Senior SOC Lead & Incident Response Architect

Oscar

England

On-site

GBP 85,000 - 110,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Oscar is seeking a Senior SOC Analyst (Level 3) / Technical Lead in Buckinghamshire. The role focuses on owning high‑severity incidents from ransomware to data breaches, with real-time containment decisions and senior client communication.

You'll conduct proactive threat hunts, develop detection content for SIEM/EDR and cloud platforms, and mentor junior analysts. On-site work pattern includes 3 days at the client location with on‑call for emergencies.

Qualifications

  • 5+ years in incident response or SOC environments.
  • Proven record leading complex investigations (ransomware/breach).
  • Advanced malware analysis capability including behavioral analysis and reverse engineering.
  • Deep expertise across enterprise SIEM platforms and EDR tooling (CrowdStrike knowledge is a strong advantage).
  • Threat hunting toolkit: YARA, IOC development, timeline analysis.

Responsibilities

  • Lead the most serious investigations in the client portfolio - ransomware, supply-chain compromise, data breaches, insider cases - owning the full lifecycle from detection through recovery.
  • Make real-time containment calls under pressure and brief client leadership, up to board level, in language they can act on.
  • Run proactive threat hunts and build detection content across SIEM, EDR and cloud platforms, tuning out noise as you go.
  • Develop SOAR playbooks and automation, and help shape the SOC's tooling roadmap and architecture.
  • Produce evidential-standard reporting fit for auditors, regulators and law enforcement.
  • Mentor the analyst team and act as senior escalation point for major incidents.

Skills

Incident response
SOC leadership
Malware analysis
Threat hunting
Executive communication
Mentoring
Intrusion detection
Cloud incident response
YARA rules
IOC development

Tools

CrowdStrike
YARA
Azure
AWS
SIEM
EDR tooling

Job description

Oscar is seeking a Senior SOC Analyst (Level 3) / Technical Lead in Buckinghamshire. The role focuses on owning high‑severity incidents from ransomware to data breaches, with real-time containment decisions and senior client communication.

You'll conduct proactive threat hunts, develop detection content for SIEM/EDR and cloud platforms, and mentor junior analysts. On-site work pattern includes 3 days at the client location with on‑call for emergencies.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior SOC Lead: Detection & Incident Response
Senior SOC Lead: Detection & Incident Response

InfoSec People Ltd • England

Hybrid
GBP 70,000 - 110,000
Senior SOC Lead — UK Wide, Onsite 3 Days/Week in Crawley
Senior SOC Lead — UK Wide, Onsite 3 Days/Week in Crawley

Morson Talent • Crawley

Hybrid
GBP 65,000 - 80,000
Senior SOC Specialist
Senior SOC Specialist

Morson Talent • Crawley

Hybrid
GBP 65,000 - 80,000
Senior SOC Analyst
Senior SOC Analyst

Barclay Simpson • England

Hybrid
GBP 68,000 - 80,000
Hybrid work model
Excellent benefits
Bonus potential
Senior L3 SOC Analyst: Threat Hunting & Incident Response
Senior L3 SOC Analyst: Threat Hunting & Incident Response

Inchcape Motors Finland Oy • Greater London

Hybrid
GBP 70,000 - 120,000
Senior SOC Analyst: 24/7 Incident Response Lead
Senior SOC Analyst: 24/7 Incident Response Lead

慨正橡扯 • Greater London

On-site
GBP 50,000 - 70,000
Lead SOC Analyst – 24/7 Threat Hunting & Response
Lead SOC Analyst – 24/7 Threat Hunting & Response

Sopra Steria • Hemel Hempstead, Farnborough

On-site
GBP 39,000 - 65,000
25 days annual leave
Health cash plan
Life assurance
+1
SOC Team Lead
SOC Team Lead

Fynity • Aylesbury

Hybrid
GBP 70,000 - 110,000
Senior SOC Analyst
Senior SOC Analyst

慨正橡扯 • Greater London

On-site
GBP 50,000 - 70,000
Senior SOC Lead – Threat Detection & Incident Response
Senior SOC Lead – Threat Detection & Incident Response

IBM • Hursley

Hybrid
GBP 65,000 - 90,000
Flexible working styles
Sabbatical programs
Maternity returners scheme
+2