United Kingdom · Technical roles · Mid-Level (2-5 years)

SOC Analyst II

Here is the whole job, in plain words. What it is, a real day, what you decide, how you're judged, how people get here and where they go next. Then the part no course gives you: twelve AI tutors who learn your work.

  • Experience bandMid-Level (2-5 years)
  • Direct reportsNo direct reports
  • Reports toSenior SOC Analyst or SOC Team Lead
  • UK framework levelUsually a coordinator, or early in a professional job

Also advertised as Mid-Level Security Operations Analyst · Cyber Defence Analyst · Incident Response Analyst (Tier 2)

Built on an analysis of 43,079 real UK job descriptions · grounded in qualifications employers recognise

Start with a free Future Fluency check, tuned to SOC Analyst II

Ten quick questions, one per Future Fluency, asked against this role rather than a generic one. About five minutes, and no card.

Start the check, free

1What this role really is

As a SOC Analyst II, you're the backbone of our security operations, the one who digs deep when an alert screams. You won't just close tickets; you'll investigate, contain, and help us learn from every incident. Think of yourself as a digital detective, piecing together clues from logs and alerts to figure out what's really going on. It's a critical role because you're often the first line of defence against actual threats, making sure our systems and data stay safe. You'll work mostly independently on your cases, but you're definitely part of a tight-knit team.

2What you'd actually use

The tools this job runs on, and how well you'd need to know each one.

Microsoft Sentinel (SIEM/SOAR)Intermediate

Running pre-built queries, triaging alerts, executing basic playbook actions, and building simple custom queries to investigate incidents. You'll be living in Sentinel.

CrowdStrike Falcon (EDR/XDR)Intermediate

Investigating EDR alerts, performing host isolation, using live response for data collection, and running basic queries to hunt for threats on endpoints.

Recorded Future (Threat Intelligence)Basic

Consuming intelligence reports to understand current threats, searching for Indicators of Compromise (IOCs), and enriching incident data with threat context.

Tenable.io (Vulnerability Management)Basic

Reviewing vulnerability scan reports, identifying and categorising critical vulnerabilities, and using the data to inform incident investigations (e.g., if a compromised host had known critical flaws).

Jira & Confluence (Collaboration/Documentation)Intermediate

Managing incident tickets in Jira, documenting investigation findings and 'Lessons Learned' in Confluence, and using these platforms for team collaboration.

Kusto Query Language (KQL)Intermediate

Writing and modifying queries to search and analyse log data within Microsoft Sentinel, which is essential for deep investigations.

3What you get to decide, and how that grows

Power in a job isn't your title. It's what you're allowed to decide. Here's how it grows as you move up.

The choiceComing inWhere you are nowThe step above
Incident Containment Actions (e.g., host isolation, IP blocking)Requires explicit approval from a senior analyst or lead for every action. Follows pre-approved steps only.Can independently execute containment actions for routine incidents following established playbooks. Escalates for novel situations or high-impact systems.Independently authorises and executes containment for complex incidents, even in ambiguous situations. Consults with Director on business-critical systems.
Alert Prioritisation & EscalationFollows strict prioritisation matrix; escalates anything outside Tier 1 for review.Independently prioritises Tier 2 alerts and decides on escalation path based on incident severity and impact. Escalates exceptions.Defines and refines prioritisation matrices for the team. Makes independent judgements on critical incident escalation, including out-of-band communications.
Tool Configuration & TuningNo authority. Reports noisy alerts or potential gaps to senior analysts.Suggests tuning adjustments for existing detection rules or proposes new basic queries to lead. Does not implement changes directly.Designs and implements new SIEM correlation rules and SOAR playbook modifications. Tunes EDR policies with Security Engineering.
Communication during IncidentsCommunicates only with immediate team lead. No direct external or cross-functional communication.Communicates with IT Operations, DevOps, and other technical teams during incident resolution. Keeps lead informed.Leads incident bridges, communicates with business stakeholders on technical details, and drafts internal incident summaries.

4How you'll be judged

The scoreboard, honestly: the hard targets, how often each one is actually looked at, and the quiet human signals that never make it onto a dashboard.

Alerts Triaged per Shift
The number of security alerts you investigate and categorise during your shift. This includes closing false positives and escalating genuine threats.
Target · Typically >100 alerts per 8-hour shift, depending on alert volume and complexity.

