×
Register Here to Apply for Jobs or Post Jobs. X

Senior SOC Analyst - Incident Response

Job in London, Greater London, W1B, England, UK
Listing for: GHD
Full Time position
Listed on 2026-09-04
Job specializations:
  • IT/Tech
    Security Management & Operations, Cybersecurity
Job Description & How to Apply Below
Help protect the systems, information and digital services that enable GHD to deliver for clients and communities around the world.

As cyber threats become more sophisticated and connected environments grow in complexity, effective incident response depends on more than technology alone. At GHD, we combine disciplined investigation, practical judgement and close collaboration to understand threats quickly, contain risk and continually strengthen our security operations.

The opportunity

We are looking for an accomplished Senior SOC Analyst – Incident Response to lead and coordinate complex, high-severity incidents across a large enterprise environment. Reporting to the SOC Manager, you will own investigations end to end, shape critical response decisions and help strengthen how incidents are detected, contained and learned from across the organisation.

This is not a conventional alert-triage role. It is for a seasoned, hands-on responder who can establish facts when evidence is incomplete, coordinate technical teams during live incidents and apply sound incident response methodology even when tooling is degraded. Microsoft Sentinel and Defender XDR will be central to your work, but calm judgement, investigative discipline and clear communication will matter just as much.

What you will doLead and coordinate high-severity and complex security incident investigations from initial assessment through containment, recovery and review.

Establish incident scope, business impact and likely root cause using Microsoft Sentinel, Defender XDR and evidence from across the enterprise environment.

Direct response actions in partnership with infrastructure, identity, cloud, application and wider IT teams.

Maintain clear investigation records, preserve evidence and produce accurate, defensible incident outcomes and post-incident reports.

Develop, tune and maintain Sentinel analytics rules, improving signal quality and reducing false positives.

Conduct hypothesis-driven threat hunting using Sentinel and Defender Advanced Hunting.

Convert purple-team and attack-simulation findings into practical detection and response improvements.

Act as a technical mentor to junior and mid-level analysts, reviewing investigations and helping define playbooks, investigation standards and escalation thresholds.

Work closely with the organisation’s managed security service provider to maintain high-quality triage and escalation.

Brief technical and non-technical stakeholders clearly during active incidents, providing concise insight to support prioritisation and decision-making.

What success looks like

You are the person colleagues look to when an incident becomes complex, fast-moving or uncertain.

You turn fragmented technical evidence into a clear view of scope, impact, likely cause and immediate priorities.

You coordinate decisive containment while protecting evidence, maintaining accurate records and keeping stakeholders informed.

You improve detections, playbooks and escalation standards so that lessons from incidents create lasting capability.

You raise the confidence and investigative discipline of analysts around you through constructive review and mentoring.

What you will bring

At least five years’ experience in security operations and incident response, ideally within a large, complex or global organisation.

Demonstrable experience leading or owning major security investigations and coordinating stakeholders through the full response lifecycle.

Deep, hands-on expertise in Microsoft Sentinel, including incidents, investigations and analytics.

Strong knowledge of Microsoft Defender XDR, identity-based attacks and hybrid cloud environments.

The ability to form, test and refine investigative hypotheses using evidence from multiple sources.

Calm, decisive judgement under pressure, with the confidence to act when information is incomplete.

Clear written and verbal communication, including the ability to brief both technical specialists and senior non-technical stakeholders.

A collaborative, curious and disciplined approach to incident handling and continuous improvement.

Additional experience that would be valuable

Experience coaching analysts or…
Position Requirements
10+ Years work experience
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary