Duty Manager / SOC Analyst (DV Cleared) Location: Hounslow Park (On-site) Salary: 65,000 + 10,000 Bonus Employment Type: Permanent Security Clearance: Must hold current MOD DV Clearance Nationality Requirement: Sole UK Nationals only Overview We are seeking an experienced Duty Manager / SOC Analyst to join a high-profile operational environment, supporting critical services within a secure, live operations centre. This is a unique hybrid position that combines operational leadership with technical awareness . You'll take ownership of the live operational picture, coordinating incident response across cyber, network, infrastructure and physical security teams while ensuring informed, timely decision-making. This role is ideal for someone who thrives in a fast-paced control room environment and can confidently lead operational response without needing to be a deep technical specialist. Key Responsibilities Maintain a single operational view across cyber, network, service and physical security domains. Monitor live operational environments and assess alerts and incidents in real time. Perform initial triage and validation of alerts, reducing noise and ensuring accurate incident classification. Control incident prioritisation and escalation in line with operational procedures. Coordinate activities across SOC, NOC, Infrastructure and Security teams. Support and lead Major Incident Management activities where required. Maintain accurate operational logs, dashboards and reporting. Deliver effective shift handovers and maintain continuous situational awareness. About the Role This position is intentionally balanced between operational leadership and technical understanding: 60% Operational Leadership & Coordination 40% Technical Awareness & Incident Triage You'll be expected to understand operational and technical information, ask the right questions, coordinate the right teams and maintain control during high-pressure situations. Essential Skills & Experience Experience within a SOC, NOC, Major Incident Management or 24/7 Operations Centre . Good understanding of SOC and NOC workflows, including alert triage and escalation processes. Ability to interpret monitoring alerts, operational dashboards and logs at a high level. Strong understanding of incident severity, business impact and prioritisation. Proven experience coordinating multiple technical teams during live incidents. Excellent communication, decision-making and stakeholder management skills. Ability to remain calm and organised in time-critical operational environments. Ideal Background We would particularly welcome applications from candidates with experience as: Major Incident Manager with technical exposure. Senior SOC Analyst or NOC Analyst with leadership responsibilities. Service Operations Lead within a 24/7 operations or command centre. Operational Duty Manager supporting secure or critical environments. What's on Offer 65,000 basic salary. 10,000 annual bonus. Permanent position. Opportunity to work within a highly secure, mission-critical environment. Challenging and rewarding operational leadership role with significant responsibility. Eligibility Requirements Due to the nature of this position, applicants must : Hold current MOD Developed Vetting (DV) Clearance . Be a sole UK national . Be able to work full-time on-site in Hounslow Park .
Jul 31, 2026
Full time
Duty Manager / SOC Analyst (DV Cleared) Location: Hounslow Park (On-site) Salary: 65,000 + 10,000 Bonus Employment Type: Permanent Security Clearance: Must hold current MOD DV Clearance Nationality Requirement: Sole UK Nationals only Overview We are seeking an experienced Duty Manager / SOC Analyst to join a high-profile operational environment, supporting critical services within a secure, live operations centre. This is a unique hybrid position that combines operational leadership with technical awareness . You'll take ownership of the live operational picture, coordinating incident response across cyber, network, infrastructure and physical security teams while ensuring informed, timely decision-making. This role is ideal for someone who thrives in a fast-paced control room environment and can confidently lead operational response without needing to be a deep technical specialist. Key Responsibilities Maintain a single operational view across cyber, network, service and physical security domains. Monitor live operational environments and assess alerts and incidents in real time. Perform initial triage and validation of alerts, reducing noise and ensuring accurate incident classification. Control incident prioritisation and escalation in line with operational procedures. Coordinate activities across SOC, NOC, Infrastructure and Security teams. Support and lead Major Incident Management activities where required. Maintain accurate operational logs, dashboards and reporting. Deliver effective shift handovers and maintain continuous situational awareness. About the Role This position is intentionally balanced between operational leadership and technical understanding: 60% Operational Leadership & Coordination 40% Technical Awareness & Incident Triage You'll be expected to understand operational and technical information, ask the right questions, coordinate the right teams and maintain control during high-pressure situations. Essential Skills & Experience Experience within a SOC, NOC, Major Incident Management or 24/7 Operations Centre . Good understanding of SOC and NOC workflows, including alert triage and escalation processes. Ability to interpret monitoring alerts, operational dashboards and logs at a high level. Strong understanding of incident severity, business impact and prioritisation. Proven experience coordinating multiple technical teams during live incidents. Excellent communication, decision-making and stakeholder management skills. Ability to remain calm and organised in time-critical operational environments. Ideal Background We would particularly welcome applications from candidates with experience as: Major Incident Manager with technical exposure. Senior SOC Analyst or NOC Analyst with leadership responsibilities. Service Operations Lead within a 24/7 operations or command centre. Operational Duty Manager supporting secure or critical environments. What's on Offer 65,000 basic salary. 10,000 annual bonus. Permanent position. Opportunity to work within a highly secure, mission-critical environment. Challenging and rewarding operational leadership role with significant responsibility. Eligibility Requirements Due to the nature of this position, applicants must : Hold current MOD Developed Vetting (DV) Clearance . Be a sole UK national . Be able to work full-time on-site in Hounslow Park .
SOC Analyst 50,000- 54,000 Hybrid - up to 2 days per week in either Glasgow/Edinburgh office We are looking for a brilliant SOC Analyst to join a market leading organisation within the energy sector embarking on a transformation of their IT Security Team. This well-established company owns and manages critical national infrastructure and is engaging in a forward funded futureproofing program with enormous potential for growth. Information Security is an integral part of their business operation, so this role is critical to the business. Within this role, you will be responsible for ensuring the IT and OT networks are secure, managed and maintained in line with policies and legal and regulatory requirements. You will act as the Security subject matter expert in your respective area and act as the primary contact when assisting with Security Incident remediation. You will possess strong technical and security knowledge, and will provide technical/non technical security support to the wider Security team and organisation. We are looking for an individual that has: Expertise in Cloud (IaaS, PaaS, SaaS) in particular AWS, MS Sentinel and Defender Good understanding of Security Operations and related security tools such as Firewalls, VPN Gateway, SIEM, SOAR, EDR, MDR, UEBA, DLP Good understanding and practical experience of Cyber Security Frameworks and standards such as NCSC security principles, NIST Framework, ISO 27001, ISO27005, IEC62443 etc. Experience and knowledge of Industrial Control Systems is advantageous, but you will be provided with the opportunity to learn new technical skills. Right to work in the UK - you must have lived in the UK for at least 5 years - you will be required to be Security Cleared.
Jul 31, 2026
Full time
SOC Analyst 50,000- 54,000 Hybrid - up to 2 days per week in either Glasgow/Edinburgh office We are looking for a brilliant SOC Analyst to join a market leading organisation within the energy sector embarking on a transformation of their IT Security Team. This well-established company owns and manages critical national infrastructure and is engaging in a forward funded futureproofing program with enormous potential for growth. Information Security is an integral part of their business operation, so this role is critical to the business. Within this role, you will be responsible for ensuring the IT and OT networks are secure, managed and maintained in line with policies and legal and regulatory requirements. You will act as the Security subject matter expert in your respective area and act as the primary contact when assisting with Security Incident remediation. You will possess strong technical and security knowledge, and will provide technical/non technical security support to the wider Security team and organisation. We are looking for an individual that has: Expertise in Cloud (IaaS, PaaS, SaaS) in particular AWS, MS Sentinel and Defender Good understanding of Security Operations and related security tools such as Firewalls, VPN Gateway, SIEM, SOAR, EDR, MDR, UEBA, DLP Good understanding and practical experience of Cyber Security Frameworks and standards such as NCSC security principles, NIST Framework, ISO 27001, ISO27005, IEC62443 etc. Experience and knowledge of Industrial Control Systems is advantageous, but you will be provided with the opportunity to learn new technical skills. Right to work in the UK - you must have lived in the UK for at least 5 years - you will be required to be Security Cleared.
CBSbutler Holdings Limited trading as CBSbutler
Hanslope, Buckinghamshire
SOC Analyst (DV Cleared) Location: Hanslope Park, Milton Keynes Salary: 65,000 + 10,000 Bonus Employment Type: Permanent Security Clearance: Must hold current MOD DV Clearance Nationality Requirement: Sole UK Nationals only Overview We are seeking an experienced SOC Analyst to join a high-profile operational environment, supporting critical services within a secure, live operations centre. This is a unique hybrid position that combines operational leadership with technical awareness . You'll take ownership of the live operational picture, coordinating incident response across cyber, network, infrastructure and physical security teams while ensuring informed, timely decision-making. This role is ideal for someone who thrives in a fast-paced control room environment and can confidently lead operational response without needing to be a deep technical specialist. Key Responsibilities Maintain a single operational view across cyber, network, service and physical security domains. Monitor live operational environments and assess alerts and incidents in real time. Perform initial triage and validation of alerts, reducing noise and ensuring accurate incident classification. Control incident prioritisation and escalation in line with operational procedures. Coordinate activities across SOC, NOC, Infrastructure and Security teams. Support and lead Major Incident Management activities where required. Maintain accurate operational logs, dashboards and reporting. Deliver effective shift handovers and maintain continuous situational awareness. About the Role This position is intentionally balanced between operational leadership and technical understanding: 60% Operational Leadership & Coordination 40% Technical Awareness & Incident Triage You'll be expected to understand operational and technical information, ask the right questions, coordinate the right teams and maintain control during high-pressure situations. Essential Skills & Experience Experience within a SOC, NOC, Major Incident Management or 24/7 Operations Centre . Good understanding of SOC and NOC workflows, including alert triage and escalation processes. Ability to interpret monitoring alerts, operational dashboards and logs at a high level. Strong understanding of incident severity, business impact and prioritisation. Proven experience coordinating multiple technical teams during live incidents. Excellent communication, decision-making and stakeholder management skills. Ability to remain calm and organised in time-critical operational environments. Ideal Background We would particularly welcome applications from candidates with experience as: Major Incident Manager with technical exposure. Senior SOC Analyst or NOC Analyst with leadership responsibilities. Service Operations Lead within a 24/7 operations or command centre. Operational Duty Manager supporting secure or critical environments. What's on Offer 65,000 basic salary. 10,000 annual bonus. Permanent position. Opportunity to work within a highly secure, mission-critical environment. Challenging and rewarding operational leadership role with significant responsibility. Eligibility Requirements Due to the nature of this position, applicants must : Hold current MOD Developed Vetting (DV) Clearance . Be a sole UK national . Be able to work full-time on-site in Hanslope Park .
