← Back to Directory

Senior SOC Analyst – Manchester

BAE Systems · Manchester, UK
Clearance Level
DV
Salary Range
Competitive
Employment Type
FULL TIME
Work Style
onsite

// Role Summary

Join BAE Systems Digital Intelligence as a Senior SOC Analyst in Manchester, playing a crucial role in a 24/7 operation to protect critical UK national infrastructure. This hands-on, shift-based role involves investigating cyber threats in cloud environments and contributing to service improvements.

// Key Responsibilities

  • Operate and improve a Security Operations Centre (SOC) for a major UK CNI organisation.
  • Monitor, triage, and investigate cyber threats using SIEM toolsets in Azure and AWS.
  • Responsible for incident response, remediation support, and producing security reports.
  • Requires SC clearance and readiness for DV clearance.
  • Hands-on, shift-based role within a 24/7 operation.
  • Develop new workflows for automation into SOAR tools and contribute to service enhancements.

// Role Specification

About BAE Systems Digital Intelligence

BAE Systems Digital Intelligence is a leading force with 4,500 digital, cyber, and intelligence experts operating across 10 countries. We collaborate to gather, connect, and interpret complex data, empowering governments, nation states, armed forces, and commercial businesses to gain a digital advantage in challenging environments.

Job Title: Senior SOC Analyst

Location: Manchester

Grade: GG09-GG10

Role Description

BAE Systems is contracted to manage and enhance a dedicated Security Operations Centre (SOC) to support the defence of a major UK Critical National Infrastructure (CNI) organisation. The networks primarily reside in Azure and AWS cloud platforms, housing hundreds of systems that require protection against significant threats. This role is integral to developing the SOC into a benchmark of best practice and excellence.

The SOC will comprise both customer and BAE Systems staff, distributed across multiple locations. However, day-to-day operations will be conducted from our Leeds office due to necessary customer network access.

These are hands-on, shift-based roles within a 24/7 operation, involving four rotating shift teams. Analysts will utilise the SOC’s Security Incident and Event Management (SIEM) toolsets to detect, investigate, and respond to potential security and service incidents within the monitored networks.

Requirements: A minimum of SC clearance is mandatory, with the preparedness to undergo DV clearance.

Initial contracts are for a blend of 6 and 12 months, with potential for extension based on programme variables. Positions are expected to be full-time, office-based roles.

Key Responsibilities:

  • Prepare and deliver shift handover briefs to the incoming team.
  • Monitor, triage, analyse, and investigate alerts, log data, and network traffic using the Protective Monitoring platform and Internet resources to identify cyber-attacks and security incidents.
  • Categorise suspected incidents according to the Security Incident policy.
  • Recognise potential, successful, and unsuccessful intrusion attempts and compromises through detailed analysis of event data and incident summaries.
  • Generate high-quality security incident tickets, leveraging existing knowledge and independent research.
  • Assist with remediation activities and perform permitted remediation actions (or support customer stakeholders) to mitigate cyber-attacks, clean IT systems, and secure networks.
  • Produce security incident review reports, detailing incidents and providing recommendations for security improvements.
  • Understand and apply Threat Intelligence in an operational context.
  • Support incident response to national-scale incidents in a coaching capacity.
  • Collaborate with other BAE Systems teams to enhance services based on customer requirements.
  • Develop new automated workflows for SOAR tools to handle common attack types.
  • Continuously improve the service by reviewing use cases and proposing changes aligned with evolving threats.

Technical Requirements:

  • Basic Python and/or scripting skills.
  • Proficiency with Windows, OS X, and Linux operating systems.
  • Experience using Splunk and Sentinel.
  • Familiarity with a range of security tooling and technology.
  • Strong understanding of security architecture, particularly networking.
  • Detailed knowledge of threat intelligence, threat actors, TTPs, and operationalising threat intelligence.
  • Experience investigating complex network intrusions (e.g., from state-sponsored groups or targeted ransomware attacks).
  • Understanding of TCP/IP component layers to identify normal and abnormal traffic.
  • Knowledge of AWS and/or Azure cloud services.
  • Experience with Splunk (with ES) and/or Sentinel; content development experience is desirable.

Non-Technical Requirements:

  • Client-side consulting experience, including stakeholder engagement and the ability to communicate insights effectively (briefing and report writing skills).
  • A coaching mindset with experience in mentoring teams.
  • Experience in security process development.
  • Ability to understand and adapt to different cultures and hierarchical structures.
  • Self-starter capable of working independently.
  • Team player adept at working in multi-disciplinary and diverse teams.

Desirable Skills:

  • Software engineering experience.
  • Penetration testing skills.

Life at BAE Systems Digital Intelligence

We embrace Hybrid Working, allowing flexibility in where and when we work to better balance personal and professional life, enhancing well-being. We leverage technology to collaborate and create, even when working remotely.

Diversity and inclusion are fundamental to our success. We foster an organisational culture where varied perspectives, skills, and experiences contribute to achieving excellence and realising individual and organisational potential.