clear and accurate documentation
Maintain detailed case notes, timelines and evidence within the case management system to support investigations and compliance requirements
Act as a key communication point between the internal security team and external SOC provider
Follow established triage and escalation procedures and suggest improvements where appropriate
Requirements:
2–4 years’ experience in a SOC, IT operations or cybersecurity support role
Understanding of key cyber threats such as malware, phishing, lateral movement and privilege escalation
Working knowledge of network fundamentals, authentication systems and Windows/Linux system logs
Experience using SIEM platforms such as Microsoft Sentinel, Splunk, Elastic or QRadar
Experience using ticketing or case management systems such as Jira, ServiceNow or The Hive
Strong analytical and investigative skills with the ability to interpret alerts and security logs