Position Summary As a SOC Shift Lead, you build on your solid experience as a SOC Analyst by supervising and guiding a team of SOC Analysts during your assigned shift. You ensure quality and consistency across all alerts and incidents handled by the team while serving as the primary point of escalation. In this role, you support team development, drive process improvements, and maintain clear, customer-centric communication with all stakeholders. You also lead quality assurance efforts and ensure that service-level agreements (SLAs) are met. Objectives & Key Results Key Responsibilities Shift Leadership and Team Coordination - You run shift operations, ensuring compliance with SLAs and maintaining high-quality incident handling. You set shift agendas, balance workloads, and promptly address any process or staffing issues. You also maintain effective, customer-centric communication with internal teams (including Security Optimisation and Engineering), customers, and their incident response partners Incident Triage and Investigation - You review and prioritise new alerts, taking initial ownership of high-priority or complex incidents, and ensure proper escalation to customers and Senior SOC Analysts. You make sound, data-driven decisions to facilitate effective triage, investigation, and escalation in line with operational standards Quality Assurance and Documentation - You conduct regular quality assurance (QA) of tickets to ensure SOC procedures and documentation standards are met, providing clear, constructive feedback to team members to improve technical skills and workflow consistency Collaboration and Mentorship - You mentor SOC Analysts in your team by offering regular, constructive feedback on triage processes and best practices. You encourage targeted training initiatives, including relevant certifications, to support career progression within the SOC Service Improvement - You contribute to ongoing service improvement through participation in supporting threat hunting activity led by Senior SOC Analysts, rule tuning, and process refinement initiatives. You assist in monthly reporting and post-incident reviews to drive improvements that reflect our commitment to transparent and reliable performance Required Qualifications & Experience You may be required to hold or obtain UK Non-Police Personnel Vetting (NPPV) and/or a Security Check (SC) clearance as part of this role Willingness to work towards or obtain intermediate cybersecurity certifications (e.g. SBT BTL2, CREST Registered Intrusion Analyst) Proficiency with SIEM platforms, endpoint security tools, and ticketing systems, with an ability to make clear, data-driven decisions under pressure Critical Competencies - Technical Fit Operating Systems - Possess detailed knowledge of Windows and Linux system architectures, with a clear understanding of how event logs (e.g., Windows Event Viewer, Syslog) reflect system security posture Networking and Protocols - Have a comprehensive understanding of TCP/IP, DNS, DCHP, VPNs, SSL/TLS, and network forensics concepts to validate network-based alerts and anomalies Cybersecurity Frameworks - Deeply understand and be able to articulate the elements of the MITRE ATT&CK framework, and Cyber Kill Chain; know how adversary tactics and techniques translate into observable indicators SIEM and Security Tools - Know the theoretical underpinnings of SIEM operations, including alert correlation, the design of automated detection rules, and the interpretation of aggregated security data Incident Triage - Understand the principles behind effective triage, including the rationale for using standardised playbooks and the criteria for escalating incidents without undertaking complex forensic analysis Threat Intelligence Integration - Be knowledgeable about the role and structure of threat intelligence - how feeds are sourced, what constitutes actionable information, and how malware indicators are defined Scripting and Automation - Understand the concepts behind using scripting for automating regular data extraction and log analysis, and the benefits such tools being to maintaining consistency in alert handling Benefits At Claranet, we go the extra mile with our people-because we believe in building a workplace where everyone feels valued and supported. What makes us unique is Team Claranet , our internal community that supports causes close to our employees' hearts. We offer paid charity leave, support local charities across our offices, and host annual fundraising events, all backed by a dedicated committee. We're proud founding members of TC4RE (Technology Community for Racial Equality) working collectively to build a more diverse and inclusive tech industry. About Claranet Founded at the beginning of the dot com bubble in 1996, our CEO Charles Nasser had a light bulb moment to develop a truly customer-focused IT business. Since then, Claranet has grown from an Internet Service Provider (ISP) in the UK to being one of the leading business modernisation experts, who deliver solutions across 11+ countries. Equal Opportunities Statement Diversity, equity and inclusion are at the heart of what we value as an organisation. Claranet is an equal opportunities employer and all qualified applicants will receive consideration for employment without regard to race, religion, sex, sexual orientation, age, disability or any other status protected by law. Our recruitment team are happy to support any reasonable adjustments that are needed within the recruitment process. Ready to take the next step in your career with Claranet? Click 'apply' - we can't wait to meet you! To view full job description please visit our careers page
