Rodeo
Get started

CyPro

Security Operations Centre (SOC) Manager (London)

London
ยฃ90k/yr
Posted about 19 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this ยท No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

IMPORTANT: No recruiters or recruitment agencies, please. You must be UK based. We cannot provide visa sponsorship.


Overview:

  • Salary: ยฃ90,000+, depending on experience.
  • Holiday: 25 days, bank holidays and one additional day for every 12 months you stay with us.
  • Working Together: Three days per week in our Canary Wharf office, 39 floors up ๐Ÿ‘€, with flexibility for the remaining two days.
  • Working Hours: 40 hours, Monday to Friday, with occasional support for serious incidents outside normal hours.
  • Training: An individual training plan and budget for one professional certification or course each year.
  • Socials: Regular drinks, team activities and the occasional bit of axe throwing.
  • Start Date: As soon as contractual notice allows

Minimum Requirements

  • SOC Leadership Experience: You must have experience leading or supervising a SOC or security operations team, either within an MSSP/MDR provider or an in-house environment. Experience supporting multiple clients is useful but not essential.
  • Technical Security Operations: You must have strong practical knowledge of SIEM, EDR/XDR, incident response, alert triage, detection engineering, threat hunting, automation and SOC reporting. Microsoft Sentinel and Defender experience is highly desirable.
  • Communication: You must be able to communicate complex security and operational matters clearly and confidently in spoken and written English, including with clients and senior stakeholders.
  • Location and Right to Work: You must already have the right to work in the UK and be able to work from our Canary Wharf office three days per week. We cannot provide visa sponsorship.
  • Professional Background: You must have a strong background in cyber security or a related technical discipline, gained through experience, qualifications or education. A degree is not mandatory.

About CyPro

CyPro is a growing cyber security business with a shared mission: to redefine cyber security for small and medium-sized businesses. Our founders built their early careers delivering cyber security for large enterprises and central government. We saw an opportunity to bring the same level of security capability, expertise and discipline to organisations that are often underserved by traditional providers.

Our Managed Detection and Response service is a key part of that mission. We are now looking for a SOC Manager to lead the day-to-day operation and development of our SOC.


The Role

As SOC Manager, you will be accountable for the day-to-day delivery and continuous improvement of CyPro's Managed Detection and Response service across a portfolio of clients. You will lead a small but growing team SOC Analysts and Senior SOC Analysts, maintain operational quality and act as a senior escalation point for incidents and service issues. You will work closely with our technical, engineering and client-facing teams to improve detections, investigations, automation, processes and reporting. As CyPro and the SOC grow, there will be significant opportunities for the role and your responsibilities to develop with them. This is not a role where you simply supervise an alert queue. Equally, we are not looking for somebody to spend all day personally investigating alerts. We want a player-coach: an experienced security operations team leader who can develop people, challenge the quality of investigations, handle important client conversations and remain technically credible enough to know when something does not look right.

Reasons to use Rodeo

Iโ€™m in my final year doing Economics and I donโ€™t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer โ€” it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) donโ€™t need a masters. Letโ€™s look at the ones youโ€™d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet โ€” that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant โ€” 2026 Scheme

PwCยทLondon, UK
ยฃ35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

Youโ€™ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon โ€” deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme โ€” client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right โ€” and where to focus when applying.


Client Delivery and Service Management

  • Own managed detection and response delivery across a portfolio of clients.
  • Act as the primary operational escalation point for clients and internal teams.
  • Lead service reviews, governance meetings and executive briefings.
  • Present incidents, trends, risks and recommendations clearly and commercially.
  • Own performance against SLAs, KPIs and contractual commitments.
  • Monitor incident trends, detection coverage, alert volumes, false positives and response performance.
  • Create service improvement plans where quality falls below expectations.
  • Lead client onboarding and service transition, coordinating deployment, documentation and stakeholders.
  • Manage major incident escalations and ensure responses are controlled, communicated and documented.

Team Leadership and People Management

  • Line manage, coach and develop SOC Analysts and Senior SOC Analysts.
  • Set clear expectations for investigation quality, ownership, communication and timeliness.
  • Conduct regular one-to-ones, performance reviews and career development discussions.
  • Build development plans and support career progression.
  • Review investigations, incident reports and client communications.
  • Manage workload, priorities, operational coverage and capacity.
  • Support recruitment, assessment and onboarding.
  • Develop senior members of the team so operational responsibility does not depend entirely on the SOC Manager.
  • Address performance issues directly and constructively.
  • Act as a role model for professionalism, ownership and delivery quality.