Jul 31, 2026
Full time
SOC Analyst (DV Cleared) Location: Hanslope Park, Milton Keynes Salary: 65,000 + 10,000 Bonus Employment Type: Permanent Security Clearance: Must hold current MOD DV Clearance Nationality Requirement: Sole UK Nationals only Overview We are seeking an experienced SOC Analyst to join a high-profile operational environment, supporting critical services within a secure, live operations centre. This is a unique hybrid position that combines operational leadership with technical awareness . You'll take ownership of the live operational picture, coordinating incident response across cyber, network, infrastructure and physical security teams while ensuring informed, timely decision-making. This role is ideal for someone who thrives in a fast-paced control room environment and can confidently lead operational response without needing to be a deep technical specialist. Key Responsibilities Maintain a single operational view across cyber, network, service and physical security domains. Monitor live operational environments and assess alerts and incidents in real time. Perform initial triage and validation of alerts, reducing noise and ensuring accurate incident classification. Control incident prioritisation and escalation in line with operational procedures. Coordinate activities across SOC, NOC, Infrastructure and Security teams. Support and lead Major Incident Management activities where required. Maintain accurate operational logs, dashboards and reporting. Deliver effective shift handovers and maintain continuous situational awareness. About the Role This position is intentionally balanced between operational leadership and technical understanding: 60% Operational Leadership & Coordination 40% Technical Awareness & Incident Triage You'll be expected to understand operational and technical information, ask the right questions, coordinate the right teams and maintain control during high-pressure situations. Essential Skills & Experience Experience within a SOC, NOC, Major Incident Management or 24/7 Operations Centre . Good understanding of SOC and NOC workflows, including alert triage and escalation processes. Ability to interpret monitoring alerts, operational dashboards and logs at a high level. Strong understanding of incident severity, business impact and prioritisation. Proven experience coordinating multiple technical teams during live incidents. Excellent communication, decision-making and stakeholder management skills. Ability to remain calm and organised in time-critical operational environments. Ideal Background We would particularly welcome applications from candidates with experience as: Major Incident Manager with technical exposure. Senior SOC Analyst or NOC Analyst with leadership responsibilities. Service Operations Lead within a 24/7 operations or command centre. Operational Duty Manager supporting secure or critical environments. What's on Offer 65,000 basic salary. 10,000 annual bonus. Permanent position. Opportunity to work within a highly secure, mission-critical environment. Challenging and rewarding operational leadership role with significant responsibility. Eligibility Requirements Due to the nature of this position, applicants must : Hold current MOD Developed Vetting (DV) Clearance . Be a sole UK national . Be able to work full-time on-site in Hanslope Park .
SOC Analyst (Level 1 / Level 2) Milton Keynes On-site DV-Clear 24/7 rota, 12 hr shifts £600 - £650 a day inside IR35 DOE Pigment Consulting is a bold and disruptive digitally-enabled transformation consultancy delivering impactful change across Central Government & Defence. Due to continued success across our Cyber Security portfolio, we are currently seeking DV-Cleared SOC Analysts to jo click apply for full job details
May 22, 2026
Contractor
SOC Analyst (Level 1 / Level 2) Milton Keynes On-site DV-Clear 24/7 rota, 12 hr shifts £600 - £650 a day inside IR35 DOE Pigment Consulting is a bold and disruptive digitally-enabled transformation consultancy delivering impactful change across Central Government & Defence. Due to continued success across our Cyber Security portfolio, we are currently seeking DV-Cleared SOC Analysts to jo click apply for full job details
Sanderson Government & Defence
Milton Keynes, Buckinghamshire
DV Cleared - L1 SOC Analyst Location : Milton Keynes Rate: £500 - £650 IR35 Status: Inside Initial Contract Length: 5 months Shift Pattern: 24/7 19 days in a month comprised of, 12-hour days, 8-hour days and 12-hour nights Clearance: Must have active DV Sanderson G&D are seeking L1 SOC Analysts, at both a junior and senior level to join a new programme of work supporting a public sector client on interesti click apply for full job details
May 21, 2026
Contractor
DV Cleared - L1 SOC Analyst Location : Milton Keynes Rate: £500 - £650 IR35 Status: Inside Initial Contract Length: 5 months Shift Pattern: 24/7 19 days in a month comprised of, 12-hour days, 8-hour days and 12-hour nights Clearance: Must have active DV Sanderson G&D are seeking L1 SOC Analysts, at both a junior and senior level to join a new programme of work supporting a public sector client on interesti click apply for full job details
SOC / Cyber Threat Detection Analyst - SANS/GIAC Cyber Threat Detection Analyst Location: Wokingham, Berkshire (On-site) Salary: Competitive (dependent on experience) + excellent benefits & training Security Clearance: Ideally SC Cleared or eligible for SC Role Overview As a Cyber Threat Detection Analyst, you will play a hands-on role within an advanced cyber defence function, focused on proactive threat hunting, adversary behaviour analysis, and high-fidelity threat detection across enterprise environments. This role goes beyond reactive alert handling. You will actively hunt for malicious activity using telemetry, SIEM data, and threat intelligence, develop hypotheses based on MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs), and support incident management and response activities when threats are identified. We are open to experienced SOC Analysts where threat hunting, investigations, and proactive detection have formed a significant part of their role, and who are looking to further develop in a more hunting-led environment. This position is well suited to analysts who enjoy thinking like an attacker, have worked alongside or supported red team or purple team activities, and want to deepen their expertise in threat detection and detection engineering. Skills & Experience We're Seeking Experience in threat hunting, cyber threat detection, SOC, blue team, or cyber defence environments, with ideally around five years hands on experience. Strong hands-on experience using SIEM platforms, including: Microsoft Sentinel (KQL) Splunk (SPL) Elastic Security/Kibana (KQL, ESQL) Practical and operational understanding of MITRE ATT&CK, attacker techniques, and adversary tradecraft Experience working with Indicators of Compromise (IOCs) and threat intelligence feeds Solid experience across the security event life cycle, including detection, investigation, and incident management Hands-on experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike, SentinelOne, or Carbon Black Strong knowledge of networking fundamentals (TCP/IP, DNS, HTTP/S, Firewalls, VPNs, Proxy technologies) Experience analysing telemetry from Windows, Linux, identity, endpoint, and network sources Strong analytical mindset with the ability to clearly communicate findings, impact, and risk Key Responsibilities Conduct proactive threat hunting activities across log, endpoint, and network telemetry to identify suspicious, stealthy, or previously unknown threats Develop and execute hunt hypotheses aligned to MITRE ATT&CK TTPs, adversary behaviours, and emerging threat intelligence Write, refine, and optimise SIEM queries using KQL, SPL, Elastic/ESQL, and Kibana Query Language Perform IOC analysis, enrichment, and validation, integrating internal and external threat intelligence sources Lead investigations from initial detection through scoping, root cause analysis, and impact assessment Support incident management and incident response activities, including containment, remediation, escalation, and lessons learned Collaborate closely with SOC teams, incident responders, red teams, and purple teams to validate detections and improve defensive coverage Contribute to detection logic improvements, use-case development, and continuous enhancement of hunting methodologies Produce clear investigation write-ups, timelines, and recommendations for technical and non-technical stakeholders Security Certifications (Highly Beneficial) SANS/GIAC certifications, including but not limited to: GCIH - Incident Handler GCIA - Intrusion Analyst GCED - Enterprise Defender GCTI - Cyber Threat Intelligence GMON - Continuous Monitoring GDAT - Defending Advanced Threats GCAT - Advanced Threat Intelligence OSCP or equivalent offensive security qualifications Crest certifications, such as: Crest Practitioner Intrusion Analyst (CPIA) Crest Registered Intrusion Analyst (CRIA) Crest Certified Threat Intelligence Analyst (CCTIA) Crest Certified Blue Team Professional (CCBTP) Microsoft SC-200 or related detection and response certifications Other recognised cyber security or threat intelligence credentials
May 20, 2026
Full time
