Senior SOC Analyst - Incident Response

GHD

North East

On-site

GBP 70,000 - 110,000

Full time

2 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

GHD is seeking a Senior SOC Analyst - Incident Response to lead complex, high-severity investigations across a large enterprise. You will own investigations end-to-end, shape critical response decisions and strengthen detection, containment and lessons across the organisation.

Reporting to the SOC Manager, you will mentor junior analysts, develop playbooks and work with infrastructure, identity, cloud and IT teams to coordinate rapid containment and recovery in a fast-moving environment.

Qualifications

  • At least five years’ experience in security operations and incident response in a large, global organisation.
  • Experience leading major security investigations and coordinating stakeholders through full response lifecycle.
  • Deep, hands-on expertise in Microsoft Sentinel, including incidents, investigations and analytics.
  • Strong knowledge of Microsoft Defender XDR, identity-based attacks and hybrid cloud environments.
  • Ability to form, test and refine investigative hypotheses using evidence from multiple sources.
  • Calm, decisive judgement under pressure, with the confidence to act when information is incomplete.
  • Collaborative, curious and disciplined approach to incident handling and continuous improvement.
  • Bonus: certifications such as SC-200, AZ-500, GCED, GCIA, GCIH, CISSP or CISM.

Responsibilities

  • Lead and coordinate high-severity security incident investigations end-to-end.
  • Establish incident scope, impact and likely root cause using Sentinel and Defender XDR.
  • Direct response actions in partnership with infrastructure, identity, cloud and IT teams.
  • Maintain investigation records and produce accurate post-incident reports.
  • Develop, tune and maintain Sentinel analytics rules to improve signal quality.
  • Conduct hypothesis-driven threat hunting using Sentinel and Defender Advanced Hunting.
  • Convert findings into practical detection and response improvements.
  • Mentor junior analysts and help define playbooks and escalation thresholds.
  • Collaborate with the managed security service provider for triage and escalation.
  • Brief technical and non-technical stakeholders during active incidents.

Skills

Security operations
Incident response
Stakeholder coordination
Mentoring
Calm under pressure
Technical communication

Tools

Microsoft Sentinel
Defender XDR
Entra ID
Microsoft 365
Azure

Job description

Job Description

Help protect the systems, information and digital services that enable GHD to deliver for clients and communities around the world.As cyber threats become more sophisticated and connected environments grow in complexity, effective incident response depends on more than technology alone. At GHD, we combine disciplined investigation, practical judgement and close collaboration to understand threats quickly, contain risk and continually strengthen our security operations.

Job Description

Help protect the systems, information and digital services that enable GHD to deliver for clients and communities around the world.As cyber threats become more sophisticated and connected environments grow in complexity, effective incident response depends on more than technology alone. At GHD, we combine disciplined investigation, practical judgement and close collaboration to understand threats quickly, contain risk and continually strengthen our security operations.

The opportunity

We are looking for an accomplished Senior SOC Analyst - Incident Response to lead and coordinate complex, high-severity incidents across a large enterprise environment. Reporting to the SOC Manager, you will own investigations end to end, shape critical response decisions and help strengthen how incidents are detected, contained and learned from across the organisation. This is not a conventional alert-triage role. It is for a seasoned, hands-on responder who can establish facts when evidence is incomplete, coordinate technical teams during live incidents and apply sound incident response methodology even when tooling is degraded. Microsoft Sentinel and Defender XDR will be central to your work, but calm judgement, investigative discipline and clear communication will matter just as much.

