Senior SOC Engineer

Anson Mccade

Glasgow

On-site

GBP 37,000 - 69,000

Full time

6 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Anson Mccade is seeking a Senior SOC Engineer to strengthen security operations in Glasgow. The role focuses on deploying and optimising the QRadar SIEM, onboarding log sources, and developing detection rules across on‑prem and cloud environments.

You will lead incident response playbooks, integrate with SOAR platforms, and collaborate with threat intelligence teams to continuously improve detection logic and security posture. On‑site with 24/7 on-call support, in Glasgow, UK.

Qualifications

  • Experience in IBM QRadar SIEM engineering.
  • Strong knowledge of log formats, parsing, and normalisation.
  • Proficiency with SIEM query languages: KQL, SPL, AQL.
  • Scripting experience with Python or PowerShell for automation.
  • Understanding of threat detection, incident response and kill chain concepts.
  • Familiarity with MITRE ATT&CK, NIST, CIS frameworks.
  • Solid communication, analytical and presentation skills.
  • Experience with ITIL processes (Incident, Problem, Change).
  • Ability to work independently and in on-call environments.
  • 3–5 years in IT security, SOC/NOC preferred.
  • Various cybersecurity certifications are advantageous.

Responsibilities

  • Deploy, configure, and maintain the QRadar SIEM platform.
  • Onboard and normalise log sources across on‑prem and cloud environments.
  • Develop and optimise analytical rules for threat and anomaly detection.
  • Design incident response playbooks for phishing, lateral movement, and exfiltration.
  • Integrate playbooks with SOAR platforms (Logic Apps, XSOAR).
  • Refine playbooks using threat intel and incident insights.
  • Monitor security alerts and conduct investigations.
  • Collaborate with threat intel teams to enhance detection logic.
  • Lead threat modelling using MITRE ATT&CK, STRIDE, Cyber Kill Chain.
  • Translate threat models into detection use cases and SIEM rules.
  • Produce reports and dashboards to communicate security posture.
  • Partner with IT, DevOps, and compliance to enforce secure configs.
  • Provide mentorship to junior staff.
  • Maintain security procedure documentation and runbooks.
  • Support pre-sales with technical requirements.

Skills

SIEM engineering
QRadar
KQL
SPL
AQL
Python
PowerShell
Threat detection
MITRE ATT&CK
Incident response

