SOC Manager

CyPro

Greater London

On-site

GBP 90,000 - 120,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

CyPro is seeking a Senior SOC Manager to lead CyPro’s 24/7 MDR across a portfolio of external clients from its Canary Wharf office. The role requires strong MSSP experience, deep security operations knowledge and senior client-facing skills.

You will coach SOC Analysts, own detections, manage incidents and drive service improvements, with a focus on quality, governance and clear executive communication.

Qualifications

  • Must have previous SOC Manager experience in an MSSP delivering services to multiple clients.
  • Strong practical security operations knowledge: SIEM, EDR/XDR, incident response, detection engineering, alert triage, threat intel, threat hunting, SOAR, automation and SOC reporting.
  • Fluent English in a senior client-facing role; able to brief executives and governance bodies.

Responsibilities

  • Lead 24/7 MDR delivery across a portfolio of clients.
  • Line manage and develop SOC Analysts and Senior SOC Analysts; own service performance and escalation.
  • Own performance against SLAs, KPIs and contractual commitments; drive continuous improvement.
  • Raise detection coverage, incident escalation and reporting; ensure high-quality client communications.
  • Support recruitment, onboarding and professional development within the SOC.

Skills

MSSP experience
Fluent business English

Education

Bachelor's degree (desirable)

Tools

SIEM
Microsoft Sentinel
Microsoft Defender XDR
SOAR
Threat hunting tools

Job description

  • No recruiters or recruitment agencies, please.
  • You must be UK based. We cannot provide visa sponsorship.
  • Previous experience working as a SOC Manager within a Managed Security Service Provider (MSSP) is mandatory. Applications that do not meet this requirement will not progress.
Overview
Holiday: 24 days, pro rata, plus your birthday off, bank holidays and one additional day for every 12 months you stay with us.
Working Together: Three days per week in our Canary Wharf office, 39 floors up, with flexibility for the remaining two days.
Working Hours: 40 hours, Monday to Friday, with occasional support for serious incidents outside normal hours.
Training: An individual training plan and budget for one professional certification or course each year.
Socials: Regular drinks, team activities and the occasional bit of axe throwing.

You must meet all five requirements below. Please do not apply if you do not.

1. Mandatory MSSP experience: You must have previous experience working specifically as a SOC Manager within an MSSP, delivering security operations services to multiple external clients rather than managing only an internal SOC.

2. Technical security operations experience: You must have strong practical knowledge of SIEM, EDR/XDR, incident investigation and response, detection engineering, alert triage, threat intelligence, threat hunting, SOAR, automation and SOC reporting. Experience with Microsoft Sentinel, Microsoft Defender XDR and the wider Microsoft security ecosystem is strongly desirable.

3. Fluent business English: This is a senior, client-facing role. You must communicate complex security and operational matters clearly and confidently in spoken and written English, including executive briefings, incident communications, governance meetings and formal reports. Communication skills will be assessed during recruitment.

4. Location: You must live within approximately 90 minutes’ commuting distance of Canary Wharf, London.

5. Education: A technical academic background in computer science, cyber security, information security, software engineering or a related field is desirable. A degree is not mandatory and equivalent professional experience or qualifications will be considered.