Aug 24, 2026
Full time
Position Summary As a SOC Shift Lead, you build on your solid experience as a SOC Analyst by supervising and guiding a team of SOC Analysts during your assigned shift. You ensure quality and consistency across all alerts and incidents handled by the team while serving as the primary point of escalation. In this role, you support team development, drive process improvements, and maintain clear, customer-centric communication with all stakeholders. You also lead quality assurance efforts and ensure that service-level agreements (SLAs) are met. Objectives & Key Results Key Responsibilities Shift Leadership and Team Coordination - You run shift operations, ensuring compliance with SLAs and maintaining high-quality incident handling. You set shift agendas, balance workloads, and promptly address any process or staffing issues. You also maintain effective, customer-centric communication with internal teams (including Security Optimisation and Engineering), customers, and their incident response partners Incident Triage and Investigation - You review and prioritise new alerts, taking initial ownership of high-priority or complex incidents, and ensure proper escalation to customers and Senior SOC Analysts. You make sound, data-driven decisions to facilitate effective triage, investigation, and escalation in line with operational standards Quality Assurance and Documentation - You conduct regular quality assurance (QA) of tickets to ensure SOC procedures and documentation standards are met, providing clear, constructive feedback to team members to improve technical skills and workflow consistency Collaboration and Mentorship - You mentor SOC Analysts in your team by offering regular, constructive feedback on triage processes and best practices. You encourage targeted training initiatives, including relevant certifications, to support career progression within the SOC Service Improvement - You contribute to ongoing service improvement through participation in supporting threat hunting activity led by Senior SOC Analysts, rule tuning, and process refinement initiatives. You assist in monthly reporting and post-incident reviews to drive improvements that reflect our commitment to transparent and reliable performance Required Qualifications & Experience You may be required to hold or obtain UK Non-Police Personnel Vetting (NPPV) and/or a Security Check (SC) clearance as part of this role Willingness to work towards or obtain intermediate cybersecurity certifications (e.g. SBT BTL2, CREST Registered Intrusion Analyst) Proficiency with SIEM platforms, endpoint security tools, and ticketing systems, with an ability to make clear, data-driven decisions under pressure Critical Competencies - Technical Fit Operating Systems - Possess detailed knowledge of Windows and Linux system architectures, with a clear understanding of how event logs (e.g., Windows Event Viewer, Syslog) reflect system security posture Networking and Protocols - Have a comprehensive understanding of TCP/IP, DNS, DCHP, VPNs, SSL/TLS, and network forensics concepts to validate network-based alerts and anomalies Cybersecurity Frameworks - Deeply understand and be able to articulate the elements of the MITRE ATT&CK framework, and Cyber Kill Chain; know how adversary tactics and techniques translate into observable indicators SIEM and Security Tools - Know the theoretical underpinnings of SIEM operations, including alert correlation, the design of automated detection rules, and the interpretation of aggregated security data Incident Triage - Understand the principles behind effective triage, including the rationale for using standardised playbooks and the criteria for escalating incidents without undertaking complex forensic analysis Threat Intelligence Integration - Be knowledgeable about the role and structure of threat intelligence - how feeds are sourced, what constitutes actionable information, and how malware indicators are defined Scripting and Automation - Understand the concepts behind using scripting for automating regular data extraction and log analysis, and the benefits such tools being to maintaining consistency in alert handling Benefits At Claranet, we go the extra mile with our people-because we believe in building a workplace where everyone feels valued and supported. What makes us unique is Team Claranet , our internal community that supports causes close to our employees' hearts. We offer paid charity leave, support local charities across our offices, and host annual fundraising events, all backed by a dedicated committee. We're proud founding members of TC4RE (Technology Community for Racial Equality) working collectively to build a more diverse and inclusive tech industry. About Claranet Founded at the beginning of the dot com bubble in 1996, our CEO Charles Nasser had a light bulb moment to develop a truly customer-focused IT