SOC / Cyber Threat Detection Analyst - SANS/GIAC Cyber Threat Detection Analyst Location: Wokingham, Berkshire (On-site) Salary: Competitive (dependent on experience) + excellent benefits & training Security Clearance: Ideally SC Cleared or eligible for SC Role Overview As a Cyber Threat Detection Analyst, you will play a hands-on role within an advanced cyber defence function, focused on proactive threat hunting, adversary behaviour analysis, and high-fidelity threat detection across enterprise environments. This role goes beyond reactive alert handling. You will actively hunt for malicious activity using telemetry, SIEM data, and threat intelligence, develop hypotheses based on MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs), and support incident management and response activities when threats are identified. We are open to experienced SOC Analysts where threat hunting, investigations, and proactive detection have formed a significant part of their role, and who are looking to further develop in a more hunting-led environment. This position is well suited to analysts who enjoy thinking like an attacker, have worked alongside or supported red team or purple team activities, and want to deepen their expertise in threat detection and detection engineering. Skills & Experience We're Seeking Experience in threat hunting, cyber threat detection, SOC, blue team, or cyber defence environments, with ideally around five years hands on experience. Strong hands-on experience using SIEM platforms, including: Microsoft Sentinel (KQL) Splunk (SPL) Elastic Security/Kibana (KQL, ESQL) Practical and operational understanding of MITRE ATT&CK, attacker techniques, and adversary tradecraft Experience working with Indicators of Compromise (IOCs) and threat intelligence feeds Solid experience across the security event life cycle, including detection, investigation, and incident management Hands-on experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike, SentinelOne, or Carbon Black Strong knowledge of networking fundamentals (TCP/IP, DNS, HTTP/S, Firewalls, VPNs, Proxy technologies) Experience analysing telemetry from Windows, Linux, identity, endpoint, and network sources Strong analytical mindset with the ability to clearly communicate findings, impact, and risk Key Responsibilities Conduct proactive threat hunting activities across log, endpoint, and network telemetry to identify suspicious, stealthy, or previously unknown threats Develop and execute hunt hypotheses aligned to MITRE ATT&CK TTPs, adversary behaviours, and emerging threat intelligence Write, refine, and optimise SIEM queries using KQL, SPL, Elastic/ESQL, and Kibana Query Language Perform IOC analysis, enrichment, and validation, integrating internal and external threat intelligence sources Lead investigations from initial detection through scoping, root cause analysis, and impact assessment Support incident management and incident response activities, including containment, remediation, escalation, and lessons learned Collaborate closely with SOC teams, incident responders, red teams, and purple teams to validate detections and improve defensive coverage Contribute to detection logic improvements, use-case development, and continuous enhancement of hunting methodologies Produce clear investigation write-ups, timelines, and recommendations for technical and non-technical stakeholders Security Certifications (Highly Beneficial) SANS/GIAC certifications, including but not limited to: GCIH - Incident Handler GCIA - Intrusion Analyst GCED - Enterprise Defender GCTI - Cyber Threat Intelligence GMON - Continuous Monitoring GDAT - Defending Advanced Threats GCAT - Advanced Threat Intelligence OSCP or equivalent offensive security qualifications Crest certifications, such as: Crest Practitioner Intrusion Analyst (CPIA) Crest Registered Intrusion Analyst (CRIA) Crest Certified Threat Intelligence Analyst (CCTIA) Crest Certified Blue Team Professional (CCBTP) Microsoft SC-200 or related detection and response certifications Other recognised cyber security or threat intelligence credentials
SOC Manager Exeter (Hybrid - 2 days onsite) Day Rate: £850 (Umbrella) / £616.61 (PAYE)SC Cleared An enterprise government backed organisation is seeking a SOC manager to provide day to day leadership of incidents and mangment of the SOC Analysts. This is a critical leadership role, responsible for protecting the organisation against real-time cyber threats, driving incident response, and ensuring resilience across a complex technology estate. Our client is offering a 6 month rolling contract, paying up to £850 PD Inside IR 35 to start ASAP to be based in Exeter 2 days per week.This is a high-impact opportunity to shape cyber strategy at an enterprise level, working closely with senior stakeholders and external agencies to strengthen security posture and response capability. You will play a key role in building and evolving the CSOC capability, operating within a highly visible and business-critical function, with regular engagement across senior leadership and external partners.To be successful, you will hold active SC clearance and bring proven experience working within Central Government, the Public Sector, or highly regulated scientific environments.Key Responsibilities Define and lead the Cyber Security Operations Centre (CSOC), ensuring effective detection, response, and remediation of cyber incidents Own and continuously improve the cyber incident response plan, ensuring readiness across the organisation Provide strategic cyber security advice to senior leadership on monitoring, logging, and threat response Establish a use-case driven monitoring and alerting capability to improve threat detection and response times Oversee threat intelligence, vulnerability management, and proactive risk mitigation across the estate Lead the analysis of network traffic and behaviours, identifying threats and communicating insights to the wider business Define and manage cyber security operations strategy, aligned to organisational risk appetite and government guidance Manage stakeholders and external agencies, including regulatory bodies where required Identify and plan cyber investment requirements across tooling, governance, and team capability Core Experience Required Proven experience leading a Security Operations Centre (SOC/CSOC) or cyber security operations function Strong background in incident response, threat detection, and cyber resilience Hands-on experience with SIEM, IDS/IPS, endpoint security, and monitoring tools Solid understanding of threat intelligence, vulnerability management, and remediation practices Knowledge of cyber frameworks and regulations including GDPR, NIS, and National Cyber Security Centre guidance Familiarity with frameworks such as MITRE ATT&CK and ITIL processes Experience operating within complex, regulated environments (e.g. public sector, financial services) Strong stakeholder management skills, with the ability to influence at senior level
May 20, 2026
Full time
SOC Manager Exeter (Hybrid - 2 days onsite) Day Rate: £850 (Umbrella) / £616.61 (PAYE)SC Cleared An enterprise government backed organisation is seeking a SOC manager to provide day to day leadership of incidents and mangment of the SOC Analysts. This is a critical leadership role, responsible for protecting the organisation against real-time cyber threats, driving incident response, and ensuring resilience across a complex technology estate. Our client is offering a 6 month rolling contract, paying up to £850 PD Inside IR 35 to start ASAP to be based in Exeter 2 days per week.This is a high-impact opportunity to shape cyber strategy at an enterprise level, working closely with senior stakeholders and external agencies to strengthen security posture and response capability. You will play a key role in building and evolving the CSOC capability, operating within a highly visible and business-critical function, with regular engagement across senior leadership and external partners.To be successful, you will hold active SC clearance and bring proven experience working within Central Government, the Public Sector, or highly regulated scientific environments.Key Responsibilities Define and lead the Cyber Security Operations Centre (CSOC), ensuring effective detection, response, and remediation of cyber incidents Own and continuously improve the cyber incident response plan, ensuring readiness across the organisation Provide strategic cyber security advice to senior leadership on monitoring, logging, and threat response Establish a use-case driven monitoring and alerting capability to improve threat detection and response times Oversee threat intelligence, vulnerability management, and proactive risk mitigation across the estate Lead the analysis of network traffic and behaviours, identifying threats and communicating insights to the wider business Define and manage cyber security operations strategy, aligned to organisational risk appetite and government guidance Manage stakeholders and external agencies, including regulatory bodies where required Identify and plan cyber investment requirements across tooling, governance, and team capability Core Experience Required Proven experience leading a Security Operations Centre (SOC/CSOC) or cyber security operations function Strong background in incident response, threat detection, and cyber resilience Hands-on experience with SIEM, IDS/IPS, endpoint security, and monitoring tools Solid understanding of threat intelligence, vulnerability management, and remediation practices Knowledge of cyber frameworks and regulations including GDPR, NIS, and National Cyber Security Centre guidance Familiarity with frameworks such as MITRE ATT&CK and ITIL processes Experience operating within complex, regulated environments (e.g. public sector, financial services) Strong stakeholder management skills, with the ability to influence at senior level
SOC Shift Lead - Watford, UK Up to £75k depending on experience On site 4 days on, 4 days off Must be eligible for DV clearance ABOUT THE CLIENT Our client operates at the forefront of Cyber Security within highly secure and regulated environments across defence and critical infrastructure. They are continuing to invest in their Security Operations capability and are seeking an experienced SOC Shift Lead to play a key role in driving operational excellence and team development. THE BENEFITS Lead a SOC team supporting critical national infrastructure Opportunity to lead and mentor a growing SOC team Exposure to complex, high impact environments Ongoing training and professional development THE SOC SHIFT LEAD ROLE As SOC Shift Lead, you will direct a team of SOC Analysts, taking ownership of monitoring, triage and investigation of security events across critical infrastructure. You will provide hands on technical leadership while also developing team capability and improving detection maturity. You will analyse network traffic, logs and host based events, enhance detection rules aligned to MITRE ATT and threat informed defence, and represent the SOC in partner meetings. This is a hands on leadership role requiring both technical depth and strong people management skills. SOC SHIFT LEAD ESSENTIAL SKILLS Proven experience within a Security Operations Centre Previous line management or team leadership experience Strong hands on experience with Microsoft Sentinel or Splunk Solid understanding of MITRE ATT and threat informed defence Strong networking knowledge including TCP IP, LAN, WAN, SMTP, HTTP, FTP, POP and LDAP Experience investigating host and network based security incidents Eligibility for DV clearance Ability to work on site in Watford on a shift basis TO BE CONSIDERED Please either apply through this advert or email me directly via . For further information please call me on . By applying for this role, you give express consent for us to process and submit, subject to required skills, your application to our client in conjunction with this vacancy only. KEY SKILLS SOC Shift Lead, Security Operations Centre, Microsoft Sentinel, Splunk, MITRE ATT, Incident Response, DV Cleared, NSD
May 20, 2026
Full time
