Overview
In this role you lead the Security Operations Centre (SOC) and incident response specialists within PA Consulting’s Digital Trust & Cyber Security practice. You balance hands-on operational leadership with advisory work to improve clients’ security operations, SIEM, SOAR and EDR capabilities, and overall cyber resilience. You work across diverse client environments, shaping modern security operations and incident response capabilities while fostering a collaborative, learning-focused culture. This is a chance to impact multiple sectors through practical improvements and strong cross-functional collaboration.
Pay / Benefits
- Health and lifestyle benefits including private healthcare
- 25 days annual leave (+ 0.5 day on Christmas Eve)
- Generous pension scheme
- Annual performance-based bonus
- PA share ownership
- Tax efficient benefits (cycle to work, give as you earn)
Responsibilities
- Lead and develop SOC analysts and incident response specialists, providing clear direction and coaching across daily security operations
- Take a hands-on leadership role during cyber security incidents, coordinating investigation, containment, eradication, recovery, and post-incident reviews
- Help clients assess and improve Security Operations capabilities by identifying gaps across people, processes and technology and translating into practical improvements
- Advise on evolution and optimization of SIEM, SOAR, EDR and threat-detection tooling to improve visibility and strengthen detection and response
- Develop and maintain incident playbooks, standard operating procedures, automated response workflows and proactive tabletop exercises
- Support development of modern Security Operations services and share expertise through coaching, mentoring and knowledge sharing across the Digital Trust & Cyber Security community
Key requirements
- SOC Leadership: experience running or supervising a SOC, CSOC, or Incident Response team
- Incident Response: practical experience managing live cyber incidents (ransomware, account takeovers, supply chain breaches)
- Technical Stack: direct experience with major SIEM/SOAR tools (e.g., Microsoft Sentinel, Splunk) and EDR/XDR platforms (e.g., Microsoft Defender for Endpoint, CrowdStrike Falcon)
- Security Frameworks: solid understanding of MITRE ATT&CK, NIST CSF, NCSC Caf v4.0 and ISO 27001
- Communication: ability to write concise incident reports and communicate with engineers and business leaders
- Communication
- Coaching and mentoring
- Cross-functional collaboration
- SIEM/SOAR tools (Microsoft Sentinel, Splunk)
- EDR/XDR platforms (Microsoft Defender for Endpoint, CrowdStrike Falcon)
- Threat detection engineering and incident response technologies
…
