SOC Senior Analyst
Role details
Job location
Tech stack
Job description
- Lead the investigation and response to complex cyber security incidents across high-security customer environments
- Act as a senior escalation point for Tier 1 and Tier 2 analysts during active security events
- Drive proactive threat hunting campaigns to identify emerging threats, vulnerabilities, and anomalous behaviour
- Develop and improve detection logic, alerting, and monitoring content within SIEM platforms including Elastic Stack
- Analyse threat intelligence, indicators of compromise (IOCs), and attacker TTPs to strengthen detection capability
- Produce detailed post-incident reports with clear recommendations and improvement actions
- Support and mentor junior SOC analysts, helping develop technical capability across the team
- Collaborate with customers and internal stakeholders during incidents, communicating clearly with both technical and non-technical audiences
- Contribute to the ongoing evolution and improvement of our SOC services, processes, and operational standards
- Participate in technical forums, knowledge sharing, and continuous improvement initiatives
Technologies:
- Support
- Linux
- Security
- Splunk
- Windows
Requirements
- Current SC clearance and eligibility to obtain UK Government DV clearance
- Experience in Security Operations Centre (SOC) environments
- Experience in threat hunting and incident response
- Experience with SIEM technologies, ideally Elastic Stack
- Knowledge of threat intelligence and attacker methodologies
- Experience with Windows and Linux operating systems
- Strong networking fundamentals, including protocols, IP addressing, and traffic analysis
- Understanding of modern attacker techniques, including LOLBins and weaponised COTS tooling
- Experience using OSINT techniques and cyber threat analysis
- Experience leading investigations and supporting junior analysts
- Ability to communicate effectively during high-pressure incidents
- Desirable: experience in high-security or government-aligned environments
- Desirable: exposure to Elastic Stack, Splunk, Sentinel, or similar SIEM platforms
- Desirable: security certifications such as CISSP, CISM, CompTIA Security, or SecurityX
Benefits & conditions
We are DXC Technology, expanding our high-security Cyber Defence capability and growing our Security Operations Centre (SOC) team based in Farnborough. We support critical customer environments and deliver mission-critical technology and cyber security services to some of the worlds largest organisations. This is a Monday to Friday core-hours role with an on-call commitment from Farnborough. We foster a collaborative, diverse, and inclusive workplace and encourage applications from women, underrepresented groups, and neurodivergent candidates, with support and adjustments available throughout the hiring process. We offer a competitive salary, bonus, and a flexible benefits package including pension, private medical cover, and wellbeing programmes, along with opportunities for continuous learning, technical growth, and leadership development.