Contract

Lead SOC Analyst - DV Cleared

Network IT
Buckinghamshire, Buckinghamshire, HP19 0UN
money-bag £80 per hour
Posted: 25 September 2026 (Today)
Closing date: 25 October 2026
Ref: 60994879

About the Role

Based in Buckinghamshire, this contract position seeks a Lead SOC Analyst - DV Cleared to provide operational leadership within a Security Monitoring function. The role involves supervising shift-based delivery, ensuring effective triage, investigation and escalation of cyber security events. Working 12-hour shifts across a 4-week rotation of days and nights, the post-holder coordinates a Senior SOC Analyst, upholding technical and documentation standards. Acting as Duty Lead, they manage incidents and maintain service quality. Candidates must hold active DV clearance and possess strong leadership, analytical and communication abilities. The rate is £80 per hour for an initial six-month term, covering 42-hour weeks.

YOU MUST HAVE ACTIVE DV CLEARANCE
Lead SOC Analyst
£80 per hour - 42 hour weeks
12 Hour shifts (7am-7pm & 7pm-7am)
7 Days & 7 Nights over a 4-week pattern
6 month contract initially
Buckinghamshire
Summary - The 3x Lead SOC Analysts will be responsible for the operational leadership of the Security Monitoring function, ensuring the consistent delivery of high-quality security monitoring, investigation and escalation activities.
Responsibilities

  • Lead the shift-based delivery of Security Monitoring services, ensuring timely and effectivemonitoring, investigation, triage and escalation of cyber security events.
  • Supervise and coordinate a Senior SOCAnalyst, ensuring investigations meet required professional, technical and documentation standards.
  • Act as Duty Lead for Security Monitoring, providing technical leadershipand making operational decisions during live cyber security events.
  • Review and quality-assure SOC investigations, confirming findings are accurate, evidence-based and clearly documented.
  • Lead complex and high-priority cyber security investigations before escalation to the Incident Response team, as delegated by the Principal SOC Analyst.
  • Deliver clear and effective shift handovers, maintaining situational awareness and continuity across ongoing investigations and incidents.
  • Coordinate with Incident Responders during cyber security incidents, clearly communicating analytical findings, timelines, indicators of compromise and supporting evidence.
  • Collaborate with SOC Engineers to improve monitoring coverage, alert quality and operational effectiveness.
  • Support the onboarding of new systems, applicationsand cloud services into SOC monitoringby validating monitoring content and operational readiness.
  • Drive continuous improvement across monitoring processes, investigation techniques and analyst efficiency, recommending enhancements to the Principal SOC Analyst.
  • Mentor and coach SOC Analysts, supporting their professional development and promoting consistent analytical standards and investigation best practice.
  • Ensure compliance with SOC operating procedures, security monitoringstandards and information-handling requirements.
  • Identify and escalate operational issues, monitoring gaps and emerging threats to the Principal SOC Analyst and SOC Manager.
Required Skills / Experience
  • Demonstrable experience working within a SOC or comparable cyber security operations environment.
  • Experience leading security monitoring activities and supervising analysts during live operational service.
  • Strong knowledge of SIEM platforms, log analysis, security monitoring technologies and security event investigation.
  • Experience investigating complex cyber security events and determining appropriate escalation paths.
  • Good understanding of cyber-attack techniques, indicators of compromise, threat intelligence and defensive monitoring.
  • Experience in mentoring or coaching technical staff within an operational environment.
  • Excellent analytical, investigative and problem-solving skills.
  • Strong written and verbal communication skills, including the ability to communicate clearly under operational pressure.
  • Ability to make timely decisions within a fast-paced 24/7 operational environment.
  • Profession certifications such as Microsoft SC-200, GIAC GCIH, GCIA, CompTIA CySA+ or equivalent.
Desirable:
  • Experience using Microsoft Sentinel, LogRhythm, or equivalent enterprise SIEM platforms.
  • Experience developing monitoring improvements, detection tuning, or operational process development.
  • Experience supporting Incident Responder activities during major cyber security incidents.
  • Experience contributing to the development of monitoring use cases and detection improvements.
  • Applied knowledge of MITRE ATT&CK or equivalent adversary behaviour frameworks.
 

Other jobs of interest...

Anson Mccade
Tewkesbury1 week ago
money-bag10000-500000 Annual
Anson Mccade
Tewkesbury2 weeks ago
money-bagNegotiable
Newto Training
Colchester2 weeks ago
money-bag10000-500000 Annual
Newto Training
Hereford2 weeks ago
money-bag10000-500000 Annual

Perform a fresh search...

  • Create your ideal job search criteria by
    completing our quick and simple form and
    receive daily job alerts tailored to you!

Jobs. Straight to your inbox!