<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
  <channel>
    <title>SOC Lead - Experis RSS Feed</title>
    <link>https://jobs.co.uk/job/soc-lead-experis--0fa64845-7189-454a-80f9-3dbdd769f3d2</link>
    <description>RSS feed for SOC Lead at Experis.</description>
    <language>en-gb</language>
    <lastBuildDate>Sat, 02 May 2026 14:03:33 GMT</lastBuildDate>
    <item>
      <title>SOC Lead - Experis</title>
      <link>https://jobs.co.uk/job/soc-lead-experis--0fa64845-7189-454a-80f9-3dbdd769f3d2</link>
      <guid>https://jobs.co.uk/job/soc-lead-experis--0fa64845-7189-454a-80f9-3dbdd769f3d2</guid>
      <pubDate>Thu, 30 Apr 2026 23:00:00 GMT</pubDate>
      <description>Location: Bath | Salary: &amp;pound;600 - &amp;pound;700/day | Type: Contract | SOC Lead     6 months     Bath - hybrid x3 days onsite x2 remote     Active SC/DV clearance required     -700 per day outside IR35         The SOC Lead - Threat Hunting &amp; Investigations is responsible for leading advanced threat detection, proactive threat hunting, and complex security investigations across the enterprise. This role focuses on identifying unknown threats, coordinating deep-dive investigations, and elevating the maturity of SOC investigative and hunting capabilities. The role combines technical leadership, hands-on expertise, and mentorship of analysts.   Key Responsibilities    Threat Hunting    Lead proactive, hypothesis-driven threat hunting activities across endpoint, network, cloud, identity, and SaaS environments  Develop and maintain threat hunting playbooks aligned to MITRE ATT&amp;CK techniques  Identify stealthy, low-and-slow, and novel attack patterns not detected by automated controls  Translate threat intelligence into actionable hunt hypotheses  Continuously refine detection logic based on hunt outcomes and emerging threats    Investigations &amp; Incident Response    Lead complex and high-severity security investigations from triage through containment and re...</description>
      <category>Contract</category>
    </item>
  </channel>
</rss>