SOC Engineering Lead in London

SOC Engineering Lead in London

London Full-Time 48000 - 84000 £ / year (est.) No home office possible
Go Premium
C

At a Glance

  • Tasks: Lead the development and implementation of security operations for a major UK organisation.
  • Company: Join BAE Systems, a leader in cyber defence with a collaborative culture.
  • Benefits: Enjoy hybrid working, competitive salary, and a £5,000 referral bonus.
  • Why this job: Make a real impact in protecting critical national infrastructure with cutting-edge technology.
  • Qualifications: Proven experience in SOC engineering and strong knowledge of Azure security.
  • Other info: Diverse and inclusive workplace with excellent career growth opportunities.

The predicted salary is between 48000 - 84000 £ per year.

BAE Systems Digital Intelligence is home to 4,500 digital, cyber and intelligence experts. We work collaboratively across 10 countries to collect, connect and understand complex data, so that governments, nation states, armed forces and commercial businesses can unlock digital advantage in the most demanding environments.

We offer a range of hybrid and flexible working arrangements — please speak to your recruiter about the options for this particular role.

BAE Systems are bidding to undertake the day-to-day operation of (and incremental improvement of) a dedicated Security Operations Centre (SOC) to support the defence of a major UK CNI organisation. The networks protected are predominantly hosted in Azure cloud platforms, with many systems within these environments that must be protected. The customer is committed to development of this improved SOC to be a benchmark of best practice and excellence in reflection of the significant threat that the protected systems are subject to.

The SOC will be staffed by a blend of customer and BAE Systems staff, based in multiple locations, but with the day-to-day operations both remotely and in the customer's premises. These roles require a minimum of SC clearance. Due to timelines for the start of operations, it will not be possible to sponsor new clearances so candidates must have existing clearances.

The SOC Engineering lead is responsible for planning and managing development, testing and implementation activities for both day-to-day activities — delivering new/updated rules and analytics for the Azure SIEM and SOAR platforms, and production of playbooks leading the Analytics and Rules (A&R) Teams prioritising and coordinating their activities across the various projects/releases — as well as long-term improvement upgrades and activities.

The day-to-day focus of the Engineering team which you will manage is working with the Protective Monitoring, Threat Intelligence and wider SOC operations Teams to scope and define the requirements for tuning existing security use cases and creating new detection content. This includes planning each release and overseeing all design, development, testing and implementation activities.

The strategic focus of the Engineering Lead is to ensure that the detection and monitoring technology remains optimised, current and tailored to the changing threat landscape, authority risk position and technology in use.

The SOC Engineering Lead is an IT and cyber technical specialist with deep knowledge of the Cyber Monitoring technologies and cyber threat tools, tactics, techniques and procedures and demonstrable experience of prior SOC Engineering roles of a similar nature, with clear understanding of how engineering impacts the people and process aspects of a SOC.

Responsibilities
  • You will help grow and evolve the customer SOC capability by documenting the platforms, feeding back lessons learned and working with the wider team in establishing best practices and repeatable engineering processes.
  • You will feed back requirements that you have captured during the project continually to appropriate customer and BAE Systems management teams to help to steer the SOC roadmap.
  • You will work with technical project managers, engineers, solution architects, as well as the end-customer senior stakeholders. Given the CNI client focus of this role, flexibility in our designs and delivery methodologies is essential to ensure timely and potentially safety compliant delivery to the customer's satisfaction.
  • Oversee deployment/implementation activities ensuring that entry criteria are met, all planned activities are completed and that rollback plans are initiated where required.
  • Develop, test and deploy updated and new content across the monitored estate in liaison with the Operations teams.
  • Take playbooks from the wider SOC teams, develop technical aspects, seek approval, and deploy - sometimes directly and sometimes as a mentor to the team.
  • Accountable for the maintenance of existing detection content to ensure it remains current and relevant to the monitored estate.
  • Assess the effectiveness of new/updated rules and analytics to feed into future development activities.
  • Review and approve all required documentation as part of a release or change including design, deployment, configuration and administration guides.
  • Oversee and remain responsible for the maintenance of underlying Azure and off-Azure infrastructure related to the SOC.
  • Obtain authorisation for implementing releases and changes through the Change Management process for ICT and SOC component changes.
RequirementsTechnical
  • Strong knowledge of how Azure security functions work as security controls as well as detection tools to protect large cloud estates; Produce content and playbooks on Sentinel to detect security breaches and recognise the importance of threat led Use Cases.
  • Knowledge of SIEM/SOAR tools (Sentinel at a minimum) and other appropriate tooling e.g. SOAR, Threat Intelligence, traffic analysis tools etc. to identify signs of an intrusion, and advise where new/improved tooling could enhance the SOC operation.
  • Deep knowledge and experience of operational ICT service delivery management.
  • Working with a range of security tooling/technology.
  • Strong understanding of security architecture, in particular networking.
  • Detailed understanding of threat intelligence and threat actors, TTPs and operationalising threat intelligence.
  • Understand TCP/IP component layers to identify normal and abnormal traffic.
  • Experience of undertaking SOC Analyst activities would be beneficial.
  • Experience developing wider SIEM/SOAR content highly desirable.
Non-technical
  • Client side consulting, including stakeholder engagement and the ability to communicate insights and concepts to others (including briefing skills and report writing).
  • Team Leadership.
  • Coaching mindset - help and mentor team.
  • Security process development.
  • Able to understand and adapt to different cultures and hierarchical structures.
  • Self-starter and capable of independent working.
  • Team player and adept at working in multi-disciplinary and diverse teams.

