Senior SOC Analyst

Reposted 4 Days Ago
Be an Early Applicant
London, Greater London, England, GBR
Hybrid
Senior level
eCommerce
The Role
The role involves developing SOC processes, managing security incidents, collaborating with teams, handling vulnerabilities, and reporting metrics.
Summary Generated by Built In
About Motorway

Motorway is the UK’s fastest-growing used car marketplace - our online-only platform connects private car sellers with thousands of verified dealers nationwide, ensuring everyone gets the best deal. Founded in 2017, our award-winning, technology-led approach has redefined the experience of selling a car. Motorway is backed by some of the world’s leading technology investors, having raised £143 million in Series C funding.

This is a unique opportunity to join a fast-growing scale-up at a crucial phase of growth and help change an industry for the better.

About the role

We’re looking for an experienced Senior SOC Analyst to assist in the development, enhancement and execution of our Security Operations capability. The successful candidate will develop SOC processes, procedures and workflows for systems security monitoring and security incident response. This role will work collaboratively with other business technical and non-technical teams.

The role will involve:
  • Triage & Analysis: This is the bread and butter. The focus here should be on MTTD (Mean Time to Detect).

  • End-to-End IR: Leading incidents requires not just technical skill, but "Incident Commander"

  • Vulnerability & Threat Hunting: This is proactive. Instead of waiting for an alarm, the lead should be searching for "indicators of compromise" (IoCs) based on recent threat intelligence.

  • Runbook Development: If a process is done more than twice, it should be in a runbook. In 2026, these are often "Executable Runbooks" (Python/Bash) rather than just PDFs.

  • Tooling & Alarms: This involves the maintenance of your SIEM/SOAR.

  • Coverage & Noise Reduction: This is critical for preventing "SOC Fatigue." A lead must ruthlessly tune out "false positives" so the team only sees high-fidelity alerts.

  • Platform & Software Engineering: This is the "Shift Left" approach.

    • Platform: Ensuring Kubernetes/Cloud environments are hardened.

    • Software: Implementing Secure by Design (e.g., automated SAST/DAST in the CI/CD pipeline).

  • Tabletops & War Games: You don't want the first time a team handles a ransomware attack to be during a real one. Regular exercises are the NCSC-recommended way to build "muscle memory."

  • Audit & Metrics: Developing dashboards that show MTTR (Mean Time to Respond) and Vulnerability Burn-down rates for the Head of Sec.

Requirements:
  • Secure by Design: Act as a security champion for Software and Platform Engineering teams to ensure "Security-as-Code" is integrated into CI/CD pipelines.

  • Advanced Threat Hunting: Proven ability to proactively hunt for threats using the MITRE ATT&CK framework, rather than solely relying on automated alerts.

  • Cloud Security Operations: Hands-on experience securing AWS and GCP environments. You must be comfortable with cloud-native logging and security tooling ( Chronicle).

  • Forensics & Investigation: Mastery of deep-dive systems forensics on both Windows and macOS. You should be able to reconstruct a timeline of events from memory dumps and filesystem artefacts.

  • Automation & Scripting: Proficiency in Python or Go for automating SOC workflows (SOAR) and creating custom detection logic via SQL or Sigma rules.

  • Modern Observability: Experience with developer-centric observability tools (e.g., Logfire, OpenTelemetry) to monitor LLM interactions and API security.

  • Audit & Reporting: Ability to develop and maintain automated dashboards for MTTR (Mean Time to Respond) and MTTD (Mean Time to Detect) for executive reporting.

  • Incident Commander: Ability to lead high-severity incidents end-to-end, managing technical workstreams while providing clear, non-technical updates to senior stakeholders.

  • Detection Engineering: Expertise in tuning SIEM/EDR (e.g.,Wiz, CrowdStrike, NetSkope) to reduce noise and maintain "data freshness."