On a busy Monday, you might triage 120 alerts, closing 100 as false positives and escalating 20 for deeper investigation.

Ticket Escalation Accuracy
The percentage of incidents you escalate that turn out to be genuine threats, and the percentage of false positives you correctly close without escalation.
Target · >98% accuracy in correctly identifying and escalating real issues, and closing false positives.

Out of 50 escalations, 49 were valid incidents. Out of 500 closed alerts, none were later found to be missed threats. That's good going.

Mean Time to Escalate (MTTE) for Critical Alerts
The average time it takes you to identify a critical security alert and escalate it to the appropriate team or lead for further action.
Target · <15 minutes for critical (P1) alerts; <30 minutes for high (P2) alerts.

A P1 alert comes in at 10:05 AM, you confirm it's a genuine threat by 10:17 AM and escalate it. That's 12 minutes, well within target.

Incident Resolution Rate
The percentage of assigned Tier 2 incidents you successfully investigate, contain, and resolve without needing significant intervention from a senior analyst.
Target · >85% of assigned Tier 2 incidents resolved independently.

You're assigned 20 Tier 2 incidents in a month and successfully close 18 of them, only needing help on two particularly tricky ones.

Investigation Quality & Documentation
How thoroughly you investigate incidents, the clarity and completeness of your findings, and how well you document your steps and conclusions in our ticketing system (Jira/Confluence).
  • Your incident reports are clear, concise, and contain all necessary technical details. Other analysts can easily pick up your cases if needed. You include 'Lessons Learned' where appropriate, even if it's just for yourself. Your lead rarely has to ask for more detail or clarification on your cases.
Proactive Problem Solving
Your ability to not just react to alerts, but to identify underlying issues, suggest improvements to detection rules, or propose new ways to reduce 'Alert Fatigue'.
  • You'll suggest tuning a noisy alert rule, or propose a new SIEM query that catches something we've missed. You might spot a recurring issue and suggest a permanent fix, rather than just patching it over each time. You're not afraid to say, 'This alert is rubbish, here's why, and here's how we fix it.'
Collaboration & Knowledge Sharing
How well you work with your team and other departments, and your willingness to share your knowledge, especially with newer analysts.
  • You're helpful in team chat, offering advice or sharing useful queries. You might run through a complex case with a junior analyst, showing them the ropes. Other teams (like IT or DevOps) find you easy to work with and appreciate your clear communication during incidents. You contribute to our internal knowledge base (Confluence) with useful articles or playbooks.
Adaptability & Learning
Your openness to new tools, techniques, and threats, and your continuous effort to improve your skills.
  • You're quick to pick up new EDR features or SIEM query languages. You actively seek out training or read up on new attack methods. When a new threat emerges, you're keen to understand it and how it might affect us, rather than just waiting to be told what to do. You don't shy away from complex or unfamiliar incidents
  • you see them as a chance to learn.

5Would you like it

The honest version. What people enjoy, and what grinds them down.

What people enjoy
Solving Complex Puzzles

You'll spend hours sifting through logs, correlating events, and trying to figure out the 'who, what, when, and how' of a security incident. It's like being a detective every day, with a new mystery to solve.

You're given an alert about unusual network activity. Instead of just blocking the IP, you'll trace it back, find the compromised host, identify the malware, and figure out how it got in, building a full timeline.

Protecting the Organisation

You get a real sense of satisfaction from knowing that your quick actions prevented a potential breach or stopped an attacker in their tracks. You're on the front lines, directly contributing to the company's security posture.

Your rapid response to a phishing attempt stops a user from clicking a malicious link, preventing a potential credential compromise and saving the company from a much larger headache.

Continuous Learning & Growth

The threat landscape changes constantly, so you're always learning about new attack techniques, tools, and defensive strategies. This role offers endless opportunities to deepen your technical knowledge and grow your career.

You encounter a new type of malware, research its behaviour using public threat intelligence, and then apply that knowledge to create a new detection rule for our SIEM, sharing it with the team.

