Motorway Logo

Motorway

Senior SOC Analyst

Reposted 2 Days Ago
Be an Early Applicant
Hybrid
London, Greater London, England
Senior level
Hybrid
London, Greater London, England
Senior level
The role involves developing SOC processes, managing security incidents, collaborating with teams, handling vulnerabilities, and reporting metrics.
The summary above was generated by AI
About Motorway

Motorway is the UK’s fastest-growing used car marketplace – our award winning, online-only platform connects private car sellers with over 7,500 verified dealers nationwide, who compete to offer the best price. Founded in 2017, our technology makes the process refreshingly easy, earning us an 'Excellent' Trustpilot rating with over 70,000 reviews. We're not just building a platform; we're changing how people sell cars.

Backed by leading investors like Index Ventures and ICONIQ Growth, and following a successful $190 million funding round, we're on a mission to transform the used car market.

About the role

We’re looking for an experienced Senior SOC Analyst to assist in the development, enhancement and execution of our Security Operations capability. The successful candidate will develop SOC processes, procedures and workflows for systems security monitoring and security incident response. This role will work collaboratively with other business technical and non-technical teams.

The role will involve:
  • Triage & Analysis: This is the bread and butter. The focus here should be on MTTD (Mean Time to Detect).

  • End-to-End IR: Leading incidents requires not just technical skill, but "Incident Commander"

  • Vulnerability & Threat Hunting: This is proactive. Instead of waiting for an alarm, the lead should be searching for "indicators of compromise" (IoCs) based on recent threat intelligence.

  • Runbook Development: If a process is done more than twice, it should be in a runbook. In 2026, these are often "Executable Runbooks" (Python/Bash) rather than just PDFs.

  • Tooling & Alarms: This involves the maintenance of your SIEM/SOAR.

  • Coverage & Noise Reduction: This is critical for preventing "SOC Fatigue." A lead must ruthlessly tune out "false positives" so the team only sees high-fidelity alerts.

  • Platform & Software Engineering: This is the "Shift Left" approach.

    • Platform: Ensuring Kubernetes/Cloud environments are hardened.

    • Software: Implementing Secure by Design (e.g., automated SAST/DAST in the CI/CD pipeline).

  • Tabletops & War Games: You don't want the first time a team handles a ransomware attack to be during a real one. Regular exercises are the NCSC-recommended way to build "muscle memory."

  • Audit & Metrics: Developing dashboards that show MTTR (Mean Time to Respond) and Vulnerability Burn-down rates for the Head of Sec.

Requirements:
  • Secure by Design: Act as a security champion for Software and Platform Engineering teams to ensure "Security-as-Code" is integrated into CI/CD pipelines.

  • Advanced Threat Hunting: Proven ability to proactively hunt for threats using the MITRE ATT&CK framework, rather than solely relying on automated alerts.

  • Cloud Security Operations: Hands-on experience securing AWS and GCP environments. You must be comfortable with cloud-native logging and security tooling ( Chronicle).

  • Forensics & Investigation: Mastery of deep-dive systems forensics on both Windows and macOS. You should be able to reconstruct a timeline of events from memory dumps and filesystem artefacts.

  • Automation & Scripting: Proficiency in Python or Go for automating SOC workflows (SOAR) and creating custom detection logic via SQL or Sigma rules.

  • Modern Observability: Experience with developer-centric observability tools (e.g., Logfire, OpenTelemetry) to monitor LLM interactions and API security.

  • Audit & Reporting: Ability to develop and maintain automated dashboards for MTTR (Mean Time to Respond) and MTTD (Mean Time to Detect) for executive reporting.

  • Incident Commander: Ability to lead high-severity incidents end-to-end, managing technical workstreams while providing clear, non-technical updates to senior stakeholders.

  • Detection Engineering: Expertise in tuning SIEM/EDR (e.g.,Wiz, CrowdStrike, NetSkope) to reduce noise and maintain "data freshness."

  • Playbook Development: Proven experience designing and implementing executable runbooks that standardise response for ransomware, phishing, and cloud-account takeovers.

  • Infrastructure Knowledge: Strong understanding of network protocols (TLS 1.3), API security (OAuth/OIDC), and container security (Kubernetes/Docker).

  • Readiness Exercises: Experience organising and running Tabletop Exercises and "War Games" to test organisational resilience.

  • Mentorship: A commitment to up-skilling junior analysts and fostering a culture of continuous learning and technical excellence.

  • Standards: Good working knowledge of ISO27001, NIST CSF, and PCI DSS v4.0 (specifically 3rd-party compliance).

Benefits
  • A competitive salary

  • BUPA health insurance

  • Discounted gym membership through BUPA

  • OnHand volunteering membership and one paid volunteering day per year

  • Hybrid working

  • Pension scheme

  • Motorway car leasing scheme - lease a zero-emissions electric vehicle at a significant discount

  • Enhanced parental leave - We offer enhanced maternity pay (26 weeks of full pay) and enhanced paternity pay (4 weeks of full pay) to eligible employees.

  • Workplace nursery scheme

  • Regular social events

  • Cycle to work scheme

Equal opportunities statement

We are committed to equality of opportunity for all employees. We work to provide a supportive and inclusive environment where people can maximise their full potential. We believe our workforce should reflect a variety of backgrounds, talents, perspectives and experiences. Our strong commitment to a culture of inclusion is evident through our constant focus on recruiting, developing and advancing individuals based on their skills and talents.

We welcome applications from all individuals regardless of age, disability, sex, gender reassignment, sexual orientation, pregnancy and maternity, race, religion or belief and marriage and civil partnerships.

Top Skills

AWS
Endpoint Protection
GCP
Ids/Ips
Iso27001
Mitre Att@Ck
Nist Csf
Pci Dss
Proxies
Scanners
SIEM
Waf

Similar Jobs

An Hour Ago
Remote or Hybrid
Senior level
Senior level
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Lead a team of Solution Sales Executives to drive new business growth, develop sales strategies, and manage performance within a territory.
Top Skills: PaasSaaS
Mid level
Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
The role involves supporting maintenance of AH-64 Apache helicopters, providing technical advice, conducting fault diagnostics, and coordinating with various stakeholders for aircraft modification and repair.
Top Skills: Ah-64 Apache Weapons SystemsAirframe Electrical SystemsData Management SystemsEnvironmental Control SystemsFire Control SystemsFlight Control SystemsHums Systems
An Hour Ago
In-Office
Mid level
Mid level
Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
The role involves managing activities and data processes in Capture & Business Development, supporting leadership with reporting, training staff, and improving business processes.
Top Skills: Customer Relationship Management (Crm) ToolsExcelPowerPointSharepointWord

What you need to know about the Manchester Tech Scene

Home to a £5 billion digital ecosystem, including MediaCity, which consists of major players like the BBC, ITV and Ericsson, Manchester is one of the U.K.'s top digital tech hubs, at the forefront of advancements in film, television and emerging sectors like as e-sports, while also fostering a community of professionals dedicated to pushing creative and technological boundaries.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account