Enable job alerts via email!

Senior/Principal SOC Analyst

Sanderson Government & Defence

England

Remote

GBP 55,000 - 70,000

Full time

2 days ago
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

A leading Cyber Security services provider is seeking a Senior/Principal SOC Engineer to enhance their virtual Security Operations Centre. This fully remote position focuses on detecting, investigating, and responding to advanced cyber threats. The role requires significant experience in cybersecurity, including incident management and threat intelligence, with a salary up to £70,000 depending on experience. The candidate must have the right to work permanently in the UK.

Qualifications

  • 4+ years in a SOC or cyber defense team, leading complex investigations.
  • Experience with SIEM, EDR, and Threat Intelligence tools required.
  • Ability to script for automation and experience with security frameworks.

Responsibilities

  • Lead incident investigations and mentor junior analysts.
  • Proactively threat hunt using SIEM and EDR tools.
  • Contribute to detection use case development and incident response playbooks.

Skills

Incident Investigation
Threat Intelligence
Threat Hunting
Analytical Skills
Log Analysis
Automation Scripting (Python, PowerShell)

Tools

Elastic Stack
Microsoft Sentinel
Microsoft Defender for Endpoint
CrowdStrike Falcon
Azure Logic Apps
Jira Automations

Job description

Senior/Principal SOC Engineer

Fully Remote (Mon-Fri, Days)
Must be UK Based
Up to £70k DOE

Role details:

We're partnering with a specialist Cyber Security services provider with exciting growth plans. They're looking for a Senior or Principal SOC Analyst to play a key role in the detection, investigation, and response to advanced cyber threats within their virtual Security Operations Centre.

Responsibilities:
  1. Lead complex incident investigations from triage to remediation and post-incident review.
  2. Act as the analyst "goto" for questions, support, and specialist analytical expertise.
  3. Guide and mentor junior analysts, providing technical leadership during incidents.
  4. Work with the analyst team to ensure proactive threat hunting using SIEM, EDR, and threat intel sources, covering the pyramid of pain, and develop analysts into threat hunters beyond IoCs.
  5. Analyse and validate security alerts, refining detection rules in collaboration with engineers.
  6. Correlate signals from multiple platforms (e.g., EDR, network, cloud, identity) to identify adversary techniques (MITRE ATT&CK).
  7. Leverage threat intelligence (including MISP) to enrich investigations and build contextual awareness.
  8. Contribute to detection use case development, helping to identify coverage gaps and recommend improvements.
  9. Support the evolution of incident response playbooks and knowledge base articles.
  10. Collaborate with other teams to support vulnerability management, purple teaming, and security awareness activities.
Requirements:
  1. 4+ years working in a SOC or cyber defence team, with demonstrable experience leading high-impact investigations.
  2. Experience with SIEM tools: Elastic Stack (Kibana, Logstash), Microsoft Sentinel.
  3. Experience with EDR tools: Microsoft Defender for Endpoint, CrowdStrike Falcon, Elastic Defend.
  4. Threat Intel: MISP (querying, correlation, pivoting).
  5. Experience with SOAR tools: Jira automations, Azure Logic Apps.
  6. Knowledge of Security Frameworks: MITRE ATT&CK, NIST, Cyber Kill Chain.
  7. Proficiency in interpreting logs from systems, endpoints, cloud services (e.g., Azure, M365), and network sources.
  8. Experience using threat intelligence to contextualise alerts and enhance response decisions.
  9. Experience in developing hypotheses, analysis, and iteration for threat hunting.
  10. Familiarity with threat hunting methodologies and anomaly detection approaches.
  11. Ability to script or automate tasks (Python, PowerShell, or similar).
Eligibility:

Must reside in the UK and have the right to work permanently.

Reasonable Adjustments:

We value diversity and inclusion. If you need any adjustments during the recruitment process, please let us know when applying or contact the recruiters directly.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Principal SOC Analyst

Babcock

null null

Remote

Remote

GBP 59.000 - 70.000

Full time

20 days ago

SOC Engineer / Consultant

Paradigm Tech

Greater London null

On-site

On-site

GBP 55.000 - 65.000

Full time

30+ days ago

Security Operations Centre Consultant / SOC Implementation / Analyst

Experis

West Midlands Combined Authority null

On-site

On-site

GBP 45.000 - 75.000

Full time

30+ days ago