Are you a hands-on security engineering leader ready to shape the technical backbone of a modern SOC?
We’re looking for an experienced SOC Engineering Lead to take ownership of our core security tooling and drive technical excellence across our Microsoft-first security stack. This is a senior individual contributor and team leadership role within a fast-paced MSP/MSSP environment ideal for someone who’s equally comfortable mentoring engineers and getting deep into detection logic.
What You’ll Be Doing
- Providing technical leadership across Microsoft Sentinel, Defender for Endpoint, Defender for Cloud, and Entra ID
- Owning the setup, integration, and ongoing optimisation of our Sentinel environment
- Writing and refining KQL queries, building detection logic, and resolving enrichment issues
- Supporting integration with platforms including Mimecast, Darktrace, and legacy EDR tools
- Collaborating with the SecDevOps Lead on Google Chronicle SOAR
- Managing and mentoring a technical security engineering team
- Driving ITIL-aligned change and incident management processes
- Contributing to Azure security architecture across Azure AD and Lighthouse environments
What We’re Looking For
- Proven experience in an MSP, MSSP, or SOC environment
- Strong hands‑on Microsoft Security Suite experience (Sentinel, Defender XDR, Defender for Cloud)
- Solid Microsoft Azure expertise (Azure AD, Lighthouse, security architecture)
- Comfortable with KQL, detection engineering, and SOAR/SIEM platforms
- Eligible to achieve HMG Security Clearance
- Microsoft Certified: Cybersecurity Architect Expert
- GIAC, GCTI, or equivalent detection/threat hunting certifications
- CompTIA Security+, CISSP, or CySA+
- Google Chronicle SOAR or GCP experience
What’s On Offer
- Based in Manchester (hybrid working available)
- Senior leadership role with real technical ownership
- Opportunity to shape SOC tooling and team capability at scale
Apply now or get in touch for a confidential conversation.
#J-18808-Ljbffr…