What frustrates people
  • Dealing with a high volume of false positive alerts that mask genuine threats.
  • The constant need to justify security recommendations to other teams who don't always understand the risk.
  • Working with incomplete or messy data when trying to investigate an incident.
  • The occasional 3 AM wake-up call for a critical incident, even if it's rare.
  • Seeing the same basic security hygiene issues (like unpatched systems) cause repeated alerts.
What this role does not give you
  • A predictable 9-to-5 routine every single day (incidents don't care about your schedule).
  • A role where you're solely building new things; a lot of it is reactive problem-solving.
  • Complete control over other teams' security practices (you'll advise and influence, not command).
  • An environment where you never have to deal with ambiguity or incomplete information.

6Who you work with

Your work directly influences our 'Dwell Time'—how long an attacker is in our systems before we find them. Shorter dwell times mean less damage, less cost, and less reputational hit. You're crucial for keeping our digital doors locked and our data safe, which, frankly, keeps the business running smoothly. You'll also contribute to our overall security posture by identifying gaps and suggesting improvements based on your investigations.

Inside the business
  • Your SOC Team Lead (for daily direction and support)
  • Other SOC Analysts (for collaboration and knowledge sharing)
  • IT Operations and Infrastructure Teams (when you need to isolate systems or apply patches)
  • DevOps Teams (when you find vulnerabilities in applications or cloud environments)
  • Legal and HR (for sensitive incidents, though this is rare at your level)
  • Security Engineering (when you need new detections or tool tuning)
Outside the business
  • Threat Intelligence Vendors (you'll use their data, but won't directly manage them)
  • Managed Security Service Providers (if we use them for certain functions, you might coordinate with their analysts)

7What you need before you start

Not a wish list. The things you would be expected to already have.

  • At least 2-3 years of hands-on experience in a Security Operations Centre (SOC) or a similar incident response role.
  • Demonstrable experience with at least one major SIEM platform (e.g., Splunk, Microsoft Sentinel, Elastic SIEM) for alert triage and investigation.
  • Proven ability to analyse security alerts from various sources (EDR, network, cloud) and determine their validity.
  • Experience with common operating systems (Windows, Linux) and networking concepts from a security perspective.
  • A solid understanding of common cyber attack techniques and how to detect them.
  • Ability to write clear, concise technical documentation and incident reports.

8What to practise next

Where the job is going, and what to do about it starting this week.

Advanced SIEM Querying & Rule Optimisation

As alert volumes grow, the ability to write highly efficient and accurate SIEM queries (especially KQL for Sentinel) becomes paramount. You'll need to move beyond basic searches to complex aggregations and optimisations.

Performance tuning for large datasets · Advanced KQL operators (e.g., 'join', 'union', 'summarize') · False positive reduction techniques · Threat modelling for detection rules

  • This month: Dedicate an hour each week to practising advanced KQL queries in a test environment or against historical data.
  • Next quarter: Take ownership of reviewing and suggesting improvements for 2-3 of our 'noisy' SIEM rules.
  • Within 6 months: Develop a new, high-fidelity detection rule for a specific TTP that we currently have weak coverage for.
  • Within 9 months: Share your advanced query techniques with the rest of the team during a knowledge-sharing session.

Quick win: Challenge yourself to rewrite one of your frequently used basic queries using more advanced KQL operators to make it more efficient or comprehensive.

Proactive Threat Hunting Techniques

Reactive defence isn't enough anymore. We need to actively seek out threats that have bypassed our automated detections. This means developing and executing more sophisticated hunting hypotheses.

Hypothesis generation based on threat intelligence · Data source identification and collection for hunting · Statistical analysis for anomaly detection in hunting · Developing hunting playbooks and procedures

  • This month: Read up on different threat hunting methodologies and examples of successful hunts.
  • Next quarter: Work with a senior analyst to participate in at least one structured threat hunt, taking a more active role in query development.
  • Within 6 months: Propose and execute a small, self-contained threat hunt based on a recent piece of threat intelligence.
  • Within 9 months: Document your hunting process and findings, contributing to our internal hunting knowledge base.

Quick win: Subscribe to a few good threat hunting blogs or newsletters and spend 15 minutes a week reading about new hunting techniques.

