Why This Role Stands Out
Advance your career as a Senior SOC Engineer in Glasgow with a leading organization, leveraging your IBM QRadar expertise to build cutting-edge detection and response strategies. This on-site role offers a competitive salary of £60,000 GBP and the opportunity to significantly impact the company's security posture by developing advanced playbooks and automation. If you are a skilled engineer passionate about threat modeling and continuous improvement, this is an excellent opportunity to grow your career.
Quick Overview
Salary
£60k/yr
Seniority
Mid Senior
Employment type
Full Time
Work mode
On Site
Location
Glasgow, United Kingdom
Posted
4 days ago
Microsoft Office
Job Description
£60,000 GBP
Onsite WORKING
Location: Glasgow, Scotland - United Kingdom Type: Permanent
Senior SOC Engineer
A leading organisation is seeking a Senior SOC Engineer to strengthen its security operations capability and drive continuous improvement across detection, response, and automation. This pivotal role requires deep expertise in IBM QRadar, with a strong focus on playbook development, analytical rule creation, and threat modelling. The Senior SOC Engineer will play a key role in building and optimising detection and response strategies, ensuring robust protection against evolving threats.
Key Responsibilities
SIEM Engineering & Management
Onsite WORKING
Location: Glasgow, Scotland - United Kingdom Type: Permanent
Senior SOC Engineer
A leading organisation is seeking a Senior SOC Engineer to strengthen its security operations capability and drive continuous improvement across detection, response, and automation. This pivotal role requires deep expertise in IBM QRadar, with a strong focus on playbook development, analytical rule creation, and threat modelling. The Senior SOC Engineer will play a key role in building and optimising detection and response strategies, ensuring robust protection against evolving threats.
Key Responsibilities
SIEM Engineering & Management
- Deploy, configure, and maintain the QRadar SIEM platform.
- Onboard and normalise log sources across on-premises and cloud environments.
- Develop and optimise analytical rules for threat detection, anomaly detection, and behavioural analysis.
- Design and implement incident response playbooks for scenarios such as phishing, lateral movement, and data exfiltration.
- Integrate playbooks with SOAR platforms (e.g., Microsoft Logic Apps, XSOAR) to streamline triage and automate response.
- Refine playbooks based on threat intelligence and incident insights.
- Monitor and analyse security alerts and events to identify potential threats.
- Conduct investigations and coordinate incident response activities.
- Collaborate with threat intelligence teams to enhance detection logic.
- Lead threat modelling exercises using frameworks such as MITRE ATT&CK, STRIDE, and Cyber Kill Chain.
- Translate threat models into actionable detection use cases and SIEM rules.
- Prioritise detection engineering based on business risk and impact.
- Produce reports and dashboards to communicate security posture and incident trends.
- Partner with IT, DevOps, and compliance teams to enforce secure configurations.
- Provide mentorship to junior analysts and engineers.
- Maintain documentation of security procedures, incident response plans, runbooks, and playbooks.
- Contribute to monthly reporting packs in line with contractual obligations.
- Support pre-sales teams with technical requirements for new opportunities.
- Demonstrate SOC tools and capabilities to clients.
- Participate in continual service improvement initiatives, recommending changes to address recurring incidents.
- Eligible for, or already holding, SC Clearance.
- Proven expertise in IBM QRadar and SIEM engineering.
- Strong knowledge of log formats, parsing, and normalisation.
- Proficiency in SIEM query languages such as KQL, SPL, AQL.
- Scripting experience with Python or PowerShell for automation.
- Deep understanding of threat detection, incident response, and the cyber kill chain.
- Familiarity with frameworks including MITRE ATT&CK, NIST, and CIS.
- Strong communication, analytical, and presentation skills.
- Solid understanding of network traffic flows, vulnerability management, and penetration testing principles.
- Knowledge of ITIL processes (Incident, Problem, Change Management).
- Ability to work independently and thrive in a 24/7 on-call environment.
- 3-5 years' experience in the IT security industry, ideally in a SOC/NOC environment.
- Cybersecurity certifications preferred (e.g., ISC2 CISSP, GIAC, SC-200, IBM QRadar Certified Specialist, Splunk Certified Admin/Power User, Google Chronicle Security Engineer).
- Hands-on experience with ServiceNow Security Suite.
- Familiarity with cloud platforms (AWS and/or Microsoft Azure).
- Proficiency in Microsoft Office products, particularly Excel and Word.
Similar jobs
- MH
Cyber Security Engineer
NewMorgan Hunt Recruitment
London🇬🇧£65k/yrHybrid6 minutes agoPenetration TestingStakeholder ManagementTechnology - OU
V05727 DIG - Level 1 SOC Cyber Analyst
NewOutsource UK
Ross-on-wye, Herefordshire🇬🇧On-site6 minutes agoSplunkTechnology - LO
Cyber Data Engineer
NewLorien
Reading, Berkshire🇬🇧On-site6 minutes agoETLDatabricksPower BITechnology - PE
Security Engineer
NewPositive Employment
London🇬🇧Hybrid6 minutes agoMFASAMLTCP/IP+7Technology - SE
Cyber Security Analyst - Microsoft Security / IAM - Contract
NewSearchability
Bristol, Somerset🇬🇧Remote7 minutes agoMFAAzureIoTTechnology - S8
Security Infrastructure Engineer
NewStandard 8
Guildford, Surrey🇬🇧Hybrid7 minutes agoDockerGCPAWS+10Technology