Skip to content
Back to jobs

SOC Lead

Experis
The Street, Bath
May 14, 2026
TBDunknown$18,000 - $21,000

Key details

Compensation
$18,000 - $21,000

Job Description

Salary: £18,000 - 21,000 per year

Requirements

  • 7+ years in Security Operations, Threat Hunting, or Incident Response
  • Proven experience leading investigations involving advanced persistent threats, insider threats, or targeted attacks
  • Strong hands-on expertise with SIEM platforms (e.g. Sentinel, Splunk, Elastic)
  • Experience with EDR/XDR solutions (e.g. Defender, CrowdStrike, SentinelOne)
  • Strong knowledge of network and cloud security telemetry
  • Understanding of MITRE ATT&CK framework
  • Familiarity with Windows, Linux, and cloud attack techniques
  • Knowledge of malware behaviors, credential abuse, lateral movement, and persistence mechanisms
  • Demonstrated ability to lead and mentor technical teams
  • Strong investigative mindset with attention to detail
  • Excellent written and verbal communication skills
  • Ability to translate technical findings into business and risk context
  • Desirable: Experience with detection engineering or SOAR automation
  • Desirable: Purple team or red team collaboration experience
  • Desirable: Forensic analysis experience (memory, disk, network)
  • Desirable: Exposure to regulatory environments (e.g. ISO 27001, NIST, GDPR)

Responsibilities

  • Lead proactive, hypothesis-driven threat hunting activities across endpoint, network, cloud, identity, and SaaS environments
  • Develop and maintain threat hunting playbooks aligned to MITRE ATT&CK techniques
  • Identify stealthy, low-and-slow, and novel attack patterns not detected by automated controls
  • Translate threat intelligence into actionable hunt hypotheses
  • Continuously refine detection logic based on hunt outcomes and emerging threats
  • Lead complex and high-severity security investigations from triage through containment and remediation
  • Act as the technical escalation point for advanced SOC investigations
  • Conduct root cause analysis and attacker kill-chain reconstruction
  • Produce clear, defensible investigation documentation suitable for executive, legal, and regulatory audiences
  • Coordinate incident response activities with IR, IT, Legal, Risk, and external partners as required
  • Define investigation standards, workflows, and quality benchmarks
  • Mentor and upskill SOC analysts in hunting methodologies and investigative techniques
  • Review and improve alert fidelity, detection coverage, and response effectiveness
  • Provide technical oversight for tooling such as SIEM, EDR/XDR, NDR, SOAR, and cloud-native security platforms
  • Collaborate with detection engineers to convert hunt findings into new or improved detections
  • Identify visibility gaps and recommend logging, telemetry, and tooling improvements
  • Validate detection performance through purple team activities and simulation
  • Consume and operationalise internal and external threat intelligence
  • Maintain awareness of attacker tactics, tools, and campaigns relevant to the organization
  • Act as a key interface between SOC, Threat Intel, Red Team, and Vulnerability Management
  • Track and report on hunt coverage, outcomes, dwell time, MTTR, and investigation quality
  • Provide regular insights to senior leadership on threat trends and risk posture

Technologies

  • Cloud
  • Linux
  • Network
  • Security
  • Splunk
  • Windows
  • DevOps

More

We are seeking a SOC Lead - Threat Hunting & Investigations to join our team in Bath with a hybrid working model of 3 days onsite and 2 days remote. In this role, you will be responsible for leading advanced threat detection and complex security investigations across our enterprise. We offer a competitive day rate of £700 outside of IR35 and an opportunity to make a significant impact as you mentor analysts and enhance our SOC capabilities.

last updated 20 week of 2026

Company & context

Evidence is labeled so you can tell internal community data from public sources.

JobiQueue salary sample

Range from 421 indexed roles at this employer: $11,000 - $145,600(mid ~58787)

Context may refresh in the background.

Trust-check this listing

Verify scam risk and ghost-job signals before you apply.

Related roles

Automation & Integration Engineer, Power Platform

Experis
TBDCharing Cross, South East London$60,000 - $90,000
Mar 13, 2026
View details

Platform Engineer - Portsmouth

Experis
TBDCommercial Road, Portsmouth
1d ago
View details

Atlassian Technical Engineer

Experis
TBDFull Remote$110,500 - $119,600
1w ago
View details

Network Design Engineer

Experis
TBDFull Remote$60,000 - $90,000
Jun 15, 2026
View details

Source: DevITJobs • Last updated May 21, 2026