Senior Security Engineer (SOC)
Core
Architecting, building, and evolving the Security Operations Center (SOC) monitoring capability, leading complex incident response, and mentoring analysts.
Role type
Senior Security Engineer (SOC Lead)
Builds
SOC operating model, detection strategy, runbooks, and automated monitoring processes.
Domain
Cybersecurity, SOC operations, Cloud Security (AWS)
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
SOC architecture, detection engineering, incident response leadership, AWS security, stakeholder management, Infrastructure as Code (IaC), automation tooling, threat modelling, forensic data collection
Preferred skills
People management, formal mentoring, advanced IaC (Terraform, Python), forensic evidence handling, NCSC Certified Cyber Professional (CCP) credentials, multiple senior certifications (GCFA, GCFR, GREM, GCTI)
Technologies
SIEM, AWS, Terraform, Python
Responsibilities
Design and build the SOC's operating model, detection strategy, and runbooks; Own the monitoring roadmap and contribute to security strategy; Lead complex investigations and act as senior technical authority during incidents; Coordinate containment, eradication, and recovery activities; Recommend and implement SIEM, detection engineering, and automation tooling; Mentor and develop SOC Analysts; Represent the SOC function to client/senior stakeholders; Support hiring as the team expands.
Seniority
Senior, hands-on IC with leadership responsibilities