SOC Analyst - SC Cleared

Sanderson Recruitment Plc
London, UK
5 days ago
Apply on www.careerboard.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Compensation
£141,700.0 - £153,400.0
Working hours
Regular working hours

Tech stack

Amazon Web Services Microsoft Azure Cloud Computing Security Cyber Security Digital Forensics Intrusion Detection and Prevention Network Security Security Information and Event Management Software Vulnerability Management Data Logging Google Cloud Cyber Threat Analysis
+5 more
SC Clearance Cybercrime Splunk Security Orchestration, Automation & Response Vulnerability Analysis

Job description

We are seeking two experienced SOC Analysts to join a specialist consultancy delivering cyber security services across a portfolio of government projects and digital transformation programmes.

This is an excellent opportunity to work within complex and dynamic security environments, helping clients protect critical services, systems, and data against evolving cyber threats. The successful candidates will play a key role in security monitoring, incident response, detection engineering, and threat analysis, working alongside Security Operations, Threat Intelligence, and Incident Response teams.

You will act as a cyber security subject matter expert, helping to strengthen defensive capabilities while contributing to the continuous improvement of security operations, threat detection, and incident response functions. Key Responsibilities

Security Monitoring & Incident Response

  • Monitor and triage security alerts generated through SIEM and security tooling.
  • Investigate and respond to cyber security incidents across cloud, endpoint, and network environments.
  • Analyse security events to determine impact, severity, and appropriate response actions.
  • Support incident containment, remediation, and post-incident review activities.
  • Participate in incident response exercises and security simulations.

Detection Engineering

  • Develop, maintain, and optimise security detection content within Splunk SIEM.
  • Create and refine correlation searches, use cases, alerts, and detection rules.
  • Identify gaps in detection coverage and recommend improvements.
  • Work closely with security teams to improve visibility and enhance monitoring capabilities.
  • Support the onboarding and optimisation of new log sources.

Security Operations Improvement

  • Review and enhance security operations processes, standards, and procedures.
  • Identify trends in incidents, attack patterns, and security monitoring activity.
  • Recommend improvements to logging, monitoring, alerting, and response capabilities.
  • Support service improvement and operational efficiency initiatives.

Threat Intelligence & Threat Hunting

  • Remain current with emerging cyber threats, threat actors, vulnerabilities, and attack techniques.
  • Leverage threat intelligence to improve detection and response capabilities.
  • Support proactive threat hunting activities.
  • Research adversary tactics, techniques, and procedures (TTPs) relevant to highly regulated environments.

Technical Leadership

  • Act as an escalation point for Junior Analysts.
  • Provide mentoring, coaching, and knowledge-sharing support.
  • Contribute to capability development across the wider security team.
  • Present technical findings and recommendations to stakeholders when required.

Additional Responsibilities

Depending on project requirements, responsibilities may also include:

  • Proactive threat hunting
  • Detection engineering and use-case development
  • Incident response playbook creation
  • Threat intelligence collection and analysis
  • Vulnerability assessment and reporting
  • Security change approval activities
  • Security capability enhancement initiatives

Requirements

  • Demonstrable experience working within a Security Operations Centre (SOC) environment.
  • Strong experience in security monitoring, alert triage, and incident investigation.
  • Hands-on experience with:
  • Splunk
  • SIEM technologies
  • Endpoint security tools
  • Security monitoring platforms
  • Experience developing and improving detection content and alert logic.
  • Strong understanding of incident response processes and cyber security operations.
  • Knowledge of network security concepts and attack methodologies.
  • Excellent analytical, investigative, and problem-solving skills.
  • Strong communication and stakeholder engagement capabilities.
  • Active SC Clearance.

Desirable Skills & Knowledge

Experience in one or more of the following areas would be advantageous:

  • Detection Engineering and Alert Development
  • Threat Hunting
  • Threat Intelligence Analysis
  • Security Automation and Orchestration
  • Incident Response Playbook Development
  • Vulnerability Management
  • Cloud Security (AWS, Azure, GCP)
  • Digital Forensics

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerboard.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

4:23 min

Boosting security operations center productivity with intelligent data analysis

Chris Wysopal Chris Wysopal +2 · World Congress 2024

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all