Skip to main content
AfterDuty

SOC Analyst - SC Cleared

Sanderson Government & Defence · London, Greater London

Salary
£545 – £590 a dayEstimated
Type
Contract
Posted
7 days ago

Overview

Your incident response and investigative discipline from policing apply here.

About this role

SOC Analyst x2 Location: UK (Hybrid, 3 days per week in London)

Security Clearance: Active SC Clearance Required

Contract Length: 6-18 Months

Rate: £545-£590 per day (Inside IR35)

Positions Available: 2

This is an excellent opportunity to work within complex and dynamic security environments, helping clients protect critical services, systems, and data against evolving cyber threats. The successful candidates will play a key role in security monitoring, incident response, detection engineering, and threat analysis, working alongside Security Operations, Threat Intelligence, and Incident Response teams.

You will act as a cyber security subject matter expert, helping to strengthen defensive capabilities while contributing to the continuous improvement of security operations, threat detection, and incident response functions.

Key ResponsibilitiesSecurity Monitoring & Incident Response

  • Monitor and triage security alerts generated through SIEM and security tooling.
  • Investigate and respond to cyber security incidents across cloud, endpoint, and network environments.
  • Analyse security events to determine impact, severity, and appropriate response actions.
  • Support incident containment, remediation, and post-incident review activities.
  • Participate in incident response exercises and security simulations.

Detection Engineering

  • Develop, maintain, and optimise security detection content within Splunk SIEM.
  • Create and refine correlation searches, use cases, alerts, and detection rules.
  • Identify gaps in detection coverage and recommend improvements.
  • Work closely with security teams to improve visibility and enhance monitoring capabilities.
  • Support the onboarding and optimisation of new log sources.

Security Operations Improvement

  • Review and enhance security operations processes, standards, and procedures.
  • Identify trends in incidents, attack patterns, and security monitoring activity.
  • Recommend improvements to logging, monitoring, alerting, and response capabilities.
  • Support service improvement and operational efficiency initiatives.

Threat Intelligence & Threat Hunting

  • Remain current with emerging cyber threats, threat actors, vulnerabilities, and attack techniques.
  • Leverage threat intelligence to improve detection and response capabilities.
  • Support proactive threat hunting activities.
  • Research adversary tactics, techniques, and procedures (TTPs) relevant to highly regulated environments.

Technical Leadership

  • Act as an escalation point for junior analysts.
  • Provide mentoring, coaching, and knowledge-sharing support.
  • Contribute to capability development across the wider security team.
  • Present technical findings and recommendations to stakeholders when required.

Additional Responsibilities Depending on project requirements, responsibilities may also include:

  • Proactive threat hunting
  • Detection engineering and use-case development
  • Incident response playbook creation
  • Threat intelligence collection and analysis
  • Vulnerability assessment and reporting
  • Security change approval activities
  • Security capability enhancement initiatives

Essential Skills & Experience

  • Demonstrable experience working within a Security Operations Centre (SOC) environment.
  • Strong experience in security monitoring, alert triage, and incident investigation.
  • Hands-on experience with:
  • Splunk
  • SIEM technologies
  • Endpoint security tools
  • Security monitoring platforms
  • Experience developing and improving detection content and alert logic.
  • Strong understanding of incident response processes and cyber security operations.
  • Knowledge of network security concepts and attack methodologies.
  • Excellent analytical, investigative, and problem-solving skills.
  • Strong communication and stakeholder engagement capabilities.
  • Active SC Clearance.

Desirable Skills & Knowledge Experience in one or more of the following areas would be advantageous:

  • Detection Engineering and Alert Development
  • Threat Hunting
  • Threat Intelligence Analysis
  • Security Automation and Orchestration
  • Incident Response Playbook Development
  • Vulnerability Management
  • Cloud Security (AWS, Azure, GCP)
  • Digital Forensics

On-Call Requirement This role includes participation in an on-call rota, averaging approximately one week per month to support priority cyber security incidents.

  • Additional compensation is provided for on-call participation.
  • Frequency may vary depending on project requirements.

Reasonable Adjustments

Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients.

If you need any help or adjustments during the recruitment process for any reason,**please let us know when you apply or talk to the recruiters directly so we can support you.*

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in London

Why this fits a police background

  • Police experience explicitly valued
  • Intelligence & OSINT
  • Incident command & response
  • Investigative casework
  • Digital forensics & cybercrime

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • £35,000 – £40,000Estimated

    Your risk assessment and incident management skills from policing are directly applicable to this GRC role.

    Posted 3 days ago

  • Full-time

    Your incident command and multi-agency coordination experience translates directly to operational resilience and third-party oversight.

    Posted 3 days ago

  • Full-time

    Your investigative mindset and evidence-handling discipline from policing transfer directly to digital forensics and incident response.

    Posted 5 days ago

  • GRC Manager - 6 month FTC

    Trayport · London

    Full-time

    Your experience managing risk, policy, and regulatory compliance under frameworks like PACE transfers directly to GRC.

    Posted 6 days ago