9Staying current once you are in

What people here do to keep up
  • Actively participate in security communities (e.g., local OWASP chapters, B-Sides conferences, online forums).
  • Regularly read security blogs, threat intelligence reports, and industry news to stay current with the latest threats and vulnerabilities.
  • Set up a home lab to experiment with new tools, practice incident response scenarios, or reverse-engineer malware in a safe environment.
  • Contribute to open-source security projects or share your knowledge through blog posts or presentations.
  • Seek out mentorship from senior analysts or leads to accelerate your learning and career growth.

10How the AI economy is changing work like this

Before we ask anything of you, here's what we can already say about AI and work of this kind:

The new skill this role is being asked for: Prompt Engineering for Security Analysis

Generative AI is changing how we analyse data and summarise information. Analysts who can effectively 'talk' to Large Language Models (LLMs) will be able to accelerate their investigations and reporting significantly.

We'll only ever tell you what we can actually back up. No hype, no scare tactics.

Your PlanIllustration

Built for SOC Analyst II

4 units that map to this job, from the qualifications that cover it.

  1. Investigations and Incident ResponseQualifi Ltd · covers 6 of 10 standardsLevel 3
  2. Incident Response, Investigations and ForensicsQualifi Ltd · covers 4 of 10 standardsLevel 4
  3. Carrying out Information Security Incident Management activitiesPearson Education Ltd · covers 3 of 10 standardsLevel 3
  4. Networked systems securityCambridge OCR · covers 1 of 10 standardsLevel 3
These are the real units behind this job, in the order they rank for it. Nothing here is marked done, because this plan has not been started by anyone yet. Yours would fill in as you go.

The rising capability

Zavmo analysis

What's rising in its place

This is where the work is heading, and the higher pay with it. Get fluent here and the shift stops being a threat and starts being your edge.

Prompt Engineering for Security Analysis

Generative AI is changing how we analyse data and summarise information. Analysts who can effectively 'talk' to Large Language Models (LLMs) will be able to accelerate their investigations and reporting significantly.

  • Context windows and token limits
  • Temperature settings for different tasks
  • Output validation and hallucination detection
  • Prompt chaining for complex analysis

Cloud-Native Security Monitoring

More and more of our infrastructure is moving to the cloud, especially Azure and AWS. Understanding how to monitor these environments is becoming absolutely critical, as traditional on-prem tools don't always translate directly.

  • Cloud logging services (Azure Monitor, AWS CloudTrail, VPC Flow Logs)
  • Cloud Identity and Access Management (IAM) security
  • Serverless function security (Azure Functions, AWS Lambda)
  • Container security monitoring (Docker, Kubernetes)

What you’ll use

Skills this role draws on

Technical

  • Incident Response Frameworks (NIST 800-61, SANS PICERL)
  • MITRE ATT&CK Framework
  • Threat Hunting Methodologies
  • Cyber Kill Chain Analysis
  • Security Metrics & Reporting (Basic)

The pathway

How you actually get there, here

How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.

  1. 1

    SOC Analyst I (Entry-Level)

    1-2 years

    Skills to master

    • Mastering Tier 1 alert triage, understanding basic security concepts, proficiency with SIEM/EDR tools, clear documentation.

    You're ready to move on when

    • Consistently and accurately triaging a high volume of alerts.
    • Demonstrating a solid grasp of our core security tools and processes.
    • Proactively seeking out opportunities to learn and take on more complex tasks.
    • Receiving positive feedback on documentation quality and teamwork.
  2. 2

    IT Support / Network Administrator with Security Focus

    2-3 years in IT, then 1-2 years in a junior security role

    Skills to master

    • Deepening understanding of security principles, incident response methodologies, log analysis, and specific security tool proficiency.

    You're ready to move on when

    • Successfully managing and troubleshooting complex IT/network issues with a security mindset.
    • Having taken on security-related projects or responsibilities in previous roles.
    • Demonstrating strong analytical and problem-solving skills applicable to security incidents.
    • Holding relevant security certifications (e.g., Security+, CySA+).
  3. 3

    Junior Incident Responder / Threat Hunter

    1-2 years

    Skills to master

    • Hands-on experience with incident containment, eradication, and recovery. Proficiency in forensic analysis tools and threat intelligence integration.

    You're ready to move on when

    • Proven ability to conduct end-to-end incident investigations.
    • Experience with advanced detection techniques beyond basic alert triage.
    • Strong understanding of adversary tactics and techniques.
    • Ability to work independently on complex security challenges.

