Senior SOC Analyst

Franklin Fitch

Basingstoke

On-site

GBP 90,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Franklin Fitch is seeking a senior, hands-on cybersecurity consultant to help customers enhance and automate their SOC capabilities. You will design, build, and optimise detections across SIEM, XDR, and SOAR with a focus on detection engineering and automation.

Key responsibilities include developing detection rules for SIEMs (especially Microsoft Sentinel), building SOAR automations, and creating MITRE ATT&CK-aligned use cases.

Qualifications

  • Experience designing and engineering SIEM solutions, preferably Microsoft Sentinel.
  • Strong hands-on skills in KQL and detection rule development.
  • Experience building automations in SOAR platforms.
  • Proficiency in Python and PowerShell for API integrations and automation.
  • Knowledge of MITRE ATT&CK framework for threat modeling.
  • Experience with leading XDR/EDR platforms such as Defender XDR, CrowdStrike, Cortex XDR, or SentinelOne.
  • Solid understanding of Azure security services and telemetry collection.
  • Customer-facing consulting with excellent communication and stakeholder management skills.
  • Ability to translate business requirements into effective security monitoring and detection strategies.

Responsibilities

  • Design, develop, and optimise detection rules for SIEM and XDR platforms, focusing on Microsoft Sentinel.
  • Build and maintain SOAR automations, incident response playbooks, and workflow integrations.
  • Develop high-quality detections using KQL, Python, and PowerShell.
  • Create detection use cases aligned with MITRE ATT&CK framework.
  • Assess customer telemetry to identify visibility gaps and improve coverage.
  • Lead Detection as Code pipelines with version-controlled content.
  • Lead customer workshops and provide strategic SOC maturity advice.
  • Collaborate with engineering, onboarding, and delivery teams to integrate detections and responses.
  • Continuously refine detection content and automation standards for SOC effectiveness.

Skills

SIEM design
KQL
SOAR automation
Python
PowerShell
MITRE ATT&CK
XDR platforms
Azure security
Communication
Detection engineering

Tools

Microsoft Sentinel
Logic Apps
Cortex XSOAR
SentinelOne
CrowdStrike Falcon
Palo Alto Cortex XDR

Job description

This is a senior, hands‑on cybersecurity consulting role focused on helping customers improve and automate their Security Operations Centre (SOC) capabilities. You'll design, build, and optimise detection and response solutions across SIEM, XDR, and SOAR platforms, with a strong emphasis on detection engineering, automation, and "detection as code."

Key Responsibilities
  • Design, develop, and optimise detection rules for SIEM and XDR platforms, with a strong emphasis on Microsoft Sentinel
  • Build and maintain SOAR automations, incident response playbooks, and workflow integrations
  • Develop high-quality detections using Kusto Query Language (KQL), Python, and PowerShell
  • Create and maintain detection use cases aligned with the MITRE ATT&CK framework
  • Assess customer logging and telemetry to identify visibility gaps and improve detection coverage
  • Implement and maintain Detection as Code pipelines, enabling reusable and version‑controlled security content
  • Lead customer workshops and provide strategic consultancy on SOC maturity, detection engineering, and security operations best practices
  • Collaborate with engineering, onboarding, and delivery teams to integrate detections, automations, and response workflows into customer environments
  • Continuously refine detection content, playbooks, and automation standards to improve SOC effectiveness and operational efficiency
Skills & Experience
  • Proven experience designing and engineering SIEM solutions, ideally with Microsoft Sentinel
  • Strong hands‑on expertise in KQL and detection rule development
  • Experience building automations within SOAR platforms such as Microsoft Logic Apps, Cortex XSOAR, or similar technologies
  • Proficiency in Python and/or PowerShell, including scripting for API integrations and automation
  • Solid understanding of detection engineering methodologies and the MITRE ATT&CK framework
  • Experience working with leading XDR/EDR platforms such as Microsoft Defender XDR, CrowdStrike Falcon, Palo Alto Cortex XDR, or SentinelOne
  • Strong knowledge of Azure security services, cloud‑native security, and telemetry collection
  • Previous customer‑facing consulting experience with excellent communication, presentation, and stakeholder management skills
  • Ability to translate business requirements into effective security monitoring and detection strategies
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Consultant
Cyber Security Consultant

Franklin Fitch • Greater London

Hybrid
GBP 55,000 - 65,000
Bonus
Senior Security Engineer
Senior Security Engineer

InfoSec People Ltd • Basingstoke

On-site
GBP 65,000 - 85,000
SOC Engineer
SOC Engineer

Proactive.IT Appointments Ltd. • Milton Keynes

On-site
GBP 55,000 - 85,000
Security clearance sponsorship
Exposure to diverse customer envs
Senior Security Analyst
Senior Security Analyst

Xact Placements Limited • Reading

Hybrid
GBP 50,000 - 60,000
Senior SOC Analyst
Senior SOC Analyst

Jobtailor • Manchester

On-site
GBP 50,000 - 55,000
SOC Operations Team Lead
SOC Operations Team Lead

Jobtailor • Greater London

On-site
GBP 70,000 - 120,000
Detection Engineer
Detection Engineer

Cybanetix • Greater London

On-site
GBP 65,000 - 95,000
Hands-on experience with modern SIEM and XDR platforms
Exposure to real-world attacker behaviors
Opportunity for career advancement
Senior Security Engineer Consultant
Senior Security Engineer Consultant

InfoSec People Ltd • Basingstoke

Hybrid
GBP 70,000 - 100,000
Hybrid working model
Comprehensive employee benefits
2nd/3rd Line Security Analyst
2nd/3rd Line Security Analyst

Xact Placements Limited • Reading

Hybrid
GBP 50,000 - 60,000
Hybrid work arrangement
Competitive salary
Senior SOC Analyst: Detection Engineer & Automation Lead
Senior SOC Analyst: Detection Engineer & Automation Lead

Franklin Fitch • Basingstoke

On-site
GBP 90,000 - 120,000