Lead Security Operations Center Analyst (f/m/d)

Thinkproject

Reading

Hybrid

GBP 65,000 - 85,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Lunch & Learn Sessions
Hybrid working
Unlimited learning

Job summary

Thinkproject in Reading is seeking a highly experienced Lead Security Operations Centre (SOC) Analyst to oversee daily operations and enhance the SOC's threat detection and response capabilities. This role involves leading investigations into advanced security threats, managing incident responses, and collaborating with cross-functional teams to strengthen security posture.

Candidates should have a Bachelor’s degree in cyber security or a related field, along with proven experience with SIEM tools and incident response procedures. The position offers a hybrid working environment and opportunities for professional development.

Qualifications

  • Strong knowledge of cybersecurity principles and incident response procedures.
  • Hands-on experience with SIEM tools and vulnerability identification.
  • Proficient in spoken and written English for effective communication.

Responsibilities

  • Investigate and respond to security alerts and events.
  • Lead proactive threat hunting activities.
  • Manage complex cybersecurity incidents from end-to-end.
  • Collaborate across teams to mitigate vulnerabilities and threats.
  • Enhance SOC operations with improved detection and response capabilities.

Skills

Incident response
Threat hunting
SIEM tools
Forensic analysis
Communication (English)

Education

Bachelor’s degree in cyber security or related field

Tools

Microsoft Sentinel
SIEM platforms
Endpoint Detection and Response (EDR)
Threat intelligence platforms
Vulnerability identification tools

Job description

Introducing Thinkproject Platform

Pioneering a new era and offering a cohesive alternative to the fragmented landscape of construction software, Thinkproject seamlessly integrates the most extensive portfolio of mature solutions with an innovative platform, providing unparalleled features, integrations, user experiences, and synergies.


What do we do?

By combining information management expertise and in-depth knowledge of the building, infrastructure, and energy industries, Thinkproject empowers customers to efficiently deliver, operate, regenerate, and dispose of their built assets across their entire lifecycle through a Connected Data Ecosystem.


What your day will look like

We are looking for a highly experienced and technically skilled Lead Security Operations Centre (SOC) Analyst to join our team and take ownership of the day to day operation and continuous improvement of our Security Operations Centre. This role combines deep technical expertise with operational leadership, people management, and project delivery responsibilities, ensuring the SOC remains effective in identifying, investigating, and responding to advanced security threats, issues, and vulnerabilities across the organisation.


As the lead member of the team, you will oversee SOC operations, manage and coordinate complex security investigations, and provide technical leadership during all incidents. You will lead investigations into sophisticated threats such as advanced persistent threats (APTs), malware outbreaks, and targeted attacks, whilst performing hands on analysis of security events, forensic evidence collection, and root cause analysis. You will also drive the development and enhancement of detection capabilities across SIEM, EDR, and other monitoring technologies, while continuously improving SOC processes, procedures, workflows, automation, and playbooks to increase operational effectiveness and maturity.


You will actively engage in threat hunting, leveraging your deep understanding of application code, infrastructure and hosting architectures (cloud and on premises), the software development lifecycle (SDLC), and CI/CD pipeline solutions to identify risks that span traditional and cloud native environments. You will collaborate closely with Security Engineering, IT, DevOps, and application teams to improve detection coverage, enhance monitoring capabilities, and strengthen the organisation's overall security posture. Alongside your technical responsibilities, you will provide line management for SOC analysts, including mentoring, coaching, performance management, and professional development, whilst overseeing workload prioritisation, SOC reporting, and the successful delivery of projects associated with SOC tooling, automation, compliance, and operational maturity.


This role encompasses reactive incident response, proactive detection engineering, threat hunting, vulnerability management, and operational leadership. You will also contribute to strategic initiatives including penetration testing coordination, security assessments, audit preparation, threat intelligence activities, and the maintenance of SOC documentation and reporting.


This role sits within the Product Operations and Corporate IT branch, reporting to the Director of Cyber Security and Networking, and operates as part of the broader Cyber Security, Network, and Security Engineering teams.