11Where this role leads

The long view:Your journey starts here, but where you go is really up to you. We're committed to providing the opportunities and support for you to build a truly impactful and rewarding career in cyber security. We want you to grow, challenge yourself, and ultimately, become a leader in this critical field.

Pay & demand

Pay and demand for this role will appear here, each figure traced to a named authoritative source (e.g. the ONS Annual Survey of Hours and Earnings, under the Open Government Licence). We don’t show numbers we can’t attribute.

The ten Future Fluencies

Zavmo analysis

The credential is what you can do today. These are what keep you valuable.

A qualification proves you can do the job as it's defined today. These ten are what decide whether you're still the obvious person for it in five years. They're the capabilities employers are now writing into senior roles faster than people are learning them. Zavmo weaves them through whatever you study, so you come out with both: the credential and the fluency.

The highlighted ones are the Fluencies your role leans on hardest, from how SOC Analyst II is actually changing. In about two minutes, the free confidence check asks where you stand on each of the ten. That's the whole check, and it's what makes the plan yours rather than generic.

12The team that's yours

No two people are taught the same way. This is one-to-one, not one-to-many.

Zavmo is a hyper-personalised AI learning platform. Twelve virtual tutors, each with a different way of teaching, and one orchestration agent that picks the right one for the moment. So every single lesson is shaped around you, your role, and the way you learn. Not a course everyone sits through. A conversation built for you, and no one else.

…and nine more, matched to you after your first chat. Meet all twelve

13What it feels like

A conversation, not a course

Because your tutor knows your role, your projects and your last session, learning sounds like this. And it's different for every single person:

Investigations and Incident ResponseLevel 3

Applied to your work in SOC Analyst II

The objective of this unit is to provide learners with a comprehensive understanding of incident response, including its core phases, tools, and processes. Learners will explore the creation of a Computer Emergency Response Team (CERT) and the role of Disaster Recovery (DR) and Business Continuity Management (BCM) in supporting cyber incident response.

How the thinking builds
  1. Remember
  2. Understand
  3. Apply
  4. Analyse
  5. Evaluate
  6. Create
An illustration of a Zavmo lesson, built from this role’s own route. The unit, its objective and every criterion above are the awarding body’s own words, not an example.

One to one, not one to many

No two people run this the same way

A course is written once and handed to everyone. This is assembled around you, and keeps changing as it learns you. Five things it reads, and what each one changes.

  1. Your actual work Every lesson is taught against a live piece of your own work, not a worked example from a textbook.
  2. What you already know The first conversation finds your starting point, so you skip what you can already do and spend the time on what you cannot.
  3. The conditions you learn under Not a learning-styles quiz. The evidence does not support those. The dimensions the research does back, read once and used to shape the plan.
  4. How far you got last time It picks up mid-thought. The tutor knows what you said, what you struggled with, and what it asked you to try.
  5. Which tutor suits the moment Twelve of them, each for a different kind of thinking. The one who walks you through a first idea is not the one who stress-tests it.

See how you learn, free. Eight questions, no sign-up. A directional taster; the diagnostic inside Zavmo goes deeper and keeps adapting.

DemonstrateIllustration

Evidenced on your work in SOC Analyst II

You do not finish by watching something. You finish by showing it on the work you already do, against the measures this job is judged on.

  • Alerts Triaged per ShiftThe number of security alerts you investigate and categorise during your shift. This includes closing false positives and escalating genuine threats.On a busy Monday, you might triage 120 alerts, closing 100 as false positives and escalating 20 for deeper investigation.Typically >100 alerts per 8-hour shift, depending on alert volume and complexity.
  • Ticket Escalation AccuracyThe percentage of incidents you escalate that turn out to be genuine threats, and the percentage of false positives you correctly close without escalation.Out of 50 escalations, 49 were valid incidents. Out of 500 closed alerts, none were later found to be missed threats. That's good going.>98% accuracy in correctly identifying and escalating real issues, and closing false positives.
  • Mean Time to Escalate (MTTE) for Critical AlertsThe average time it takes you to identify a critical security alert and escalate it to the appropriate team or lead for further action.A P1 alert comes in at 10:05 AM, you confirm it's a genuine threat by 10:17 AM and escalate it. That's 12 minutes, well within target.<15 minutes for critical (P1) alerts; <30 minutes for high (P2) alerts.
  • Incident Resolution RateThe percentage of assigned Tier 2 incidents you successfully investigate, contain, and resolve without needing significant intervention from a senior analyst.You're assigned 20 Tier 2 incidents in a month and successfully close 18 of them, only needing help on two particularly tricky ones.>85% of assigned Tier 2 incidents resolved independently.
These are this job's own measures, with its own targets. Nothing is marked evidenced, because nobody has started this yet. Yours would fill in from the work you bring.