business. Since then, Claranet has grown from an Internet Service Provider (ISP) in the UK to being one of the leading business modernisation experts, who deliver solutions across 11+ countries. Equal Opportunities Statement Diversity, equity and inclusion are at the heart of what we value as an organisation. Claranet is an equal opportunities employer and all qualified applicants will receive consideration for employment without regard to race, religion, sex, sexual orientation, age, disability or any other status protected by law. Our recruitment team are happy to support any reasonable adjustments that are needed within the recruitment process. Ready to take the next step in your career with Claranet? Click 'apply' - we can't wait to meet you! To view full job description please visit our careers page
Senior SecOps Engineer - Microsoft Security UK Predominantly Remote Occasional presence in London Permanent We are partnering with a specialist Microsoft Security organisation looking to appoint two highly experienced Senior SecOps Engineers to its growing Microsoft Cyber Engineering team. This is not a traditional SOC Analyst position. We are looking for technically strong Microsoft Security Engineers with genuine hands-on experience designing, implementing, engineering and optimising Microsoft Sentinel and Defender solutions within enterprise customer environments. The organisation works extensively across the Microsoft Security portfolio and is looking for individuals who can bring significant technical depth while remaining hands-on with complex customer environments. The Role Working alongside Security Engineers, SOC Analysts and wider delivery teams, you will take responsibility for the implementation, optimisation and ongoing improvement of Microsoft security solutions. Responsibilities will include: Design, implementation and support of Microsoft Sentinel and Microsoft Defender / Defender XDR Engineering and optimisation of SIEM capabilities across enterprise environments Developing and tuning KQL queries, analytics and detection rules Designing and implementing SOC automation, playbooks and scripting Improving security event detection and response capabilities Conducting Microsoft tenant health checks, security audits and architecture reviews Analysing cloud security risks and recommending appropriate security controls Supporting complex incident triage and resolution Designing and documenting security engineering standards and processes Researching and implementing new Microsoft security capabilities Producing high-quality technical and customer-facing documentation Working directly with customers and technical stakeholders Supporting and mentoring more junior members of the engineering team Essential Experience To be considered, you should have strong commercial experience across the following: Microsoft Sentinel / Azure Sentinel Microsoft Defender / Defender XDR Strong KQL / Kusto Query Language capability Security Engineering, SOC Engineering or Microsoft Security Consulting SIEM engineering rather than solely alert monitoring or incident triage Detection engineering and security monitoring optimisation Automation, scripting, SOAR or Sentinel playbooks Cloud security assessments, controls and risk analysis Designing and documenting security processes Customer-facing technical delivery Candidates whose experience is predominantly L1/L2 SOC monitoring without hands-on Sentinel and Defender engineering are unlikely to be suitable for this position. Highly Desirable Experience across any of the following would be particularly valuable: Microsoft Purview Microsoft Defender for Endpoint Defender for Cloud Defender for Identity Defender for Office 365 Microsoft Entra ID Intune Azure security architecture Logic Apps / Sentinel playbooks PowerShell or Python MITRE ATT&CK Microsoft Security architecture and tenant assessments Previous experience working directly for Microsoft , or within a leading Microsoft Security Partner, MSSP or specialist Microsoft consultancy, would be highly advantageous. Microsoft Certifications Relevant Microsoft certifications are strongly preferred, particularly: SC-200 - Microsoft Security Operations Analyst AZ-500 - Azure Security Engineer Associate AZ-104 - Azure Administrator Associate AZ-305 - Azure Solutions Architect Expert Equivalent or additional Microsoft Security certifications will also be considered. The Opportunity This is an opportunity to join a highly specialised Microsoft Security environment rather than a broad IT or generalist cybersecurity function. You'll work alongside experienced security professionals on complex customer engagements, with significant exposure to the wider Microsoft Security ecosystem and continued investment in technical training and development. The position would particularly suit an established Microsoft Security Engineer who wants to remain technically hands-on while taking greater ownership of solution design, engineering standards, customer environments and the development of security operations capabilities. If your core expertise sits across Microsoft Sentinel, Defender and Security Operations Engineering , email your CV If you receive suspicious outreach claiming to be from us, please contact us via the ManpowerGroup website.