SOC Shift Lead - Watford, UK Up to £75k depending on experience On site 4 days on, 4 days off Must be eligible for DV clearance ABOUT THE CLIENT Our client operates at the forefront of Cyber Security within highly secure and regulated environments across defence and critical infrastructure. They are continuing to invest in their Security Operations capability and are seeking an experienced SOC Shift Lead to play a key role in driving operational excellence and team development. THE BENEFITS Lead a SOC team supporting critical national infrastructure Opportunity to lead and mentor a growing SOC team Exposure to complex, high impact environments Ongoing training and professional development THE SOC SHIFT LEAD ROLE As SOC Shift Lead, you will direct a team of SOC Analysts, taking ownership of monitoring, triage and investigation of security events across critical infrastructure. You will provide hands on technical leadership while also developing team capability and improving detection maturity. You will analyse network traffic, logs and host based events, enhance detection rules aligned to MITRE ATT and threat informed defence, and represent the SOC in partner meetings. This is a hands on leadership role requiring both technical depth and strong people management skills. SOC SHIFT LEAD ESSENTIAL SKILLS Proven experience within a Security Operations Centre Previous line management or team leadership experience Strong hands on experience with Microsoft Sentinel or Splunk Solid understanding of MITRE ATT and threat informed defence Strong networking knowledge including TCP IP, LAN, WAN, SMTP, HTTP, FTP, POP and LDAP Experience investigating host and network based security incidents Eligibility for DV clearance Ability to work on site in Watford on a shift basis TO BE CONSIDERED Please either apply through this advert or email me directly via . For further information please call me on . By applying for this role, you give express consent for us to process and submit, subject to required skills, your application to our client in conjunction with this vacancy only. KEY SKILLS SOC Shift Lead, Security Operations Centre, Microsoft Sentinel, Splunk, MITRE ATT, Incident Response, DV Cleared, NSD
Role: DV-Cleared Cyber Security Analyst / SOC Analyst Salary/Rate: £540-640 per day inside IR35 Location: on site Corsham 5x pw Contract Duration: contract until April 2027 We are currently looking for a Cyber Security Analyst / SOC Analyst for our government client. This Cyber Security Analyst / SOC Analyst role is based fully on site, 5 days per week in Corsham, over 13-hour shifts spanning days and nights, including weekends, 4 on 5 off, then 5 on 4 off. There is no further flexibility with the on-site requirement or office location. Security Clearance: Developed Vetting (DV Clearance) + sole UK national + Sensitive Post Check (which can take 3 months) The contract for this Cyber Security Analyst / SOC Analyst position is until April 2027, with potential to extend, operating inside IR35. This role is inside IR35 - Due to the service of the role, it will now be based on an Umbrella solution. Essential Skills / Experience required: Industry standard SOC Security qualifications (SANS, ISC2, etc.) Proven Tier 2/3 SOC Analyst experience (2 years+) Perform triage of security events ; determine scope, priority and impact, and make recommendations that enable expeditious remediation. Demonstratable experience working with SIEM technology and SIEM engineering (including tool configuration) i.e. ArcSight within an enterprise SOC. Experience in creation of use-cases, analytics and playbooks . An understanding of cloud Conduct real-time management of security incidents from detection to resolution. Technical Knowledge within anti-virus, networking, vulnerability management, encryption, Microsoft technologies, Linux. Knowledge of Information Security standards , legislation and practices, including GDPR & Data Protection Act 2018. Experience in dealing with a wide range of Information Security matters and operating in an ITIL based environment. Strong problem-solving ability, with flexibility to think creatively and adapt to and implement rapidly changing systems and services. Incident management experience and an ability to quickly tailor responses to deal with fast-moving situations. Highly desirable: Degree level qualification; preferably in technical, engineering or computing subject. Lead experience but would take a Tier 2 Analyst. Defence experience Role / Responsibilities: Responsible for supporting information security delivery work, including the development and implementation of Information Security Policies, Standards, processes and guidance. Responsibility for the security of Digital infrastructure by proactively analysing security threats/challenges/risks to the environment, including conducting penetration testing and compliance reviews monitoring of Information Security and information management to ensure compliance including reviewing and monitoring system and network logs for malicious activity or unacceptable use. If you are interested in the above role, please click Apply Now and send a CV for quick review. As a member of the Disability Confident Scheme, Circle and our Client guarantees to interview all candidates who have a disability and who meet all the essential criteria for the vacancy. In cases where we have a high volume of candidates who have a disability who meet all the essential criteria, we will interview the best candidates from within that group. Our client is proud to support the Armed Forces Covenant and as such, they guarantee to interview all veterans, spouses / partners of military personnel who meet all the essential criteria for the vacancy. In cases where they have a high volume of ex-military candidates / military spouses, partners, who meet all of the essential criteria, they will interview the best candidates from within that group. If you qualify, please notify us on igs at circlerecruitment dot com. We will be in touch to discuss your suitability and arrange your guaranteed interview. Should you require reasonable adjustments at any point during the recruitment process, if there is a better way for us to communicate, please do let us know. Circle Recruitment is acting as an Employment Agency in relation to this vacancy. Earn yourself a referral bonus if you refer somebody else who fills the role! We also offer an iPad if you refer a new client to us and we recruit for them. Follow us on Facebook - Circle Recruitment , Twitter and LinkedIn - Circle Recruitment.
May 19, 2026
Contractor
Role: DV-Cleared Cyber Security Analyst / SOC Analyst Salary/Rate: £540-640 per day inside IR35 Location: on site Corsham 5x pw Contract Duration: contract until April 2027 We are currently looking for a Cyber Security Analyst / SOC Analyst for our government client. This Cyber Security Analyst / SOC Analyst role is based fully on site, 5 days per week in Corsham, over 13-hour shifts spanning days and nights, including weekends, 4 on 5 off, then 5 on 4 off. There is no further flexibility with the on-site requirement or office location. Security Clearance: Developed Vetting (DV Clearance) + sole UK national + Sensitive Post Check (which can take 3 months) The contract for this Cyber Security Analyst / SOC Analyst position is until April 2027, with potential to extend, operating inside IR35. This role is inside IR35 - Due to the service of the role, it will now be based on an Umbrella solution. Essential Skills / Experience required: Industry standard SOC Security qualifications (SANS, ISC2, etc.) Proven Tier 2/3 SOC Analyst experience (2 years+) Perform triage of security events ; determine scope, priority and impact, and make recommendations that enable expeditious remediation. Demonstratable experience working with SIEM technology and SIEM engineering (including tool configuration) i.e. ArcSight within an enterprise SOC. Experience in creation of use-cases, analytics and playbooks . An understanding of cloud Conduct real-time management of security incidents from detection to resolution. Technical Knowledge within anti-virus, networking, vulnerability management, encryption, Microsoft technologies, Linux. Knowledge of Information Security standards , legislation and practices, including GDPR & Data Protection Act 2018. Experience in dealing with a wide range of Information Security matters and operating in an ITIL based environment. Strong problem-solving ability, with flexibility to think creatively and adapt to and implement rapidly changing systems and services. Incident management experience and an ability to quickly tailor responses to deal with fast-moving situations. Highly desirable: Degree level qualification; preferably in technical, engineering or computing subject. Lead experience but would take a Tier 2 Analyst. Defence experience Role / Responsibilities: Responsible for supporting information security delivery work, including the development and implementation of Information Security Policies, Standards, processes and guidance. Responsibility for the security of Digital infrastructure by proactively analysing security threats/challenges/risks to the environment, including conducting penetration testing and compliance reviews monitoring of Information Security and information management to ensure compliance including reviewing and monitoring system and network logs for malicious activity or unacceptable use. If you are interested in the above role, please click Apply Now and send a CV for quick review. As a member of the Disability Confident Scheme, Circle and our Client guarantees to interview all candidates who have a disability and who meet all the essential criteria for the vacancy. In cases where we have a high volume of candidates who have a disability who meet all the essential criteria, we will interview the best candidates from within that group. Our client is proud to support the Armed Forces Covenant and as such, they guarantee to interview all veterans, spouses / partners of military personnel who meet all the essential criteria for the vacancy. In cases where they have a high volume of ex-military candidates / military spouses, partners, who meet all of the essential criteria, they will interview the best candidates from within that group. If you qualify, please notify us on igs at circlerecruitment dot com. We will be in touch to discuss your suitability and arrange your guaranteed interview. Should you require reasonable adjustments at any point during the recruitment process, if there is a better way for us to communicate, please do let us know. Circle Recruitment is acting as an Employment Agency in relation to this vacancy. Earn yourself a referral bonus if you refer somebody else who fills the role! We also offer an iPad if you refer a new client to us and we recruit for them. Follow us on Facebook - Circle Recruitment , Twitter and LinkedIn - Circle Recruitment.
