Security Operations Centre (SOC) Manager (London)

CyPro

Greater London

Hybrid

GBP 80,000 - 120,000

Full time

44 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Training budget
Social activities
Canary Wharf office

Job summary

CyPro is a growing cyber security business seeking a SOC Manager to lead day-to-day MDR delivery across a portfolio of clients from our Canary Wharf office. You will lead SOC Analysts and Senior SOC Analysts, drive detections, investigations and reporting, and develop the team while maintaining high incident-response standards.

We value practical security operations expertise, strong stakeholder communication, and a track record of building capability within a SOC.

Qualifications

  • Experience leading or supervising a SOC or security operations team.
  • Strong practical knowledge of SIEM, EDR/XDR, incident response, alert triage, detection engineering, threat hunting, automation and SOC reporting.
  • Excellent written and spoken English for client and senior stakeholder communication.
  • Must have right to work in the UK and be able to work from Canary Wharf office three days per week.

Responsibilities

  • Own MDR delivery across a portfolio of clients.
  • Lead SOC Analysts and Senior SOC Analysts; escalation point for incidents.
  • Improve detections, investigations, automation, processes and reporting.
  • Develop people, challenge investigations and maintain technical credibility.
  • Manage workloads, SLAs, KPIs, and client communications.
  • Support onboarding, runbooks, and service improvements.
  • Coach and develop team; ensure quality of investigations and runbooks.

Skills

SOC leadership
Security operations
English communication
UK right to work
Cyber security background

Job description

Overview:

Holiday: 25 days, bank holidays and one additional day for every 12 months you stay with us.

Working Together: Three days per week in our Canary Wharf office, 39 floors up, with flexibility for the remaining two days.

Working Hours: 40 hours, Monday to Friday, with occasional support for serious incidents outside normal hours.

Training: An individual training plan and budget for one professional certification or course each year.

Socials: Regular drinks, team activities and the occasional bit of axe throwing.

Start Date: As soon as contractual notice allows

  • SOC leadership experience: You must have experience leading or supervising a SOC or security operations team, either within an MSSP/MDR provider or an in-house environment. Experience supporting multiple clients is useful but not essential.
  • Technical security operations: You must have strong practical knowledge of SIEM, EDR/XDR, incident response, alert triage, detection engineering, threat hunting, automation and SOC reporting. Microsoft Sentinel and Defender experience is highly desirable.
  • Communication: You must be able to communicate complex security and operational matters clearly and confidently in spoken and written English, including with clients and senior stakeholders.
  • Location and right to work: You must already have the right to work in the UK and be able to work from our Canary Wharf office three days per week. We cannot provide visa sponsorship.
  • Professional background: You must have a strong background in cyber security or a related technical discipline, gained through experience, qualifications or education. A degree is not mandatory.
About CyPro
  • CyPro is a growing cyber security business with a shared mission: to redefine cyber security for small and medium-sized businesses.
  • Our founders built their early careers delivering cyber security for large enterprises and central government. We saw an opportunity to bring the same level of security capability, expertise and discipline to organisations that are often underserved by traditional providers.
  • Our Managed Detection and Response service is a key part of that mission. We are now looking for a SOC Manager to lead the day-to-day operation and development of our SOC.
The Role
  • As SOC Manager, you will be accountable for the day-to-day delivery and continuous improvement of CyPro's Managed Detection and Response service across a portfolio of clients.
  • You will lead a small but growing team SOC Analysts and Senior SOC Analysts, maintain operational quality and act as a senior escalation point for incidents and service issues.
  • You will work closely with our technical, engineering and client-facing teams to improve detections, investigations, automation, processes and reporting.
  • As CyPro and the SOC grow, there will be significant opportunities for the role and your responsibilities to develop with them.
  • This is not a role where you simply supervise an alert queue.
  • Equally, we are not looking for somebody to spend all day personally investigating alerts.
  • We want a player-coach: an experienced security operations team leader who can develop people, challenge the quality of investigations, handle important client conversations and remain technically credible enough to know when something does not look right.
Client Delivery and Service Management
  • Own managed detection and response delivery across a portfolio of clients.
  • Act as the primary operational escalation point for clients and internal teams.
  • Lead service reviews, governance meetings and executive briefings.
  • Present incidents, trends, risks and recommendations clearly and commercially.
  • Own performance against SLAs, KPIs and contractual commitments.
  • Monitor incident trends, detection coverage, alert volumes, false positives and response performance.
  • Create service improvement plans where quality falls below expectations.
  • Lead client onboarding and service transition, coordinating deployment, documentation and stakeholders.
  • Manage major incident escalations and ensure responses are controlled, communicated and documented.
  • Line manage, coach and develop SOC Analysts and Senior SOC Analysts.
  • Set clear expectations for investigation quality, ownership, communication and timeliness.
  • Conduct regular one-to-ones, performance reviews and career development discussions.
  • Build development plans and support career progression.
  • Review investigations, incident reports and client communications.
  • Manage workload, priorities, operational coverage and capacity.
  • Support recruitment, assessment and onboarding.
  • Develop senior members of the team so operational responsibility does not depend entirely on the SOC Manager.
  • Address performance issues directly and constructively.
  • Act as a role model for professionalism, ownership and delivery quality.
Detection, Investigation and Response
  • Maintain oversight of detection coverage across client environments.
  • Ensure alerts and incidents are investigated consistently and appropriately.
  • Act as a senior escalation point during complex or high-severity incidents.
  • Review investigations and challenge incomplete analysis or weak conclusions.
  • Provide technical guidance to analysts where necessary.
  • Work with analysts, engineers and platform specialists to improve detection use cases.
  • Improve detection logic and reduce unnecessary false positives without weakening coverage.
  • Support the onboarding of new log sources and security technologies.
  • Identify opportunities to automate repetitive investigation and response activities.
  • Support threat hunting and the effective use of threat intelligence.
  • Turn lessons from incidents into improved detections, runbooks and response procedures.
  • Maintain awareness of emerging threats, attacker techniques and relevant SOC technologies.
  • You will not be expected to personally investigate every alert or build every detection rule.
  • You do, however, need sufficient technical depth to recognise poor analysis, ask the right questions and provide credible direction to the team.
Service Improvement and Practice Development
  • Own and improve runbooks, playbooks, workflows and operational procedures.
  • Ensure documentation is clear, current and usable during live incidents.
  • Standardise investigation, escalation and reporting across client environments.
  • Improve quality assurance for alerts, investigations, incidents and client deliverables.
  • Use operational data to identify weaknesses and prioritise improvements.
  • Improve client reporting and service governance.
  • Help develop repeatable operating models that allow the SOC to grow without reducing quality.
  • Evaluate security technologies, automation and AI-supported SOC tooling where appropriate.
  • Support proofs of concept and technical evaluations.
  • Contribute to the development of new Managed Detection and Response capabilities.
Client Delivery & Service Management
  • Own day-to-day MDR delivery across a portfolio of clients.
  • Act as a senior operational escalation point for clients and internal teams.
  • Support service reviews, governance meetings and executive briefings.
  • Present incidents, trends, risks and recommendations clearly.
  • Maintain oversight of agreed SLAs, KPIs and contractual service commitments.
  • Monitor incident trends, detection coverage, alert volumes and investigation quality.
  • Ensure service issues are owned, communicated and driven through to resolution.
  • Give clients confidence that their security operations service is being managed effectively.
Supporting CyPro's Growth

