Senior SOC Analyst / Senior Security Analyst / Detection Engineer / Threat Hunter / Incident Responder (SOC)

Senior SOC Analyst / Senior Security Analyst / Detection Engineer / Threat Hunter / Incident Responder (SOC)

Full-Time 50000 - 65000 Β£ / year (est.) No working from home possible
Made Tech

At a Glance

  • Tasks: Lead threat hunts, incident response, and improve detection content in a hands-on role.
  • Company: Join Made Tech, a forward-thinking company enhancing public sector digital services.
  • Benefits: Enjoy 30 days holiday, flexible working hours, remote options, and paid counselling.
  • Other info: Be part of a diverse team that values inclusion and personal growth.
  • Why this job: Make a real impact on public security while growing your technical skills.
  • Qualifications: Must hold a foundational security credential; experience with SIEM platforms is a plus.

The predicted salary is between 50000 - 65000 Β£ per year.

hackajob is collaborating with Made Tech to connect them with exceptional professionals for this role. Made Tech helps UK public sector organisations build and run secure, user-centred digital services. Our Cyber practice works directly with government departments, agencies, and other public bodies β€” embedding alongside client teams to raise their security capability, not just deliver a report and leave.

As a Senior Security Analyst, you'll be a core part of that practice, operating in a security operations context where the stakes are real: the systems we protect carry sensitive public data and underpin services that people depend on. This is a hands-on technical role with genuine scope and influence. You'll lead threat hunts and intrusion investigations, author and tune detection content, and help your team respond to incidents in a way that leaves things better than you found them. You'll translate threat intelligence into actionable detections, align your work to frameworks like the NCSC Cyber Assessment Framework and GovAssure, and communicate clearly with client security stakeholders who need to understand what's happening and why it matters.

Key responsibilities:

  • Lead threat hunts and intrusion investigations β€” form and test hypotheses, map adversary activity against MITRE ATT&CK, perform forensic artefact analysis, and establish scope and root cause clearly enough that the team and client can act on your findings.
  • Author, tune, and peer-review detection content - treat detections as code (version-controlled, reviewed), translate threat intelligence into new rules, and contribute to iterative improvement of the SIEM ruleset; onboard new log sources, including cloud and application feeds, to close coverage gaps.
  • Own sub-cycles of the intelligence lifecycle - run structured collection against defined requirements, track actor TTPs, manage indicator lifecycles, and produce situational-awareness products that inform both detection priorities and client risk decisions.
  • Lead incident response and drive improvement - co-ordinate containment across engineering and analyst teams, communicate incident detail clearly to client stakeholders, and turn every incident into improved detection content, hardening, or runbook coverage; design for resilience by anticipating failure modes and ensuring systems degrade gracefully.
  • Build SOAR playbooks and auto-triage - identify toil and repetition in analyst workflows, and build automation that saves the team time and improves consistency without removing human judgement where it matters.
  • Align security operations to UK public sector standards - ensure investigations, evidence handling, and detection coverage reflect NCSC CAF Objective C, GovAssure requirements, and lawful-monitoring obligations; feed gaps back into risk governance.
  • Mentor junior analysts and raise team standards - pair deliberately on complex investigations, review triage work, share adversary tradecraft with the team, and help create an environment where people feel safe raising concerns and learning from mistakes.
  • Contribute to the practice beyond your immediate engagement - improve shared SOC standards and onboarding documentation, turn good solutions into reusable playbooks and accelerators the next team can pick up, contribute detection content to practice-level repositories, and engage with cross-government security communities such as NCSC CISP and relevant ISACs.

Skills, knowledge and expertise:

  • Essential: Hold one of the following - Systems Security Certified Practitioner (SSCP), CompTIA Security, or an equivalent foundational operational security credential expected of Senior SOC analysts.
  • Desirable: Certifications that would strengthen your application: Certified Cloud Security Professional (CCSP), CompTIA Advanced Security Practitioner (CASP), HTB Certified Defensive Security Analyst (HTB CDSA).
  • Capabilities that set strong applications apart: Experience applying structured analytical techniques - ACH, key-assumptions checks, or similar, to produce rigorous, bias-resistant intelligence assessments, and comfort peer-reviewing others' analytic tradecraft.
  • Working knowledge of cloud security event investigation and cloud detection tuning, particularly across AWS, Azure, or GCP environments, including understanding of infrastructure-level telemetry.
  • Experience framing security findings in risk terms for non-technical stakeholders β€” communicating likelihood, impact, and recommended treatment clearly, and reflecting asset criticality and threat context in prioritisation decisions.
  • Evidence of building or improving SOAR playbooks, automated triage workflows, or equivalent automation that reduced analyst toil in a SOC or detection-engineering context.
  • Familiarity with UK government security frameworks β€” in particular the NCSC CAF, GovAssure, and HMG Security Policy Framework β€” and experience aligning detection or response work to those standards in a government or regulated environment.
  • Experience working within an agile or Kanban-based team model, contributing to workflow improvement, running or participating in retrospectives, and helping the team improve its own practices β€” not just delivering within them.
  • Experience acting as a trusted working-level contact for client security stakeholders β€” anchoring on their actual outcomes, raising concerns or opportunities proactively, and contributing subject-matter expertise to proposals or bids.

Tools and practice familiarity:

  • Hands-on experience with at least one major SIEM platform (for example, Splunk, Microsoft Sentinel, or Elastic Security) including writing and tuning detection rules.
  • Familiarity with threat intelligence platforms, OSINT tooling, or indicator lifecycle management in an operational context.

Job benefits:

  • 30 days Holiday - we offer 30 days of paid annual leave.
  • Flexible Working Hours - we are flexible with what hours you work.
  • Flexible Parental Leave - we offer flexible parental leave options.
  • Remote Working - we offer part-time remote working for all our staff.
  • Paid counselling - we offer paid counselling as well as financial and legal advice.

Senior SOC Analyst / Senior Security Analyst / Detection Engineer / Threat Hunter / Incident Responder (SOC) employer: Made Tech

Made Tech is an exceptional employer, dedicated to fostering a collaborative and inclusive work culture that empowers employees to make a real impact in the public sector. With a strong focus on professional development, you will have the opportunity to mentor junior analysts and enhance your technical skills while working on meaningful projects that protect sensitive public data. Our generous benefits package, including 30 days of holiday and flexible working arrangements, ensures a healthy work-life balance, making Made Tech a truly rewarding place to grow your career.

Made Tech

Contact Details:

Made Tech Recruitment Team

We think you need these skills to ace Senior SOC Analyst / Senior Security Analyst / Detection Engineer / Threat Hunter / Incident Responder (SOC)

Threat Hunting
Intrusion Investigation
Detection Content Authoring
Forensic Artefact Analysis
Incident Response
Cloud Security
SOAR Playbook Development