About CyPro
  • CyPro is an innovative cyber security business with a shared mission: to redefine cyber security for small and medium-sized businesses.
  • Our founders, Jonny and Rob, built their early careers delivering cyber security for large enterprises and central government. They saw a need for a different approach for smaller organisations.
  • We help clients prevent attacks, secure larger customers and scale confidently. This role offers the opportunity to shape a growing SOC alongside experienced professionals.
The Role
  • As SOC Manager, you will be accountable for the day-to-day delivery of CyPro’s 24/7 managed detection and response services across a portfolio of clients.
  • You will lead SOC Analysts, maintain operational quality and act as a senior client contact.
  • You will own service performance, incident escalation, detection coverage and continuous improvement.
  • This is not a role where you simply supervise an alert queue. You must understand the technology, challenge poor-quality output and continually improve the service.
  • All CyPro employees are expected to be strong problem-solvers, adaptable and comfortable taking ownership in a fast-paced environment with limited guardrails.
Client Delivery and Service Management
  • Own managed detection and response delivery across a portfolio of clients.
  • Act as the primary operational escalation point for clients and internal teams.
  • Lead service reviews, governance meetings and executive briefings.
  • Present incidents, trends, risks and recommendations clearly and commercially.
  • Own performance against SLAs, KPIs and contractual commitments.
  • Monitor incident trends, detection coverage, alert volumes, false positives and response performance.
  • Create service improvement plans where quality falls below expectations.
  • Lead client onboarding and service transition, coordinating deployment, documentation and stakeholders.
  • Manage major incident escalations and ensure responses are controlled, communicated and documented.
  • Line manage and develop SOC Analysts and Senior SOC Analysts.
  • Set clear expectations and hold team members accountable for quality and timeliness.
  • Conduct one-to-ones, performance reviews and career development discussions.
  • Build development plans and support career progression.
  • Review investigations, incident reports and client communications.
  • Manage workload, capacity, priorities and operational coverage.
  • Support recruitment, assessment and onboarding.
  • Act as a role model for professionalism, ownership and delivery quality.
Detection, Investigation and Response
  • Maintain oversight of detection coverage across client environments.
  • Ensure alerts and incidents are investigated consistently and appropriately.
  • Provide technical guidance during complex or high-severity incidents.
  • Work with analysts, engineers and platform specialists to develop detection use cases.
  • Improve detection logic and reduce false positives without weakening coverage.
  • Oversee onboarding of new log sources and security technologies.
  • Identify opportunities to automate repetitive investigation and response activities.
  • Track alert quality, triage, investigation, containment and automation performance.
  • Use operational data to identify weaknesses and drive improvement.
  • Support threat hunting and the use of threat intelligence.
  • Turn incident lessons into improved detections, playbooks and response procedures.
  • Maintain awareness of emerging threats, attacker techniques and SOC technologies.
Service Improvement and Practice Development
  • Own and improve runbooks, playbooks, workflows and operational procedures.
  • Ensure documentation is clear, current and usable during live incidents.
  • Standardise investigation, escalation and reporting across client accounts.
  • Develop repeatable operating models that allow the SOC to scale without reducing quality.
  • Improve quality assurance for alerts, incidents and client deliverables.
  • Improve client reporting and service governance.
  • Contribute to new managed detection and response services.
  • Evaluate security technologies, automation and AI-supported SOC tooling.
  • Support proofs of concept and vendor assessments.
  • Align operational priorities with the wider SOC roadmap.
Commercial and Business Development
  • Support pre-sales discussions for managed detection and response opportunities.
  • Explain CyPro’s SOC capabilities clearly to prospective clients.
  • Contribute to service designs, proposals, pricing and Statements of Work.
  • Estimate onboarding effort, service capacity and technical resource requirements.
  • Identify opportunities to improve or expand services for existing clients.
  • Understand account profitability and the relationship between scope, capacity and delivery cost.
  • Ensure additional requests are assessed, scoped and commercially agreed.
Professional Development
  • Maintain your technical and professional credibility through relevant learning and industry engagement.
  • Strong candidates will typically hold two or more relevant certifications, or demonstrate equivalent experience. Examples include Microsoft SC-200, AZ-500, CISSP, CISM, GCIA, GCIH, CompTIA CySA+ and CREST Certified Intrusion Analyst.
  • Effective: You remove obstacles, establish ownership and drive work through to completion.
  • Accountable and Humble: You take responsibility for SOC performance, accept feedback and change your approach when needed.
  • Calm Under Pressure: You remain structured, prioritise clearly and communicate confidently during serious incidents.
  • Technically Credible: You understand security operations well enough to challenge investigations, identify weak reasoning and guide the team.
  • Client Focused: You provide timely communication, clear recommendations and confidence that the service is well managed.
  • People Developer: You invest in your team, give direct feedback and address poor performance.
  • Commercially Aware: You balance strong security outcomes with contractual scope, resources and sustainable delivery.
  • Adaptable: You make sensible decisions in an evolving environment and help build processes that do not yet exist.

We can generally take candidates through the full process within 10 days.

Telephone Interview: A 20-minute initial conversation with a senior member of the Cyber Security team.

Psychometric Testing: Three 15-minute cognitive assessments.

Assessment Centre: A morning in our Canary Wharf office involving practical exercises and a final interview with a practice partner.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Analyst
Cyber Security Analyst

CyPro • Greater London

Hybrid
GBP 30,000 - 36,000
24 days paid holiday (pro rata) + your
Birthday off + bank holidays + one new
Training budget for one certification
+1
Graduate SOC Analyst
Graduate SOC Analyst

CyPro • Greater London

Hybrid
GBP 40,000 - 65,000
Holiday: 25 days paid holiday plus 9/7
Flexible Working: three days in London
Working Hours: 9:00–17:30, potential 7
+3
SOC Manager (MSSP Leader) - Hybrid
SOC Manager (MSSP Leader) - Hybrid

Resillion • Glasgow

Hybrid
GBP 90,000 - 120,000
SOC Manager: AI-Driven Security & Growth Leader
SOC Manager: AI-Driven Security & Growth Leader

Resillion • Glasgow

Hybrid
GBP 90,000 - 120,000
Manager SOC Security Specialist
Manager SOC Security Specialist

Fox-IT • Manchester

On-site
GBP 50,000 - 70,000
Flexible Working
Generous Holiday Allowance
Medicash & Critical Illness Scheme
+6
SOC Analyst
SOC Analyst

NCC Group • Manchester

On-site
GBP 42,000 - 64,000
Flexible Working
Generous Holiday Allowance
Medicash & Critical Illness Scheme
+7
SOC Operations Lead: Proactive Detection & Incident Response
SOC Operations Lead: Proactive Detection & Incident Response

SPG Resourcing • York and North Yorkshire

On-site
GBP 70,000 - 95,000
Pension scheme (up to 12% employer)
Life Assurance (up to 10x salary)
Private medical cover
+2
SOC Analyst - Tier 1
SOC Analyst - Tier 1

Methods Business and Digital Technology • Greater London

Hybrid
GBP 42,000 - 54,000
Private Medical Insurance
Pension
Life Assurance
+2
SOC Analyst - Tier 1
SOC Analyst - Tier 1

Methods • Greater London

Hybrid
GBP 28,000 - 52,000
Flexible Working - home working
25 days annual leave
Pension
+2
SecOps Engineer
SecOps Engineer

Manchester Arndale • Greater London

Hybrid
GBP 60,000 - 90,000