  • Playbook Development: Proven experience designing and implementing executable runbooks that standardise response for ransomware, phishing, and cloud-account takeovers.

  • Infrastructure Knowledge: Strong understanding of network protocols (TLS 1.3), API security (OAuth/OIDC), and container security (Kubernetes/Docker).

  • Readiness Exercises: Experience organising and running Tabletop Exercises and "War Games" to test organisational resilience.

  • Mentorship: A commitment to up-skilling junior analysts and fostering a culture of continuous learning and technical excellence.

  • Standards: Good working knowledge of ISO27001, NIST CSF, and PCI DSS v4.0 (specifically 3rd-party compliance).

Benefits
  • A competitive salary

  • BUPA health insurance

  • Discounted gym membership through BUPA

  • OnHand volunteering membership and one paid volunteering day per year

  • Hybrid working

  • Pension scheme

  • Motorway car leasing scheme - lease a zero-emissions electric vehicle at a significant discount

  • Enhanced parental leave - We offer enhanced maternity pay (26 weeks of full pay) and enhanced paternity pay (4 weeks of full pay) to eligible employees.

  • Workplace nursery scheme

  • Regular social events

  • Cycle to work scheme

Equal opportunities statement

We are committed to equality of opportunity for all employees. We work to provide a supportive and inclusive environment where people can maximise their full potential. We believe our workforce should reflect a variety of backgrounds, talents, perspectives and experiences. Our strong commitment to a culture of inclusion is evident through our constant focus on recruiting, developing and advancing individuals based on their skills and talents.

We welcome applications from all individuals regardless of age, disability, sex, gender reassignment, sexual orientation, pregnancy and maternity, race, religion or belief and marriage and civil partnerships.

Skills Required

  • Proven experience in a Security Operations Centre as a Senior SOC Analyst or experienced Junior
  • Strong knowledge of the information security threat landscape and associated attack vectors
  • Strong knowledge of Incident response planning and playbook design
  • Strong knowledge of threat detection rule design/tuning
  • Good technical knowledge of best practice security for networks, systems, web applications, APIs, and databases
  • Good knowledge and hands-on experience with common security tools like SIEM, endpoint protection, scanners
  • Some technical knowledge of AWS and GCP administration and cloud security operations
  • Some knowledge of security standards and frameworks such as ISO27001, PCI DSS
  • Some Systems forensics and investigation skills (MACOS and Windows)
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Brighton
446 Employees
Year Founded: 2017

What We Do

Motorway started in 2017 with a vision to build a better car market for everyone, harnessing the power of technology to deliver an amazing experience. We're on a journey to make selling used cars better for everyone. With our network of more than 5,000 professional car dealers bidding directly on our platform, we enable customers to sell their car for a great price in as little as 24 hours. We support our car dealer partners to easily acquire the best used car stock. Whilst our customers can sell their car from the comfort of their own home. Since launch, we've helped people sell over 250 thousand cars and the journey's only just begun. This is the way to sell your car. This is the Motorway.

Similar Jobs

Focus Group (UK) Logo Focus Group (UK)

Senior SOC Analyst

Information Technology • Cybersecurity
In-Office
Manchester, Greater Manchester, England, GBR
638 Employees
50K-55K Annually

Darktrace Logo Darktrace

Senior Internal SOC Analyst

Security • Cybersecurity
In-Office
2 Locations
1763 Employees

Capco Logo Capco

Business Analyst

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Hybrid
London, England, GBR
6000 Employees

bet365 Logo bet365

Accountant

Digital Media • Gaming • Software • Esports • Automation
Hybrid
Stoke-on-Trent, Staffordshire, England, GBR
10000 Employees

Similar Companies Hiring

PRIMA Thumbnail
Travel • Software • Marketing Tech • Hospitality • eCommerce
US
15 Employees
Scotch Thumbnail
Artificial Intelligence • eCommerce • Fintech • Payments • Retail • Software • Analytics
US
35 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account