Aug 23, 2026
Full time
Senior SecOps Engineer - Microsoft Security UK Predominantly Remote Occasional presence in London Permanent We are partnering with a specialist Microsoft Security organisation looking to appoint two highly experienced Senior SecOps Engineers to its growing Microsoft Cyber Engineering team. This is not a traditional SOC Analyst position. We are looking for technically strong Microsoft Security Engineers with genuine hands-on experience designing, implementing, engineering and optimising Microsoft Sentinel and Defender solutions within enterprise customer environments. The organisation works extensively across the Microsoft Security portfolio and is looking for individuals who can bring significant technical depth while remaining hands-on with complex customer environments. The Role Working alongside Security Engineers, SOC Analysts and wider delivery teams, you will take responsibility for the implementation, optimisation and ongoing improvement of Microsoft security solutions. Responsibilities will include: Design, implementation and support of Microsoft Sentinel and Microsoft Defender / Defender XDR Engineering and optimisation of SIEM capabilities across enterprise environments Developing and tuning KQL queries, analytics and detection rules Designing and implementing SOC automation, playbooks and scripting Improving security event detection and response capabilities Conducting Microsoft tenant health checks, security audits and architecture reviews Analysing cloud security risks and recommending appropriate security controls Supporting complex incident triage and resolution Designing and documenting security engineering standards and processes Researching and implementing new Microsoft security capabilities Producing high-quality technical and customer-facing documentation Working directly with customers and technical stakeholders Supporting and mentoring more junior members of the engineering team Essential Experience To be considered, you should have strong commercial experience across the following: Microsoft Sentinel / Azure Sentinel Microsoft Defender / Defender XDR Strong KQL / Kusto Query Language capability Security Engineering, SOC Engineering or Microsoft Security Consulting SIEM engineering rather than solely alert monitoring or incident triage Detection engineering and security monitoring optimisation Automation, scripting, SOAR or Sentinel playbooks Cloud security assessments, controls and risk analysis Designing and documenting security processes Customer-facing technical delivery Candidates whose experience is predominantly L1/L2 SOC monitoring without hands-on Sentinel and Defender engineering are unlikely to be suitable for this position. Highly Desirable Experience across any of the following would be particularly valuable: Microsoft Purview Microsoft Defender for Endpoint Defender for Cloud Defender for Identity Defender for Office 365 Microsoft Entra ID Intune Azure security architecture Logic Apps / Sentinel playbooks PowerShell or Python MITRE ATT&CK Microsoft Security architecture and tenant assessments Previous experience working directly for Microsoft , or within a leading Microsoft Security Partner, MSSP or specialist Microsoft consultancy, would be highly advantageous. Microsoft Certifications Relevant Microsoft certifications are strongly preferred, particularly: SC-200 - Microsoft Security Operations Analyst AZ-500 - Azure Security Engineer Associate AZ-104 - Azure Administrator Associate AZ-305 - Azure Solutions Architect Expert Equivalent or additional Microsoft Security certifications will also be considered. The Opportunity This is an opportunity to join a highly specialised Microsoft Security environment rather than a broad IT or generalist cybersecurity function. You'll work alongside experienced security professionals on complex customer engagements, with significant exposure to the wider Microsoft Security ecosystem and continued investment in technical training and development. The position would particularly suit an established Microsoft Security Engineer who wants to remain technically hands-on while taking greater ownership of solution design, engineering standards, customer environments and the development of security operations capabilities. If your core expertise sits across Microsoft Sentinel, Defender and Security Operations Engineering , email your CV If you receive suspicious outreach claiming to be from us, please contact us via the ManpowerGroup website.
