Senior SOC Engineer
Location: Home-based — two days a month in the office (SE location) all travel paid
Salary: Up to £70,000 Type: Permanent, full time Hours: Monday to Friday, 9:00am – 5:30pm — no shifts, no on-call
This is a genuinely home-based role. Two days a month on site in Basingstoke, with travel and expenses covered in full.
The roleThis is a build role, not a monitoring one.
You'll be the engineer behind the SOC — designing and running the Microsoft security platform the analysts depend on. If you've spent time in a SOC wishing you could fix the tooling rather than work around it, this is that job.
You'll join an established Security Operations team as new headcount, reporting to the Lead SOC Engineer. This is a managed security service provider, so you'll see a far wider range of customer environments and problems than any single in-house SOC would give you — and you'll lead the engineering side of onboarding new customers onto the platform.
What you'll be doing- Designing and maintaining the SIEM and XDR platform — data ingestion, log parsing and normalisation, retention, performance
- Writing and tuning detections in KQL, and building automation to cut manual analyst effort
- Scripting custom connectors and integrations across the security toolset
- Leading the technical onboarding of new customers alongside SOC Operations
- Acting as senior escalation for complex engineering issues
- Supporting and mentoring engineers and analysts across the team
- Around 3–5 years in a Security Operations Centre in an engineering or platform capacity
- Strong Microsoft Sentinel experience, with confident KQL
- Hands-on with Microsoft Defender and the wider Microsoft security stack — Intune, Entra ID, Defender for Endpoint
- Exposure to endpoint tooling such as CrowdStrike, Carbon Black or Darktrace
- Scripting in Python or PowerShell for automation and log analysis
- Some vulnerability management experience — Tenable, Rapid7, Qualys or similar
- Automation and orchestration exposure — Logic Apps, Cortex XSOAR or similar — is welcome but not essential
- Eligible for UK SC or DV security clearance — essential
Experience at an MSSP, MDR provider or security reseller is a real advantage, though we're equally happy to hear from strong in-house SOC engineers. You don't need every tool on this list. Strong Sentinel and KQL with a willingness to develop the rest is enough.
What's on offer- Up to £65,000 depending on experience
- Fully home-based, with two paid trips a month to Basingstoke
- Genuine 9-to-5 — no shift rota, no on-call
- New headcount in a growing team
- Access to lab environments, cyber ranges and hands-on training labs
- Certification and training support with a clear technical progression path
- Exposure to enterprise security estates across multiple industries
Apply through Reed with an up-to-date CV, or get in touch for a confidential conversation.
Fazer Recruitment is acting as an employment agency in relation to this vacancy.