Senior SOC Analyst

3 months, 3 weeks ago
Full-time
Senior
Cybersecurity
Phoenix Software

Phoenix Software

Phoenix Software specializes in leveraging information technology to empower the UK public sector to innovate and transform, facilitating the delivery of smart connected services to various stakeholders, including staff, citizens, patients, and students.

IT Services
251-1K
Founded 1990

Description

  • Lead major security incidents from detection through remediation, including containment and attacker activity analysis.
  • Support clients through high-severity security events and critical decision-making during incident response.
  • Proactively hunt for threats using advanced KQL analytics and other SOC investigation techniques.
  • Enhance SIEM and EDR detections, tune rules, and develop signatures aligned to MITRE ATT&CK.
  • Perform malware triage and behavioural analysis, including reverse engineering when needed.
  • Produce clear investigation reports, timelines, and intelligence summaries for technical and non-technical audiences.
  • Contribute to SOC playbooks and help improve SOC processes, tooling, and overall capability.
  • Mentor junior analysts and support skill development within the SOC team.
  • Support onboarding of new customers and help integrate them into SOC operations.
  • Participate in the 24x7 on-call rota to provide expert support during critical incidents.

Requirements

  • Strong background in DFIR, SOC operations, or incident response.
  • Experience leading complex investigations and high-severity security incidents.
  • Ability to make confident decisions and guide clients through critical situations.
  • Strong communication skills with the ability to translate technical findings for any audience.
  • Collaborative mindset with willingness to work closely across teams.
  • Ability to mentor junior analysts and support skill development.
  • Comfortable working in fast-paced, high-pressure environments.
  • Proactive approach to improving SOC processes, playbooks, and detection capabilities.
  • Advanced SIEM expertise, ideally with Microsoft Sentinel and Defender XDR.
  • High-level KQL capability, with Python and PowerShell for automation.
  • Core digital forensics skills.
  • Experience with Velociraptor, KAPE, and sandbox tools.
  • Solid understanding of detection engineering.
  • Strong technical reporting and documentation skills.
  • Must have lived in the UK continuously for at least 5 years and have no criminal record to achieve clearance.
  • Must already have, or be able to obtain, NPPV3.
  • Fully remote role apart from an initial onboarding week on-site in Pocklington.
  • Shift pattern is 9:00am to 5:00pm with flexible start and finish times, plus on-call responsibilities.

Benefits

  • Fully remote working apart from an initial onboarding week on-site in Pocklington.
  • Flexible start and finish times.
  • Opportunity to join a culture focused on encouragement, support, and skill development.
  • Chance to work for a UK IT solution and managed service provider with a strong people-first culture.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Transaction Monitoring and Fraud Analyst

Mews 251-1K Consumer Services

Mews is hiring a FinCrime professional to monitor transactions and payment activity, investigate suspicious behavior, and help reduce fraud and financial crime at scale across its growing payments platform.

Python SQL
1 day, 3 hours ago

Writer, Threat Intelligence & Communications

SecurityScorecard 251-1K IT Services

SecurityScorecard is hiring a cybersecurity content strategist to turn threat intelligence and technical findings into executive- and practitioner-facing communications.

Cybersecurity Python Splunk SQL
1 day, 3 hours ago

Writer, Threat Intelligence & Communications

SecurityScorecard 251-1K IT Services

SecurityScorecard is hiring a cybersecurity content specialist to create executive-facing threat intelligence and communications content that translates complex security topics into clear narratives for technical and business audiences.

Cybersecurity Python Splunk SQL
1 day, 4 hours ago

Principal Dark Web Collection Analyst

Recorded Future 251-1K Professional Services

Recorded Future is hiring a dark web intelligence expert to own underground community collection strategy and hands-on source access for its expanding threat intelligence operations.

Python
2 days, 3 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers