About this role
Salary: £35,000 - 75,000 per year
Requirements: Current SC clearance and eligibility to obtain UK Government DV clearanceExperience in Security Operations Centre (SOC) environmentsExperience in threat hunting and incident responseExperience with SIEM technologies, ideally Elastic StackKnowledge of threat intelligence and attacker methodologiesExperience with Windows and Linux operating systemsStrong networking fundamentals, including protocols, IP addressing, and traffic analysisUnderstanding of modern attacker techniques, including LOLBins and weaponised COTS toolingExperience using OSINT techniques and cyber threat analysisExperience leading investigations and supporting junior analystsAbility to communicate effectively during high-pressure incidentsDesirable: experience in high-security or government-aligned environmentsDesirable: exposure to Elastic Stack, Splunk, Sentinel, or similar SIEM platformsDesirable: security certifications such as CISSP, CISM, CompTIA Security, or SecurityX Responsibilities: Lead the investigation and response to complex cyber security incidents across high-security customer environmentsAct as a senior escalation point for Tier 1 and Tier 2 analysts during active security eventsDrive proactive threat hunting campaigns to identify emerging threats, vulnerabilities, and anomalous behaviourDevelop and improve detection logic, alerting, and monitoring content within SIEM platforms including Elastic StackAnalyse threat intelligence, indicators of compromise (IOCs), and attacker TTPs to strengthen detection capabilityProduce detailed post-incident reports with clear recommendations and improvement actionsSupport and mentor junior SOC analysts, helping develop technical capability across the teamCollaborate with customers and internal stakeholders during incidents, communicating clearly with both technical and non-technical audiencesContribute to the ongoing evolution and improvement of our SOC services, processes, and operational standardsParticipate in technical forums, knowledge sharing, and continuous improvement initiatives Technologies: SupportLinuxSecuritySplunkWindows More:
We are DXC Technology, expanding our high-security Cyber Defence capability and growing our Security Operations Centre (SOC) team based in Farnborough. We support critical customer environments and deliver mission-critical technology and cyber security services to some of the worlds largest organisations. This is a Monday to Friday core-hours role with an on-call commitment from Farnborough. We foster a collaborative, diverse, and inclusive workplace and encourage applications from women, underrepresented groups, and neurodivergent candidates, with support and adjustments available throughout the hiring process. We offer a competitive salary, bonus, and a flexible benefits package including pension, private medical cover, and wellbeing programmes, along with opportunities for continuous learning, technical growth, and leadership development.
last updated 29 week of 2026