Security Operations Manager

PA Consulting

Belfast City District

Hybrid

GBP 70,000 - 105,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Health and lifestyle perks
25 days annual leave
Generous pension
Annual performance-based bonus
PA share ownership
Cycle to work

Job summary

PA Consulting is seeking a Security Operations Manager to lead SOC analysts and incident response specialists within its Digital Trust & Cyber Security practice. You will manage live incidents, drive improvements to SIEM, SOAR and EDR, and guide clients in modernising security operations and resilience.

You will work across enterprise and public sector engagements, coach teams, and contribute to a culture of learning, collaboration and client impact. UK residency may be needed for clearance.

Qualifications

  • Experience leading a SOC/CSOC or incident response team.
  • Proven track record handling live cyber incidents (ransomware, account takeovers, supply chain).
  • Solid understanding of MITRE ATT&CK, NIST CSF, NCSC Caf v4.0 and ISO 27001.
  • Ability to communicate incident findings clearly to engineers and leaders.

Responsibilities

  • Lead and develop SOC analysts and incident response specialists with clear direction.
  • Lead hands-on during cyber incidents including containment and recovery.
  • Help clients assess and improve their Security Operations capabilities across people, processes and tech.
  • Advise on evolution of SIEM, SOAR and EDR tooling to improve detection and response.
  • Develop incident playbooks, runbooks and automated response workflows.
  • Share expertise across PA's Digital Trust & Cyber Security community through coaching and mentoring.

Skills

SOC Leadership
Incident Response
Communication
Security Frameworks
Client-facing Advisory

Tools

SIEM/SOAR tools
EDR/XDR platforms
Cloud security monitoring

Job description

Company Description

We believe in the power of ingenuity to build a positive human future.

As strategies, technologies, and innovation collide, we create opportunity from complexity. Our teams of interdisciplinary experts combine innovative thinking and breakthrough technologies to progress further, faster. Our clients adapt and transform, and together we achieve enduring results. We are over 4,000 strategists, innovators, designers, consultants, digital experts, scientists, engineers, and technologists. And we have deep expertise in consumer and manufacturing, defence and security, energy and utilities, financial services, government and public services, health and life sciences, and transport. Our teams operate globally from offices across the UK, Ireland, US, Nordics, and Netherlands.

PA. Bringing Ingenuity to Life.

Job Description

We are looking for a Security Operations Manager to join our Digital Trust & Cyber Security practice. Working on behalf of our clients, you will lead Security Operations Centre (SOC) analysts and incident response specialists. You will combine hands‑on operational leadership with advisory work. This means managing live incident containment and day‑to‑day SOC operations, while helping enterprise and public sector clients modernise their security operations, improve their SIEM, SOAR and EDR capabilities, and build stronger cyber resilience.

Why consider joining our Digital & Data community?
  • Join our Digital & Data team and work alongside cyber security, product, design and technology specialists in cross‑disciplinary teams to solve complex client challenges and bring ideas to life.
  • Build a flexible and distinctive career in a trust‑based, inclusive environment that values excellence, innovation and curiosity. You can progress through a technical career track without needing to follow the Partner career track if that does not align with your ambitions.
  • Work across a broad range of Security Operations engagements, client environments and technology stacks spanning seven sectors. No two projects are the same.
  • Join a supportive and collaborative cyber and technology community, with knowledge sharing, peer support, coaching and mentoring from other specialists.
  • Deepen your expertise through our culture of learning and growth, with access to a development budget for technical and non‑technical training and professional certifications.
  • Benefit from a hybrid working approach, with an expectation of being in the office or on a client site for a minimum of two days per week, depending on the role and assignment.
What you’ll do
  • Lead and develop SOC analysts and incident response specialists, providing clear operational direction, coaching and support across day‑to‑day security operations.
  • Take a hands‑on leadership role during cyber security incidents, coordinating investigation, containment, eradication, recovery, stakeholder communications and post‑incident reviews.
  • Help enterprise and public sector clients assess and improve their Security Operations capabilities, identifying gaps across people, processes and technology and translating these into practical improvements.
  • Advise on the evolution and optimisation of SIEM, SOAR, EDR and threat‑detection tooling to improve visibility, reduce noise and strengthen detection and response capabilities.
  • Develop and maintain incident playbooks, standard operating procedures, automated response workflows and proactive tabletop exercises.
  • Support the development of modern Security Operations services and ways of working, sharing your expertise across our Digital Trust & Cyber Security community through coaching, mentoring and knowledge sharing.
Security technologies you’ll work with
  • SIEM and security analytics platforms, such as Microsoft Sentinel and Splunk.
  • SOAR and security automation technologies used for enrichment, triage and response orchestration.
  • Endpoint Detection and Response (EDR/XDR) platforms, such as Microsoft Defender for Endpoint and CrowdStrike Falcon.
  • Threat intelligence, detection engineering, investigation and incident response technologies.
  • Cloud security monitoring across Microsoft Azure, AWS and GCP environments.
What you can expect
  • Work collaboratively across multiple technical teams and stakeholder groups, using your Security Operations expertise to solve complex client problems and contribute to internal initiatives.
  • Participate in live, in‑person working sessions to investigate incidents, assess operational challenges and design practical improvements, alongside asynchronous collaboration through Microsoft Teams.
  • Work with the team at client sites or in our offices for a minimum of two days per week. The time you spend and where you work will vary by role and assignment, including the possibility of being on a client site for up to five days per week.
  • Work in an environment that takes its values seriously and places collaboration, inclusion, learning and client impact at the heart of how teams operate.
Qualifications
Essential requirements
  • SOC Leadership: Experience running or supervising a SOC, CSOC, or Incident Response team.
  • Incident Response: Practical experience managing live cyber incidents (such as ransomware, account takeovers, or supply chain breaches).
  • Technical Stack: Direct experience working with major SIEM/SOAR tools (e.g., Microsoft Sentinel, Splunk) and EDR/XDR platforms (e.g., Microsoft Defender for Endpoint, CrowdStrike Falcon).
  • Security Frameworks: Solid understanding of MITRE ATT&CK, NIST CSF, NCSC Caf v4.0 and ISO 27001.
  • Communication: Ability to write concise incident reports and speak comfortably with both engineers and business leaders.
Desirable
  • Experience working in management consulting, managed services (MSSP), or client‑facing advisory roles.
  • Experience in regulated UK environments (such as Central Government, Defence, or Critical National Infrastructure).
  • Hands‑on familiarity with cloud security monitoring in AWS, Azure, or GCP.