Role: SOC Manager Salary/Rate: £700-850 per day inside IR35 Location: Mainly remote, must be UK-based Contract Duration: 6-month contract We are currently looking for a SOC Manager for our government client. This SOC Manager role is mainly remote, however successful candidates must be able to travel to UK sites as required. There is no further flexibility with the on-site requirement. The contract for this SOC Manager position is for 6-months, with potential to extend, operating inside IR35. Security Clearance: Security Check (SC Clearance) This role is inside IR35 - Due to the service of the role, it will now be based on an Umbrella solution. Essential skills/experience required: Demonstrated ability to lead and manage a team , this includes decision-making, effective communication and service management skills. In-depth knowledge of incident management processes, including the ability to assess the impact of critical security incidents and lead the response efforts, ensuring procedures are available and maintained. Proven experience delivering an effective security monitoring capability, with continuous improvements that reflect changes from risks and threats in a timely manner, including proactive threat hunting and intrusion detection . Proven experience delivering threat intelligence and assessment in the context of the organisation to stakeholders by gathering and analysing information to identify and mitigate cyber threats from both open-source (OSINT) and commercial threat intelligence. Proven experience operating cyber security solutions and tools e.g. Security Information and Event Management ( SIEM ), maintaining security records and documentation in accordance with security operating procedures. Demonstrated experience in managing relationships with external vendors, managed security service providers ( MSSPs ), and technology partners, ensuring contractual obligations, service level agreements (SLAs), and performance metrics are consistently met or exceeded. Role / Responsibilities: Lead, manage and mentor a team of cyber security analysts to ensure the team operate effectively. Develop the team utilising the career framework to identify learning needs and career pathways Lead incident detection, triage, escalation and resolution processes; assessing impacts and directing appropriate measures to contain and mitigate threats, conduct post-incident reviews and drive continual service improvement including exercising to test procedures. Be the escalation point for alerts. Provide direction for improvements to monitoring systems for our environment covering specific technologies or threats. Direct the development and tuning of new and existing rules Stay up to date on the latest cyber threats and attack techniques, incorporating threat intelligence into security practices, cascading to relevant stakeholders. Define cyber security metrics and targets. Prepare and present regular reports on security incidents, and trends to management, translating technical metrics into business-focused risk insights Oversee service providers, managing Service Level Agreements (SLAs) and Key Performance Indicators (KPIs), serve as the principal interface with cross-government departmental SOCs Support the management of the department budget to ensure optimal allocation of resources to meet security objectives. If you are interested in the above role, please click Apply Now and send a CV for quick review. As a member of the Disability Confident Scheme, Circle and our Client guarantees to interview all candidates who have a disability and who meet all the essential criteria for the vacancy. In cases where we have a high volume of candidates who have a disability who meet all the essential criteria, we will interview the best candidates from within that group. Our client is proud to support the Armed Forces Covenant and as such, they guarantee to interview all veterans, spouses / partners of military personnel who meet all the essential criteria for the vacancy. In cases where they have a high volume of ex-military candidates / military spouses, partners, who meet all of the essential criteria, they will interview the best candidates from within that group. If you qualify, please notify us on igs at circlerecruitment dot com. We will be in touch to discuss your suitability and arrange your guaranteed interview. Should you require reasonable adjustments at any point during the recruitment process, if there is a better way for us to communicate, please do let us know. Security, Cyber, Infosec, Information Security, SOC, Security Operations Centre, Threat, Security Check, Sc Level, Sc Cleared, Sc Clearance, Security Cleared, Security Clearance, Security Vetting Clearance, Active SC, SC Vetted, Cleared To A High Government Standard, DV Cleared, DV Clearance, DV Check, Developed Vetted, Developed Vetting, DV Strap, Active DV, Circle Recruitment is acting as an Employment Agency in relation to this vacancy. Earn yourself a referral bonus if you refer somebody else who fills the role! We also offer an iPad if you refer a new client to us and we recruit for them. Follow us on Facebook - Circle Recruitment , Twitter and LinkedIn - Circle Recruitment.
May 18, 2026
Contractor
Role: SOC Manager Salary/Rate: £700-850 per day inside IR35 Location: Mainly remote, must be UK-based Contract Duration: 6-month contract We are currently looking for a SOC Manager for our government client. This SOC Manager role is mainly remote, however successful candidates must be able to travel to UK sites as required. There is no further flexibility with the on-site requirement. The contract for this SOC Manager position is for 6-months, with potential to extend, operating inside IR35. Security Clearance: Security Check (SC Clearance) This role is inside IR35 - Due to the service of the role, it will now be based on an Umbrella solution. Essential skills/experience required: Demonstrated ability to lead and manage a team , this includes decision-making, effective communication and service management skills. In-depth knowledge of incident management processes, including the ability to assess the impact of critical security incidents and lead the response efforts, ensuring procedures are available and maintained. Proven experience delivering an effective security monitoring capability, with continuous improvements that reflect changes from risks and threats in a timely manner, including proactive threat hunting and intrusion detection . Proven experience delivering threat intelligence and assessment in the context of the organisation to stakeholders by gathering and analysing information to identify and mitigate cyber threats from both open-source (OSINT) and commercial threat intelligence. Proven experience operating cyber security solutions and tools e.g. Security Information and Event Management ( SIEM ), maintaining security records and documentation in accordance with security operating procedures. Demonstrated experience in managing relationships with external vendors, managed security service providers ( MSSPs ), and technology partners, ensuring contractual obligations, service level agreements (SLAs), and performance metrics are consistently met or exceeded. Role / Responsibilities: Lead, manage and mentor a team of cyber security analysts to ensure the team operate effectively. Develop the team utilising the career framework to identify learning needs and career pathways Lead incident detection, triage, escalation and resolution processes; assessing impacts and directing appropriate measures to contain and mitigate threats, conduct post-incident reviews and drive continual service improvement including exercising to test procedures. Be the escalation point for alerts. Provide direction for improvements to monitoring systems for our environment covering specific technologies or threats. Direct the development and tuning of new and existing rules Stay up to date on the latest cyber threats and attack techniques, incorporating threat intelligence into security practices, cascading to relevant stakeholders. Define cyber security metrics and targets. Prepare and present regular reports on security incidents, and trends to management, translating technical metrics into business-focused risk insights Oversee service providers, managing Service Level Agreements (SLAs) and Key Performance Indicators (KPIs), serve as the principal interface with cross-government departmental SOCs Support the management of the department budget to ensure optimal allocation of resources to meet security objectives. If you are interested in the above role, please click Apply Now and send a CV for quick review. As a member of the Disability Confident Scheme, Circle and our Client guarantees to interview all candidates who have a disability and who meet all the essential criteria for the vacancy. In cases where we have a high volume of candidates who have a disability who meet all the essential criteria, we will interview the best candidates from within that group. Our client is proud to support the Armed Forces Covenant and as such, they guarantee to interview all veterans, spouses / partners of military personnel who meet all the essential criteria for the vacancy. In cases where they have a high volume of ex-military candidates / military spouses, partners, who meet all of the essential criteria, they will interview the best candidates from within that group. If you qualify, please notify us on igs at circlerecruitment dot com. We will be in touch to discuss your suitability and arrange your guaranteed interview. Should you require reasonable adjustments at any point during the recruitment process, if there is a better way for us to communicate, please do let us know. Security, Cyber, Infosec, Information Security, SOC, Security Operations Centre, Threat, Security Check, Sc Level, Sc Cleared, Sc Clearance, Security Cleared, Security Clearance, Security Vetting Clearance, Active SC, SC Vetted, Cleared To A High Government Standard, DV Cleared, DV Clearance, DV Check, Developed Vetted, Developed Vetting, DV Strap, Active DV, Circle Recruitment is acting as an Employment Agency in relation to this vacancy. Earn yourself a referral bonus if you refer somebody else who fills the role! We also offer an iPad if you refer a new client to us and we recruit for them. Follow us on Facebook - Circle Recruitment , Twitter and LinkedIn - Circle Recruitment.
Senior Conflicts Attorney Powerhouse US law firm renowned for its excellence and impactful global work is seeking a Senior Conflicts Attorney on a permanent, full-time basis. Highly generous salary + exceptional benefits, including free meals/snacks/refreshments 09:30-17:30 (Monday-Friday) Hybrid working (4 days office / Fridays WFH) As a Senior Conflicts Attorney in the London office, you will be working with partners, attorneys, and clients to ensure potential conflicts are resolved firm-wide - assessing all areas of conflicts of interest and new client intake inherent in a large global law firm. Senior Conflicts Attorney Key Responsibilities: Act as primary contact for partner conflict inquiries on a firm-wide basis. Interface with partners and associates to confirm the status of existing or pending transactions and resolve identified conflict issues. Manage conflict research process and procedures ensuring potential conflicts are quickly and accurately identified and resolved and conflicts are cleared for new matters and new clients firm-wide. Provide guidance, monitor processes with respect to new clients and matters, screening, and waivers. Advise attorneys on conflicts rules and assist in adherence to such rules and firm policies when drafting, reviewing, and coordinating client engagement and conflict waiver letters. Ensure firm policies and procedures relating to conflicts and client intake are communicated and make recommendations for changes when appropriate. Provide guidance to attorneys, analysts and firm personnel related to conflict of interest rules and procedures as required. Maintain current knowledge of conflicts rules in New York and all jurisdictions where the firm has offices and/or conducts business. Senior Conflicts Attorney Skills & Requirements: 5+ years' legal experience in a law firm or in-house counsel is required. Proficient knowledge of large firm practice areas: financial organizations, banking and capital markets, private equity firms and other business organizations. Ability to identify and resolve actual and potential conflicts of interest within various types of transactions, restructurings, bankruptcies and litigation. Proficiency in internet research, WCO, CapitalIQ and other corporate databases including corporate ownership/SEC filings. Ability to research and understand complex corporate relationships and determine how proposed relationship relate to the firm's existing engagements. Ability to analyse and summarize conflict situations, articulate potential issues, and suggest resolutions to attorneys as required.
