Lorien
Senior Soc Analyst

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Senior SOC Analyst – Threat Hunting & Detection Engineering
Contract: 6 Months
Location: UK (Hybrid)
Day Rate: Competitive
Sector: Life & Pensions / Financial Services
Overview
We are seeking an experienced SOC / Senior SOC Analyst to join a leading Life & Pensions organisation, supporting the continued maturity of its Cyber Security Operations capability. This role is focused on proactive threat detection, threat hunting, incident investigation, and detection engineering within a Microsoft security technology stack.
The successful candidate will operate beyond traditional alert monitoring, taking ownership of identifying emerging threats, enhancing security monitoring capabilities, and improving the effectiveness of security controls across the organisation. Working closely with Security Operations, Infrastructure, Cloud, Compliance, and Risk teams, you will play a key role in strengthening cyber resilience within a highly regulated financial services environment.
Key Responsibilities
- Conduct proactive threat hunting activities using intelligence-led and hypothesis-driven methodologies across cloud, endpoint, identity and infrastructure environments.
- Design, develop and optimise detection use cases, analytics rules and alerting mechanisms within Microsoft Sentinel.
- Investigate and triage complex security incidents, providing senior-level analysis, containment recommendations and remediation guidance.
- Act as an escalation point for security events and incidents identified by SOC analysts and automated tooling.
- Develop and maintain detection engineering standards to improve visibility and reduce false positives.
- Build, refine and optimise KQL queries, workbooks, dashboards and analytics rules within Microsoft Sentinel.
- Enhance monitoring coverage across Microsoft Defender technologies including Defender for Endpoint, Defender for Identity and Defender for Cloud.
- Leverage threat intelligence feeds, MITRE ATT&CK techniques and industry threat trends to improve detection capabilities.
- Support incident response activities and post-incident reviews, identifying opportunities for control and process improvements.
- Contribute to security automation initiatives through SOAR playbooks, scripting and workflow optimisation.
- Produce high-quality investigation reports, detection documentation, playbooks and operational procedures.
- Mentor junior analysts and support the ongoing development of SOC capabilities and best practices.
- Collaborate with infrastructure, cloud, architecture, governance and risk teams to ensure findings are remediated effectively.
- Support security and regulatory initiatives across FCA, PRA and broader financial services control frameworks.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Essential Skills & Experience
- Proven experience working within a Security Operations Centre (SOC) environment as a SOC Analyst, Senior SOC Analyst, Threat Hunter or Detection Engineer.
- Strong hands-on experience with Microsoft Sentinel, including:
- KQL query development
- Analytics rules creation and tuning
- Workbooks and dashboards
- Incident investigation and hunting
- Data connector management
- Strong experience across the Microsoft Defender suite, including:
- Microsoft Defender for Endpoint
- Microsoft Defender for Identity
- Microsoft Defender for Cloud
- Microsoft Defender XDR
- Demonstrable threat hunting experience within enterprise environments.
- Experience developing, tuning and maintaining detection logic and detection use cases.
- Strong understanding of incident response methodologies and cyber threat analysis.
- Experience investigating endpoint, identity, network and cloud-based security incidents.
- Ability to work independently while managing multiple priorities and security investigations.
- Excellent stakeholder engagement and communication skills.
- Previous experience working within Financial Services, Banking, Insurance, Life & Pensions or other regulated environments.
- Strong understanding of security operations processes, controls and governance.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Desirable Skills & Experience
- Experience using the MITRE ATT&CK framework for threat hunting and detection development.
- Knowledge of attack techniques, adversary behaviours and threat actor tactics.
- Experience developing SOAR playbooks and automation workflows.
- Scripting experience using Python, PowerShell or automation tooling.
- Experience with threat intelligence platforms and threat-led security operations.
- Familiarity with cloud security monitoring across Microsoft Azure environments.
- Exposure to DORA, FCA, PRA or other financial services regulatory frameworks.
- Experience supporting cyber resilience and operational resilience programmes.
Certifications (Desirable)
- Microsoft SC-200 Security Operations Analyst
- CISSP
- GCIH
- GCFA
- GCIA
- Microsoft Security Certifications
- Azure Security Certifications
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location