Cyber Security Operations Centre Analyst

Nottingham Trent House (95002), United Kingdom, Nottingham, Nottinghamshire

At Capital One, we're building a leading information-based technology company. Still founder-led by Chairman and Chief Executive Officer Richard Fairbank, Capital One is on a mission to help our customers succeed by bringing ingenuity, simplicity, and humanity to banking. We measure our efforts by the success our customers enjoy and the advocacy they exhibit. We are succeeding because they are succeeding.

Guided by our shared values, we thrive in an environment where collaboration and openness are valued. We believe that innovation is powered by perspective and that teamwork and respect for each other lead to superior results. We elevate each other and obsess about doing the right thing. Our associates serve with humility and a deep respect for their responsibility in helping our customers achieve their goals and realize their dreams. Together, we are on a quest to change banking for good.

Cyber Security Operations Centre Analyst

Capital One is looking for a talented Information Security Analyst with network security monitoring experience to join our Cyber Security Operations Centre (CSOC) in Nottingham. The Senior Associate level analyst position will require strong understanding of network protocols and infrastructure, familiarity with troubleshooting and root cause analysis techniques. Additionally, the position requires a strong desire and aptitude for self-guided learning and growth. You will be in a rapidly evolving environment, that will bring new challenges and opportunities for growth on a regular basis and be empowered to develop and explore your unique passions in Cybersecurity Operations.

Your mission is to find the bad guys attempting to attack Capital One infrastructure and stop any malicious actors who make it past our defenses. You will not be staring at a SIEM hoping to find the actionable alert in a sea of noise; you will not simply be following a script and escalating alerts to a Tier 3 team. You will be responsible for investigations from start to finish, and for initiating your own investigations to locate malicious activity.

In addition to the technical skills, you will need to be someone who enjoys training and mentoring teammates, and a person who can encourage and elevate the team.

Basic Qualifications:

  • Demonstrable experience conducting Cybersecurity investigations into network and application activity
  • Demonstrable experience working in a Security Operations Centre (SOC) with SIEM technology
  • Demonstrable experience analyzing common application and network based attacks
  • Demonstrable experience working with *nix and Windows operating systems
  • Demonstrable experience interpreting, and identifying abuse in, routed and routing protocols and application traffic
  • Demonstrable experience leveraging core security and infrastructure technologies during investigations (e.g. firewall logs, network security tools, malware detonation devices, proxies, IPS/IDS)
  • Demonstrable experience with PCAP analysis, including extracting files and content from PCAPs, identifying gzipped content, and base64 detection

Preferred Qualifications:
  • Bachelor's Degree in Information Technology, Cyber Security, Computer Science, or equivalent military experience
  • SANS GIAC 503 or 504 Certifications
  • Security+ Certification
  • Previous hands-on experience with coordinating and supporting incident handling and remediation
  • Previous experience in a Cybersecurity operations role
  • Previous experience configuring security appliances
  • Previous experience developing SIEM alerts and IPS/IDS signatures

What's in it for you:
  • We are continuing our journey into the public cloud and have problems of scale, security, availability and performance for you to help solve.
  • We love continuous learning and that's why we give you 10% of your time to work on cutting-edge innovative projects that shape the way we will work in the future
  • We offer high performers strong and diverse career progression, investing heavily in developing great people through our Capital One University training programmes (and appropriate external providers)
  • Immediate access to our core benefits including pension scheme, bonus, generous holiday entitlement and private medical insurance - with flexible benefits available including season-ticket loans, cycle to work scheme and enhanced parental leave
  • Open-plan workspaces and facilities designed to inspire and support you. Our Nottingham head-office has a fully-serviced gym, subsidised restaurant, mindfulness and music rooms. In London, you can heighten your mood with a run on our rooftop running track or an espresso at the Workshop Coffee café
  • Find out more through our UK careers site ( or by exploring the @IAmCapitalOne Twitter tag.

Capital One is committed to diversity in the workplace.

Capital One is committed to diversity in the workplace.

If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at 1-800-304-9102 or via email at All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.

For technical support or questions about Capital One's recruiting process, please send an email to

Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.

Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).

Back to top