Please be aware that some of our UK roles at PA Consulting require a UK security clearance. All PA people are required to undergo background checks and to achieve the Baseline Personnel Security Standard however, some UK roles also require higher levels of National Security Vetting, where applicants must have at least 5 years of continuous residency in the UK. We therefore ask that you only apply if you meet the residency requirements (i.e. you are a British citizen or have been resident in the UK for the past 5 years), as this is the prerequisite for a security clearance. If you're unsure about your eligibility, we encourage you to review the UK Government’s guidance on security vetting before applying.

Additional Information
Assessment process

Please note that the interview stages may be subject to change based on the specific requirements of the role.

  • Quick call with one of our Tech Recruiters – to discuss your application, the role and PA
  • Round 1: Either a competency or technical interview (60 mins)
  • Round 2: Either a competency or technical interview, whichever you didn’t do at first round (60 mins)
  • Final round: Meeting with a PA leader - a mini case study and discussion around your client‑centricity (60 mins)

Life At PA encompasses our peoples' experience at PA. It's about how we enrich peoples' working lives by giving them access to unique people and growth opportunities and purpose led meaningful work. Our purpose guides how we work with our clients and our teams, and support our communities, to deliver insight and impact, solving the world's most complex challenges. We're focused on building a workplace that values human difference and diverse mindsets, and a culture of inclusion and equality that unlocks the potential in our people so everyone can be their best self.

Find out more about Life at PA here.

We're committed to advancing equality. We recruit, retain, reward and develop our people based solely on their abilities and contributions and without reference to their age, background, disability, genetic information, parental or family status, religion or belief, race, ethnicity, nationality, sex, sexual orientation, gender identity (or expression), political belief, veteran status, any other range of human difference brought about by identity and experience. We welcome applications from underrepresented groups.

  • Health and lifestyle perks accompanying private healthcare for you and your family
  • 25 days annual leave (plus a bonus half day on Christmas Eve) with the opportunity to buy 5 additional days
  • Generous company pension scheme
  • Opportunity to get involved with community and charity-based initiatives
  • Annual performance‑based bonus
  • PA share ownership
  • Tax efficient benefits (cycle to work, give as you earn)

Adjustments or accommodations - Should you need any adjustments or accommodations to the recruitment process, at either application or interview, please contact us on recruitmentenquiries@paconsulting.com

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Operations Manager
Security Operations Manager

PA Consulting Group • Belfast City District

Hybrid
GBP 75,000 - 110,000
Health and lifestyle perks
25 days annual leave
Pension
+4
Security Operations Consultant
Security Operations Consultant

Remote Worker LTD. • Belfast City District

Hybrid
GBP 70,000 - 100,000
Health and lifestyle perks
25 days annual leave
Generous pension scheme
+3
Security Operations Consultant
Security Operations Consultant

PA Consulting Group • Belfast City District

Hybrid
GBP 70,000 - 110,000
Health and lifestyle perks
25 days annual leave
Generous pension scheme
+4
Security Operations Manager
Security Operations Manager

Remote Worker LTD. • Belfast City District

Hybrid
GBP 90,000 - 120,000
Health and lifestyle perks
25 days annual leave
Generous pension
+4
Security Architect
Security Architect

PA Consulting • Greater London

On-site
GBP 80,000 - 120,000
Health and lifestyle perks
25 days annual leave (plus bonus half‑
Generous pension
+2
Security Architect
Security Architect

PA Consulting • Manchester

On-site
GBP 50,000 - 70,000
Health and lifestyle perks
25 days annual leave plus a bonus half day
Generous company pension scheme
+2
Information Security Analyst - Security Operations Centre
Information Security Analyst - Security Operations Centre

PA Consulting Group • West of England

Hybrid
GBP 60,000 - 90,000
Health and lifestyle perks
25 days annual leave
Generous pension
+4
Security Architect
Security Architect

PA Consulting • City of Westminster

On-site
GBP 50,000 - 70,000
Private healthcare
25 days annual leave
Generous pension scheme
+3
Security Architect
Security Architect

PA Consulting • Bristol

On-site
GBP 90,000 - 120,000
Health perks
Annual leave 25 days
Pension scheme
+3
Security Architect Consultant
Security Architect Consultant

PA Consulting • West of England

On-site
Confidential
Health and lifestyle perks
25 days annual leave
Generous pension scheme
+2