Senior SOC Analyst

InfoSec People Ltd
UK
1 day ago
Apply on www.collegerecruiter.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Compensation
£82,000.0
Working hours
Regular working hours

Tech stack

Active Directory Microsoft Azure Cloud Computing Cyber Security Identity and Access Management Python (Programming Language) Microsoft Security Essentials Windows PowerShell Kusto Query Language Security Information and Event Management Scripting Office365
+3 more
Mitre Att&ck Mttr Cybercrime

Job description

This role sits at the sharp end of detection, investigation, and response. You’ll be responsible for handling complex security incidents, improving detection capability, and acting as a technical escalation point for the wider SOC team, while working closely with engineering, threat intelligence, and security leadership., * Act as the final escalation point for complex security alerts and incidents across the enterprise

  • Lead and coordinate incident response activities, including containment, eradication, and post-incident reviews
  • Perform advanced threat hunting and proactive investigations using SIEM, EDR, and cloud telemetry
  • Develop, tune, and optimise detection rules aligned to MITRE ATT&CK
  • Work extensively with the Microsoft Security stack, including Sentinel, Defender XDR, Entra ID, and M365 Security
  • Improve SOC processes, playbooks, and response procedures to reduce MTTD and MTTR
  • Support and mentor Level 1 and Level 2 analysts, raising overall SOC capability
  • Collaborate with wider security teams (engineering, IAM, cloud, risk) on remediation and security improvements
  • Provide clear technical reporting and recommendations to both technical and non-technical stakeholders

Requirements

  • Proven experience working as a Level 3 / Senior SOC Analyst or equivalent role
  • Strong hands-on experience with the Microsoft security ecosystem (Sentinel, Defender, MDE, MDI)
  • Deep understanding of incident response, attacker TTPs, and kill-chain methodologies
  • Experience creating and tuning SIEM detections and alerts
  • Strong knowledge of Windows environments, Active Directory, Azure, and M365
  • Experience with threat hunting and forensic investigation techniques
  • Comfortable working in a hybrid on-site model (1-3 days per week in London)
  • Experience in large-scale or enterprise environments
  • Exposure to retail, e-commerce, or high-volume customer-facing environments
  • Scripting or automation experience (PowerShell, KQL, Python)
  • Relevant certifications such as GCIA, GCED, GCIH, SC-200, or similar

Benefits & conditions

  • Salary up to £82,000 depending on experience
  • Annual performance bonus
  • Hybrid working (London-based, 1-3 days per week)
  • Opportunity to work in a high-impact SOC role within a well-funded security programme
  • Clear progression and the chance to influence SOC strategy and detection maturity

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.collegerecruiter.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

3:08 min

Aligning engineering processes with core business impact metrics

Chris Riley · World Congress 2021

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

3:07 min

Establishing service level agreements directly for internal platforms

Pawel Piwosz · LIVE

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

5:01 min

Bridging the gap between software development and security

Vandana Verma · LIVE

Videos

See all

Related articles

See all