We are looking for a Security Operations Consultant to join our Digital Trust & Cyber Security practice. Working on behalf of our clients, you will lead Security Operations Centre (SOC) analysts and incident response specialists.
You will combine hands-on operational leadership with advisory work. This means managing live incident containment and day-to-day SOC operations, while helping enterprise and public sector clients modernise their security operations, improve their SIEM, SOAR and EDR capabilities, and build stronger cyber resilience.
Why consider joining our Digital & Data community?
Join our Digital & Data team and work alongside cyber security, product, design and technology specialists in cross-disciplinary teams to solve complex client challenges and bring ideas to life.
Build a flexible and distinctive career in a trust-based, inclusive environment that values excellence, innovation and curiosity. You can progress through a technical career track without needing to follow the Partner career track if that does not align with your ambitions.
Work across a broad range of Security Operations engagements, client environments and technology stacks spanning seven sectors. No two projects are the same.
Join a supportive and collaborative cyber and technology community, with knowledge sharing, peer support, coaching and mentoring from other specialists.
Deepen your expertise through our culture of learning and growth, with access to a development budget for technical and non-technical training and professional certifications.
Benefit from a hybrid working approach, with an expectation of being in the office or on a client site for a minimum of two days per week, depending on the role and assignment.
What you'll do
Lead and develop SOC analysts and incident response specialists, providing clear operational direction, coaching and support across day-to-day security operations.
Take a hands-on leadership role during cyber security incidents, coordinating investigation, containment, eradication, recovery, stakeholder communications and post-incident reviews.
Help enterprise and public sector clients assess and improve their Security Operations capabilities, identifying gaps across people, processes and technology and translating these into practical improvements.
Advise on the evolution and optimisation of SIEM, SOAR, EDR and threat-detection tooling to improve visibility, reduce noise and strengthen detection and response capabilities.
Develop and maintain incident playbooks, standard operating procedures, automated response workflows and proactive tabletop exercises.
Support the development of modern Security Operations services and ways of working, sharing your expertise across our Digital Trust & Cyber Security community through coaching, mentoring and knowledge sharing.
Security technologies you'll work with
We advocate using the right technology for the right task. Depending on the client environment and engagement, you can expect to work across technologies including:
- SIEM and security analytics platforms, such as Microsoft Sentinel and Splunk.
- SOAR and security automation technologies used for enrichment, triage and response orchestration.
- Endpoint Detection and Response (EDR/XDR) platforms, such as Microsoft Defender for Endpoint and CrowdStrike Falcon.
- Threat intelligence, detection engineering, investigation and incident response technologies.
- Cloud security monitoring across Microsoft Azure, AWS and GCP environments.
What you can expect
Work collaboratively across multiple technical teams and stakeholder groups, using your Security Operations expertise to solve complex client problems and contribute to internal initiatives.
Participate in live, in-person working sessions to investigate incidents, assess operational challenges and design practical improvements, alongside asynchronous collaboration through Microsoft Teams.
Work with the team at client sites or in our offices for a minimum of two days per week. The time you spend and where you work will vary by role and assignment, including the possibility of being on a client site for up to five days per week.
Work in an environment that takes its values seriously and places collaboration, inclusion, learning and client impact at the heart of how teams operate.
Essential requirements
Even if you don't meet every requirement below, feel free to still apply as we are often hiring for similar roles which your background might be better suited to.
- SOC Leadership: Experience running or supervising a SOC, CSOC, or Incident Response team.
- Incident Response: Practical experience managing live cyber incidents (such as ransomware, account takeovers, or supply chain breaches).
- Technical Stack: Direct experience working with major SIEM/SOAR tools (e.g., Microsoft Sentinel, Splunk) and EDR/XDR platforms (e.g., Microsoft Defender for Endpoint, CrowdStrike Falcon).
- Security Frameworks: Solid understanding of MITRE ATT&CK, NIST CSF, NCSC Caf v4.0
#J-18808-Ljbffr
Security Operations Consultant employer: Paconsulting
Join our Digital & Data community where innovation meets inclusivity, and your career can flourish in a trust-based environment. With a strong focus on employee growth, we offer extensive learning opportunities, hybrid working arrangements, and the chance to work on diverse projects across various sectors. Experience a supportive culture that values collaboration and excellence, all while contributing to meaningful solutions that tackle complex business challenges.