Your passport

This isn't a certificate you file away. It's a passport to the life you're designing.

Every credit you earn and every fluency you build adds up: evidence where it counts, carried with you. Zavmo keeps the map: where you are, where you're heading, and the next step, at your pace, around your life. From SOC Analyst II to Senior SOC Analyst / Incident Responder (Level 3), and whatever you decide comes after.

Level 3 · in progressAI Fluency→ Senior SOC Analyst / Incident Responder (Level 3)→ your design
Where this takes you

Your journey starts here, but where you go is really up to you. We're committed to providing the opportunities and support for you to build a truly impactful and rewarding career in cyber security. We want you to grow, challenge yourself, and ultimately, become a leader in this critical field.

See Your Progress GrowIllustration
SOC Analyst II
  • Incident Response Frameworks (NIST 800-61, SANS PICERL)
  • MITRE ATT&CK Framework
  • Threat Hunting Methodologies
  • Cyber Kill Chain Analysis
  • Security Metrics & Reporting (Basic)
This is your Mind Palace on learn.zavmo.ai. Every skill above comes from this role's own record, not an example borrowed from another job. A node lights up when you evidence it, and what you build stays yours between jobs. That is the part a course cannot do.

14The detail, folded away

Everything else the record holds

The career branches in full, how AI is already showing up in the day-to-day, and the questions people ask about this job. Here when you want them, out of the way while you decide.

Where it leads next, rung by rung

Where it leads

The career path, and where it branches

SOC Analyst II is a start, not a ceiling. Each step below asks for new skills and hands back more autonomy.

  1. Senior SOC Analyst / Incident Responder (Level 3)

    3-5 years in this SOC Analyst II role

    This is the natural next step, where you'll take on the most complex incidents, mentor junior analysts, and start contributing to the design of new detection rules and playbooks.

    • Expertise in developing new SIEM correlation rules and SOAR playbooks from scratch.
    • Advanced threat hunting methodologies, including hypothesis generation and data source identification.
    • Deep understanding of malware analysis techniques and reverse engineering basics.
    • Proficiency in scripting (e.g., Python, PowerShell) for automation and custom tool development.
    • Leading tabletop exercises and purple team engagements.
Working with AI on the job

Working with AI

Where AI is starting to help

Let's be real, security operations can be a bit of a grind. You're sifting through mountains of alerts, writing the same queries, and trying to keep up with the latest threats. But what if you could cut out a huge chunk of that repetitive work and focus on the really interesting stuff? That's where AI comes in.

We're not talking about robots taking over your job; we're talking about smart tools that make you faster, more accurate, and frankly, less stressed. For a SOC Analyst II, AI isn't just a buzzword; it's a practical co-pilot that helps you get through your workload quicker, spot things you might miss, and give you more time for deep investigations and learning. Think of it as having an extra pair of hands that never gets tired.

Alert Triage Automation

Imagine your SOAR platform automatically investigating and closing those low-level, high-volume alerts—the port scans, the benign credential failures. AI can enrich data, check threat intel, and close the ticket if there's no real threat, all before you even see it. This frees you up to focus on the truly suspicious stuff, not the noise.

Anomaly Detection Acceleration

Our User and Entity Behaviour Analytics (UEBA) models use AI to surface weird activity that rule-based systems just can't catch. Think of an admin logging in from a new country at 3 AM and then accessing unusual files. AI spots these deviations from the norm, reducing the time it takes to discover a threat from weeks (if you were hunting manually) to near real-time. It's like having a sixth sense for trouble.

Threat Intel Synthesis

Instead of spending an hour reading through dozens of daily threat intelligence reports, CVE announcements, and security blogs, an AI assistant can do it for you. It'll extract the key Tactics, Techniques, and Procedures (TTPs), Indicators of Compromise (IOCs), and affected technologies, giving you a concise brief for your morning stand-up. You get the gist in minutes, not hours.