May 14, 2026
Full time
Senior Conflicts Attorney Powerhouse US law firm renowned for its excellence and impactful global work is seeking a Senior Conflicts Attorney on a permanent, full-time basis. Highly generous salary + exceptional benefits, including free meals/snacks/refreshments 09:30-17:30 (Monday-Friday) Hybrid working (4 days office / Fridays WFH) As a Senior Conflicts Attorney in the London office, you will be working with partners, attorneys, and clients to ensure potential conflicts are resolved firm-wide - assessing all areas of conflicts of interest and new client intake inherent in a large global law firm. Senior Conflicts Attorney Key Responsibilities: Act as primary contact for partner conflict inquiries on a firm-wide basis. Interface with partners and associates to confirm the status of existing or pending transactions and resolve identified conflict issues. Manage conflict research process and procedures ensuring potential conflicts are quickly and accurately identified and resolved and conflicts are cleared for new matters and new clients firm-wide. Provide guidance, monitor processes with respect to new clients and matters, screening, and waivers. Advise attorneys on conflicts rules and assist in adherence to such rules and firm policies when drafting, reviewing, and coordinating client engagement and conflict waiver letters. Ensure firm policies and procedures relating to conflicts and client intake are communicated and make recommendations for changes when appropriate. Provide guidance to attorneys, analysts and firm personnel related to conflict of interest rules and procedures as required. Maintain current knowledge of conflicts rules in New York and all jurisdictions where the firm has offices and/or conducts business. Senior Conflicts Attorney Skills & Requirements: 5+ years' legal experience in a law firm or in-house counsel is required. Proficient knowledge of large firm practice areas: financial organizations, banking and capital markets, private equity firms and other business organizations. Ability to identify and resolve actual and potential conflicts of interest within various types of transactions, restructurings, bankruptcies and litigation. Proficiency in internet research, WCO, CapitalIQ and other corporate databases including corporate ownership/SEC filings. Ability to research and understand complex corporate relationships and determine how proposed relationship relate to the firm's existing engagements. Ability to analyse and summarize conflict situations, articulate potential issues, and suggest resolutions to attorneys as required.
Senior Conflicts Attorney Powerhouse US law firm renowned for its excellence and impactful global work is seeking a Senior Conflicts Attorney on a permanent, full-time basis. Highly generous salary + exceptional benefits, including free meals/snacks/refreshments 09:30-17:30 (Monday-Friday) Hybrid working (4 days office / Fridays WFH) As a Senior Conflicts Attorney in the London office, you will be working with partners, attorneys, and clients to ensure potential conflicts are resolved firm-wide - assessing all areas of conflicts of interest and new client intake inherent in a large global law firm. Senior Conflicts Attorney Key Responsibilities: Act as primary contact for partner conflict inquiries on a firm-wide basis. Interface with partners and associates to confirm the status of existing or pending transactions and resolve identified conflict issues. Manage conflict research process and procedures ensuring potential conflicts are quickly and accurately identified and resolved and conflicts are cleared for new matters and new clients firm-wide. Provide guidance, monitor processes with respect to new clients and matters, screening, and waivers. Advise attorneys on conflicts rules and assist in adherence to such rules and firm policies when drafting, reviewing, and coordinating client engagement and conflict waiver letters. Ensure firm policies and procedures relating to conflicts and client intake are communicated and make recommendations for changes when appropriate. Provide guidance to attorneys, analysts and firm personnel related to conflict of interest rules and procedures as required. Maintain current knowledge of conflicts rules in New York and all jurisdictions where the firm has offices and/or conducts business. Senior Conflicts Attorney Skills & Requirements: 5+ years' legal experience in a law firm or in-house counsel is required. Proficient knowledge of large firm practice areas: financial organizations, banking and capital markets, private equity firms and other business organizations. Ability to identify and resolve actual and potential conflicts of interest within various types of transactions, restructurings, bankruptcies and litigation. Proficiency in internet research, WCO, CapitalIQ and other corporate databases including corporate ownership/SEC filings. Ability to research and understand complex corporate relationships and determine how proposed relationship relate to the firm's existing engagements. Ability to analyse and summarize conflict situations, articulate potential issues, and suggest resolutions to attorneys as required.
May 11, 2026
Full time
Senior Conflicts Attorney Powerhouse US law firm renowned for its excellence and impactful global work is seeking a Senior Conflicts Attorney on a permanent, full-time basis. Highly generous salary + exceptional benefits, including free meals/snacks/refreshments 09:30-17:30 (Monday-Friday) Hybrid working (4 days office / Fridays WFH) As a Senior Conflicts Attorney in the London office, you will be working with partners, attorneys, and clients to ensure potential conflicts are resolved firm-wide - assessing all areas of conflicts of interest and new client intake inherent in a large global law firm. Senior Conflicts Attorney Key Responsibilities: Act as primary contact for partner conflict inquiries on a firm-wide basis. Interface with partners and associates to confirm the status of existing or pending transactions and resolve identified conflict issues. Manage conflict research process and procedures ensuring potential conflicts are quickly and accurately identified and resolved and conflicts are cleared for new matters and new clients firm-wide. Provide guidance, monitor processes with respect to new clients and matters, screening, and waivers. Advise attorneys on conflicts rules and assist in adherence to such rules and firm policies when drafting, reviewing, and coordinating client engagement and conflict waiver letters. Ensure firm policies and procedures relating to conflicts and client intake are communicated and make recommendations for changes when appropriate. Provide guidance to attorneys, analysts and firm personnel related to conflict of interest rules and procedures as required. Maintain current knowledge of conflicts rules in New York and all jurisdictions where the firm has offices and/or conducts business. Senior Conflicts Attorney Skills & Requirements: 5+ years' legal experience in a law firm or in-house counsel is required. Proficient knowledge of large firm practice areas: financial organizations, banking and capital markets, private equity firms and other business organizations. Ability to identify and resolve actual and potential conflicts of interest within various types of transactions, restructurings, bankruptcies and litigation. Proficiency in internet research, WCO, CapitalIQ and other corporate databases including corporate ownership/SEC filings. Ability to research and understand complex corporate relationships and determine how proposed relationship relate to the firm's existing engagements. Ability to analyse and summarize conflict situations, articulate potential issues, and suggest resolutions to attorneys as required.
SOC Analyst (Level 1 / Level 2) Milton Keynes On-site DV-Clear 24/7 rota, 12 hr shifts £600 - £650 a day inside IR35 DOE Pigment Consulting is a bold and disruptive digitally-enabled transformation consultancy delivering impactful change across Central Government & Defence. Due to continued success across our Cyber Security portfolio, we are currently seeking DV-Cleared SOC Analysts to jo click apply for full job details
May 05, 2026
Contractor
SOC Analyst (Level 1 / Level 2) Milton Keynes On-site DV-Clear 24/7 rota, 12 hr shifts £600 - £650 a day inside IR35 DOE Pigment Consulting is a bold and disruptive digitally-enabled transformation consultancy delivering impactful change across Central Government & Defence. Due to continued success across our Cyber Security portfolio, we are currently seeking DV-Cleared SOC Analysts to jo click apply for full job details
DV Cleared - L1 SOC Analyst Location : Milton Keynes Rate: £500 - £650 IR35 Status: Inside Initial Contract Length: 5 months Shift Pattern: 24/7 19 days in a month comprised of, 12-hour days, 8-hour days and 12-hour nights Clearance: Must have active DV Sanderson G&D are seeking L1 SOC Analysts, at both a junior and senior level to join a new programme of work supporting a public sector client on interesting and critical work. Responsibilities: Real-time security event monitoring and triage Incident Analysis and Escalation Compliance with internal security protocols and reporting standards, with continuous improvement Continuous monitoring of security alerts and logs across internal systems Incident triage and escalation Daily operational reports and incident summaries; contribution to monthly performance reviews Adherence to security standards and participation in processes improvement initiatives Effective communication with internal teams and external partners during incidents and investigations Reasonable Adjustments: Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients. If you need any help or adjustments during the recruitment process for any reason , please let us know when you apply or talk to the recruiters directly so we can support you.
May 04, 2026
Contractor
DV Cleared - L1 SOC Analyst Location : Milton Keynes Rate: £500 - £650 IR35 Status: Inside Initial Contract Length: 5 months Shift Pattern: 24/7 19 days in a month comprised of, 12-hour days, 8-hour days and 12-hour nights Clearance: Must have active DV Sanderson G&D are seeking L1 SOC Analysts, at both a junior and senior level to join a new programme of work supporting a public sector client on interesting and critical work. Responsibilities: Real-time security event monitoring and triage Incident Analysis and Escalation Compliance with internal security protocols and reporting standards, with continuous improvement Continuous monitoring of security alerts and logs across internal systems Incident triage and escalation Daily operational reports and incident summaries; contribution to monthly performance reviews Adherence to security standards and participation in processes improvement initiatives Effective communication with internal teams and external partners during incidents and investigations Reasonable Adjustments: Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients. If you need any help or adjustments during the recruitment process for any reason , please let us know when you apply or talk to the recruiters directly so we can support you.
Are you a Detection Engineer ready to take on the fight against modern adversaries? Join a well-established SOC working with high-profile Defence clients, where your expertise genuinely matters. In this hands-on technical role, you'll own the end-to-end design, development and maturity of detection logic across SIEM platforms-engineering effective responses to real-world attacker techniques. You'll operate with a high degree of autonomy, acting as a trusted SME across multiple secure environments within a complex MSSP setting. This is a standout opportunity to advance your career at the sharp end of cyber defence. Location: Hybrid working - 2 days per week in our Farnborough office. Security: You must hold or be eligible for SC Clearance. What you'll be doing: ? Design, build, test and continuously refine advanced SIEM detection logic, including rules, correlations and analytics. Research emerging threats, vulnerabilities and adversary TTPs, mapping them to MITRE ATT&CK to close detection and visibility gaps. Tune and validate detections to minimise false positives and deliver high-fidelity alerts for SOC analysts. Act as a technical authority, providing expert guidance to SOC Analysts, Architects and Engineers to strengthen overall detection capability. Define, implement and maintain technical detection standards across environments. Clearly communicate complex technical risks and detection logic to both technical teams and non-technical stakeholders. What you'll bring: Deep SIEM expertise, building advanced detection logic, automation and complex queries in Splunk (SPL) and Microsoft Sentinel (KQL). A proven track record delivering complex detection engineering projects within enterprise or MSSP environments. Strong analytical skills, with the ability to break down sophisticated attacks into actionable detection patterns. Confidence to own technical delivery end-to-end, driving work through to completion with minimal escalation. Expert knowledge of MITRE ATT&CK, with real-world application in detection engineering. A BSc in Computer Science, IT, or a related discipline. Solid scripting skills in Python, PowerShell, or similar, supporting automation and data manipulation. Experience developing detections in QRadar and/or conducting EDR-focused threat hunting (e.g. CrowdStrike, Microsoft Defender for Endpoint). Broad infrastructure awareness across Cloud (Azure/AWS), on-prem, and SaaS / PaaS / IaaS environments. If you are interested in this role but not sure if your skills and experience are exactly what we're looking for, please do apply, we'd love to hear from you! Employment Type: Full-time, Permanent. Location: Hybrid: 2 days per week in Farnborough. Security Clearance Level: SC Cleared or eligible. Internal Recruiter: Jane. Salary: To £65,000. Benefits: 25 days annual leave with the choice to buy additional days, health cash plan, life assurance and pension. Sopra Steria: Our Aerospace, Defence and Security business designs, develops and deploys digital solutions to Central Government clients. The work we do makes a real difference to the client's goal of National Security, and we operate in a unique and privileged environment. We are given time for professional development activities, and we coach and mentor our colleagues, sharing knowledge and learning from each other. We foster a culture in which employees feel valued and supported and have pride in their work for the customer, delivering outstanding rates of customer satisfaction in the UK's most complex safety- and security-critical markets.