We're looking for a Senior SOC Analyst (L2 / L3) for our consultancy client supporting a major cyber security programme for a financial services organisation. This is an initial 6 month contract paying up to £600 per day Outside IR35. The role focuses on supporting security operations monitoring and incident response activities within a large enterprise environment. This role allows remote working with occasional travel to London when required. The successful SOC Analyst will possess proven skills working with the following - • Monitoring security alerts and events across enterprise environments • Investigating potential cyber security incidents and responding appropriately • Working with SIEM platforms such as Splunk, Sentinel or QRadar • Conducting threat analysis and triaging security alerts • Supporting incident response and remediation activities • Working with security engineering teams to improve detection capabilities Experience within financial services, fintech or other regulated environments would be beneficial. Interested? Please apply below SOC Analyst, Security Operations Analyst, Cyber Security Analyst, SIEM Analyst, Splunk, Microsoft Sentinel, Incident Response, Outside IR35 Contract
May 22, 2026
Contractor
We're looking for a Senior SOC Analyst (L2 / L3) for our consultancy client supporting a major cyber security programme for a financial services organisation. This is an initial 6 month contract paying up to £600 per day Outside IR35. The role focuses on supporting security operations monitoring and incident response activities within a large enterprise environment. This role allows remote working with occasional travel to London when required. The successful SOC Analyst will possess proven skills working with the following - • Monitoring security alerts and events across enterprise environments • Investigating potential cyber security incidents and responding appropriately • Working with SIEM platforms such as Splunk, Sentinel or QRadar • Conducting threat analysis and triaging security alerts • Supporting incident response and remediation activities • Working with security engineering teams to improve detection capabilities Experience within financial services, fintech or other regulated environments would be beneficial. Interested? Please apply below SOC Analyst, Security Operations Analyst, Cyber Security Analyst, SIEM Analyst, Splunk, Microsoft Sentinel, Incident Response, Outside IR35 Contract
Cyber Security Operations Manager Liverpool (Hybrid) - £70 000 - £75,000 We're working with a growing UK business looking to hire a Cyber Security Operations Manager to take full ownership of its security operations function, ensuring the organisation is protected, resilient, and continuously improving against an increasingly complex threat landscape. This is a high-impact position where you'll lead the security operations function end-to-end, driving improvements across threat detection, incident response, and overall security posture within a complex, evolving environment. The Role You'll take ownership of security operations, ensuring the business is protected against evolving threats while continuously improving processes, tooling, and team capability. Key responsibilities include: Leading the day-to-day operations of the Security Operations function, including oversight of any outsourced SOC Managing the full incident response lifecycle (detection through to recovery and post-incident review) Overseeing threat detection, vulnerability management, and cyber defence capabilities Driving improvements across SIEM, SOAR, EDR/XDR, and security tooling Ensuring robust monitoring, alerting, and response across cloud, network, and endpoint environments Partnering with Infrastructure, Cloud, and Risk teams to strengthen security across the business Leading and developing a team of cyber engineers and analysts Driving automation initiatives to improve response times and operational efficiency Supporting governance, compliance, and audit requirements Reporting on security performance, risks, and KPIs to senior stakeholders What We're Looking For Proven experience leading a Security Operations or SOC function Strong understanding of SIEM, SOAR, EDR/XDR, IDS/IPS, and security tooling Experience managing incident response and threat management in complex environments Strong knowledge of frameworks such as NIST, ISO 27001, or CIS Controls Experience working in cloud environments (Azure, AWS, or GCP) Strong leadership and stakeholder management skills Ability to balance hands-on technical understanding with strategic oversight Why Join? Opportunity to lead and shape the security operations function High visibility role across technology and leadership teams Business actively investing in cyber security and resilience If you're looking for a role where you can lead, influence, and strengthen cyber security at scale, we'd love to hear from you. Apply today with your most up to date CV. BH36094
May 19, 2026
Full time
