SOC Manager

IMPORTANT:

  • THIS IS A SOC ROLE.
  • No recruiters or recruitment agencies, please.
  • You must be UK based. We cannot provide visa sponsorship.
  • Previous experience working as a SOC Manager within a Managed Security Service Provider (MSSP) is mandatory. Applications that do not meet this requirement will not progress.

Overview:

๐Ÿ’ฐ Salary: ยฃ75,000+, depending on experience.

๐Ÿ–๏ธ Holiday: 24 days, pro rata, plus your birthday off, bank holidays and one additional day for every 12 months you stay with us.

๐Ÿข Working Together: Three days per week in our Canary Wharf office, 39 floors up ๐Ÿ‘€, with flexibility for the remaining two days.

๐Ÿ•ฐ๏ธ Working Hours: 40 hours, Monday to Friday, with occasional support for serious incidents outside normal hours.

๐ŸŽ“ Training: An individual training plan and budget for one professional certification or course each year.

๐Ÿบ Socials: Regular drinks, team activities and the occasional bit of axe throwing.

๐Ÿพ Start Date: October 2026.

Minimum Requirements

You must meet all five requirements below. Please do not apply if you do not.

1. Mandatory MSSP experience: You must have previous experience working specifically as a SOC Manager within an MSSP, delivering security operations services to multiple external clients rather than managing only an internal SOC.

2. Technical security operations experience: You must have strong practical knowledge of SIEM, EDR/XDR, incident investigation and response, detection engineering, alert triage, threat intelligence, threat hunting, SOAR, automation and SOC reporting. Experience with Microsoft Sentinel, Microsoft Defender XDR and the wider Microsoft security ecosystem is strongly desirable.

3. Fluent business English: This is a senior, client-facing role. You must communicate complex security and operational matters clearly and confidently in spoken and written English, including executive briefings, incident communications, governance meetings and formal reports. Communication skills will be assessed during recruitment.

4. Location: You must live within approximately 90 minutesโ€™ commuting distance of Canary Wharf, London.

5. Education: A technical academic background in computer science, cyber security, information security, software engineering or a related field is desirable. A degree is not mandatory and equivalent professional experience or qualifications will be considered.

About CyPro

  • CyPro is an innovative cyber security business with a shared mission: to redefine cyber security for small and medium-sized businesses.
  • Our founders, Jonny and Rob, built their early careers delivering cyber security for large enterprises and central government. They saw a need for a different approach for smaller organisations.
  • We help clients prevent attacks, secure larger customers and scale confidently. This role offers the opportunity to shape a growing SOC alongside experienced professionals.

The Role

  • As SOC Manager, you will be accountable for the day-to-day delivery of CyProโ€™s 24/7 managed detection and response services across a portfolio of clients.
  • You will lead SOC Analysts, maintain operational quality and act as a senior client contact.
  • You will own service performance, incident escalation, detection coverage and continuous improvement.
  • This is not a role where you simply supervise an alert queue. You must understand the technology, challenge poor-quality output and continually improve the service.
  • All CyPro employees are expected to be strong problem-solvers, adaptable and comfortable taking ownership in a fast-paced environment with limited guardrails.

๐Ÿ† Client Delivery and Service Management

  • Own managed detection and response delivery across a portfolio of clients.
  • Act as the primary operational escalation point for clients and internal teams.
  • Lead service reviews, governance meetings and executive briefings.
  • Present incidents, trends, risks and recommendations clearly and commercially.
  • Own performance against SLAs, KPIs and contractual commitments.
  • Monitor incident trends, detection coverage, alert volumes, false positives and response performance.
  • Create service improvement plans where quality falls below expectations.
  • Lead client onboarding and service transition, coordinating deployment, documentation and stakeholders.
  • Manage major incident escalations and ensure responses are controlled, communicated and documented.

