Lead SOC Analyst
We are recruiting three experienced Lead SOC Analysts to provide operational leadership within a 24/7 Security Operations Centre. Working alongside established SOC engineers and analysts, you will lead security monitoring, investigation, triage and escalation activities during your assigned shifts.
Key responsibilities
- Act as the Duty Lead for Security Monitoring during operational shifts.
- Lead the investigation of complex and high-priority cybersecurity events.
- Supervise and coordinate the work of Senior SOC Analysts.
- Review and quality-assure investigations, ensuring findings are accurate, evidence-based and fully documented.
- Make technical and operational decisions during live cyber events.
- Coordinate with Incident Responders, providing timelines, indicators of compromise and supporting evidence.
- Maintain effective handovers and continuity between shifts.
- Work with SOC Engineers to improve alert quality, monitoring coverage and operational effectiveness.
- Support the onboarding of new systems, applications and cloud services into SOC monitoring.
- Mentor and coach SOC Analysts, promoting consistent analytical and investigative standards.
Essential skills and experience
- Strong experience within a SOC or comparable cybersecurity operations environment.
- Proven experience leading security-monitoring activities and supervising analysts within a live operational service.
- Strong knowledge of SIEM platforms, log analysis, monitoring technologies and security event investigation.
- Experience investigating complex cyber events and determining appropriate escalation routes.
- Knowledge of cyberattack techniques, indicators of compromise, threat intelligence and defensive monitoring.
- Experience in incident investigation and response, intrusion detection, forensics, protective security and secure operations.
- Ability to make timely decisions within a fast-paced 24/7 environment.
- Strong analytical, problem-solving and communication skills.
- Experience mentoring or coaching technical staff.
- Relevant certification such as Microsoft SC-200, GIAC GCIH, GCIA, CompTIA CySA+ or equivalent.
Experience of Microsoft Sentinel, LogRhythm, MITRE ATT&CK, NCSC guidance, detection tuning or working within Government, Defence, Critical National Infrastructure or another regulated environment would be highly beneficial.
Working arrangementsThis is a site-based position at Hanslope Park, Milton Keynes, with no hybrid or remote-working option. The role operates a 24/7/365 Panama rota comprising 12-hour day and night shifts.
Security clearanceCandidates must be British nationals and capable of obtaining UK Government Developed Vetting, DV clearance. Current DV clearance is not mandatory, but candidates who already hold an active DV clearance will have a significant advantage due to the urgency of the requirement and the time associated with vetting.
What you need to do now
If you're interested in this role, click 'apply now' to forward an up-to-date copy of your CV, or call us now.
If this job isn't quite right for you, but you are looking for a new position, please contact us for a confidential discussion about your career.
Hays EA is a trading division of Hays Specialist Recruitment Limited and acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at hays.co.uk