At a Glance
- Tasks: Lead advanced threat detection and incident response for diverse customer environments.
- Company: Join MTI, a leading cybersecurity firm with over 35 years of experience.
- Benefits: Enjoy competitive salary, professional development, and access to global resources.
- Other info: Dynamic team environment with opportunities for continuous learning and career growth.
- Why this job: Make a real impact in cybersecurity while mentoring the next generation of analysts.
- Qualifications: 5+ years in MSSP/MSP, proficiency in SIEM and EDR tools, strong communication skills.
The predicted salary is between 63000 - 77000 £ per year.
MTI provides award-winning, end-to-end technology solutions and services in cyber security and data centre for over 35 years.
MTI has 250+ staff, with offices across the UK, France and Germany.
MTI was acquired by Ricoh in 2020 as part of their transformation into a global digital services company.
As part of the Ricoh family, MTI benefits from access to a much broader set of specialist IT services and significant technical resources available on a global scale.
More information can be found at mti. com
The Role
As a
Senior SOC Engineer within our Managed Security Services team, you will play a critical role in delivering security operations across a portfolio of customer environments.
You will be responsible for leading advanced threat detection, incident response, onboarding of new customers, and managing the transition of services into business‑as‑usual (BAU) support.
This role requires hands‑on experience with SIEM, EDR, automation tooling, and a deep understanding of delivering cybersecurity services in an MSP setting.
- Key Areas of Responsibility
- Customer Onboarding and Transition to BAU
- Lead technical onboarding for new customers joining the managed service, ensuring a smooth transition into operational support.
- Work with customers and internal stakeholders to define onboarding scope, required access, and configuration timelines.
- Set up secure remote access (e. g., Azure Lighthouse, delegated access) and ensure correct identity and access permissions are in place.
- Ingest new log and telemetry sources into the SIEM platform (Microsoft Sentinel, Splunk, etc.) and validate data visibility and parsing.
- Perform configuration and health validation checks across SIEM and EDR environments post‑onboarding.
- Create and maintain onboarding documentation, playbooks, and configuration baselines for repeatable service delivery.
- Threat Monitoring and Detection
- Monitor security alerts and events from SIEM platforms, EDR solutions, and other security tools.
- Analyse logs, network traffic, and endpoint data to identify potential security incidents.
- Tune and optimize detection rules to reduce false positives and improve threat detection accuracy.
- Incident Investigation and Response
- Conduct in‑depth investigations of security incidents to determine root cause, scope, and impact.
- Perform analysis on compromised systems, malware, and other indicators of compromise (IOCs).
- Coordinate with client IT teams and stakeholders to contain and remediate incidents.
- Document incidents, including timelines, actions taken, and lessons learned.
- Threat Intelligence and Hunting
- Leverage threat intelligence feeds and platforms to stay informed about emerging threats and attack techniques.
- Proactively hunt for threats and anomalies within client environments using advanced tools and techniques.
- Develop and share actionable threat intelligence with clients and internal teams.
- Reporting and Communication
- Generate detailed reports and provide regular updates to clients and internal stakeholders.
- Present findings and recommendations to technical and non‑technical audiences.
- Maintain accurate documentation of incidents, investigations, and response activities.
- Mentorship and Collaboration
- Mentor and guide junior SOC analysts, providing training and knowledge sharing.
- Collaborate with other team members to enhance overall security posture.
- Participate in SOC process improvement initiatives and contribute to the development of playbooks and runbooks.
- Tool Management and Optimization
- Manage and maintain SOC tools, including SIEM, EDR, and threat intelligence platforms.
- Develop and implement automation scripts and workflows to improve SOC efficiency.
- Stay current with the latest security technologies and recommend enhancements to the SOC toolset.
Skills & Qualifications
- Proficiency with SIEM tools (e. g., Microsoft Sentinel, Level Blue USM), EDR platforms (e. g., Defender for Endpoint, Trend Micro Vision One), and log management.
- Experience with KQL, Power Shell, or similar languages to automate detection and operational tasks.
- Strong understanding of network protocols, log analysis, and threat actor behaviour.
- Solid understanding of security frameworks such as NIST, CIS, ISO 27001, and MITRE ATT&CK.
- Strong communication and presentation skills.
- Ability to manage multiple stakeholders and priorities.
- Leadership and mentoring capabilities.
- Attention to detail and commitment to continuous improvement.
Experience
- 5+ years proven experience working in a Managed Security Service Provider (MSSP/MSP) environment.
- Strong understanding of customer onboarding lifecycle, access provisioning (e. g., Azure Lighthouse), and managed detection and response delivery.
- Client‑facing experience in a security advisory capacity.
- #J-18808-Ljbffr
Senior SOC Engineer employer: MTI
MTI Technology is an exceptional employer, offering a dynamic work environment that fosters innovation and collaboration in the cybersecurity sector. With access to Ricoh's extensive resources and a commitment to employee growth, MTI provides ample opportunities for professional development and training, ensuring that team members are equipped to excel in their roles. Located across the UK, employees benefit from a supportive culture that values teamwork and customer engagement, making it a rewarding place to build a meaningful career.
StudySmarter Expert Advice🤫
We think this is how you could land Senior SOC Engineer
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including MTI, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through MTI
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at MTI. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Senior SOC Engineer
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at MTI insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to MTI that you’re committed to staying ahead in the game.
How to prepare for a job interview at MTI
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at MTI to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at MTI.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.