Salary: £? - ? per year
Requirements:
- Current Developed Vetting (DV) clearance is essential.
- Strong experience administering and tuning SIEM and SOAR platforms.
- Hands on experience with technologies such as Elastic, Trend Micro, Tripwire, Tanium, Clearswift, and SolarWinds.
- Experience in threat hunting, incident response, digital forensics, and malware analysis.
- Strong understanding of Windows and Linux environments.
- Experience writing and tuning detection signatures, correlation rules, and monitoring use cases.
- Knowledge of log collection, aggregation, and analysis technologies including ELK Stack, Syslog, and Windows Event Forwarding.
- Experience with scripting and automation using Python, PowerShell, Bash, Perl, or similar.
- Understanding of network forensics, threat intelligence, and cyber threat detection methodologies.
- Knowledge of ISO 27001:2022, MITRE ATT&CK, and IT Service Management principles.
Responsibilities:
- Maintain and optimise SOC Protect, Detect, and Respond tooling.
- Configure, implement, and support new security monitoring technologies.
- Develop detection rules, correlation logic, automation scripts, and response playbooks.
- Manage vulnerability scanning platforms and contribute to wider SOC strategy.
- Integrate and onboard standard and non standard log sources into SIEM platforms.
- Monitor, investigate, and respond to security incidents and emerging threats.
- Conduct forensic investigations and malware analysis, producing actionable intelligence and Indicators of Compromise (IoCs).
- Tune and enhance SIEM, SOAR, EDR, DLP, email security, and intrusion detection technologies.
- Analyse attacker tactics, techniques, and procedures (TTPs) using frameworks such as MITRE ATT&CK.
- Produce dashboards, reports, and recommendations to improve security posture.
- Ensure adherence to operational processes, SLAs, KPIs, and security policies.
- Drive continuous improvement across SOC processes, tooling, and service delivery.
Technologies:
- Bash
- ELK
- Support
- Linux
- Network
- Perl
- PowerShell
- Python
- Security
- Windows
We are seeking an experienced Senior SOC Analyst to join a high performing Cyber Security Operations Centre supporting critical national security environments. This is a long term contract opportunity of 9 months plus, offered inside IR35, with a day rate of £575 to £630. The role is based in Corsham or Portsmouth. We work at the forefront of cyber defence, supporting complex enterprise environments and strengthening cyber resilience through threat detection, incident response, vulnerability management, and continuous improvement of our security monitoring capabilities.