Senior SOC Analyst
Location: London
Salary: Up to £80,000
Working pattern: Four days per week on site in London, with one day working remotely
We are looking for an experienced Senior SOC Analyst to join a growing security operations team in London.
This is a hands-on position for someone with strong incident detection, investigation and response experience. You will take the lead on complex security incidents, support the development of junior analysts and help improve the organisation’s overall detection and response capabilities.
Key responsibilities
- Investigating and responding to complex security alerts and incidents
- Leading incident triage, containment and remediation activities
- Performing threat hunting and identifying suspicious behaviour across the environment
- Developing and improving SIEM rules, alerts and security use cases
- Analysing endpoint, network, cloud and identity-related security events
- Producing clear incident reports and communicating findings to technical and non-technical stakeholders
- Supporting the development and mentoring of junior SOC analysts
- Improving SOC processes, playbooks and response procedures
- Working with wider security and infrastructure teams to address vulnerabilities and strengthen security controls
- Supporting continuous improvement across the SOC
Skills and experience
- Strong experience working in a SOC or security operations environment
- Demonstrable experience investigating and responding to security incidents
- Good knowledge of SIEM, EDR and security monitoring technologies
- Experience analysing logs from endpoints, networks, cloud platforms and identity services
- Understanding of common attack techniques and frameworks such as MITRE ATT&CK
- Strong knowledge of incident response processes and security best practices
- Experience creating or tuning detection rules and security use cases
- The ability to communicate complex security issues clearly
- A proactive and analytical approach to problem-solving
Experience with threat hunting, security automation, scripting or cloud security would be particularly beneficial.
This role offers the opportunity to take ownership of complex investigations, influence how the SOC operates and play an important part in developing the organisation’s security capabilities.
Applicants must be comfortable working four days per week on site in London.