/

L2.5 — SOC Incident Analyst

Closing Date: 28/08/2026
Location: Dublin
Reference #: 2092

Role Title:

L2.5 — SOC Incident Analyst

Business Area:

Information Security

About This Role:

Role Purpose

The SOC Incident Analyst owns security incidents from acceptance through investigation, scope determination, containment recommendation and closure. The role provides the primary interface between SOC triage and advanced incident response.

Expectations From The Role:

Key Responsibilities

  • Accept incidents escalated by the Triage Lead.

  • Determine incident scope, severity and business impact.

  • Build detailed attack timelines.

  • Investigate:

    • Endpoint compromise.

    • Identity compromise.

    • Microsoft 365 account or email compromise.

    • Azure and cloud-resource activity.

    • Network intrusion indicators.

    • Malware execution and persistence.

  • Map activity to MITRE ATT&CK.

  • Recommend containment, eradication and recovery actions.

  • Coordinate technical updates with customers.

  • Produce formal incident reports.

  • Document indicators affected entities and outstanding risks.

  • Feed lessons into detection and playbook improvement.


Requirements For A Successful Application:

Experience

  • 5–6 years of ICT / Cybersecurity experience.

  • At least 12 months in the completed L2.0 band or equivalent.

  • Experience owning medium- and high-severity investigations.

  • Demonstrated customer-facing incident communication.

  • Practical experience with hybrid Microsoft cloud and on-premises environments.

Qualification Alignment

Required or Target

  • Third Level - Computer Science Degree

  • Third Level - Cybersecurity Qualification

  • SOC Analyst Qualification.

  • CompTIA CySA+ or equivalent.

  • Cisco CCNA or equivalent.

  • CSA CCSK or equivalent cloud-security knowledge.

Desirable

  • Microsoft SC-200.

  • Microsoft SC-300 or equivalent Entra ID competence.

  • Microsoft Azure administration or security training.

  • Cisco CCNP Cybersecurity/Security preparation or equivalent.

  • Palo Alto XSIAM Engineer preparation.

  • CSA CCZT preparation or equivalent.

  • Incident-handling or forensic fundamentals qualification.

 

Performance Requirements

  • Minimum 90% investigation QA score.

  • Accurate scope, severity and impact determination.

  • Evidence-supported containment recommendations.

  • High-quality technical and customer reports.

  • Effective ownership from escalation to closure.

  • Regular detection, query or playbook improvement contributions.

  • Successful complex incident simulation.

Others:


About eir 
Our purpose is to connect for a better Ireland.   
 
Our ambition is to be the number one choice for telecommunications and technology solutions, delivering for our customers today and into the future. 
 
Our new values and behaviours reflect both who we are and who we strive to become.  They are the way that we bring our purpose to life in eir. 
 Picture 
 
We are committed to creating an inclusive and supportive work environment. If you require any reasonable adjustments during the application or interview process, please let us know, and we will work with you to meet your needs. 
 
If successful in the interview process, eir reserves the right to conduct appropriate suitability checks in relation to prospective employees including but not limited to reference checking and/or other searches using publicly available information.