Cyber Security Operations Manager Liverpool (Hybrid) - £70 000 - £75,000 We're working with a growing UK business looking to hire a Cyber Security Operations Manager to take full ownership of its security operations function, ensuring the organisation is protected, resilient, and continuously improving against an increasingly complex threat landscape. This is a high-impact position where you'll lead the security operations function end-to-end, driving improvements across threat detection, incident response, and overall security posture within a complex, evolving environment. The Role You'll take ownership of security operations, ensuring the business is protected against evolving threats while continuously improving processes, tooling, and team capability. Key responsibilities include: Leading the day-to-day operations of the Security Operations function, including oversight of any outsourced SOC Managing the full incident response lifecycle (detection through to recovery and post-incident review) Overseeing threat detection, vulnerability management, and cyber defence capabilities Driving improvements across SIEM, SOAR, EDR/XDR, and security tooling Ensuring robust monitoring, alerting, and response across cloud, network, and endpoint environments Partnering with Infrastructure, Cloud, and Risk teams to strengthen security across the business Leading and developing a team of cyber engineers and analysts Driving automation initiatives to improve response times and operational efficiency Supporting governance, compliance, and audit requirements Reporting on security performance, risks, and KPIs to senior stakeholders What We're Looking For Proven experience leading a Security Operations or SOC function Strong understanding of SIEM, SOAR, EDR/XDR, IDS/IPS, and security tooling Experience managing incident response and threat management in complex environments Strong knowledge of frameworks such as NIST, ISO 27001, or CIS Controls Experience working in cloud environments (Azure, AWS, or GCP) Strong leadership and stakeholder management skills Ability to balance hands-on technical understanding with strategic oversight Why Join? Opportunity to lead and shape the security operations function High visibility role across technology and leadership teams Business actively investing in cyber security and resilience If you're looking for a role where you can lead, influence, and strengthen cyber security at scale, we'd love to hear from you. Apply today with your most up to date CV. BH36094
We're expanding our Security Operations Centre in Farnborough and looking for sharp, collaborative L2 SOC Analysts to protect enterprise-scale environments across the Defence sector. You'll investigate real threats, tune detections, and make measurable impact-using Microsoft Sentinel, Splunk, and MISP. Your work fuels national security. Your growth fuels our mission. Role based on site in our Farnborough office and is shift work. 2 x 6am to 6pm, 2 x 6pm to 6am, 4 days off. You do need to be eligible for DV Clearance for this role, and cannot start until your clearance is through. What you'll be doing: Monitor, analyse security alerts and events, conduct initial investigations, and determine the appropriate response. Raise complex incidents to Senior Analysts. Manage SOC Incident queues. Support the maintenance of monitored asset baselines of the customer environments. Prepare reports for managed clients to both technical and non-technical audiences, Collaborate on improving detection rules and use cases aligned with Mitre Att&ck and threat-informed defense. Participate in a team effort to guarantee that corporate data and technology platform components are shielded from known threats. Collaborate with team members to maintain and update security incident documentation, including incident reports, analysis findings, and recommended mitigation strategies. Aid the development and use of threat intelligence throughout the service. Ability to work shifts from our office in Farnborough. What you'll bring: Experience demonstrated in Security Operations Centre. Experience using Microsoft Sentinel and Splunk. Knowledge and experience with Mitre Att&ck Framework. Basic knowledge of client-server applications, multi-tier web applications, relational databases, firewalls, VPNs, and enterprise AntiVirus products. Understanding of networking principles including TCP/IP, WANs, LANs and commonly used Internet protocols such as SMTP, HTTP, FTP, POP, LDAP. Entry level cyber security certification (e.g. CompTIA Security+, CEH, CPSA). CREST Practitioner Intrusion Analyst/Blue Teams Level 1 or other SOC related certifications. Completed an academic module in cyber security or a related subject It would be great if you had: Programming and scripting such as Python, Perl, Bash, PowerShell, C++. CREST Practitioner Intrusion Analyst/Blue Teams Level 1 or other SOC related certifications. Experience with SIEM technologies, namely Sentinel and Splunk, with some experience with QRadar. If you are interested in this role but not sure if your skills and experience are exactly what we're looking for, please do apply, we'd love to hear from you! Employment Type: Permanent Location: Office based in Farnborough Security Clearance Level: Eligible for DV Clearance Internal Recruiter: Jane Salary: To £58K Depending on experience, plus on shift allowance. Benefits: 25 days annual leave with the choice to buy additional days, health cash plan, life assurance, pension. Loved reading about this job and want to know more about us? Sopra Steria's Aerospace, Defence and Security business designs, develops and deploys digital solutions to Central Government clients. The work we do makes a real difference to the client's goal of National Security, and we operate in a unique and privileged environment. We are given time for professional development activities, and we coach and mentor our colleagues, sharing knowledge and learning from each other. We foster a culture in which employees feel valued and supported and have pride in their work for the customer, delivering outstanding rates of customer satisfaction in the UK's most complex safety- and security-critical markets.