๐Ÿ’๐Ÿผ Team Leadership and People Management

  • Line manage and develop SOC Analysts and Senior SOC Analysts.
  • Set clear expectations and hold team members accountable for quality and timeliness.
  • Conduct one-to-ones, performance reviews and career development discussions.
  • Build development plans and support career progression.
  • Review investigations, incident reports and client communications.
  • Manage workload, capacity, priorities and operational coverage.
  • Support recruitment, assessment and onboarding.
  • Act as a role model for professionalism, ownership and delivery quality.

๐Ÿ›ก๏ธ Detection, Investigation and Response

  • Maintain oversight of detection coverage across client environments.
  • Ensure alerts and incidents are investigated consistently and appropriately.
  • Provide technical guidance during complex or high-severity incidents.
  • Work with analysts, engineers and platform specialists to develop detection use cases.
  • Improve detection logic and reduce false positives without weakening coverage.
  • Oversee onboarding of new log sources and security technologies.
  • Identify opportunities to automate repetitive investigation and response activities.
  • Track alert quality, triage, investigation, containment and automation performance.
  • Use operational data to identify weaknesses and drive improvement.
  • Support threat hunting and the use of threat intelligence.
  • Turn incident lessons into improved detections, playbooks and response procedures.
  • Maintain awareness of emerging threats, attacker techniques and SOC technologies.

โš™๏ธ Service Improvement and Practice Development

  • Own and improve runbooks, playbooks, workflows and operational procedures.
  • Ensure documentation is clear, current and usable during live incidents.
  • Standardise investigation, escalation and reporting across client accounts.
  • Develop repeatable operating models that allow the SOC to scale without reducing quality.
  • Improve quality assurance for alerts, incidents and client deliverables.
  • Improve client reporting and service governance.
  • Contribute to new managed detection and response services.
  • Evaluate security technologies, automation and AI-supported SOC tooling.
  • Support proofs of concept and vendor assessments.
  • Align operational priorities with the wider SOC roadmap.

๐Ÿ“ˆ Commercial and Business Development

  • Support pre-sales discussions for managed detection and response opportunities.
  • Explain CyProโ€™s SOC capabilities clearly to prospective clients.
  • Contribute to service designs, proposals, pricing and Statements of Work.
  • Estimate onboarding effort, service capacity and technical resource requirements.
  • Identify opportunities to improve or expand services for existing clients.
  • Understand account profitability and the relationship between scope, capacity and delivery cost.
  • Ensure additional requests are assessed, scoped and commercially agreed.

๐ŸŽ“ Professional Development

  • Maintain your technical and professional credibility through relevant learning and industry engagement.
  • Strong candidates will typically hold two or more relevant certifications, or demonstrate equivalent experience. Examples include Microsoft SC-200, AZ-500, CISSP, CISM, GCIA, GCIH, CompTIA CySA+ and CREST Certified Intrusion Analyst.

๐Ÿง  Soft Skills

  • Effective: You remove obstacles, establish ownership and drive work through to completion.
  • Accountable and Humble: You take responsibility for SOC performance, accept feedback and change your approach when needed.
  • Calm Under Pressure: You remain structured, prioritise clearly and communicate confidently during serious incidents.
  • Technically Credible: You understand security operations well enough to challenge investigations, identify weak reasoning and guide the team.
  • Client Focused: You provide timely communication, clear recommendations and confidence that the service is well managed.
  • People Developer: You invest in your team, give direct feedback and address poor performance.
  • Commercially Aware: You balance strong security outcomes with contractual scope, resources and sustainable delivery.
  • Adaptable: You make sensible decisions in an evolving environment and help build processes that do not yet exist.

๐Ÿ’ป Interview Process

We can generally take candidates through the full process within 10 days ๐ŸŽ‰.

๐Ÿ“ž Telephone Interview: A 20-minute initial conversation with a senior member of the Cyber Security team.

๐Ÿงช Psychometric Testing: Three 15-minute cognitive assessments.

๐ŸŽฎ Assessment Centre: A morning in our Canary Wharf office involving practical exercises and a final interview with a practice partner.

Job Details

Company
CyPro
Location
City of London, London, United Kingdom
Posted