Home/For women/Employers/JP Morgan
Apply on company site
WORK180 logo

WORK180 currently operates in

  • Australia
  • United Kingdom
  • United States

Join our network:

Social Traders Badge
Good to know
  • Our story
  • Our mission
  • Join our team
Top pages for women
  • Top employers
  • Job search
  • Create an account
  • Join the community
Top pages for employers
  • Products and services
  • Getting endorsed
  • Employer resources
  • Employer login
  • Manage jobs
Useful links
  • Blog
  • Events
  • Contact us
  • Sitemap
Policies
  • Cookie policy
  • Privacy policy
  • Social media terms
  • Terms of use

Quick job search

Discipline:
 Accounting - Administration - Business Development and Sales - Customer service and support - Engineering - Executive and general management - IT - Legal - Marketing and communications - Operations - Product management - Program and project management - Purchasing and procurement - Retail - Trades and technicians
Industry:
 Auto - Banking, investment and finance - Construction - Consulting and professional services - Engineering - Healthcare and medical - IT, digital and online media services - Manufacturing and operations - Mining, resources and energy - Retail and fashion - Telecommunications - Transport, shipping and logistics
Location:
 All Australia - Sydney - Melbourne - Brisbane - Adelaide - Perth - Hobart - All United Kingdom - London - Manchester - Liverpool - Birmingham - Edinburgh - Glasgow - All United States
Copyright © 2026 WORK180. All rights reserved.
WORK180 logo
  • Top employers
    • Flexible and remote working
    • Paid time off
    • Paid parental leave
    • Women in leadership
    • Pay equity
    • Career development
    • Policies and support
  • Job search
    • Mining and energy jobs
    • IT jobs
    • Part time jobs
    • Finance jobs
    • Marketing jobs
    • View all job categories
  • Events
  • Career inspiration
  • For employers
    • How we help
    • Get endorsed
    • Workshops & consulting
    • WGEA Support
    • Resources
    • Testimonials
    • Equitable workplace awards
    • Book a call
    • Employer login
  • About us
    • Our story
    • Our impact
    • Our badge
    • Our approach
    • Our culture & values
    • WORK180 in the media
    • Join the community
    • Contact us
  • Region:
  • My account
UpdatesLatest jobsFind employersFollowed employersMy job activity
•My details
•My job details
•Job preferences
•Notification preferences
•Saved job searches
Parental leave calculatorProfessional women's network

About JPMorganChase and the Team

JPMorganChase is a global leader in financial services, serving millions of clients and many of the world's most prominent corporate, institutional, and government clients. Protecting the firm, its customers, and the integrity of the global financial system is a foundational priority, and the Cybersecurity Operations organization is central to that mission. Within it, the Detection and Response team serves as the front line of the firm's cyber defense, operating a global "follow-the-sun" model that delivers 24/7 monitoring, detection, and response across regions. The London SOC is a critical hub anchoring coverage across EMEA, working seamlessly with partner centers worldwide to ensure continuous, uninterrupted protection.

Role Overview

This is a hands-on detection and response role at the core of the firm's cyber defense operations. The analyst will primarily triage security alerts and investigate cases end-to-end, while contributing to threat hunting, detection engineering, and the adoption of AI-assisted tooling to improve investigative efficiency and accuracy. The position suits a technically strong practitioner who thrives in a fast-paced, high-stakes environment and is motivated by continuous improvement.

Working Model and Schedule

The team operates a follow-the-sun model to guarantee continuous global coverage. Analysts work standard weekday business hours, for the most part, with weekend shift coverage required on a rotational basis approximately once every five (5) weeks. This rotation ensures uninterrupted monitoring and response capability across all time zones and handoff points.

Key Responsibilities

  • Triage and analyze security alerts from SIEM, EDR, and other detection tooling, prioritizing based on severity, risk, and business impact.
  • Investigate security incidents and cases end-to-end, from initial detection through containment, eradication, and documented resolution.
  • Conduct proactive threat hunting across endpoints, networks, cloud, and identity telemetry to identify undetected threats and emerging adversary behavior.
  • Contribute to detection engineering: develop, tune, and refine detection rules, use cases, and correlation logic to reduce false positives and improve coverage.
  • Leverage AI and automation tooling (e.g., AI-assisted triage, enrichment, and summarization) to accelerate investigations and improve analyst efficiency.
  • Document findings, maintain accurate case records, and produce clear incident reports and post-incident reviews.
  • Collaborate with global SOC teams, threat intelligence, incident response, and engineering functions to ensure seamless handoffs under the follow-the-sun model.
  • Contribute to continuous improvement of SOC playbooks, runbooks, and standard operating procedures.
  • Stay current with the evolving threat landscape, attacker TTPs (mapped to frameworks such as MITRE ATT&CK), and industry best practices.

Required Qualifications, Capabilities, and Skills

  • Demonstrable experience in a SOC, incident response, or security analyst role (typically 2+ years).
  • Solid understanding of security monitoring and investigation across SIEM, EDR/XDR, and network security tooling.
  • Working knowledge of common attack techniques, the cyber kill chain, and the MITRE ATT&CK framework.
  • Strong understanding of core networking concepts (TCP/IP, DNS, HTTP/S, proxies, firewalls) and operating system internals (Windows, Linux).
  • Experience investigating alerts across endpoint, network, cloud, and identity/authentication logs.
  • Ability to analyze logs, correlate events across multiple data sources, and reconstruct incident timelines.
  • Strong written and verbal communication skills for clear documentation and stakeholder updates.
  • Ability to work under pressure, prioritize effectively, and participate in weekend shift rotation (approximately once every five weeks).

Preferred Qualifications, Capabilities, and Skills

  • Experience with detection engineering and writing/tuning detection content (e.g., Sigma, YARA, KQL, SPL, or equivalent).
  • Hands-on threat hunting experience using hypothesis-driven methodologies.
  • Familiarity with SOAR platforms, scripting/automation, and AI-assisted security tooling.
  • Experience defending large, complex enterprise or financial-services environments.
  • Exposure to cloud security monitoring (AWS, Azure, or GCP).
  • Knowledge of threat intelligence concepts and integration into detection and response workflows.

Education and Certifications

  • Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience.
  • Industry certifications are advantageous, such as: CompTIA Security+, CompTIA CySA+, GIAC (GCIH, GCIA, GCFA, GDAT), Blue Team Level 1/2 (BTL1/BTL2), CEH, or cloud security certifications (AWS/Azure/GCP security).
View all jobs from JP Morgan

Security Operations Analyst (SOC analyst) - London, England, United Kingdom

London, England, United Kingdom
Full time
Posted 1 month ago
Logo of JP Morgan
JP Morgan
Banking, investment & finance
10,001+ employees
690 jobs
Compare top employers