What You Will Do
  • Lead and coordinate high-severity and complex security incident investigations from initial assessment through containment, recovery and review.
  • Establish incident scope, business impact and likely root cause using Microsoft Sentinel, Defender XDR and evidence from across the enterprise environment.
  • Direct response actions in partnership with infrastructure, identity, cloud, application and wider IT teams.
  • Maintain clear investigation records, preserve evidence and produce accurate, defensible incident outcomes and post-incident reports.
  • Develop, tune and maintain Sentinel analytics rules, improving signal quality and reducing false positives.
  • Conduct hypothesis-driven threat hunting using Sentinel and Defender Advanced Hunting.
  • Convert purple-team and attack-simulation findings into practical detection and response improvements.
  • Act as a technical mentor to junior and mid-level analysts, reviewing investigations and helping define playbooks, investigation standards and escalation thresholds.
  • Work closely with the organisation’s managed security service provider to maintain high-quality triage and escalation.
  • Brief technical and non-technical stakeholders clearly during active incidents, providing concise insight to support prioritisation and decision-making.
What Success Looks Like
  • You are the person colleagues look to when an incident becomes complex, fast-moving or uncertain.
  • You turn fragmented technical evidence into a clear view of scope, impact, likely cause and immediate priorities.
  • You coordinate decisive containment while protecting evidence, maintaining accurate records and keeping stakeholders informed.
  • You improve detections, playbooks and escalation standards so that lessons from incidents create lasting capability.
  • You raise the confidence and investigative discipline of analysts around you through constructive review and mentoring.
What You Will Bring
  • At least five years’ experience in security operations and incident response, ideally within a large, complex or global organisation.
  • Demonstrable experience leading or owning major security investigations and coordinating stakeholders through the full response lifecycle.
  • Deep, hands-on expertise in Microsoft Sentinel, including incidents, investigations and analytics.
  • Strong knowledge of Microsoft Defender XDR, identity-based attacks and hybrid cloud environments.
  • The ability to form, test and refine investigative hypotheses using evidence from multiple sources.
  • Calm, decisive judgement under pressure, with the confidence to act when information is incomplete.
  • Clear written and verbal communication, including the ability to brief both technical specialists and senior non-technical stakeholders.
  • A collaborative, curious and disciplined approach to incident handling and continuous improvement.
Additional Experience That Would Be Valuable
  • Experience coaching analysts or raising capability within a SOC.
  • Exposure to breach and attack simulation, purple teaming or collaboration with red teams.
  • Practical knowledge of Entra ID, Microsoft 365 and Azure environments.
  • One or more relevant certifications, such as Microsoft SC-200 or AZ-500, GCED, GCIA, GCIH, CISSP or CISM.

Practical investigative capability and real-world incident leadership matter more to us than certifications alone.

Why GHD?

GHD is a global professional services company working across water, energy and resources, environment, property and buildings, and transportation. Privately owned by our people, we connect engineering, architecture, environmental, advisory and construction expertise to create lasting community benefit.

You will join a collaborative security environment where technical depth, measured judgement and knowledge-sharing are valued. Your expertise will influence incident response practice across the SOC, and you will have the opportunity to turn lessons from challenging investigations into lasting security improvements.

Our commitment to you

We will give you the trust, tools and connected expertise to do your best work, recognise your contribution and support your continued development. We are committed to an inclusive and flexible culture where different perspectives are heard and people can succeed while balancing their individual circumstances with the needs of clients, teams and the organisation.

GHD is an equal opportunity employer. We value a diverse workforce and an inclusive culture, and we want everyone to be able to participate fully in our recruitment process. Please let us know if you require any reasonable adjustments.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior SOC Analyst - Incident Response
Senior SOC Analyst - Incident Response

GHD • Greater London

On-site
GBP 90,000 - 120,000
Senior SOC Analyst - Incident Response
Senior SOC Analyst - Incident Response

GHD • Manchester

On-site
GBP 65,000 - 100,000
Senior SOC Analyst - Incident Response
Senior SOC Analyst - Incident Response

GHD Group • City Of London

On-site
GBP 70,000 - 100,000
Senior SOC Analyst – Incident Response Leader
Senior SOC Analyst – Incident Response Leader

GHD • England

On-site
GBP 65,000 - 100,000
Senior SOC Incident Response Lead
Senior SOC Incident Response Lead

GHD • Greater London

On-site
GBP 90,000 - 120,000
Senior SOC Analyst — Incident Response Lead
Senior SOC Analyst — Incident Response Lead

GHD • North East

On-site
GBP 70,000 - 110,000
Senior SOC Analyst
Senior SOC Analyst

Focus Group • Manchester

Hybrid
GBP 60,000 - 90,000
Senior SOC Incident Response Lead
Senior SOC Incident Response Lead

GHD • Manchester

On-site
GBP 65,000 - 100,000
Senior SOC Analyst: Incident Response Lead
Senior SOC Analyst: Incident Response Lead

GHD Group • City Of London

On-site
GBP 70,000 - 100,000
Senior Incident Response Consultant 2
Senior Incident Response Consultant 2

Sophos • Oxford

On-site
CAD 131,000 - 219,000