Role: Lead SOC Analyst
Location: London
Salary: Competitive salary and package dependent on experience
Career Level: Specialist
Please Note:
Any offer of employment is subject to satisfactory BPSS and the candidate being granted a level of security clearance which typically requires 10 years continuous UK address history, usually including no periods of 30 consecutive days or more spent outside of the UK, and a declaration of being a British passport holder with no dual nationalism at the point of application.
Note: The above information relates to a specific client requirement
Role Description
The Lead SOC Analyst (L3) provides advanced investigation and analysis, acting as the escalation point for complex or high-severity incidents. They conduct root-cause analysis, guide L1 analysts, and support incident containment and remediation efforts.
Our work will be sensitive, secure, 24×7 and on the most up-to-date high-density compute stacks available. Shift teams will be set up and operate 24×7, and successful candidates working on shift will be paid a shift premium for the non-standard unsociable shift hours that will be part of that rota.
- Investigate escalated incidents to determine attack vectors, scope, and potential impact.
- Correlate events across multiple data sources to build a comprehensive incident narrative.
- Execute containment, eradication, and recovery activities in coordination with IT/OT stakeholders.
- Lead response for medium to high-severity incidents and document detailed investigation reports.
- Conduct tuning of detection rules and thresholds in collaboration with the Security Content Engineer.
- Support continuous improvement by identifying gaps in detection coverage and playbooks.
- Mentor and provide technical guidance to L1 Analysts.
- Participate in periodic SOC exercises and simulated incident response drills.
- Be part of 24/7 SOC team, need to work in shifts.
Role Requirements
- Education: Bachelor’s degree in Cybersecurity, Computer Science, or related field.
- Experience: 3 – 5 years in SOC, Incident Response, or Threat Analysis roles.
- Certifications (preferred): GCIA, GCIH, CompTIA CySA+, Microsoft SC-200, or Splunk Certified Power User.
The following skills and experience are essential for this role
- Strong analytical mindset, in-depth knowledge of SIEM/EDR tools, malware behaviour, and incident handling methodologies.
Closing Date for Applications
01/06/2026
Accenture reserves the right to close the role prior to this date should a suitable applicant be found.
#J-18808-Ljbffr…
