About the role:
As a TSG Trainee SOC Analyst, you will join the Cyber Care team on a structured programme designed to develop you into a competent Security Operations Analyst. Cyber Care is TSG's fast growing managed detection and response service, protecting 100’s customers and several thousand endpoints. You will work alongside our existing analysts on the daily operation of the service, triaging security alerts, delivering identity and access administration on behalf of customers, and contributing to the regular service reviews through which customers understand their security posture. This is a hands-on operational role for someone who wants to learn security by working live customer environments.
This is initially a 12 month fixed term with view to going permanent at the end should all of your behavioural, technical and certification milestones be met.
Who are we?
TSG (Technology Services Group) are a Managed IT Services provider supporting businesses UK wide with their technology solutions. As a Microsoft Partner we are committed to delivering excellence for our customers alongside investing in our colleagues to provide them with the knowledge and tools required to deliver great results.
TSG are one of the few Microsoft Partners in the UK who hold all six Microsoft designations, and one of the only partners who specialise in mid-market. Our commitment to excellence for our customers and employees is backed by our consistent world class NPS score of +80 and our accreditation as a ‘Great Place to Work’ in addition to being placed on the ‘UK’s Best Workplaces in Tech’ list in both 2024 and again in 2025. Our guiding principles of Team TSG, Service Excellence and Shared growth are at the heart of everything we do.
Ownership at TSG
Every role at TSG comes with our Ownership Ladder. It sets out what ownership means here — from doing your own task well to owning the outcome end-to-end, following the work through every handoff until it lands, and bringing solutions rather than just problems. We include it in every job description because it applies to every person, whatever the role or level. It's the standard we hire to, work to, and back each other on. When you join us, you'll be operating above the ownership line — seeing it, owning it, solving it, and delivering it.
Why should I work for TSG?
-
Employee ownership – as a growing business we want to ensure that everybody who contributes towards our success, shares in our success. High performing members of Team TSG are entered into an employee benefits trust (EBT). The EBT is the single largest beneficiary within TSG meaning employees will share the benefits of the proceeds, driving a high performing culture with long term value and mutually beneficial outcomes
-
Our open and honest culture where feedback is taken on-board and acted upon
-
Our social events – annual all expenses paid ‘TSG Festival’ and team building funds
-
Two paid CSR days per annum that you can use to support the community
-
Giving something back – the ‘TSG Foundation’ established in November 2022 has so far donated over £160,000 to support nominated businesses and charities
-
Our responsibility to the environment as we work towards net carbon zero
-
Flexible working opportunities including home working and hybrid options
-
Annual salary benchmarking
-
Excellent progression opportunities, training and support, including recognised qualifications
Job responsibilities will include, but are not limited to;
-
Support the SOC team in the triage of security alerts across the customer base, including but not limited to initial assessment, evidence gathering, false positive identification and escalation to senior analysts
-
Follow established playbooks and runbooks consistently, and record actions and findings accurately
-
Escalate promptly and clearly where an alert may represent genuine malicious activity.
-
Contribute to reducing alert noise by identifying recurring false positives and tuning opportunities
-
Carry out the joiners, movers and leavers process on behalf of customers, including but not limited to account creation, permission changes, license assignment and account deprovisioning
-
Ensure all access changes are completed accurately, within agreed service levels, and with a clear audit trail
-
Identify and raise access-related risks observed during routine administration, such as dormant accounts or excessive privilege
-
Support and, in time, deliver quarterly service reviews with customers, presenting alert and incident activity, service performance and recommended actions
-
Prepare reporting packs and supporting data ahead of reviews
-
Record and follow up on actions agreed with customers
-
Work towards agreed learning objectives and relevant industry certifications during the 12-month term
-
Develop working knowledge of the Microsoft security stack, including Defender, Sentinel and Entra ID
-
Support the wider cyber practice as required, including but not limited to incident response activity and onboarding of new Cyber Care customers
-
Keep pace with current threats and attacker techniques relevant to our customer base
Knowledge, Skills & Experience;
-
Cyber security qualifications / certifications would be desirable
-
Demonstrable evidence of a genuine and sustained interest in security operations, which might include self-directed study, home lab or SIEM experimentation, blue team capture-the-flag participation, online courses or certifications in progress, a relevant academic module, or any other credible evidence that you have pursued this subject on your own initiative
-
A general working knowledge of IT systems, particularly Windows, Microsoft 365 and cloud identity
-
Sound understanding of core concepts such as authentication, phishing, malware and privilege
-
The ability to work methodically through a defined process without cutting corners
-
Clear written communication, sufficient to record findings that a colleague or customer can rely on
-
Strong verbal communication, relationship building and customer service skills
-
Comfort working to service levels and managing competing priorities
Benefits;
-
25 days annual leave + public holidays, rising with length of service
-
Employee benefits trust
-
Company bonus scheme
-
Life assurance 4 x Salary
-
Contributory pension scheme at 4% matched
-
Healthcare and cash plan
-
Electric vehicle salary sacrifice scheme
-
Cycle to work scheme
-
Employee discounts
-
Employee assistance programme
-
Paid CSR Days
-
Company sick pay and income protection cover
-
Enhanced Maternity and Paternity pay
-
Employee recognition scheme
-
Eyecare vouchers
-
Discounted gym membership
-
Long service rewards
If this sounds like the role for you, please apply today to be considered.