Senior SOC Analyst
Manchester (Hybrid | 3 days per week in the office) Internal Level: Specialist
Join Focus Group's growing Cyber Security team as a Senior SOC Analyst, where you'll play a pivotal role in protecting customers against evolving cyber threats. This position combines advanced technical investigation skills with operational leadership, giving you the opportunity to shape security operations, enhance service delivery, and support the development of the wider SOC team.
You'll be responsible for leading security monitoring and incident response activities, driving continuous improvement across services, and acting as a trusted escalation point for both customers and colleagues.
The Role
As a Senior SOC Analyst, you'll take ownership of complex security investigations while supporting the day-to-day running of our Security Operations Centre. Working closely with Cyber Security leadership, you'll help strengthen our detection capabilities, improve operational processes, and ensure an exceptional service experience for customers.
Key Responsibilities
- Oversee daily SOC activities, ensuring incidents are effectively prioritised, investigated, and escalated where required
- Serve as the senior escalation point for high-priority security events and cyber incidents
- Investigate advanced threats across endpoint, network, cloud, and identity environments
- Conduct proactive threat hunting exercises to identify previously undetected risks
- Refine detection rules and monitoring content to improve visibility and reduce false positives
- Coach and support SOC Analysts, providing guidance, technical mentorship, and knowledge sharing
- Maintain high standards of ticket management, documentation, and SLA performance
- Assist with the implementation and onboarding of new customers into managed security services
- Work collaboratively with internal teams to advance SOC processes, tooling, and operational maturity
- Analyse security logs and telemetry to identify indicators of compromise and suspicious behaviour
- Create and maintain operational runbooks, investigation procedures, and technical documentation
- Produce concise, customer-friendly incident reports and recommendations
- Participate in customer calls relating to incident response, service reviews, and security discussions
- Identify opportunities for automation and efficiency improvements across SOC operations
- Keep abreast of emerging threats, attack techniques, and industry best practices
About You
You'll be an experienced cyber security professional who thrives in a fast-paced environment and enjoys solving complex security challenges. You'll have a strong technical foundation, excellent communication skills, and a passion for developing others.
Essential Skills & Experience
- 4+ years of experience within a SOC, MDR, or MSSP environment
- Strong experience investigating and responding to cyber security incidents
- Hands-on knowledge of SIEM platforms such as Microsoft Sentinel, Splunk, Elastic, or similar technologies
- Experience working with EDR/XDR tools including Microsoft Defender, SentinelOne, Bitdefender, or equivalent solutions
- In-depth understanding of threat detection principles, adversary behaviours, and the MITRE ATT&CK framework
- Strong analytical skills with the ability to investigate and correlate activity across multiple data sources
- Confidence managing critical incidents and making informed decisions under pressure
- Ability to communicate technical findings clearly to both technical and non-technical audiences
- Previous experience supporting, mentoring, or supervising junior analysts
- Strong organisational skills with the ability to manage competing priorities effectively
- A continuous improvement mindset and passion for cyber security
Desirable Experience
- Industry certifications such as SC-200, Security+, GCIH, GCIA, BTL1, or equivalent
- Experience working within a managed security services environment
- Knowledge of the Microsoft Security ecosystem, including Defender XDR and Microsoft Sentinel
- Understanding of cloud security concepts and modern identity protection controls
- Experience with KQL or other SIEM query languages
- Scripting or automation skills using PowerShell, Python, or similar
- Exposure to SOAR platforms and threat intelligence solutions
- Familiarity with security and compliance frameworks such as ISO 27001, NIST, and Cyber Essentials
Why Join Focus Group?
This is an excellent opportunity to take the next step in your cyber security career within a growing and ambitious organisation. You'll work alongside experienced security professionals, influence the direction of our SOC, and play a key role in protecting customers from an ever-changing threat landscape.
Career Progression Opportunities
- SOC Manager
- Security Operations Lead
- Detection Engineering Lead
- Incident Response Manager
- Threat Intelligence Lead
- Cyber Security Consultant
- Head of Security Operations
IND1