Tools

IBM QRadar
ServiceNow
XSOAR
Logic Apps
Azure
AWS
Splunk
Microsoft Office

Job description

Salary: £37,000 - 68,500 per year

Requirements:
  • Eligible for, or already holding, SC Clearance.
  • Proven expertise in IBM QRadar and SIEM engineering.
  • Strong knowledge of log formats, parsing, and normalisation.
  • Proficiency in SIEM query languages such as KQL, SPL, and AQL.
  • Scripting experience with Python or PowerShell for automation.
  • Deep understanding of threat detection, incident response, and the cyber kill chain.
  • Familiarity with frameworks including MITRE ATT&CK, NIST, and CIS.
  • Strong communication, analytical, and presentation skills.
  • Solid understanding of network traffic flows, vulnerability management, and penetration testing principles.
  • Knowledge of ITIL processes, including Incident, Problem, and Change Management.
  • Ability to work independently and thrive in a 24/7 on-call environment.
  • 3-5 years experience in the IT security industry, ideally in a SOC/NOC environment.
  • Cybersecurity certifications preferred, such as ISC2 CISSP, GIAC, SC-200, IBM QRadar Certified Specialist, Splunk Certified Admin/Power User, or Google Chronicle Security Engineer.
  • Hands-on experience with ServiceNow Security Suite.
  • Familiarity with cloud platforms, including AWS and/or Microsoft Azure.
  • Proficiency in Microsoft Office products, particularly Excel and Word.
Responsibilities:
  • Deploy, configure, and maintain the QRadar SIEM platform.
  • Onboard and normalise log sources across on-premises and cloud environments.
  • Develop and optimise analytical rules for threat detection, anomaly detection, and behavioural analysis.
  • Design and implement incident response playbooks for scenarios such as phishing, lateral movement, and data exfiltration.
  • Integrate playbooks with SOAR platforms such as Microsoft Logic Apps and XSOAR to streamline triage and automate response.
  • Refine playbooks based on threat intelligence and incident insights.
  • Monitor and analyse security alerts and events to identify potential threats.
  • Conduct investigations and coordinate incident response activities.
  • Collaborate with threat intelligence teams to enhance detection logic.
  • Lead threat modelling exercises using frameworks such as MITRE ATT&CK, STRIDE, and Cyber Kill Chain.
  • Translate threat models into actionable detection use cases and SIEM rules.
  • Prioritise detection engineering based on business risk and impact.
  • Produce reports and dashboards to communicate security posture and incident trends.
  • Partner with IT, DevOps, and compliance teams to enforce secure configurations.
  • Provide mentorship to junior analysts and engineers.
  • Maintain documentation of security procedures, incident response plans, runbooks, and playbooks.
  • Contribute to monthly reporting packs in line with contractual obligations.
  • Support pre-sales teams with technical requirements for new opportunities.
  • Demonstrate SOC tools and capabilities to clients.
  • Participate in continual service improvement initiatives, recommending changes to address recurring incidents.
Technologies:
  • AWS
  • Azure
  • Cloud
  • DevOps
  • Excel
  • IBM
  • Support
  • ITIL
  • Network
  • PowerShell
  • Python
  • Security
  • ServiceNow
  • Splunk

More:

We are a leading organisation seeking a Senior SOC Engineer to strengthen our security operations capability and drive continuous improvement across detection, response, and automation. This is a permanent onsite role based in Glasgow, Scotland, United Kingdom, with a salary of £60,000 GBP. We focus on building and optimising detection and response strategies to ensure robust protection against evolving threats, and we offer the opportunity to work across SIEM engineering, playbook development, threat modelling, reporting, collaboration, and continual service improvement.

last updated 36 week of 2026

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Solution Engineer
SOC Solution Engineer

Anson McCade • England

Hybrid
GBP 70,000 - 85,000
25 days annual leave + public holidays
Private healthcare, dental, wellbeing support
Contributory pension scheme
+1
Senior SOC Analyst
Senior SOC Analyst

Searchability NS&D • Farnborough

On-site
GBP 42,000 - 70,000
Shift allowance included within the包
Ongoing training and professional dev
Support towards cyber security certs
+1
Security Engineer
Security Engineer

Franklin Fitch • Reading

Hybrid
GBP 60,000 - 70,000
Hybrid work model
Senior SOC Analyst
Senior SOC Analyst

Focus Group • Manchester

Hybrid
GBP 60,000 - 90,000
Senior SOC Analyst
Senior SOC Analyst

Searchability • Farnborough

On-site
GBP 63,000 - 77,000
Shift allowance
Training & certifications support
Opportunity to work on high profile UK
+1
Senior SIEM Engineer - Threat Detection & Automation
Senior SIEM Engineer - Threat Detection & Automation

Anson Mccade • Glasgow

On-site
GBP 37,000 - 69,000
Senior Security Engineer - Monitoring & Detection
Senior Security Engineer - Monitoring & Detection

Made Tech Limited • West of England

On-site
GBP 55,000 - 85,000
30 days Holiday
Flexible Working Hours
Remote Working (part-time)
+1
Senior Security Engineering Consultant
Senior Security Engineering Consultant

Infosec • Basingstoke

Hybrid
GBP 56,000 - 80,000
Salary up to £80,000
Bonuses
Hybrid work
Senior SOC Analyst
Senior SOC Analyst

InfoSec People Ltd • England

Hybrid
GBP 69,000 - 82,000
Annual performance bonus
Hybrid working model
Clear progression opportunities
SOC Analyst - SC Cleared
SOC Analyst - SC Cleared

Sanderson Government & Defence • Greater London

Hybrid
GBP 146,000 - 151,000