This is primarily an operational leadership role, not a sales position. From time to time you will:

  • Support pre-sales discussions where SOC expertise is required.
  • Explain CyPro's MDR capabilities to prospective clients.
  • Provide input into service designs and Statements of Work.
  • Help estimate onboarding effort, service capacity and technical resource requirements.
  • Identify operational opportunities to improve or expand services for existing clients.
  • Ensure new client requirements are technically realistic and can be delivered sustainably.
  • Commercial ownership, pricing and sales targets will not sit solely with the SOC Manager.
Professional Development
  • Maintain your technical and professional credibility through relevant learning and industry engagement.
  • Strong candidates will typically hold two or more relevant certifications, or demonstrate equivalent experience. Examples include Microsoft SC-200, AZ-500, CISSP, CISM, GCIA, GCIH, CompTIA CySA+ and CREST Certified Intrusion Analyst.
  • Effective: You remove obstacles, establish ownership and drive work through to completion.
  • Accountable and Humble: You take responsibility for SOC performance, accept feedback and change your approach when needed.
  • Calm Under Pressure: You remain structured, prioritise clearly and communicate confidently during serious incidents.
  • Technically Credible: You understand security operations well enough to challenge investigations, identify weak reasoning and guide the team.
  • Client Focused: You provide timely communication, clear recommendations and confidence that the service is well managed.
  • People Developer: You invest in your team, give direct feedback and address poor performance.
  • Commercially Aware: You balance strong security outcomes with contractual scope, resources and sustainable delivery.
  • Adaptable: You make sensible decisions in an evolving environment and help build processes that do not yet exist.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SOC Manager (MSSP Leader) - Hybrid
SOC Manager (MSSP Leader) - Hybrid

Resillion • Glasgow

Hybrid
GBP 90,000 - 120,000
SOC Manager (MSSP Leader) - Hybrid
SOC Manager (MSSP Leader) - Hybrid

Resillion • Birmingham

Hybrid
GBP 75,000 - 120,000
Senior Consultant - Cyber Security
Senior Consultant - Cyber Security

CyPro • Greater London

On-site
GBP 52,000 - 70,000
Holiday allowance
Birthday day off
Annual training budget
+2
Cyber Security Senior Consultant
Cyber Security Senior Consultant

CyPro • Greater London

On-site
GBP 47,000 - 57,000
Training budget for certification
Office Canary Wharf (London)
Social events and team outings
SOC Manager: AI-Driven Security & Growth Leader
SOC Manager: AI-Driven Security & Growth Leader

Resillion • Glasgow

Hybrid
GBP 90,000 - 120,000
SOC Lead
SOC Lead

SecurityHQ • Greater London

Hybrid
GBP 70,000 - 110,000
Technical Services Director
Technical Services Director

Hamilton Barnes ? • Greater London

On-site
GBP 90,000 - 120,000
Senior SOC Analyst
Senior SOC Analyst

Focus Group • Manchester

Hybrid
GBP 75,000 - 95,000
Manager SOC Security Specialist
Manager SOC Security Specialist

Fox-IT • Manchester

On-site
GBP 50,000 - 70,000
Flexible Working
Generous Holiday Allowance
Medicash & Critical Illness Scheme
+6
Senior SOC Analyst
Senior SOC Analyst

GCS Recruitment • England

On-site
GBP 90,000 - 120,000