Main Responsibilities


  • Independently investigate and respond to security alerts and events from SIEM, EDR, and other security tools across endpoints, networks, cloud platforms, and applications.

  • Lead proactive threat hunting activities, leveraging threat intelligence, application logs, and infrastructure telemetry to uncover indicators of compromise or stealthy threat activity.

  • Perform in-depth analysis of logs, API configurations and traffic, container environments, network data, application and infrastructure architecture, as well as data centre hosting environments to support threat detection, incident investigation, and root cause analysis.

  • Manage complex cybersecurity incidents end-to-end, including containment, eradication, recovery, and post-incident analysis, while coordinating closely with cross-functional stakeholders.

  • Deploy, operate, configure, and tune SIEM platforms and detection tools to enhance signal accuracy, reduce alert fatigue, and maintain effective detection coverage.

  • Design, build, and maintain incident response playbooks and automation workflows to increase the efficiency, speed, and consistency of incident response processes.

  • Simultaneously manage multiple active investigations and day-to-day SOC operations, effectively prioritise tasks and manage time under pressure.

  • Conduct forensic analysis during investigations, including evidence preservation, malware analysis, memory examination, and root cause identification.

  • Collaborate with DevOps, IT, and development teams to ensure timely containment, mitigation, and remediation of vulnerabilities and threats.

  • Coordinate outputs from security assessment tools and penetration tests, ensuring clear ownership and timely closure of identified issues.

  • Participate in and lead security testing exercises to evaluate and strengthen detection capabilities and response procedures.

  • Drive continuous improvement of SOC operations by identifying logging gaps, proposing monitoring enhancements, and introducing new detection or response technologies.

  • Maintain comprehensive documentation of investigations, incidents, tuning efforts, and threat intelligence to support reporting, knowledge sharing, and audit readiness.

  • Stay current with evolving threat landscapes, adversary techniques, and emerging security tools and practices to strengthen SOC capabilities.

  • Adapt SOC processes, solutions, and procedures to enhance the monitoring of the organization's IT network health.

  • Ensure security operations and incident response practices are aligned with industry recognised frameworks such as ISO 27001.

  • Implement solutions within CI/CD pipelines to identify and block security issues reaching production environments.

  • Support the development and refinement of SOC procedures, training materials, and operational standards to enhance maturity and consistency across the team.

  • Act as the operational lead for the SOC, overseeing day-to-day activities, workload prioritisation, incident coordination, and service delivery to ensure effective security monitoring and response capabilities.

  • Provide line management, coaching, mentoring, and professional development support to SOC analysts, fostering a high-performing and collaborative security operations culture.


What you need to fulfill the role

You Must Have


  • Proficiency in spoken and written English, with the ability to communicate effectively across both technical and non-technical audiences.

  • The ability to communicate difficult or sensitive information tactfully.


Education & Experience


  • Bachelor’s degree in cyber security or a related field, or equivalent professional experience.

  • Strong knowledge of cybersecurity principles, threat landscapes, and incident response procedures.

  • Awareness of current and emerging cyber threats affecting SaaS organisations.


Technical Skills


  • Hands‑on experience with implementation, ongoing management and maturing of Security Information and Event Management (SIEM) tools, Endpoint Detection and Response (EDR) platforms, threat intelligence platforms, and vulnerability identification tools.

  • Experience integrating custom‑built applications into SIEM platforms.

  • Experience with implementation of automation solutions, enhancing SOC efficiency and speeding incident response.

  • Familiarity with Security Orchestration, Automation and Response (SOAR) platforms, including developing and maintaining automated response playbooks.

  • Experience with threat hunting focused on application code, application, infrastructure and hosting architecture, leveraging coding skills and a solid understanding of the software development lifecycle (SDLC) and infrastructure components.

  • Experience managing security issues identified through internal tools and external assessments, ensuring remediation is completed in line with company policies and standards.

  • Knowledge of common security frameworks and best practices.

  • Experience implementing solutions to detect and block security risks in CI/CD pipelines to prevent vulnerable code from being deployed into production.


SOC Operations


  • Experience in complex incident response and investigation, including forensic evidence handling and root cause analysis.

