NCC Group Logo

NCC Group

Senior SOC Analyst

Reposted Yesterday
Be an Early Applicant
Hybrid
Manchester, Greater Manchester, England, GBR
Senior level
Hybrid
Manchester, Greater Manchester, England, GBR
Senior level
Monitor global systems for threats, perform in-depth analysis using Microsoft XDR (Sentinel/Defender), handle and remediate incidents, mentor junior analysts, liaise with clients, produce reports, and contribute to SOC process improvement and threat hunting.
The summary above was generated by AI
The MXDR Senior SOC Analyst is a senior technical position within the Managed Extended Detection and Response (MXDR) team. Acting as a technical leader across security operations, the Senior Analyst is responsible for leading complex investigations, supporting incident response activities, driving detection improvements and acting as a key escalation point for analysts and customer tickets. 
The role combines operational responsibilities within the Security Operations Centre with strategic contributions to the continual enhancement of the MXDR service. Working closely with Detection Engineering, Threat Hunting, Customer Success, Technical Account Managers and Service Delivery teams, the Senior Analyst will help ensure customers receive world class detection and response capabilities while driving innovation across Microsoft Sentinel, Microsoft Defender XDR, and the wider MXDR technology stack. 
As a recognised Subject Matter Expert (SME), the Senior Analyst will provide guidance and mentorship to analysts, lead technical investigations, support customer onboarding activities and contribute to the development of analytics, automation and AI-driven security operations capabilities.
Working Hours: The working hours are 0900-1730hrs Mon-Fri, and you would be expected to be working and contactable throughout those times. There is no scheduled out of hours work but may be required in emergency situations only. 

Key Responsibilities
  • Monitor global customer environments for potential threats, vulnerabilities, and indicators of compromise. 
  • Perform advanced analysis and investigation of security alerts utilising Microsoft Sentinel, Microsoft Defender XDR and associated security platforms across the MXDR technology stack, including Splunk, CrowdStrike, SentinelOne and Carbon Black. 
  • Act as a senior incident responder and technical lead during high-priority security incidents. 
  • Provide incident remediation guidance, technical recommendations and preventative security advice to customers. 
  • Actively contribute to the triage and investigation queue, ensuring incidents are handled in accordance with service level agreements. 
  • Act as the primary escalation point for analysts during complex investigations and security incidents. 
  • Provide out-of-hours escalation support when required for customer incidents. 
  • Work closely with Automation Development (ADEV) teams to tune existing detections and develop new analytics and use cases. 
  • Identify detection gaps through investigations, threat hunting activities and customer feedback, proposing improvements to monitoring coverage. 
  • Contribute to the development and optimisation of detection content, automation workflows and response playbooks. 
  • Support customer onboarding and service transition activities, ensuring effective implementation of monitoring and detection capabilities. 
  • Act as a technical point of contact for customer escalations and service related security discussions. 
  • Serve as a Subject Matter Expert (SME) across the MXDR technology stack, providing technical leadership, guidance and support during investigations, service improvements and customer engagements. 

  • Conduct proactive threat hunting activities to identify malicious activity, validate detections and strengthen customer security posture. 
  • Provide technical mentoring and guidance to analysts, supporting capability development across the SOC. 
  • Contribute to the continual improvement of MXDR processes, procedures, documentation and service offerings. 
  • Perform other duties as assigned. 

Skills, Knowledge & Expertise
Required Functional and Technical Skills: 
Security Operations & Incident Response 
  • Extensive experience investigating and responding to cyber security incidents within a MXDR SOC environment. 
  • Strong understanding of incident response methodologies, threat hunting techniques and attacker behaviours. 
  • Ability to lead technical investigations and coordinate response activities during major security incidents. 
  • Experience analysing endpoint, identity, cloud, email and network based threats. 
   Security Monitoring & Detection Platforms 
  • Advanced and practical knowledge of enterprise security monitoring technologies, including Microsoft Sentinel, Splunk, CrowdStrike, SentinelOne, Carbon Black and associated cloud security platforms used within the MXDR service. 
  • Strong understanding of security telemetry, log analysis, threat detection methodologies and investigation workflows across endpoint, identity, cloud, email, and network security domains. 
  • Experience developing and tuning detection logic, analytics, correlation rules and automated response capabilities across multiple security technologies. 
  • Ability to leverage platform specific query languages, hunting capabilities and investigation tools to identify threats, validate detections and support incident response activities. 
   Detection Engineering & Continuous Improvement 
  • Experience tuning and improving security analytics to reduce false positives and improve detection fidelity. 
  • Ability to identify detection gaps and develop recommendations for enhanced monitoring coverage. 
  • Experience collaborating with engineering and development teams to deliver security use cases and automation solutions. 
   Client Communication & Stakeholder Management 
  • Strong written and verbal communication skills with the ability to explain technical concepts to both technical and non technical audiences. 
  • Experience supporting customer facing investigations and escalations. 
   Security Platforms & Technologies 
  • Strong understanding of operating systems, networking fundamentals, authentication protocols and cloud technologies. 
  • Knowledge of MITRE ATT&CK, Cyber Kill Chain and common adversary behaviours. 
  • Experience working with SOAR, SIEM, EDR and threat intelligence platforms. 
   Collaboration & Leadership 
  • Ability to act as a senior technical authority and escalation point within the MXDR team. 
  • Experience mentoring analysts and supporting technical development initiatives. 
  • Ability to work collaboratively across operations, engineering, onboarding and customer success teams. 

Job Benefits
  • Flexible Working: Balance your work and personal life with our flexible working options.
  • Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave.
  • Medicash & Critical Illness Scheme
  • Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme.
  • Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities.
  • Green Car Scheme: Drive green and save money with our eco-friendly car scheme.
  • Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme.
  • Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet.
  • Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.


About
We assess, develop and manage cyber threats across our increasingly connected society. We advise global technology, manufacturers, financial institutions, critical national infrastructure providers, retailers and governments on the best way to keep businesses, software and personal data safe.With our knowledge, experience and global footprint, we are best placed to help businesses identify, assess, mitigate & respond to the risks they face.We are passionate about making the Internet safer and revolutionising the way in which organisations think about cyber security.Headquartered in Manchester, UK, with over 35 offices across the world, NCC Group employs more than 2,000 people and is a trusted advisor to 15,000 clients worldwide.
HQ

NCC Group Manchester, England Office

Manchester, United Kingdom

NCC Group Manchester, England Office

XYZ, 2 Hardman Blvd, Manchester , Manchester, United Kingdom, M3 3AQ

Similar Jobs

2 Days Ago
In-Office
Manchester, Greater Manchester, England, GBR
Senior level
Senior level
Information Technology • Cybersecurity
The Senior SOC Analyst will lead SOC operations, manage complex security incidents, mentor junior analysts, and improve detection strategies while ensuring service excellence.
Top Skills: Bitdefender)Edr Tools (Microsoft DefenderElasticKqlLogpoint)PowershellPythonSentineloneSiem Platforms (Microsoft SentinelSplunk
19 Minutes Ago
Remote or Hybrid
United Kingdom
Expert/Leader
Expert/Leader
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Lead cross-domain detection strategy and execution across endpoint, cloud, identity, NG-SIEM and SaaS. Design high-fidelity correlation detections, prioritize threat-informed investments, coordinate multi-team coverage, apply AI/LLM to detection workflows, coach detection engineers, and influence product/platform telemetry to improve detection quality.
Top Skills: Adaptive ShieldAIAWSAzureCrowdstrike FalconEdrFalcon CompleteGCPKubernetesLinuxLlmmacOSMitre Att&CkNg-SiemOverwatchPlatform Ioas (Cde)SIEMWindows
20 Minutes Ago
In-Office
Expert/Leader
Expert/Leader
Aerospace • Artificial Intelligence • Machine Learning • Robotics • Software
Leads engineering teams developing and deploying autonomy solutions for unmanned weapon systems. Owns system architecture, technical objectives, engineering decisions, risk mitigation, product quality, technical requirements, system documentation, and software delivery. Provides technical oversight for internal R&D and defense contracts, supports customer-facing engineering leadership, contributes to government proposals, and manages teams of 6–20 engineers.
Top Skills: ControlsEstimationGuidance Navigation And Control (Gnc)Hivemind AutonomyPerceptionPlanningRobotics

What you need to know about the Manchester Tech Scene

Home to a £5 billion digital ecosystem, including MediaCity, which consists of major players like the BBC, ITV and Ericsson, Manchester is one of the U.K.'s top digital tech hubs, at the forefront of advancements in film, television and emerging sectors like as e-sports, while also fostering a community of professionals dedicated to pushing creative and technological boundaries.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account