Overview
We are seeking a skilled SOC Monitoring Analyst to enhance the operation and continuous improvement of a critical Security Operations Centre (SOC) supporting a Ministry of Defence programme. The ideal candidate will be responsible for various security functions, working directly with vulnerability management, incident response, and a variety of SOC services within a highly regulated environment. This position requires an active DV clearance and is strictly onsite in Preston.
Responsibilities
- Act as the escalation point for all security incidents.
- Conduct vulnerability management and incident response activities.
- Prepare reports on incidents and SOC performance metrics for leadership.
- Work hands-on with SIEM detection tooling and develop reporting for use-case advancement.
- Contribute to reporting, configuration changes, enhancements, and operational alignment.
- Ensure incident workflows, escalation paths, and operational procedures are robust and auditable.
Requirements
- Experience in SOC operations within government, defence, or critical infrastructure.
- Hands-on experience in vulnerability management and incident response.
- Understanding of SIEM platforms, detection engineering, and vulnerability alert management.
- Familiarity with ITSM tooling, ideally ServiceNow.
- Strong stakeholder management and reporting capabilities.
- Knowledge of regulated environments (MOD, HMG, defence primes, or similar).
- Exposure to large-scale programmes (e.g. GCAP, major defence or aerospace programmes) is a plus.
- Active DV clearance is required.