Focus Group (UK) Logo

Focus Group (UK)

Senior SOC Analyst

Reposted 24 Days Ago
Be an Early Applicant
In-Office
Manchester, Greater Manchester, England, GBR
Senior level
In-Office
Manchester, Greater Manchester, England, GBR
Senior level
The Senior SOC Analyst will lead SOC operations, manage complex security incidents, mentor junior analysts, and improve detection strategies while ensuring service excellence.
The summary above was generated by AI

Senior SOC Analyst

(Internal Job Level Reference: Specialist)

UK • Hybrid - 3 days a week in our Manchester office (Suite B, Maple Court, M60 Office Park, Wynne Ave, Swinton, Clifton, Manchester, M27 8FF)

Focus Group is looking for a Senior SOC Analyst to play a key role within our Managed Security Services team. This is a dual‑focused position combining hands‑on technical expertise with day‑to‑day operational leadership, ensuring high‑quality delivery of managed detection and response services across a diverse customer base.

You’ll lead SOC operations, act as the escalation point for complex security incidents, and mentor junior analysts—driving both service excellence and team development.

What you’ll do

  • Lead day‑to‑day SOC operations, ensuring effective triage, escalation, and communication workflows
  • Act as the primary escalation point for complex security investigations and incidents
  • Conduct advanced threat investigations across endpoints, networks, and cloud environments
  • Perform proactive threat hunting and detection tuning to improve coverage and reduce noise
  • Manage and mentor Tier 1–2 analysts, supporting development and technical growth
  • Ensure ticket quality, SLA adherence, and high service standards across SOC operations
  • Support onboarding of new customers into monitoring and detection platforms
  • Collaborate with Cyber Security leadership to improve detection strategy and SOC maturity
  • Analyse logs and security data to identify malicious or suspicious activity
  • Develop and maintain playbooks, runbooks, and knowledge base content
  • Produce clear, actionable incident reports for internal and customer stakeholders
  • Engage directly with customers during escalations, incident reviews, and briefings
  • Identify opportunities for automation, process improvement, and enhanced detection capabilities
  • Stay up to date with emerging threats, attack techniques, and MITRE ATT&CK developments

What you’ll bring

  • 4–6 years’ experience in a SOC or MSSP environment at Tier 2–3 or Lead level
  • Strong hands‑on experience with SIEM platforms (e.g. Microsoft Sentinel, Splunk, Elastic, LogPoint)
  • Experience with EDR tools such as Microsoft Defender, SentinelOne, or Bitdefender
  • Deep understanding of MITRE ATT&CK and modern threat detection methodologies
  • Strong incident response, investigation, and log analysis capability across multiple data sources
  • Ability to lead during high‑pressure incidents with calm, confident decision‑making
  • Strong communication skills, including producing clear incident reports and updates
  • Proven ability to mentor, coach, and support junior analysts
  • Organised approach with the ability to manage multiple concurrent incidents
  • Proactive mindset focused on continuous improvement and service optimisation

Nice to have

  • Certifications such as SC‑200, GCIH, GCIA, Security+, or BTL1
  • Experience in an MSSP or multi‑customer environment
  • Microsoft security stack experience (Defender XDR, Sentinel, M365 security)
  • Knowledge of cloud security, email security, and vulnerability management
  • Experience with KQL or other query languages
  • Scripting skills (PowerShell, Python)
  • Familiarity with SOAR and threat intelligence platforms
  • Understanding of compliance frameworks (ISO 27001, NIST, Cyber Essentials)

Future opportunities

  • SOC Manager / Head of Security Operations
  • Cyber Security Technical Lead
  • Detection Engineering Lead
  • Threat Intelligence Lead
  • Incident Response Manager
  • Security Consultant / Advisory

IND1

Focus Group (UK) Manchester, England Office

Clarendon House, Clarendon Road, Manchester, United Kingdom, M30 9AL

Similar Jobs

Senior level
Financial Services
Monitor and investigate security threats, vulnerabilities, and incidents through log and network analysis. Triage alerts, lead incident response, develop detection and response playbooks, document processes, and provide cybersecurity intelligence to acquired organizations. Collaborate with technical and non-technical teams, identify security gaps, drive remediation efforts, and escalate complex issues while supporting continuous improvement of the organization’s security posture.
Top Skills: CryptographyEmail Security SolutionsEndpoint Detection And Response (Edr)Extended Detection And Response (Xdr)Intrusion Detection Systems (Ids)LinuxMalware Analysis ToolsScriptingSIEMWindows
16 Days Ago
Remote or Hybrid
2 Locations
Senior level
Senior level
Other • Professional Services • Real Estate • Energy
Lead complex security incident investigations from assessment through recovery, coordinate technical response teams, determine scope and root cause, preserve evidence, and produce post-incident reports. Develop and tune Microsoft Sentinel detections, conduct threat hunting with Defender XDR, improve playbooks through purple-team findings, mentor SOC analysts, manage MSSP escalation, and brief technical and senior non-technical stakeholders during incidents.
Top Skills: AzureDefender Advanced HuntingEntra IdMicrosoft 365Microsoft Defender XdrMicrosoft Sentinel
21 Days Ago
In-Office
Senior level
Senior level
Fintech • Software • Financial Services
Lead 24/7 SOC monitoring, threat detection, investigation, and incident response. Handle complex and high-severity incidents, perform advanced log and alert correlation, improve detection quality, automate SOC processes, refine playbooks, evaluate AI-enabled security tools, and mentor junior analysts. Work cross-functionally across endpoint, network, cloud, identity, application, database, and mobile environments, including participation in on-call rotations.
Top Skills: Ai-Enabled Security ToolsCloud EnvironmentsEdr/XdrIdentity SystemsMcp SolutionsSecurity SandboxesSIEMSoarThreat Intelligence PlatformsVulnerability Management

What you need to know about the Manchester Tech Scene

Home to a £5 billion digital ecosystem, including MediaCity, which consists of major players like the BBC, ITV and Ericsson, Manchester is one of the U.K.'s top digital tech hubs, at the forefront of advancements in film, television and emerging sectors like as e-sports, while also fostering a community of professionals dedicated to pushing creative and technological boundaries.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account