SOC Lead
Key details
- Compensation
- $18,000 - $21,000
Job Description
Salary: £18,000 - 21,000 per year
Requirements
- 7+ years in Security Operations, Threat Hunting, or Incident Response
- Proven experience leading investigations involving advanced persistent threats, insider threats, or targeted attacks
- Strong hands-on expertise with SIEM platforms (e.g. Sentinel, Splunk, Elastic)
- Experience with EDR/XDR solutions (e.g. Defender, CrowdStrike, SentinelOne)
- Strong knowledge of network and cloud security telemetry
- Understanding of MITRE ATT&CK framework
- Familiarity with Windows, Linux, and cloud attack techniques
- Knowledge of malware behaviors, credential abuse, lateral movement, and persistence mechanisms
- Demonstrated ability to lead and mentor technical teams
- Strong investigative mindset with attention to detail
- Excellent written and verbal communication skills
- Ability to translate technical findings into business and risk context
- Desirable: Experience with detection engineering or SOAR automation
- Desirable: Purple team or red team collaboration experience
- Desirable: Forensic analysis experience (memory, disk, network)
- Desirable: Exposure to regulatory environments (e.g. ISO 27001, NIST, GDPR)
Responsibilities
- Lead proactive, hypothesis-driven threat hunting activities across endpoint, network, cloud, identity, and SaaS environments
- Develop and maintain threat hunting playbooks aligned to MITRE ATT&CK techniques
- Identify stealthy, low-and-slow, and novel attack patterns not detected by automated controls
- Translate threat intelligence into actionable hunt hypotheses
- Continuously refine detection logic based on hunt outcomes and emerging threats
- Lead complex and high-severity security investigations from triage through containment and remediation
- Act as the technical escalation point for advanced SOC investigations
- Conduct root cause analysis and attacker kill-chain reconstruction
- Produce clear, defensible investigation documentation suitable for executive, legal, and regulatory audiences
- Coordinate incident response activities with IR, IT, Legal, Risk, and external partners as required
- Define investigation standards, workflows, and quality benchmarks
- Mentor and upskill SOC analysts in hunting methodologies and investigative techniques
- Review and improve alert fidelity, detection coverage, and response effectiveness
- Provide technical oversight for tooling such as SIEM, EDR/XDR, NDR, SOAR, and cloud-native security platforms
- Collaborate with detection engineers to convert hunt findings into new or improved detections
- Identify visibility gaps and recommend logging, telemetry, and tooling improvements
- Validate detection performance through purple team activities and simulation
- Consume and operationalise internal and external threat intelligence
- Maintain awareness of attacker tactics, tools, and campaigns relevant to the organization
- Act as a key interface between SOC, Threat Intel, Red Team, and Vulnerability Management
- Track and report on hunt coverage, outcomes, dwell time, MTTR, and investigation quality
- Provide regular insights to senior leadership on threat trends and risk posture
Technologies
- Cloud
- Linux
- Network
- Security
- Splunk
- Windows
- DevOps
More
We are seeking a SOC Lead - Threat Hunting & Investigations to join our team in Bath with a hybrid working model of 3 days onsite and 2 days remote. In this role, you will be responsible for leading advanced threat detection and complex security investigations across our enterprise. We offer a competitive day rate of £700 outside of IR35 and an opportunity to make a significant impact as you mentor analysts and enhance our SOC capabilities.
last updated 20 week of 2026
Company & context
Evidence is labeled so you can tell internal community data from public sources.
Range from 421 indexed roles at this employer: $11,000 - $145,600(mid ~58787)
Context may refresh in the background.
Trust-check this listing
Verify scam risk and ghost-job signals before you apply.
Related roles
Platform Engineer - Portsmouth
Atlassian Technical Engineer
Network Design Engineer
Source: DevITJobs • Last updated May 21, 2026