The MXDR Senior SOC Analyst is a senior technical position within the Managed Extended Detection and Response (MXDR) team. Acting as a technical leader across security operations, the Senior Analyst is responsible for leading complex investigations, supporting incident response activities, driving detection improvements and acting as a key escalation point for analysts and customer tickets.
The role combines operational responsibilities within the Security Operations Centre with strategic contributions to the continual enhancement of the MXDR service. Working closely with Detection Engineering, Threat Hunting, Customer Success, Technical Account Managers and Service Delivery teams, the Senior Analyst will help ensure customers receive world class detection and response capabilities while driving innovation across Microsoft Sentinel, Microsoft Defender XDR, and the wider MXDR technology stack.
As a recognised Subject Matter Expert (SME), the Senior Analyst will provide guidance and mentorship to analysts, lead technical investigations, support customer onboarding activities and contribute to the development of analytics, automation and AI-driven security operations capabilities.
Working Hours: The working hours are 0900-1730hrs Mon-Fri, and you would be expected to be working and contactable throughout those times. There is no scheduled out of hours work but may be required in emergency situations only.
-
Monitor global customer environments for potential threats, vulnerabilities, and indicators of compromise.
- Perform advanced analysis and investigation of security alerts utilising Microsoft Sentinel, Microsoft Defender XDR and associated security platforms across the MXDR technology stack, including Splunk, CrowdStrike, SentinelOne and Carbon Black.
- Act as a senior incident responder and technical lead during high-priority security incidents.
- Provide incident remediation guidance, technical recommendations and preventative security advice to customers.
- Actively contribute to the triage and investigation queue, ensuring incidents are handled in accordance with service level agreements.
- Act as the primary escalation point for analysts during complex investigations and security incidents.
- Provide out-of-hours escalation support when required for customer incidents.
- Work closely with Automation Development (ADEV) teams to tune existing detections and develop new analytics and use cases.
- Identify detection gaps through investigations, threat hunting activities and customer feedback, proposing improvements to monitoring coverage.
- Contribute to the development and optimisation of detection content, automation workflows and response playbooks.
- Support customer onboarding and service transition activities, ensuring effective implementation of monitoring and detection capabilities.
- Act as a technical point of contact for customer escalations and service related security discussions.
- Serve as a Subject Matter Expert (SME) across the MXDR technology stack, providing technical leadership, guidance and support during investigations, service improvements and customer engagements.
-
- Conduct proactive threat hunting activities to identify malicious activity, validate detections and strengthen customer security posture.
- Provide technical mentoring and guidance to analysts, supporting capability development across the SOC.
- Contribute to the continual improvement of MXDR processes, procedures, documentation and service offerings.
- Perform other duties as assigned.
Required Functional and Technical Skills:
Security Operations & Incident Response
- Extensive experience investigating and responding to cyber security incidents within a MXDR SOC environment.
- Strong understanding of incident response methodologies, threat hunting techniques and attacker behaviours.
- Ability to lead technical investigations and coordinate response activities during major security incidents.
- Experience analysing endpoint, identity, cloud, email and network based threats.
Security Monitoring & Detection Platforms
- Advanced and practical knowledge of enterprise security monitoring technologies, including Microsoft Sentinel, Splunk, CrowdStrike, SentinelOne, Carbon Black and associated cloud security platforms used within the MXDR service.
- Strong understanding of security telemetry, log analysis, threat detection methodologies and investigation workflows across endpoint, identity, cloud, email, and network security domains.
- Experience developing and tuning detection logic, analytics, correlation rules and automated response capabilities across multiple security technologies.
- Ability to leverage platform specific query languages, hunting capabilities and investigation tools to identify threats, validate detections and support incident response activities.
Detection Engineering & Continuous Improvement
- Experience tuning and improving security analytics to reduce false positives and improve detection fidelity.
- Ability to identify detection gaps and develop recommendations for enhanced monitoring coverage.
- Experience collaborating with engineering and development teams to deliver security use cases and automation solutions.
Client Communication & Stakeholder Management
- Strong written and verbal communication skills with the ability to explain technical concepts to both technical and non technical audiences.
- Experience supporting customer facing investigations and escalations.
Security Platforms & Technologies
- Strong understanding of operating systems, networking fundamentals, authentication protocols and cloud technologies.
- Knowledge of MITRE ATT&CK, Cyber Kill Chain and common adversary behaviours.
- Experience working with SOAR, SIEM, EDR and threat intelligence platforms.
Collaboration & Leadership
- Ability to act as a senior technical authority and escalation point within the MXDR team.
- Experience mentoring analysts and supporting technical development initiatives.
- Ability to work collaboratively across operations, engineering, onboarding and customer success teams.
-
Flexible Working: Balance your work and personal life with our flexible working options.
- Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave.
- Medicash & Critical Illness Scheme
- Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme.
- Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities.
- Green Car Scheme: Drive green and save money with our eco-friendly car scheme.
- Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme.
- Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet.
- Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.
We assess, develop and manage cyber threats across our increasingly connected society. We advise global technology, manufacturers, financial institutions, critical national infrastructure providers, retailers and governments on the best way to keep businesses, software and personal data safe.
With our knowledge, experience and global footprint, we are best placed to help businesses identify, assess, mitigate & respond to the risks they face.
We are passionate about making the Internet safer and revolutionising the way in which organisations think about cyber security.
Headquartered in Manchester, UK, with over 35 offices across the world, NCC Group employs more than 2,000 people and is a trusted advisor to 15,000 clients worldwide.
We review every application received and will get in touch if your skills and experience match what we’re looking for. If you don’t hear back from us within 10 days, please don’t be too disappointed – we may keep your CV on our database for any future vacancies and we would encourage you to keep an eye on our career opportunities as there may be other suitable roles.
If you do not want us to retain your details, you can utilise the Manage Your Data tool provided by Pinpoint or contact us directly at:
[email protected]. All personal data is held in accordance with the NCC Group Privacy Notice.
We are committed to diversity and flexibility in the workplace. If you require any reasonable adjustments to support you during the application process, please tell us at any stage.
Please note that this role involves mandatory pre-employment background checks due to the nature of the work NCC Group does. To apply, you must be willing and able to undergo the vetting process.