SOC Analyst Level 3
NatWest Group
- Led the investigation of user-reported suspicious endpoint activity, identifying unrecognised archive downloads and Microsoft Defender telemetry that had not surfaced through the standard SOC alert queue.
- Contained the potential compromise through endpoint isolation, account disablement, and credential-reset actions. I extracted hashes, IP addresses, and domains for estate-wide scoping, briefed First Response, and produced the evidence handover supporting a device rebuild.
- Worked with threat intelligence teams, peer financial institutions, and national cyber-security partners to monitor geopolitical threats and hostile-state activity targeting the UK financial sector, translating intelligence into hunting and monitoring priorities.
- Responded to a large-scale Layer 7 DDoS and SMS-pumping campaign, correlating application, network, geographic, and telecommunications indicators to identify malicious infrastructure and abuse patterns.
- Supported targeted IP blocking, geoblocking, and telephone-number controls during the campaign while investigating associated account activity and potential insider involvement.
- Conducted proactive threat hunts following bug-bounty disclosures, translating web-application findings into searches for exploitation indicators, suspicious requests, and post-compromise behaviour.
- Trained and supported L1 and L2 analysts across endpoint analysis, telemetry correlation, containment, case progression, and response-team handover.
