Senior Security Operations Centre (SOC) Analyst
Location: UK (Hybrid) Leeds or Thame
This is a full time permanent position.
We’re looking for a Senior SOC Analyst to play a critical role in protecting PEXA’s platforms, data, and operations. This is a hands-on, senior position where you’ll lead complex security investigations, act as a key escalation point, and help shape the future of our Security Operations capability.
You’ll operate across cloud, endpoint, identity, and network environments - ensuring threats are rapidly detected, contained, and remediated. Alongside incident response, you’ll contribute to the ongoing maturity of the SOC through process improvement, detection engineering, and strategic initiatives.
This role combines deep technical expertise, operational leadership, and strategic influence within a growing and evolving security function.
What You'll Be Doing
- Lead investigations into complex security incidents across multiple domains
- Act as a senior escalation point within the SOC
- Manage P1 & P2 incidents, including post-incident reviews and lessons learned
- Perform event triage, analysis, and response to security alerts
- Lead engagements with MSSPs and security vendors
- Validate escalations, challenge assumptions, and ensure high-quality outputs
- Collaborate with infrastructure, engineering, and product teams to drive remediation
- Communicate clearly with stakeholders, including senior leadership
- Develop and deliver a continuous SOC improvement roadmap
- Create and refine playbooks and incident response processes
- Tune detection rules and improve SIEM performance (Splunk)
- Enhance automation to reduce false positives and improve efficiency
- Identify monitoring gaps and align detection with emerging threats
- Support threat hunting and purple team initiatives
- Mentor and support SOC analysts, embedding best practices
- Contribute to capability uplift and skills development across the team
- Act as delegate for the Head of UK Security when required
- Support security awareness initiatives across UK business units
Security Operations & Incident Response
Vendor & Stakeholder Management
SOC Improvement & Strategy
Leadership & Mentorship
What We’re Looking For
- Solid experience in Security Operations or Security Services delivery within a Tech Business (FinTech ideal)
- Proven experience in incident response and investigation
- Experience leading or contributing to SOC improvement initiatives
- Hands-on experience with SIEM platforms (e.g. Splunk)
- Exposure to cloud environments (AWS and/or Azure)
- Strong understanding of:
- Incident Response lifecycle
- Endpoint security, DLP, and cloud security
- Network fundamentals (TCP/IP, routing, switching)
- System logging and log analysis
- Ability to interpret SIEM data and provide meaningful insights
- Working knowledge of scripting/programming (Python, Shell, SQL)
- Familiarity with frameworks such as MITRE ATT&CK
- Strong analytical and problem-solving skills
- Excellent written and verbal communication, including executive-level engagement
- Ability to work autonomously and manage multiple priorities
- High attention to detail with a proactive, investigative mindset
- Collaborative approach with the confidence to challenge constructively
Core Competencies