SOC Analyst (Level 3)
NatWest Group
- Led the investigation of user-reported suspicious endpoint activity, identifying unrecognised archive downloads and Microsoft Defender telemetry that had not surfaced through the standard SOC alert queue.
- Contained the potential compromise through endpoint isolation, account disablement and credential-reset actions; extracted hashes, IP addresses and domains for estate-wide scoping, briefed First Response, and produced the evidence handover supporting a device rebuild.
- Worked with threat intelligence teams, peer financial institutions and national cyber-security partners to monitor geopolitical threats and hostile-state activity targeting the UK financial sector, translating intelligence into actionable hunting and monitoring priorities
- Responded to a large-scale Layer 7 DDoS and SMS-pumping campaign, correlating application, network, geographic and telecommunications indicators to identify malicious infrastructure and abuse patterns.
- Supported targeted IP blocking, geoblocking and telephone-number controls during the campaign, while investigating associated account activity and potential insider involvement.
- Conducted proactive threat hunts following bug bounty disclosed web-application vulnerabilities, translating bug-bounty findings into searches for exploitation indicators, suspicious requests and post-compromise behaviour.
- Trained and mentored L1/L2 analysts, improving investigative capability across endpoint analysis, telemetry correlation, containment, case progression, and response-team handover.