May 03, 2026
Full time
We're expanding our Security Operations Centre in Farnborough and looking for sharp, collaborative L2 SOC Analysts to protect enterprise-scale environments across the Defence sector. You'll investigate real threats, tune detections, and make measurable impact-using Microsoft Sentinel, Splunk, and MISP. Your work fuels national security. Your growth fuels our mission. Role based on site in our Farnborough office and is shift work. 2 x 6am to 6pm, 2 x 6pm to 6am, 4 days off. You do need to be eligible for DV Clearance for this role, and cannot start until your clearance is through. What you'll be doing: Monitor, analyse security alerts and events, conduct initial investigations, and determine the appropriate response. Raise complex incidents to Senior Analysts. Manage SOC Incident queues. Support the maintenance of monitored asset baselines of the customer environments. Prepare reports for managed clients to both technical and non-technical audiences, Collaborate on improving detection rules and use cases aligned with Mitre Att&ck and threat-informed defense. Participate in a team effort to guarantee that corporate data and technology platform components are shielded from known threats. Collaborate with team members to maintain and update security incident documentation, including incident reports, analysis findings, and recommended mitigation strategies. Aid the development and use of threat intelligence throughout the service. Ability to work shifts from our office in Farnborough. What you'll bring: Experience demonstrated in Security Operations Centre. Experience using Microsoft Sentinel and Splunk. Knowledge and experience with Mitre Att&ck Framework. Basic knowledge of client-server applications, multi-tier web applications, relational databases, firewalls, VPNs, and enterprise AntiVirus products. Understanding of networking principles including TCP/IP, WANs, LANs and commonly used Internet protocols such as SMTP, HTTP, FTP, POP, LDAP. Entry level cyber security certification (e.g. CompTIA Security+, CEH, CPSA). CREST Practitioner Intrusion Analyst/Blue Teams Level 1 or other SOC related certifications. Completed an academic module in cyber security or a related subject It would be great if you had: Programming and scripting such as Python, Perl, Bash, PowerShell, C++. CREST Practitioner Intrusion Analyst/Blue Teams Level 1 or other SOC related certifications. Experience with SIEM technologies, namely Sentinel and Splunk, with some experience with QRadar. If you are interested in this role but not sure if your skills and experience are exactly what we're looking for, please do apply, we'd love to hear from you! Employment Type: Permanent Location: Office based in Farnborough Security Clearance Level: Eligible for DV Clearance Internal Recruiter: Jane Salary: To £58K Depending on experience, plus on shift allowance. Benefits: 25 days annual leave with the choice to buy additional days, health cash plan, life assurance, pension. Loved reading about this job and want to know more about us? Sopra Steria's Aerospace, Defence and Security business designs, develops and deploys digital solutions to Central Government clients. The work we do makes a real difference to the client's goal of National Security, and we operate in a unique and privileged environment. We are given time for professional development activities, and we coach and mentor our colleagues, sharing knowledge and learning from each other. We foster a culture in which employees feel valued and supported and have pride in their work for the customer, delivering outstanding rates of customer satisfaction in the UK's most complex safety- and security-critical markets.