Incident Report Drafting

After you've contained an incident, you can feed the technical timeline and findings from Jira or Confluence into a generative AI model. It'll then create a first draft of a non-technical summary for your lead or even for other teams, focusing on the business impact, root cause, and remediation steps. This saves you valuable time on documentation, letting you get back to the next investigation faster.

Common questions

Common questions

How do you become an SOC Analyst II?

Common routes in include SOC Analyst I (Entry-Level) (1-2 years), IT Support / Network Administrator with Security Focus (2-3 years in IT, then 1-2 years in a junior security role) and Junior Incident Responder / Threat Hunter (1-2 years). Times vary with prior experience.

Where can an SOC Analyst II progress to?

This role can lead on to Senior SOC Analyst / Incident Responder (Level 3) (3-5 years in this SOC Analyst II role), depending on the skills you build.

What level is an SOC Analyst II in the UK?

This role aligns to RQF Level 3 on the UK framework, a guide to the depth of qualification it maps to, not a hard entry bar.

What new skills matter most for an SOC Analyst II?

Increasingly, Prompt Engineering for Security Analysis and Cloud-Native Security Monitoring. These are the areas where the higher-paid, future-proof work is heading.

The honest bit

You’ve started things before

Most of them were built for a room full of people who aren’t you. A cohort moves on whether or not your week allowed it, and by the third week the thing you’re behind on becomes the reason you stop opening it.

There’s no cohort here, and no timetable to fall behind. Before anything starts, Zavmo asks when you’re sharpest and how long you can realistically sit down for, then builds the sessions around those answers. A bad fortnight changes your pace. It doesn’t put you behind.

And you only pay once you start learning. Searching and planning are free, and you can cancel any time — so the cost of finding out is an afternoon, not a year.

What it costs

Less than one coaching session. Every month.

A single career-coaching hour costs more than a month of this, and it ends when the hour does. Zavmo doesn't. It's £70 a month, about £2.30 a day, for a companion that knows an SOC Analyst II, works on the job you actually do, and keeps going at your pace rather than a timetable's.

  • Searching and planning stay free. You only pay when you start learning.
  • Your credits are yours. Regulated, and they don't vanish when a subscription ends.
  • Cancel any time and billing stops. No notice period, no minimum term.

Your path, personalised

You have the map. Walking it is the part we do together.

This route runs to 10 national skill standards. That is a real journey.

Zavmo shapes a learning experience as unique as you are. It fits how you learn, your pace and the work you already do. Every step stays benchmarked to recognised national standards. That’s the plan for becoming an SOC Analyst II: personal to you, and it still counts. The first steps are free.

Independent research finds well-designed intelligent tutoring performs nearly as well as one-to-one human tutoring: VanLehn (2011), Educational Psychologist.

A private tutor in the UK averages £35–40 an hour . Zavmo is £70/month.

A real plan on learn.zavmo.ai: Ofqual-regulated units, credits, and a three-month run at your own pace.
Start free No commitment. See your first steps free.

15Where to go from here

Other roles at Level 3

Same depth of qualification, different job. Useful if the work appeals but this particular role does not.

Other roles in Technical roles

Stay in the field you know and move sideways rather than up.

If you leave this industry

The skills you'll gain as a SOC Analyst II are highly transferable across almost any industry. Every company needs strong security operations. You could move into consulting, work for a security vendor developing new products, or specialise in a niche area like automotive or healthcare security. The world is your oyster, frankly.

Not sure this is the right direction?

Work out what you actually want from work first, then come back and see which roles fit it. Takes about ten minutes.

This role profile is © 2026Growth Engineering Technologies Ltd. Built from UK occupational standards and regulated qualification data, and written for Zavmo.

You're not behind. You're right on time. The shift is only just beginning. Your role won't look the same in two years. Be the one who leads the change, not the one it happens to. Build my plan, free Here's the first ten minutes: a 2-minute confidence check → your personalised roadmap → meet the tutors matched to you. No card, cancel any time. No card. Build your plan, see your roadmap and meet the twelve tutors matched to you. All free. When you're ready to start learning, it's £70 a month, billed monthly. Cancel any time and billing stops.