This is a place where you'll be able to make a real difference. You'll be part of an inclusive culture that values diversity, rewards integrity, and merit, and where you'll be empowered to fulfil your potential. We welcome candidates from all backgrounds and particularly from sections of the community who are currently underrepresented within our industry, including women, ethnic minorities, people with disabilities and LGBTQ+ individuals.

We also want to make sure that our recruitment processes are as inclusive as possible. If you have a disability or health condition (for example dyslexia, autism, an anxiety disorder etc.) that may affect your performance in certain assessment types, please speak to your recruiter about potential reasonable adjustments.

Life at BAE Systems Digital Intelligence embraces Hybrid Working. This means you and your colleagues may be working in different locations, such as from home, another BAE Systems office or client site, some or all of the time, and work might be going on at different times of the day. By embracing technology, we can interact, collaborate and create together, even when we're working remotely from one another. Hybrid Working allows for increased flexibility in when and where we work, helping us to balance our work and personal life more effectively, and enhance well-being.

Diversity and inclusion are integral to the success of BAE Systems Digital Intelligence. We are proud to have an organisational culture where employees with varying perspectives, skills, life experiences and backgrounds - the best and brightest minds - can work together to achieve excellence and realise individual and organisational potential.

SOC Engineering Lead in London employer: Cyber Security training courses

BAE Systems Digital Intelligence is an exceptional employer, offering a dynamic work environment in London and Leeds that embraces hybrid working arrangements for enhanced flexibility. With a strong commitment to diversity and inclusion, employees are empowered to grow their careers while contributing to critical national security projects, ensuring that every team member's unique perspective is valued and utilised.
C

Contact Detail:

Cyber Security training courses Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land SOC Engineering Lead in London

✨Tip Number 1

Network, network, network! Get out there and connect with people in the industry. Attend meetups, webinars, or even just chat with folks on LinkedIn. You never know who might have a lead on your dream job!

✨Tip Number 2

Prepare for interviews like it's a mission! Research the company, understand their values, and be ready to discuss how your skills align with their needs. Practise common interview questions and have your own questions ready to show you're genuinely interested.

✨Tip Number 3

Showcase your skills through projects or contributions to open-source. This is a great way to demonstrate your expertise in SOC engineering and cloud security. Plus, it gives you something tangible to discuss during interviews!

✨Tip Number 4

Don't forget to apply through our website! We want to see your application and help you land that SOC Engineering Lead role. Keep an eye on our careers page for the latest opportunities and make sure your profile stands out!

We think you need these skills to ace SOC Engineering Lead in London

Azure Security
SIEM/SOAR Tools (Sentinel)
Threat Intelligence
Traffic Analysis
Security Architecture
TCP/IP Networking
Operational ICT Service Delivery Management
Stakeholder Engagement
Team Leadership
Coaching and Mentoring
Security Process Development
Adaptability to Different Cultures
Independent Working
Collaboration in Multi-Disciplinary Teams

Some tips for your application 🫡

Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience with Azure security and SOC operations. We want to see how your skills align with the role of SOC Engineering Lead, so don’t hold back on showcasing your relevant achievements!

Showcase Your Technical Skills: Since this role is all about technical expertise, be sure to detail your knowledge of SIEM/SOAR tools and any experience you have with threat intelligence. We’re looking for someone who can hit the ground running, so let us know what you bring to the table!

Be Clear and Concise: When writing your application, keep it straightforward and to the point. Use bullet points where possible to make it easy for us to read through your qualifications and experiences. We appreciate clarity just as much as you do!

Apply Through Our Website: We encourage you to submit your application directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, you’ll find all the details you need about the role and our company culture there!

How to prepare for a job interview at Cyber Security training courses

✨Know Your Tech Inside Out

Make sure you brush up on your knowledge of Azure security functions, SIEM/SOAR tools, and threat intelligence. Be ready to discuss how these technologies work together to protect cloud environments, as this will show your technical expertise and understanding of the role.

✨Showcase Your Leadership Skills

As a SOC Engineering Lead, you'll need to demonstrate your ability to lead and mentor a team. Prepare examples of how you've successfully managed projects or guided teams in the past, focusing on your coaching mindset and collaborative approach.

✨Understand the Client's Needs

Research BAE Systems and their clients, especially regarding critical national infrastructure (CNI). Be prepared to discuss how you can tailor SOC operations to meet specific client requirements and enhance their security posture.

✨Prepare for Scenario-Based Questions

Expect questions that assess your problem-solving skills in real-world scenarios. Think about potential security incidents and how you would handle them, including your approach to developing detection content and playbooks. This will highlight your practical experience and strategic thinking.

SOC Engineering Lead in London
Cyber Security training courses
Location: London
Go Premium

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

C
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>