May 03, 2026
Full time
Are you a Detection Engineer ready to take on the fight against modern adversaries? Join a well-established SOC working with high-profile Defence clients, where your expertise genuinely matters. In this hands-on technical role, you'll own the end-to-end design, development and maturity of detection logic across SIEM platforms-engineering effective responses to real-world attacker techniques. You'll operate with a high degree of autonomy, acting as a trusted SME across multiple secure environments within a complex MSSP setting. This is a standout opportunity to advance your career at the sharp end of cyber defence. Location: Hybrid working - 2 days per week in our Farnborough office. Security: You must hold or be eligible for SC Clearance. What you'll be doing: ? Design, build, test and continuously refine advanced SIEM detection logic, including rules, correlations and analytics. Research emerging threats, vulnerabilities and adversary TTPs, mapping them to MITRE ATT&CK to close detection and visibility gaps. Tune and validate detections to minimise false positives and deliver high-fidelity alerts for SOC analysts. Act as a technical authority, providing expert guidance to SOC Analysts, Architects and Engineers to strengthen overall detection capability. Define, implement and maintain technical detection standards across environments. Clearly communicate complex technical risks and detection logic to both technical teams and non-technical stakeholders. What you'll bring: Deep SIEM expertise, building advanced detection logic, automation and complex queries in Splunk (SPL) and Microsoft Sentinel (KQL). A proven track record delivering complex detection engineering projects within enterprise or MSSP environments. Strong analytical skills, with the ability to break down sophisticated attacks into actionable detection patterns. Confidence to own technical delivery end-to-end, driving work through to completion with minimal escalation. Expert knowledge of MITRE ATT&CK, with real-world application in detection engineering. A BSc in Computer Science, IT, or a related discipline. Solid scripting skills in Python, PowerShell, or similar, supporting automation and data manipulation. Experience developing detections in QRadar and/or conducting EDR-focused threat hunting (e.g. CrowdStrike, Microsoft Defender for Endpoint). Broad infrastructure awareness across Cloud (Azure/AWS), on-prem, and SaaS / PaaS / IaaS environments. If you are interested in this role but not sure if your skills and experience are exactly what we're looking for, please do apply, we'd love to hear from you! Employment Type: Full-time, Permanent. Location: Hybrid: 2 days per week in Farnborough. Security Clearance Level: SC Cleared or eligible. Internal Recruiter: Jane. Salary: To £65,000. Benefits: 25 days annual leave with the choice to buy additional days, health cash plan, life assurance and pension. Sopra Steria: Our Aerospace, Defence and Security business designs, develops and deploys digital solutions to Central Government clients. The work we do makes a real difference to the client's goal of National Security, and we operate in a unique and privileged environment. We are given time for professional development activities, and we coach and mentor our colleagues, sharing knowledge and learning from each other. We foster a culture in which employees feel valued and supported and have pride in their work for the customer, delivering outstanding rates of customer satisfaction in the UK's most complex safety- and security-critical markets.
SOC / Cyber Threat Detection Analyst - SANS/GIAC Cyber Threat Detection Analyst Location: Wokingham, Berkshire (On-site) Salary: Competitive (dependent on experience) + excellent benefits & training Security Clearance: Ideally SC Cleared or eligible for SC Role Overview As a Cyber Threat Detection Analyst, you will play a hands-on role within an advanced cyber defence function, focused on proactive threat hunting, adversary behaviour analysis, and high-fidelity threat detection across enterprise environments. This role goes beyond reactive alert handling. You will actively hunt for malicious activity using telemetry, SIEM data, and threat intelligence, develop hypotheses based on MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs), and support incident management and response activities when threats are identified. We are open to experienced SOC Analysts where threat hunting, investigations, and proactive detection have formed a significant part of their role, and who are looking to further develop in a more hunting-led environment. This position is well suited to analysts who enjoy thinking like an attacker, have worked alongside or supported red team or purple team activities, and want to deepen their expertise in threat detection and detection engineering. Skills & Experience We're Seeking Experience in threat hunting, cyber threat detection, SOC, blue team, or cyber defence environments, with ideally around five years hands on experience. Strong hands-on experience using SIEM platforms, including: Microsoft Sentinel (KQL) Splunk (SPL) Elastic Security/Kibana (KQL, ESQL) Practical and operational understanding of MITRE ATT&CK, attacker techniques, and adversary tradecraft Experience working with Indicators of Compromise (IOCs) and threat intelligence feeds Solid experience across the security event life cycle, including detection, investigation, and incident management Hands-on experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike, SentinelOne, or Carbon Black Strong knowledge of networking fundamentals (TCP/IP, DNS, HTTP/S, Firewalls, VPNs, Proxy technologies) Experience analysing telemetry from Windows, Linux, identity, endpoint, and network sources Strong analytical mindset with the ability to clearly communicate findings, impact, and risk Key Responsibilities Conduct proactive threat hunting activities across log, endpoint, and network telemetry to identify suspicious, stealthy, or previously unknown threats Develop and execute hunt hypotheses aligned to MITRE ATT&CK TTPs, adversary behaviours, and emerging threat intelligence Write, refine, and optimise SIEM queries using KQL, SPL, Elastic/ESQL, and Kibana Query Language Perform IOC analysis, enrichment, and validation, integrating internal and external threat intelligence sources Lead investigations from initial detection through scoping, root cause analysis, and impact assessment Support incident management and incident response activities, including containment, remediation, escalation, and lessons learned Collaborate closely with SOC teams, incident responders, red teams, and purple teams to validate detections and improve defensive coverage Contribute to detection logic improvements, use-case development, and continuous enhancement of hunting methodologies Produce clear investigation write-ups, timelines, and recommendations for technical and non-technical stakeholders Security Certifications (Highly Beneficial) SANS/GIAC certifications, including but not limited to: GCIH - Incident Handler GCIA - Intrusion Analyst GCED - Enterprise Defender GCTI - Cyber Threat Intelligence GMON - Continuous Monitoring GDAT - Defending Advanced Threats GCAT - Advanced Threat Intelligence OSCP or equivalent offensive security qualifications Crest certifications, such as: Crest Practitioner Intrusion Analyst (CPIA) Crest Registered Intrusion Analyst (CRIA) Crest Certified Threat Intelligence Analyst (CCTIA) Crest Certified Blue Team Professional (CCBTP) Microsoft SC-200 or related detection and response certifications Other recognised cyber security or threat intelligence credentials
Apr 30, 2026
Full time
SOC / Cyber Threat Detection Analyst - SANS/GIAC Cyber Threat Detection Analyst Location: Wokingham, Berkshire (On-site) Salary: Competitive (dependent on experience) + excellent benefits & training Security Clearance: Ideally SC Cleared or eligible for SC Role Overview As a Cyber Threat Detection Analyst, you will play a hands-on role within an advanced cyber defence function, focused on proactive threat hunting, adversary behaviour analysis, and high-fidelity threat detection across enterprise environments. This role goes beyond reactive alert handling. You will actively hunt for malicious activity using telemetry, SIEM data, and threat intelligence, develop hypotheses based on MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs), and support incident management and response activities when threats are identified. We are open to experienced SOC Analysts where threat hunting, investigations, and proactive detection have formed a significant part of their role, and who are looking to further develop in a more hunting-led environment. This position is well suited to analysts who enjoy thinking like an attacker, have worked alongside or supported red team or purple team activities, and want to deepen their expertise in threat detection and detection engineering. Skills & Experience We're Seeking Experience in threat hunting, cyber threat detection, SOC, blue team, or cyber defence environments, with ideally around five years hands on experience. Strong hands-on experience using SIEM platforms, including: Microsoft Sentinel (KQL) Splunk (SPL) Elastic Security/Kibana (KQL, ESQL) Practical and operational understanding of MITRE ATT&CK, attacker techniques, and adversary tradecraft Experience working with Indicators of Compromise (IOCs) and threat intelligence feeds Solid experience across the security event life cycle, including detection, investigation, and incident management Hands-on experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike, SentinelOne, or Carbon Black Strong knowledge of networking fundamentals (TCP/IP, DNS, HTTP/S, Firewalls, VPNs, Proxy technologies) Experience analysing telemetry from Windows, Linux, identity, endpoint, and network sources Strong analytical mindset with the ability to clearly communicate findings, impact, and risk Key Responsibilities Conduct proactive threat hunting activities across log, endpoint, and network telemetry to identify suspicious, stealthy, or previously unknown threats Develop and execute hunt hypotheses aligned to MITRE ATT&CK TTPs, adversary behaviours, and emerging threat intelligence Write, refine, and optimise SIEM queries using KQL, SPL, Elastic/ESQL, and Kibana Query Language Perform IOC analysis, enrichment, and validation, integrating internal and external threat intelligence sources Lead investigations from initial detection through scoping, root cause analysis, and impact assessment Support incident management and incident response activities, including containment, remediation, escalation, and lessons learned Collaborate closely with SOC teams, incident responders, red teams, and purple teams to validate detections and improve defensive coverage Contribute to detection logic improvements, use-case development, and continuous enhancement of hunting methodologies Produce clear investigation write-ups, timelines, and recommendations for technical and non-technical stakeholders Security Certifications (Highly Beneficial) SANS/GIAC certifications, including but not limited to: GCIH - Incident Handler GCIA - Intrusion Analyst GCED - Enterprise Defender GCTI - Cyber Threat Intelligence GMON - Continuous Monitoring GDAT - Defending Advanced Threats GCAT - Advanced Threat Intelligence OSCP or equivalent offensive security qualifications Crest certifications, such as: Crest Practitioner Intrusion Analyst (CPIA) Crest Registered Intrusion Analyst (CRIA) Crest Certified Threat Intelligence Analyst (CCTIA) Crest Certified Blue Team Professional (CCBTP) Microsoft SC-200 or related detection and response certifications Other recognised cyber security or threat intelligence credentials