  • Experience managing business‑as‑usual (BAU) security operations workload alongside project‑based work, both independently and in coordination with other team members.

  • Experience managing outputs from cybersecurity assessment tools, coordinating timely mitigation and remediation with key stakeholders.

  • Experience coordinating outsourced penetration tests, ensuring smooth execution without service disruption.

  • Experience conducting security assessment exercises to evaluate SOC operational effectiveness and the organization’s ability to respond to cybersecurity incidents.

  • Experience in tuning detection rules and alerts to improve accuracy and reduce false positives in security monitoring.


Technical Expertise


  • Experience with Azure, Azure AD, and AWS technologies and services.

  • Experience conducting forensic analysis of cybersecurity incidents.


Teamwork & Leadership


  • A positive, self‑motivated attitude.

  • The ability to work effectively in a team environment, collaborating with cross‑functional teams to achieve shared objectives.

  • Strong time management and prioritisation skills, with the ability to manage your own workload.

  • The ability to perform effectively under pressure, prioritise tasks, and make sound decisions in high‑stress or emergency situations.

  • A proactive mindset with the ability to critically evaluate your own work, identify improvement opportunities, and automate, simplify, or standardise processes where appropriate.

  • Experience mentoring, coaching, or providing technical leadership to junior team members.

  • Experience coordinating and prioritising team activities within a security operations environment.


Language Skills


  • Proficiency in German (spoken and written). (Optional)


SOC Operations (Advanced)


  • Experience conducting red or purple team exercises to validate detection capabilities and improve response playbooks.

  • Familiarity with security operations in containerised environments and microservices architectures (e.g., Kubernetes, Docker).


Technical Skills (Advanced)


  • Understanding of advanced detection engineering techniques, such as creating custom correlation rules and behavioural analytics in SIEM platforms.

  • Exposure to secure software development practices and security testing of APIs, containers, and cloud‑native applications.

  • Experience conducting both external and internal penetration testing of applications and infrastructure.


Technical Expertise (Advanced)


  • Experience with Microsoft Sentinel SIEM Solutions.

  • Experience working within a SaaS or software‑driven organisation, particularly in multi‑tenant or cloud‑native environments.

  • Experience with AI technologies, including understanding the cybersecurity threats they pose to organisations and how they can be leveraged to enhance operational effectiveness.


What we offer

Lunch & Learn Sessions • Women’s Network • LGBTQIA+ Network • Coffee Chat Roulette • Free English Lessons • Thinkproject Academy • Social Events • Volunteering Activities • Open Forum with Leadership Team (Tp Café) • Hybrid working • Unlimited learning

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Automation Engineer
SOC Automation Engineer

Phoenix Software • Pocklington

On-site
GBP 65,000 - 90,000
Hybrid working
SC clearance support
SOC Operations Technical Lead
SOC Operations Technical Lead

Nettitude Group • Birmingham

On-site
GBP 90,000 - 120,000
SOC Manager
SOC Manager

CyPro • Greater London

On-site
GBP 90,000 - 120,000
SOC Operations Technical Lead
SOC Operations Technical Lead

LRQA • Birmingham

Hybrid
GBP 70,000 - 90,000
SOC Manager: AI-Driven Security & Growth Leader
SOC Manager: AI-Driven Security & Growth Leader

Resillion • Glasgow

Hybrid
GBP 90,000 - 120,000
SOC Engineer
SOC Engineer

Spectrum IT Recruitment • Milton Keynes

On-site
GBP 41,000 - 50,000
SOC Lead
SOC Lead

NCC Group • Greater London

Hybrid
GBP 65,000 - 90,000
Flexible working
25 days holiday
Pension & Life Assurance
+2
24/7 SOC Analyst
24/7 SOC Analyst

Nomios • Basingstoke

On-site
GBP 35,000 - 52,000
SecOps Engineer
SecOps Engineer

Manchester Arndale • Greater London

Hybrid
GBP 60,000 - 90,000
SOC Manager (MSSP Leader) - Hybrid
SOC Manager (MSSP Leader) - Hybrid

Resillion • Glasgow

Hybrid
GBP 90,000 - 120,000