Why This Role Stands Out
Advance your career as a Senior SOC Engineer with a leading organization in Glasgow, where you'll leverage your QRadar expertise to build and optimize cutting-edge security detection and response strategies. This impactful role offers significant growth potential as you develop advanced playbooks and threat models, making it an ideal opportunity for experienced security professionals seeking to elevate their skills and contribute to robust cyber defenses.
Quick Overview
Salary
£60k/yr
Seniority
Mid Senior
Employment type
Full Time
Work mode
On Site
Location
Glasgow, Scotland, United Kingdom
Posted
2 days ago
Microsoft Office
Job Description
Senior SOC Engineer
£60,000 GBP
Onsite WORKING
Location: Glasgow, Scotland - United Kingdom Type: Permanent
Senior SOC Engineer
A leading organisation is seeking a Senior SOC Engineer to strengthen its security operations capability and drive continuous improvement across detection, response, and automation. This pivotal role requires deep expertise in IBM QRadar, with a strong focus on playbook development, analytical rule creation, and threat modelling. The Senior SOC Engineer will play a key role in building and optimising detection and response strategies, ensuring robust protection against evolving threats.
Key Responsibilities
SIEM Engineering & Management
#ryhu
£60,000 GBP
Onsite WORKING
Location: Glasgow, Scotland - United Kingdom Type: Permanent
Senior SOC Engineer
A leading organisation is seeking a Senior SOC Engineer to strengthen its security operations capability and drive continuous improvement across detection, response, and automation. This pivotal role requires deep expertise in IBM QRadar, with a strong focus on playbook development, analytical rule creation, and threat modelling. The Senior SOC Engineer will play a key role in building and optimising detection and response strategies, ensuring robust protection against evolving threats.
Key Responsibilities
SIEM Engineering & Management
- Deploy, configure, and maintain the QRadar SIEM platform.
- Onboard and normalise log sources across on-premises and cloud environments.
- Develop and optimise analytical rules for threat detection, anomaly detection, and behavioural analysis.
- Design and implement incident response playbooks for scenarios such as phishing, lateral movement, and data exfiltration.
- Integrate playbooks with SOAR platforms (e.g., Microsoft Logic Apps, XSOAR) to streamline triage and automate response.
- Refine playbooks based on threat intelligence and incident insights.
- Monitor and analyse security alerts and events to identify potential threats.
- Conduct investigations and coordinate incident response activities.
- Collaborate with threat intelligence teams to enhance detection logic.
- Lead threat modelling exercises using frameworks such as MITRE ATT&CK, STRIDE, and Cyber Kill Chain.
- Translate threat models into actionable detection use cases and SIEM rules.
- Prioritise detection engineering based on business risk and impact.
- Produce reports and dashboards to communicate security posture and incident trends.
- Partner with IT, DevOps, and compliance teams to enforce secure configurations.
- Provide mentorship to junior analysts and engineers.
- Maintain documentation of security procedures, incident response plans, runbooks, and playbooks.
- Contribute to monthly reporting packs in line with contractual obligations.
- Support pre-sales teams with technical requirements for new opportunities.
- Demonstrate SOC tools and capabilities to clients.
- Participate in continual service improvement initiatives, recommending changes to address recurring incidents.
- Eligible for, or already holding, SC Clearance.
- Proven expertise in IBM QRadar and SIEM engineering.
- Strong knowledge of log formats, parsing, and normalisation.
- Proficiency in SIEM query languages such as KQL, SPL, AQL.
- Scripting experience with Python or PowerShell for automation.
- Deep understanding of threat detection, incident response, and the cyber kill chain.
- Familiarity with frameworks including MITRE ATT&CK, NIST, and CIS.
- Strong communication, analytical, and presentation skills.
- Solid understanding of network traffic flows, vulnerability management, and penetration testing principles.
- Knowledge of ITIL processes (Incident, Problem, Change Management).
- Ability to work independently and thrive in a 24/7 on-call environment.
- 3-5 years' experience in the IT security industry, ideally in a SOC/NOC environment.
- Cybersecurity certifications preferred (e.g., ISC2 CISSP, GIAC, SC-200, IBM QRadar Certified Specialist, Splunk Certified Admin/Power User, Google Chronicle Security Engineer).
- Hands-on experience with ServiceNow Security Suite.
- Familiarity with cloud platforms (AWS and/or Microsoft Azure).
- Proficiency in Microsoft Office products, particularly Excel and Word.
#ryhu
Similar jobs
- NT
Trainee Cyber Security No Experience Required
NEWTO TRAINING LIMITED
Sheffield, South Yorkshire🇬🇧£30k - £65k/yrHybrid2 weeks agoAzureTechnology - HA
Sailpoint Engineer
Hays
Manchester Science Park, Manchester🇬🇧On-site4 days agoEngineering - GS
Security Project Engineer
Get Staff
Romford, Essex🇬🇧£40k - £45k/yrHybrid6 days agoAdministrative - HA
Senior Information Security Officer
NewHackajob Ltd
Bournemouth, Dorset🇬🇧HybridYesterdayAgileAdministrative - SH
Cyber Security Specialist
NewSharpAtoms
United Kingdom🇬🇧Remote6 hours agoAWSAzureHIPAATechnology - IR
Hardware Security Engineer
NewIC Resources
cambridge🇬🇧Hybrid6 hours agoTechnology