SOC Analyst - SC Cleared

Sanderson Government & Defence

Greater London

Hybrid

GBP 146,000 - 151,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Sanderson Government & Defence is seeking two experienced SOC Analysts to join a specialist consultancy delivering cyber security services across government projects from London. You will lead security monitoring, incident response, and threat detection in complex, regulated environments with exposure to Splunk SIEM and threat hunting activities.

Ideal candidates have proven SOC experience, strong incident response skills, and active SC clearance.

Qualifications

  • Demonstrable experience working within a Security Operations Centre (SOC) environment.
  • Strong experience in security monitoring, alert triage, and incident investigation.
  • Hands-on experience with Splunk, SIEM technologies, endpoint security tools, and security monitoring platforms.
  • Experience developing and improving detection content and alert logic.
  • Strong understanding of incident response processes and cyber security operations.
  • Knowledge of network security concepts and attack methodologies.
  • Excellent analytical, investigative, and problem-solving skills.
  • Strong communication and stakeholder engagement capabilities.
  • Active SC Clearance.

Responsibilities

  • Monitor and triage security alerts generated through SIEM and security tooling.
  • Investigate and respond to cyber security incidents across cloud, endpoint, and network environments.
  • Analyse security events to determine impact, severity, and appropriate response actions.
  • Support incident containment, remediation, and post-incident review activities.
  • Participate in incident response exercises and security simulations.
  • Develop, maintain, and optimise security detection content within Splunk SIEM.
  • Identify gaps in detection coverage and recommend improvements.
  • Work closely with security teams to improve visibility and enhance monitoring capabilities.
  • Remain current with emerging cyber threats, threat actors, vulnerabilities, and attack techniques.

Skills

SOC operations
Security monitoring
Incident investigation
Splunk
SIEM
Endpoint security
Threat detection
Incident response
Threat intelligence
Communication
SC Clearance

Tools

Splunk
SIEM technologies
Endpoint security tools
Security monitoring platforms

Job description

SOC Analyst x2

Location: UK (Hybrid, 3 days per week in London)
Security Clearance: Active SC Clearance Required
Contract Length: 6-18 Months
Rate: £545-£590 per day (Inside IR35)
Positions Available: 2

About the Role

We are seeking two experienced SOC Analysts to join a specialist consultancy delivering cyber security services across a portfolio of government projects and digital transformation programmes.

This is an excellent opportunity to work within complex and dynamic security environments, helping clients protect critical services, systems, and data against evolving cyber threats. The successful candidates will play a key role in security monitoring, incident response, detection engineering, and threat analysis, working alongside Security Operations, Threat Intelligence, and Incident Response teams.

You will act as a cyber security subject matter expert, helping to strengthen defensive capabilities while contributing to the continuous improvement of security operations, threat detection, and incident response functions.

Key Responsibilities
Security Monitoring & Incident Response
  • Monitor and triage security alerts generated through SIEM and security tooling.
  • Investigate and respond to cyber security incidents across cloud, endpoint, and network environments.
  • Analyse security events to determine impact, severity, and appropriate response actions.
  • Support incident containment, remediation, and post-incident review activities.
  • Participate in incident response exercises and security simulations.
Detection Engineering
  • Develop, maintain, and optimise security detection content within Splunk SIEM.
  • Create and refine correlation searches, use cases, alerts, and detection rules.
  • Identify gaps in detection coverage and recommend improvements.
  • Work closely with security teams to improve visibility and enhance monitoring capabilities.
  • Support the onboarding and optimisation of new log sources.
Security Operations Improvement
  • Review and enhance security operations processes, standards, and procedures.
  • Identify trends in incidents, attack patterns, and security monitoring activity.
  • Recommend improvements to logging, monitoring, alerting, and response capabilities.
  • Support service improvement and operational efficiency initiatives.
Threat Intelligence & Threat Hunting
  • Remain current with emerging cyber threats, threat actors, vulnerabilities, and attack techniques.
  • Leverage threat intelligence to improve detection and response capabilities.
  • Support proactive threat hunting activities.
  • Research adversary tactics, techniques, and procedures (TTPs) relevant to highly regulated environments.
Technical Leadership
  • Act as an escalation point for junior analysts.
  • Provide mentoring, coaching, and knowledge-sharing support.
  • Contribute to capability development across the wider security team.
  • Present technical findings and recommendations to stakeholders when required.
Additional Responsibilities