Detection, Investigation and Response

  • Maintain oversight of detection coverage across client environments.
  • Ensure alerts and incidents are investigated consistently and appropriately.
  • Act as a senior escalation point during complex or high-severity incidents.
  • Review investigations and challenge incomplete analysis or weak conclusions.
  • Provide technical guidance to analysts where necessary.
  • Work with analysts, engineers and platform specialists to improve detection use cases.
  • Improve detection logic and reduce unnecessary false positives without weakening coverage.
  • Support the onboarding of new log sources and security technologies.
  • Identify opportunities to automate repetitive investigation and response activities.
  • Support threat hunting and the effective use of threat intelligence.
  • Turn lessons from incidents into improved detections, runbooks and response procedures.
  • Maintain awareness of emerging threats, attacker techniques and relevant SOC technologies. You will not be expected to personally investigate every alert or build every detection rule. You do, however, need sufficient technical depth to recognise poor analysis, ask the right questions and provide credible direction to the team.

Service Improvement and Practice Development

  • Own and improve runbooks, playbooks, workflows and operational procedures.
  • Ensure documentation is clear, current and usable during live incidents.
  • Standardise investigation, escalation and reporting across client environments.
  • Improve quality assurance for alerts, investigations, incidents and client deliverables.
  • Use operational data to identify weaknesses and prioritise improvements.
  • Improve client reporting and service governance.
  • Help develop repeatable operating models that allow the SOC to grow without reducing quality.
  • Evaluate security technologies, automation and AI-supported SOC tooling where appropriate.
  • Support proofs of concept and technical evaluations.
  • Contribute to the development of new Managed Detection and Response capabilities.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Client Delivery & Service Management

  • Own day-to-day MDR delivery across a portfolio of clients.
  • Act as a senior operational escalation point for clients and internal teams.
  • Support service reviews, governance meetings and executive briefings.
  • Present incidents, trends, risks and recommendations clearly.
  • Maintain oversight of agreed SLAs, KPIs and contractual service commitments.
  • Monitor incident trends, detection coverage, alert volumes and investigation quality.
  • Ensure service issues are owned, communicated and driven through to resolution.
  • Give clients confidence that their security operations service is being managed effectively.

Supporting CyPro's Growth

This is primarily an operational leadership role, not a sales position. From time to time you will:

  • Support pre-sales discussions where SOC expertise is required.
  • Explain CyPro's MDR capabilities to prospective clients.
  • Provide input into service designs and Statements of Work.
  • Help estimate onboarding effort, service capacity and technical resource requirements.
  • Identify operational opportunities to improve or expand services for existing clients.
  • Ensure new client requirements are technically realistic and can be delivered sustainably. Commercial ownership, pricing and sales targets will not sit solely with the SOC Manager.

Professional Development

Maintain your technical and professional credibility through relevant learning and industry engagement. Strong candidates will typically hold two or more relevant certifications, or demonstrate equivalent experience. Examples include Microsoft SC-200, AZ-500, CISSP, CISM, GCIA, GCIH, CompTIA CySA+ and CREST Certified Intrusion Analyst.


Soft Skills

  • Effective: You remove obstacles, establish ownership and drive work through to completion.
  • Accountable and Humble: You take responsibility for SOC performance, accept feedback and change your approach when needed.
  • Calm Under Pressure: You remain structured, prioritise clearly and communicate confidently during serious incidents.
  • Technically Credible: You understand security operations well enough to challenge investigations, identify weak reasoning and guide the team.
  • Client Focused: You provide timely communication, clear recommendations and confidence that the service is well managed.
  • People Developer: You invest in your team, give direct feedback and address poor performance.
  • Commercially Aware: You balance strong security outcomes with contractual scope, resources and sustainable delivery.
  • Adaptable: You make sensible decisions in an evolving environment and help build processes that do not yet exist.

Interview Process

We can generally take candidates through the full process within 10 days ๐ŸŽ‰.

  • Telephone Interview: A 20-minute initial conversation with a senior member of the Cyber Security team.
  • Psychometric Testing: Three 15-minute cognitive assessments.
  • Assessment Centre: A morning in our Canary Wharf office involving practical exercises and a final interview with a practice partner.
Trusted by 25,000+ job seekers

โ€œIt took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what Iโ€™ve been looking for.โ€

Jessica, London

Get help applying for this job

Location

London, England, United Kingdom

Sign up to applySee more jobs like this