Proact Group logo

Senior Security Operations Analyst

Hiring from
United Kingdom
Work type
Hybrid
Posted
Sep 29, 2026
Is this job info correct?

About Proact

Proact is Europe’s leading independent data centre and cloud services provider. By delivering flexible, secure, and accessible IT solutions and services, Proact enables organisations to reduce risk and cost while increasing agility, productivity, and operational efficiency. Proact’s ambition is to support business agility and to become the world’s most trusted IT services partner.

While technology underpins Proact’s services, trust itself is built by people. Proact recognises that its success is driven by the talent, commitment, and collaboration of its people, working together towards a shared purpose. It is through the expertise and dedication of these individuals that Proact delivers lasting value for customers.

About the SOC Team

Proact’s Security Operations Centre (SOC) is comprised of skilled professionals with experience across a wide range of mainstream platforms, as well as specialist and niche technologies, covering a broad spectrum of security services and governance, risk, and compliance. The team combines deep technical expertise with proven operational and process capability to deliver robust and effective security outcomes.

The SOC operates 24x7x365, providing continuous monitoring and response capabilities. Within the SOC, the Operations function plays a central role in the investigation and response to security events, supporting both Proact and customer environments.

The Operations function within the SOC supports a dedicated Graduate programme, where continuous education and mentoring are core priorities delivered collaboratively by the wider team. This approach develops strong foundational skills and ensures sustainable, long‑term capability within the SOC.

The SOC plays a central role across the full breadth of security, maintaining strong expertise in security standards, solution architecture, threat assessment, and vulnerability management. This expertise underpins effective collaboration with Proact’s Service Operations teams and enables the delivery of cohesive, secure services to customers.

Role Summary

This is a temporary opportunity covering an internal secondment for an anticipated period of approximately 14 months. The successful candidate will join Proact's 24x7x365 Security Operations Centre, working a shift pattern of four days on, four days off, comprising 12-hour shifts, including weekends and public holidays. This role provides an opportunity to play a key part in the monitoring, investigation, response, and continuous improvement of security operations across both Proact and customer environments.

Personal Skills

This role requires a highly self-motivated individual who can also motivate and inspire others. The successful candidate will be able to effectively manage multiple tasks and competing priorities across a range of timelines, while also demonstrating the ability to focus exclusively on high-priority activities when required.

Excellent verbal and written communication skills are essential, along with a strong attention to detail in planning, implementation, documentation, and follow-up. Candidates must be capable of working both independently and collaboratively as part of a team, adapting their approach to suit the needs of the business.

The ideal candidate will be reliable, punctual, personable, and customer-focused, with the ability to remain calm, patient, and professional when providing phone-based technical support. They should be comfortable working in both remote and in-person environments and possess the flexibility to quickly adapt to changing priorities and switch effectively between tasks.


A positive and energetic attitude, combined with a genuine desire to learn and continuously develop new skills, is essential for success in this role.

Professional Skills and Experience

  • At least three years' experience working within a Security Operations Centre (SOC), with demonstrable experience investigating, managing, and responding to security incidents within an operational environment.

  • Strong understanding of Security Operations Centre processes, incident lifecycle management, alert triage, threat detection, and incident response.

  • Hands-on experience working with Security Information and Event Management (SIEM) platforms, preferably Microsoft Sentinel.

  • Working with Microsoft security technologies, including Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, Microsoft Defender for Cloud, and Microsoft Entra.

  • Conducting proactive threat hunting activities using security telemetry, threat intelligence, and behavioural analysis techniques.

  • Investigating and responding to advanced threats, including phishing, malware, ransomware, compromised accounts, insider threats, and suspicious network activity.

  • Detection engineering, including the development, tuning, testing, and optimisation of detection logic, analytics rules, correlation searches, use cases, and alerting mechanisms to improve detection coverage and reduce false positives.

  • Experience with additional SIEM and security monitoring platforms, such as Splunk, IBM QRadar, LogRhythm, Elastic, Google Chronicle, ArcSight, or similar technologies, would be advantageous.

  • Strong understanding of change control and change management principles, ensuring changes are implemented in a controlled and coordinated manner while promoting adherence to established processes and best practices.

  • Mentoring, coaching, or supporting the development of less experienced analysts would be advantageous.

Core Responsibilities

  • Conduct threat hunting and incident response activities to identify, investigate, and mitigate security threats.

  • Monitor, investigate, and respond to security alerts generated through Microsoft Sentinel, Microsoft Defender, and other security monitoring technologies.

  • Lead complex incident investigations and coordinate response activities across technical and business stakeholders.

  • Act as a key point of contact, collaborator, and escalation path for Security Operations, Security Engineering, Service Operations, and other business teams.

  • Provide senior technical and process guidance to Security Operations Analysts, acting as an escalation point for complex issues and incidents.

  • Mentor junior analysts and graduates, supporting their technical development and operational effectiveness.

  • Deliver and support both individual and collaborative projects and operational tasks.

  • Lead by example in day-to-day Security Operations activities, supporting team objectives and maintaining high operational standards.

  • Perform proactive threat hunting activities using telemetry from Microsoft Defender and other security platforms.

  • Develop and improve detection logic, analytics rules, automation playbooks, workbooks, and SOC operational processes.

  • Maintain and develop expertise through relevant training and industry-recognised certifications.

  • Contribute to the development, review, and continuous improvement of security processes, procedures, and policies.

  • Work as part of the SOC's 24x7x365 shift rota, consisting of 12-hour shifts on a four-on, four-off basis, including weekends and public holidays.

Additional Duties

  • Contribute to the response to security incidents, with a proactive focus on root cause analysis and the prevention of recurrence.

  • Willingness to travel occasionally to other Proact offices to support collaboration, knowledge sharing, and cross-team engagement.

  • Support knowledge-sharing initiatives across the wider SOC, contributing to team capability, operational maturity, and continuous improvement.

Benefits

  • Comprehensive private healthcare cover

  • Company pension scheme

  • 33 days' annual leave inclusive of UK bank holidays

  • 3 fully paid charity days per year

  • Option to purchase up to 5 additional days of annual leave

  • Company-provided laptop and mobile phone

Similar jobs

Apply for this job