
How your CV stacks up
Upload your CV to see how well it fits this job role
?%
IMPORTANT: THIS IS A SOC ROLE. No recruiters or recruitment agencies, please. You must be UK based. We cannot provide visa sponsorship. Previous experience working as a SOC Manager within a Managed Security Service Provider (MSSP) is mandatory. Applications that do not meet this requirement will not progress.
Overview:
- Salary: £75,000+, depending on experience.
- Holiday: 24 days, pro rata, plus your birthday off, bank holidays and one additional day for every 12 months you stay with us.
- Working Together: Three days per week in our Canary Wharf office, 39 floors up 👀, with flexibility for the remaining two days.
- Working Hours: 40 hours, Monday to Friday, with occasional support for serious incidents outside normal hours.
- Training: An individual training plan and budget for one professional certification or course each year.
- Socials: Regular drinks, team activities and the occasional bit of axe throwing.
- Start Date: October 2026.
Minimum Requirements
You must meet all five requirements below. Please do not apply if you do not.
- Mandatory MSSP experience: You must have previous experience working specifically as a SOC Manager within an MSSP, delivering security operations services to multiple external clients rather than managing only an internal SOC.
- Technical security operations experience: You must have strong practical knowledge of SIEM, EDR/XDR, incident investigation and response, detection engineering, alert triage, threat intelligence, threat hunting, SOAR, automation and SOC reporting. Experience with Microsoft Sentinel, Microsoft Defender XDR and the wider Microsoft security ecosystem is strongly desirable.
- Fluent business English: This is a senior, client-facing role. You must communicate complex security and operational matters clearly and confidently in spoken and written English, including executive briefings, incident communications, governance meetings and formal reports. Communication skills will be assessed during recruitment.
- Location: You must live within approximately 90 minutes’ commuting distance of Canary Wharf, London.
- Education: A technical academic background in computer science, cyber security, information security, software engineering or a related field is desirable. A degree is not mandatory and equivalent professional experience or qualifications will be considered.
About CyPro
CyPro is an innovative cyber security business with a shared mission: to redefine cyber security for small and medium-sized businesses. Our founders, Jonny and Rob, built their early careers delivering cyber security for large enterprises and central government. They saw a need for a different approach for smaller organisations. We help clients prevent attacks, secure larger customers and scale confidently. This role offers the opportunity to shape a growing SOC alongside experienced professionals.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
The Role
Client Delivery and Service Management
- Own managed detection and response delivery across a portfolio of clients.
- Act as the primary operational escalation point for clients and internal teams.
- Lead service reviews, governance meetings and executive briefings.
- Present incidents, trends, risks and recommendations clearly and commercially.
- Own performance against SLAs, KPIs and contractual commitments.
- Monitor incident trends, detection coverage, alert volumes, false positives and response performance.
- Create service improvement plans where quality falls below expectations.
- Lead client onboarding and service transition, coordinating deployment, documentation and stakeholders.
- Manage major incident escalations and ensure responses are controlled, communicated and documented.
Team Leadership and People Management
- Line manage and develop SOC Analysts and Senior SOC Analysts.
- Set clear expectations and hold team members accountable for quality and timeliness.
- Conduct one-to-ones, performance reviews and career development discussions.
- Build development plans and support career progression.
- Review investigations, incident reports and client communications.
- Manage workload, capacity, priorities and operational coverage.
- Support recruitment, assessment and onboarding.
- Act as a role model for professionalism, ownership and delivery quality.
Detection, Investigation and Response
- Maintain oversight of detection coverage across client environments.
- Ensure alerts and incidents are investigated consistently and appropriately.
- Provide technical guidance during complex or high-severity incidents.
- Work with analysts, engineers and platform specialists to develop detection use cases.
- Improve detection logic and reduce false positives without weakening coverage.
- Oversee onboarding of new log sources and security technologies.
- Identify opportunities to automate repetitive investigation and response activities.
- Track alert quality, triage, investigation, containment and automation performance.
- Use operational data to identify weaknesses and drive improvement.
- Support threat hunting and the use of threat intelligence.
- Turn incident lessons into improved detections, playbooks and response procedures.
- Maintain awareness of emerging threats, attacker techniques and SOC technologies.
Service Improvement and Practice Development
- Own and improve runbooks, playbooks, workflows and operational procedures.
- Ensure documentation is clear, current and usable during live incidents.
- Standardise investigation, escalation and reporting across client accounts.
- Develop repeatable operating models that allow the SOC to scale without reducing quality.
- Improve quality assurance for alerts, incidents and client deliverables.
- Improve client reporting and service governance.
- Contribute to new managed detection and response services.
- Evaluate security technologies, automation and AI-supported SOC tooling.
- Support proofs of concept and vendor assessments.
- Align operational priorities with the wider SOC roadmap.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Commercial and Business Development
- Support pre-sales discussions for managed detection and response opportunities.
- Explain CyPro’s SOC capabilities clearly to prospective clients.
- Contribute to service designs, proposals, pricing and Statements of Work.
- Estimate onboarding effort, service capacity and technical resource requirements.
- Identify opportunities to improve or expand services for existing clients.
- Understand account profitability and the relationship between scope, capacity and delivery cost.
- Ensure additional requests are assessed, scoped and commercially agreed.
Professional Development
- Maintain your technical and professional credibility through relevant learning and industry engagement.
- Strong candidates will typically hold two or more relevant certifications, or demonstrate equivalent experience. Examples include Microsoft SC-200, AZ-500, CISSP, CISM, GCIA, GCIH, CompTIA CySA+ and CREST Certified Intrusion Analyst.
Soft Skills
- Effective: You remove obstacles, establish ownership and drive work through to completion.
- Accountable and Humble: You take responsibility for SOC performance, accept feedback and change your approach when needed.
- Calm Under Pressure: You remain structured, prioritise clearly and communicate confidently during serious incidents.
- Technically Credible: You understand security operations well enough to challenge investigations, identify weak reasoning and guide the team.
- Client Focused: You provide timely communication, clear recommendations and confidence that the service is well managed.
- People Developer: You invest in your team, give direct feedback and address poor performance.
- Commercially Aware: You balance strong security outcomes with contractual scope, resources and sustainable delivery.
- Adaptable: You make sensible decisions in an evolving environment and help build processes that do not yet exist.
Interview Process
- Telephone Interview: A 20-minute initial conversation with a senior member of the Cyber Security team.
- Psychometric Testing: Three 15-minute cognitive assessments.
- Assessment Centre: A morning in our Canary Wharf office involving practical exercises and a final interview with a practice partner.
We can generally take candidates through the full process within 10 days 🎉.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location