SOC / Cyber Threat Detection Analyst - SANS/GIAC Cyber Threat Detection Analyst Location: Wokingham, Berkshire (On-site) Salary: Competitive (dependent on experience) + excellent benefits & training Security Clearance: Ideally SC Cleared or eligible for SC Role Overview As a Cyber Threat Detection Analyst, you will play a hands-on role within an advanced cyber defence function, focused on proactive threat hunting, adversary behaviour analysis, and high-fidelity threat detection across enterprise environments. This role goes beyond reactive alert handling. You will actively hunt for malicious activity using telemetry, SIEM data, and threat intelligence, develop hypotheses based on MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs), and support incident management and response activities when threats are identified. We are open to experienced SOC Analysts where threat hunting, investigations, and proactive detection have formed a significant part of their role, and who are looking to further develop in a more hunting-led environment. This position is well suited to analysts who enjoy thinking like an attacker, have worked alongside or supported red team or purple team activities, and want to deepen their expertise in threat detection and detection engineering. Skills & Experience We're Seeking Experience in threat hunting, cyber threat detection, SOC, blue team, or cyber defence environments, with ideally around five years hands on experience. Strong hands-on experience using SIEM platforms, including: Microsoft Sentinel (KQL) Splunk (SPL) Elastic Security/Kibana (KQL, ESQL) Practical and operational understanding of MITRE ATT&CK, attacker techniques, and adversary tradecraft Experience working with Indicators of Compromise (IOCs) and threat intelligence feeds Solid experience across the security event life cycle, including detection, investigation, and incident management Hands-on experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike, SentinelOne, or Carbon Black Strong knowledge of networking fundamentals (TCP/IP, DNS, HTTP/S, Firewalls, VPNs, Proxy technologies) Experience analysing telemetry from Windows, Linux, identity, endpoint, and network sources Strong analytical mindset with the ability to clearly communicate findings, impact, and risk Key Responsibilities Conduct proactive threat hunting activities across log, endpoint, and network telemetry to identify suspicious, stealthy, or previously unknown threats Develop and execute hunt hypotheses aligned to MITRE ATT&CK TTPs, adversary behaviours, and emerging threat intelligence Write, refine, and optimise SIEM queries using KQL, SPL, Elastic/ESQL, and Kibana Query Language Perform IOC analysis, enrichment, and validation, integrating internal and external threat intelligence sources Lead investigations from initial detection through scoping, root cause analysis, and impact assessment Support incident management and incident response activities, including containment, remediation, escalation, and lessons learned Collaborate closely with SOC teams, incident responders, red teams, and purple teams to validate detections and improve defensive coverage Contribute to detection logic improvements, use-case development, and continuous enhancement of hunting methodologies Produce clear investigation write-ups, timelines, and recommendations for technical and non-technical stakeholders Security Certifications (Highly Beneficial) SANS/GIAC certifications, including but not limited to: GCIH - Incident Handler GCIA - Intrusion Analyst GCED - Enterprise Defender GCTI - Cyber Threat Intelligence GMON - Continuous Monitoring GDAT - Defending Advanced Threats GCAT - Advanced Threat Intelligence OSCP or equivalent offensive security qualifications Crest certifications, such as: Crest Practitioner Intrusion Analyst (CPIA) Crest Registered Intrusion Analyst (CRIA) Crest Certified Threat Intelligence Analyst (CCTIA) Crest Certified Blue Team Professional (CCBTP) Microsoft SC-200 or related detection and response certifications Other recognised cyber security or threat intelligence credentials
Apr 30, 2026
Full time
SOC / Cyber Threat Detection Analyst - SANS/GIAC Cyber Threat Detection Analyst Location: Wokingham, Berkshire (On-site) Salary: Competitive (dependent on experience) + excellent benefits & training Security Clearance: Ideally SC Cleared or eligible for SC Role Overview As a Cyber Threat Detection Analyst, you will play a hands-on role within an advanced cyber defence function, focused on proactive threat hunting, adversary behaviour analysis, and high-fidelity threat detection across enterprise environments. This role goes beyond reactive alert handling. You will actively hunt for malicious activity using telemetry, SIEM data, and threat intelligence, develop hypotheses based on MITRE ATT&CK Tactics, Techniques, and Procedures (TTPs), and support incident management and response activities when threats are identified. We are open to experienced SOC Analysts where threat hunting, investigations, and proactive detection have formed a significant part of their role, and who are looking to further develop in a more hunting-led environment. This position is well suited to analysts who enjoy thinking like an attacker, have worked alongside or supported red team or purple team activities, and want to deepen their expertise in threat detection and detection engineering. Skills & Experience We're Seeking Experience in threat hunting, cyber threat detection, SOC, blue team, or cyber defence environments, with ideally around five years hands on experience. Strong hands-on experience using SIEM platforms, including: Microsoft Sentinel (KQL) Splunk (SPL) Elastic Security/Kibana (KQL, ESQL) Practical and operational understanding of MITRE ATT&CK, attacker techniques, and adversary tradecraft Experience working with Indicators of Compromise (IOCs) and threat intelligence feeds Solid experience across the security event life cycle, including detection, investigation, and incident management Hands-on experience with EDR/XDR technologies such as Microsoft Defender, CrowdStrike, SentinelOne, or Carbon Black Strong knowledge of networking fundamentals (TCP/IP, DNS, HTTP/S, Firewalls, VPNs, Proxy technologies) Experience analysing telemetry from Windows, Linux, identity, endpoint, and network sources Strong analytical mindset with the ability to clearly communicate findings, impact, and risk Key Responsibilities Conduct proactive threat hunting activities across log, endpoint, and network telemetry to identify suspicious, stealthy, or previously unknown threats Develop and execute hunt hypotheses aligned to MITRE ATT&CK TTPs, adversary behaviours, and emerging threat intelligence Write, refine, and optimise SIEM queries using KQL, SPL, Elastic/ESQL, and Kibana Query Language Perform IOC analysis, enrichment, and validation, integrating internal and external threat intelligence sources Lead investigations from initial detection through scoping, root cause analysis, and impact assessment Support incident management and incident response activities, including containment, remediation, escalation, and lessons learned Collaborate closely with SOC teams, incident responders, red teams, and purple teams to validate detections and improve defensive coverage Contribute to detection logic improvements, use-case development, and continuous enhancement of hunting methodologies Produce clear investigation write-ups, timelines, and recommendations for technical and non-technical stakeholders Security Certifications (Highly Beneficial) SANS/GIAC certifications, including but not limited to: GCIH - Incident Handler GCIA - Intrusion Analyst GCED - Enterprise Defender GCTI - Cyber Threat Intelligence GMON - Continuous Monitoring GDAT - Defending Advanced Threats GCAT - Advanced Threat Intelligence OSCP or equivalent offensive security qualifications Crest certifications, such as: Crest Practitioner Intrusion Analyst (CPIA) Crest Registered Intrusion Analyst (CRIA) Crest Certified Threat Intelligence Analyst (CCTIA) Crest Certified Blue Team Professional (CCBTP) Microsoft SC-200 or related detection and response certifications Other recognised cyber security or threat intelligence credentials
Sanderson Government & Defence
Milton Keynes, Buckinghamshire
DV Cleared - L1 SOC Analyst Location : Milton Keynes Rate: £500 - £650 IR35 Status: Inside Initial Contract Length: 5 months Shift Pattern: 24/7 19 days in a month comprised of, 12-hour days, 8-hour days and 12-hour nights Clearance: Must have active DV Sanderson G&D are seeking L1 SOC Analysts, at both a junior and senior level to join a new programme of work supporting a public sector client on interesti click apply for full job details
Apr 29, 2026
Contractor
DV Cleared - L1 SOC Analyst Location : Milton Keynes Rate: £500 - £650 IR35 Status: Inside Initial Contract Length: 5 months Shift Pattern: 24/7 19 days in a month comprised of, 12-hour days, 8-hour days and 12-hour nights Clearance: Must have active DV Sanderson G&D are seeking L1 SOC Analysts, at both a junior and senior level to join a new programme of work supporting a public sector client on interesti click apply for full job details