Team Lead, SOC
NCC Group provide a range of managed and hosted services delivered from our UK based Security Operations Centre SOC which operates 24/7, 365 days a year. Our team of over 30 accredited security experts are available 24/7, dealing daily with over 200 million log events and providing support for over 5,000 network devices.
NCC Group’s Cloud XDR Team provide a world class Extended Detection and Response (XDR) services, detecting, responding and mitigating cyber-attacks on our customers networks in our Security Operations Centres using the Microsoft Sentinel ecosystem.
The Cloud XDR Team are looking for a Team Lead with a passion for security to join the team to help the customers get the most out of our services and to protect their networks.
This is an opportunity to join a technically advanced and talented team and help NCC Group build and deliver world class services to our customers.
This role is ideal for a seasoned SOC Analyst with experience in cyber security looking to broaden their scope of cyber skills with a strong focus on detection and response to cyber incidents.
- Monitor global systems looking for potential threats, vulnerabilities and indicators of compromise.
- Perform in-depth analysis of security alerts utilizing Microsoft XDR suite (Sentinel/Defender etc)
- Act as incident handlers during high priority incidents
- Provide Incident remediation and prevention documentation and recommendations to customers based on defined procedures and analyst experience.
- Document and conform to processes related to security monitoring procedures.
- Provide customer service that always exceeds our customers’ expectations.
- Initiate escalation procedure to counteract potential threats, vulnerabilities and threat actors.
- Compilation and review of service focused reporting.
- Act as an escalation point for more junior members of the team, providing assistance and mentoring where necessary.
- Providing assistance to XDR SOC Analysts on general Triage and Threat Hunting engagements.
- Contributing to the continuous improvement of SOC procedures and documentation.
- Actively liaise with clients in order to understand specific risk areas and act as a touch point for issues raised
- Perform other duties as assigned.
- Experience working in relevant SOC analyst roles
- Practical knowledge and experience of security and networking toolsets such including Microsoft’s XDR suite (Sentinel/Defender)
- Pre-existing, in-depth knowledge of common network protocols and endpoint detection/forensics
- Pre-existing, in-depth knowledge of Windows and Linux based operating systems.
- Experience in the extensive analysis of common security incidents.
- Ability to stay calm in highly sensitive and high-pressure incidents.
Certifications
The following certifications are desirable, but not a requirement. Successful candidates that do not possess these certifications may be tasked with working towards them at the beginning of their employment:
- Azure based certifications (SC-200, AZ-500, MS-500)
- GIAC GCIA/GCIH
- CREST CPSA / CRIA / CMRE / CNIA / CHIA
- CompTIA Security+
- CompTIA Network+
- Other relevant certifications.
- Flexible Working: Balance your work and personal life with our flexible working options.
- Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave.
- Medicash & Critical Illness Scheme
- Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme.
- Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities.
- Green Car Scheme: Drive green and save money with our eco-friendly car scheme.
- Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme.
- Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet.
- Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.