SOC Level 3 Technical Lead
Senior SOC Analyst (Level 3)/Technical Lead | Buckinghamshire (hybrid)
A rapidly scaling managed security provider is hiring the most senior technical hire in its Security Operations Centre. The SOC runs around the clock protecting clients ranging from mid-market firms to household-name enterprises - but this role sits on a standard daytime pattern, with on-call participation for genuine emergencies only.
This is the job for someone who's outgrown alert triage and wants to own the hard problems: the ransomware call at the worst possible moment, the intrusion that's been dwelling for months, the investigation that ends up in front of regulators.
Salary: £60-70k DOE + competitive package
Location: Buckinghamshire (3 days onsite)
What You'll Do:
- Lead the most serious investigations in the client portfolio - ransomware, supply-chain compromise, data breaches, insider cases - owning the full life cycle from detection through recovery
- Make Real Time containment calls under pressure and brief client leadership, up to board level, in language they can act on
- Run proactive threat hunts and build detection content across SIEM, EDR and cloud platforms, tuning out noise as you go
- Develop SOAR playbooks and automation, and help shape the SOC's tooling roadmap and architecture
- Produce evidential-standard reporting fit for auditors, regulators and law enforcement
- Mentor the analyst team and act as senior escalation point for major incidents
What You'll Bring:
- 5+ years in incident response or SOC environments, ideally with managed services (MSSP) exposure
- A proven record leading complex investigations - ransomware and breach cases you can walk through in depth
- Advanced hands-on malware analysis capability, spanning behavioural analysis and reverse engineering
- Deep expertise across enterprise SIEM platforms and EDR tooling (CrowdStrike knowledge a strong advantage)
- A well-developed threat hunting toolkit: YARA rules, IOC development, timeline analysis and adversary profiling
- Cloud investigation experience - Azure and/or AWS incident response, log analysis and cloud-native threats
- The communication skills to translate deep technical findings for senior, non-technical audiences
- A natural mentoring style that helps Junior Analysts ask questions, learn and progress
Apply now or get in touch for a confidential discussion.
Oscar Associates (UK) Limited is acting as an Employment Agency in relation to this vacancy.
To understand more about what we do with your data please review our privacy policy in the privacy section of the Oscar website.