Haystack
← Back to Jobs
Temporary/Casual
Technology
NI

Lead SOC Analyst - DV Cleared

Network ITSouth East London, London🇬🇧United KingdomPosted 26 Sept 2026

Why This Role Stands Out

This is an exciting opportunity to lead a critical Security Operations Center function, making a significant impact on national security with your expertise. You'll thrive here if you are a DV-cleared, mid-senior analyst eager to mentor a team and drive operational excellence in a dynamic hybrid environment. Apply now to leverage your skills and contribute to a highly reputable organization.

Quick Overview

Salary
£80/hr
Seniority
Mid Senior
Employment type
Temporary/Casual
Work mode
Hybrid
Location
South East London, London, United Kingdom
Posted
17 hours ago

Job Description

YOU MUST HAVE ACTIVE DV CLEARANCE
Lead SOC Analyst
£80 per hour - 42 hour weeks
12 Hour shifts (7am-7pm & 7pm-7am)
7 Days & 7 Nights over a 4-week pattern
6 month contract initially
Buckinghamshire
Summary - The 3x Lead SOC Analysts will be responsible for the operational leadership of the Security Monitoring function, ensuring the consistent delivery of high-quality security monitoring, investigation and escalation activities.
Responsibilities
  • Lead theshift-based delivery of Security Monitoring services, ensuring timely and effectivemonitoring, investigation, triage and escalation of cybersecurity events.
  • Supervise and coordinate a Senior SOCAnalyst, ensuring investigationsmeet required professional, technicaland documentation standards.
  • Act as Duty Lead for Security Monitoring, providing technical leadershipand makingoperational decisions during live cybersecurity events.
  • Review and quality-assureSOC investigations, confirming findings are accurate, evidence-based and clearly documented.
  • Lead complex and high-priority cyber securityinvestigations before escalation to the IncidentResponse team, as delegated by the Principal SOC Analyst.
  • Deliver clear and effectiveshift handovers, maintaining situational awareness and continuity across ongoing investigations and incidents.
  • Coordinate with Incident Responders during cyber security incidents,clearly communicating analytical findings, timelines, indicators of compromise and supporting evidence.
  • Collaborate with SOC Engineers to improve monitoringcoverage, alert quality and operational effectiveness.
  • Support the onboarding of new systems, applicationsand cloud services into SOC monitoringby validating monitoring content and operational readiness.
  • Drive continuous improvement across monitoring processes, investigation techniques and analyst efficiency, recommending enhancements to the Principal SOC Analyst.
  • Mentor and coach SOC Analysts, supporting their professional developmentand promoting consistent analytical standards andinvestigation best practice.
  • Ensure compliance with SOCoperating procedures, security monitoringstandards and information-handling requirements.
  • Identify and escalate operational issues, monitoring gaps and emerging threats to the Principal SOC Analyst and SOC Manager.
Required Skills / Experience
  • Demonstrable experience working within a SOC or comparable cyber security operations environment.
  • Experience leading security monitoring activities and supervising analysts during live operational service.
  • Strong knowledge of SIEM platforms, log analysis, security monitoring technologies and security event investigation.
  • Experience investigating complex cyber security events and determining appropriate escalation paths.
  • Good understanding of cyber-attack techniques, indicators of compromise, threat intelligence and defensive monitoring.
  • Experience in mentoring or coaching technical staff within an operational environment.
  • Excellent analytical, investigative and problem-solving skills.
  • Strong written and verbal communication skills, including the ability to communicate clearly under operational pressure.
  • Ability to make timely decisions within a fast-paced 24/7 operational environment.
  • Profession certifications such as Microsoft SC-200, GIAC GCIH, GCIA, CompTIA CySA+ or equivalent.
Desirable:
  • Experience using Microsoft Sentinel, LogRhythm, or equivalent enterprise SIEM platforms.
  • Experience developing monitoring improvements, detection tuning, or operational process development.
  • Experience supporting Incident Responder activities during major cyber security incidents.
  • Experience contributing to the development of monitoring use cases and detection improvements.
  • Applied knowledge of MITRE ATT&CK or equivalent adversary behaviour frameworks.

Similar jobs