Monitor, detect, investigate, and respond to security events using Splunk Enterprise Security. Triage incidents, perform log analysis and event correlation, assist threat hunting and vulnerability remediation, escalate significant incidents, and maintain incident documentation and SOC playbooks.
We are seeking an experienced Lead SOC Analyst to oversee Security Operations Centre (SOC) activities, lead incident response efforts, and mentor a team of analysts. The successful candidate will have strong expertise in cyber threat detection, incident investigation, and the Splunk Enterprise Security (ES) platform.
Key Responsibilities
- Lead day-to-day SOC operations and provide technical guidance to SOC Analysts.
- Monitor, investigate, and respond to security incidents and alerts.
- Develop, optimise, and maintain Splunk Enterprise Security use cases, correlation searches, dashboards, and reports.
- Conduct threat hunting and advanced forensic investigations.
- Coordinate incident response activities and provide detailed post-incident analysis.
- Collaborate with IT, security, and business stakeholders to improve security posture.
- Support SOC processes, playbooks, and continuous improvement initiatives.
Skills, Knowledge and Expertise
- Extensive experience working in a SOC, Cyber Security, or Incident Response role.
- Strong hands-on experience with Splunk Enterprise Security.
- Experience leading security investigations and major incident response activities.
- Knowledge of MITRE ATT&CK, SIEM technologies, threat intelligence, and security best practices.
- Relevant certifications such as Splunk Certified Cybersecurity Defence Analyst, CISSP, GCIA, GCIH, or equivalent are desirable.
Benefits
We have a high-performance culture which is balanced evenly with world-class well-being initiatives and benefits:
- Flexible Working: Balance your work and personal life with our flexible working options.
- Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave.
- Medicash & Critical Illness Scheme
- Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme.
- Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities.
- Green Car Scheme: Drive green and save money with our eco-friendly car scheme.
- Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme.
- Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet.
- Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.
About
We assess, develop and manage cyber threats across our increasingly connected society. We advise global technology, manufacturers, financial institutions, critical national infrastructure providers, retailers and governments on the best way to keep businesses, software and personal data safe.With our knowledge, experience and global footprint, we are best placed to help businesses identify, assess, mitigate & respond to the risks they face.We are passionate about making the Internet safer and revolutionising the way in which organisations think about cyber security.Headquartered in Manchester, UK, with over 35 offices across the world, NCC Group employs more than 2,000 people and is a trusted advisor to 15,000 clients worldwide.
Similar Jobs
Artificial Intelligence • Machine Learning • Analytics
Lead overnight SOC operations: conduct advanced investigations, incident response, and threat hunting; perform QC on Tier 1/2 work; mentor analysts; own escalations and client contact; improve runbooks and detection tuning; support monthly reporting and trend analysis.
Top Skills:
CrowdstrikeEdrMicrosoft SentinelPowershellPythonSIEMSplunkTenableVulnerability Management
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Drive pipeline and bookings growth through strategic Global Systems Integrator partnerships across Europe. Develop joint business plans, coordinate enterprise sales pursuits, generate demand, strengthen executive relationships, expand partner-led services and platform adoption, and monitor performance through business reporting. Collaborate with Sales, Marketing, Product, Services, Finance, and alliance teams to execute go-to-market initiatives and deliver measurable revenue outcomes.
Top Skills:
Artificial IntelligenceCloud ComputingCybersecurityFalcon FlexSaaS
Cloud • Information Technology • Productivity • Security • Software • App development • Automation
Partner with sales and partners to run pre-sales discovery, demonstrate Atlassian products, map customer problems to solutions, identify expansion opportunities, capture product feedback, and support pipeline development for mid-market/enterprise accounts.
Top Skills:
Atlassian PlatformAtlassian Products
What you need to know about the London Tech Scene
London isn't just a hub for established businesses; it's also a nursery for innovation. Boasting one of the most recognized fintech ecosystems in Europe, attracting billions in investments each year, London's success has made it a go-to destination for startups looking to make their mark. Top U.K. companies like Hoptin, Moneybox and Marshmallow have already made the city their base — yet fintech is just the beginning. From healthtech to renewable energy to cybersecurity and beyond, the city's startups are breaking new ground across a range of industries.



