About the Role
This temporary position as Lead SOC Analyst - DV Cleared in Buckinghamshire offers £80 per hour on a 42-hour week. The successful candidate must hold active DV clearance. Working a 12-hour shift pattern covering 7am-7pm and 7pm-7am, across 7 days and 7 nights within a four-week rotation, this six-month contract centres on operational leadership of the Security Monitoring function. Responsibilities include overseeing shift-based delivery, ensuring prompt investigation, triage and escalation of cyber events, and supervising a Senior SOC Analyst to maintain professional and technical standards. The post holder also acts as Duty Lead, coordinating responses and upholding consistent, high-quality security monitoring throughout every rotation.
YOU MUST HAVE ACTIVE DV CLEARANCE
Lead SOC Analyst
£80 per hour - 42 hour weeks
12 Hour shifts (7am-7pm and 7pm-7am)
7 Days and 7 Nights over a 4-week pattern
6 month contract initially
Buckinghamshire
Summary - The 3x Lead SOC Analysts will be responsible for the operational leadership of the Security Monitoring function, ensuring the consistent delivery of high-quality security monitoring, investigation and escalation activities.
Responsibilities
- Lead the shift-based delivery of Security Monitoring services, ensuring timely and effectivemonitoring, investigation, triage and escalation of cyber security events.
- Supervise and coordinate a Senior SOCAnalyst, ensuring investigations meet required professional, technical and documentation standards.
- Act as Duty Lead for Security Monitoring, providing technical leadershipand making operational decisions during live cyber security events.
- Review and quality-assure SOC investigations, confirming findings are accurate, evidence-based and clearly documented.
- Lead complex and high-priority cyber security investigations before escalation to the Incident Response team, as delegated by the Principal SOC Analyst.
- Deliver clear and effective shift handovers, maintaining situational awareness and continuity across ongoing investigations and incidents.
- Coordinate with Incident Responders during cyber security incidents, clearly communicating analytical findings, timelines, indicators of compromise and supporting evidence.
- Collaborate with SOC Engineers to improve monitoring coverage, alert quality and operational effectiveness.
- Support the onboarding of new systems, applicationsand cloud services into SOC monitoringby validating monitoring content and operational readiness.
- Drive continuous improvement across monitoring processes, investigation techniques and analyst efficiency, recommending enhancements to the Principal SOC Analyst.
- Mentor and coach SOC Analysts, supporting their professional development and promoting consistent analytical standards and investigation best practice.
- Ensure compliance with SOC operating procedures, security monitoringstandards and information-handling requirements.
- Identify and escalate operational issues, monitoring gaps and emerging threats to the Principal SOC Analyst and SOC Manager.
Required Skills / Experience
- Demonstrable experience working within a SOC or comparable cyber security operations environment.
- Experience leading security monitoring activities and supervising analysts during live operational service.
- Strong knowledge of SIEM platforms, log analysis, security monitoring technologies and security event investigation.
- Experience investigating complex cyber security events and determining appropriate escalation paths.
- Good understanding of cyber-attack techniques, indicators of compromise, threat intelligence and defensive monitoring.
- Experience in mentoring or coaching technical staff within an operational environment.
- Excellent analytical, investigative and problem-solving skills.
- Strong written and verbal communication skills, including the ability to communicate clearly under operational pressure.
- Ability to make timely decisions within a fast-paced 24/7 operational environment.
- Profession certifications such as Microsoft SC-200, GIAC GCIH, GCIA, CompTIA CySA+ or equivalent.
Desirable:
- Experience using Microsoft Sentinel, LogRhythm, or equivalent enterprise SIEM platforms.
- Experience developing monitoring improvements, detection tuning, or operational process development.
- Experience supporting Incident Responder activities during major cybe
Other jobs of interest...
Perform a fresh search...
-
Create your ideal job search criteria by
completing our quick and simple form and
receive daily job alerts tailored to you!