Depending on project requirements, responsibilities may also include:

  • Proactive threat hunting
  • Detection engineering and use-case development
  • Incident response playbook creationThreat intelligence collection and analysis
  • Vulnerability assessment and reporting
  • Security change approval activities
  • Security capability enhancement initiatives
Essential Skills & Experience
  • Demonstrable experience working within a Security Operations Centre (SOC) environment.
  • Strong experience in security monitoring, alert triage, and incident investigation.
  • Hands-on experience with:
    • Splunk
    • SIEM technologies
    • Endpoint security tools
    • Security monitoring platforms
  • Experience developing and improving detection content and alert logic.
  • Strong understanding of incident response processes and cyber security operations.
  • Knowledge of network security concepts and attack methodologies.
  • Excellent analytical, investigative, and problem-solving skills.
  • Strong communication and stakeholder engagement capabilities.
  • Active SC Clearance.
Desirable Skills & Knowledge

Experience in one or more of the following areas would be advantageous:

  • Detection Engineering and Alert Development
  • Threat Hunting
  • Threat Intelligence Analysis
  • Security Automation and Orchestration
  • Incident Response Playbook Development
  • Vulnerability Management
  • Cloud Security (AWS, Azure, GCP)
  • Digital Forensics
On-Call Requirement

This role includes participation in an on-call rota, averaging approximately one week per month to support priority cyber security incidents.

  • Additional compensation is provided for on-call participation.
  • Frequency may vary depending on project requirements.
Reasonable Adjustments

Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients.

If you need any help or adjustments during the recruitment process for any reason, please let us know when you apply or talk to the recruiters directly so we can support you.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Analyst
SOC Analyst

Head Resourcing Ltd • Harlow

Hybrid
GBP 65,000 - 120,000
SOC Analyst - #3107759
SOC Analyst - #3107759

Dynamic Search Solutions • United Kingdom

Remote
GBP 30,000 - 40,000
SOC Analyst (Tier 2/3) – High Impact Cyber Defence Role
SOC Analyst (Tier 2/3) – High Impact Cyber Defence Role

Cyber UK • Corsham

On-site
GBP 42,000 - 60,000
Senior SOC Analyst
Senior SOC Analyst

Searchability NS&D • Farnborough

On-site
GBP 42,000 - 70,000
Shift allowance included within the包
Ongoing training and professional dev
Support towards cyber security certs
+1
SOC Analyst - Active SC required
SOC Analyst - Active SC required

Matchtech • Essex

Hybrid
GBP 83,000 - 111,000
Remote with ad-hoc visits
Inside IR35
Senior SOC Analyst - DV Clearance
Senior SOC Analyst - DV Clearance

Xpand Group • City Of London

On-site
GBP 70,000 - 100,000
SC Cleared Cyber Security Engineer
SC Cleared Cyber Security Engineer

Lorien • Stevenage

On-site
GBP 180,000 - 210,000
SOC Analyst - Tier 2 and Tier 3 (SC and DV)
SOC Analyst - Tier 2 and Tier 3 (SC and DV)

Pigment Consulting • Manchester

On-site
GBP 60,000 - 74,000
SOC Analyst
SOC Analyst

慨正橡扯 • Cheltenham

On-site
GBP 30,000 - 50,000
25 days' vacation per year
Private medical insurance
3 extra days leave for charitable work
Senior SOC Analyst
Senior SOC Analyst

Searchability • Farnborough

On-site
GBP 63,000 - 77,000
Shift allowance
Training & certifications support
Opportunity to work on high profile UK
+1