Resume and JobRESUME AND JOB
BAE Systems logo

SOC Engineering Lead

BAE Systems

Software and Technology Jobs

SOC Engineering Lead

full-timePosted: Jan 7, 2026

Job Description

 

Location(s): UK, Europe & Africa : UK : London || UK, Europe & Africa : UK : Leeds 

 

BAE Systems Digital Intelligence is home to 4,500 digital, cyber and intelligence experts. We work collaboratively across 10 countries to collect, connect and understand complex data, so that governments, nation states, armed forces and commercial businesses can unlock digital advantage in the most demanding environments.
 

 

Job Title: SOC Engineering Lead

Requisition ID: 122577

Location: London We offer a range of hybrid and flexible working arrangements – please speak to your recruiter about the options for this particular role.

Grade: GG11

Referral Bonus: £5,000

 

SOC Engineering Lead

 

Role description

 

BAE Systems are bidding to undertake the day to day operation of (and incremental improvement of) a dedicated Security Operations Centre (SOC) to support the defence of a major UK CNI organisation.  The networks protected are predominantly hosted in Azure cloud platforms, with many systems within these environments that must be protected.  The customer is committed to development of this improved SOC to be a benchmark of best practice and excellence in reflection of the significant threat that the protected systems are subject to.

The SOC will be staffed by a blend of customer and BAE Systems staff, based in multiple locations, but with the day to day operations both remotely and in the customer’s premises.

These roles require a minimum of SC clearance.  Due to timelines for the start of operations, it will not be possible to sponsor new clearances so candidates must have existing clearances.

The SOC Engineering lead is responsible for planning and managing development, testing and implementation activities for both day to day activities – delivering new / updated rules and analytics for the Azure SIEM and SOAR platforms, and production of playbooks leading the Analytics and Rules (A&R) Teams prioritising and coordinating their activities across the various projects / releases – as well as long term improvement upgrades and activities.

The day-to-day focus of the Engineering team which you will manage day to day is working with the Protective Monitoring, Threat Intelligence and wider SOC operations Teams to scope and define the requirements for tuning existing security use cases and creating new detection content. This includes planning each release and overseeing all design, development, testing and implementation activities.

The strategic focus of the Engineering Lead is to ensure that the detection and monitoring technology remains optimised, current and tailored to the changing threat landscape, authority risk position and technology in use.

The SOC Engineering Lead is an IT and cyber technical specialist with deep knowledge of the Cyber Monitoring technologies and cyber threat tools, tactics, techniques and procedures and demonstrable experience of prior SOC Engineering roles of a similar nature, with clear understanding of how engineering impacts the people and process aspects of a SOC.

 

 

Responsibilities

 

  • You will help grow and evolve the customer SOC capability by documenting the platforms, feeding back lessons learned and working with the wider team in establishing best practices and repeatable engineering processes.  You will feed back requirements that you have captured during the project continually to appropriate customer and BAE Systems management teams to help to steer the SOC roadmap.
  • You will work with technical project managers, engineers, solution architects, as well as the end-customer senior stakeholders. Given the CNI client focus of this role, flexibility in our designs and delivery methodologies is essential to ensure timely and potentially safety complaint delivery to the customer’s satisfaction.
  • Oversee deployment / implementation activities ensuring that entry criteria are met, all planned activities are completed and that rollback plans are initiated where required.
  • Develop, test and deploy updated and new content across the monitored estate in liaison with the Operations teams.
  • Take playbooks from the wider SOC teams, develop technical aspects, seek approval, and deploy – sometimes directly and sometimes as am mentor to the team.
  • Accountable for the maintenance of existing detection content to ensure it remains current and relevant to the monitored estate.
  • Assess the effectiveness of new / updated rules and analytics to feed into future development activities.
  • Review and approve all required documentation as part of a release or change including design, deployment, configuration and administration guides.
  • Oversee and remain responsible for the maintenance of underlying Azure and off-Azure infrastructure related to the SOC.
  • Obtain authorisation for implementing releases and changes through the Change Management process for ICT and SOC component changes.

 

Requirements

 

Technical

 

  • Strong knowledge of how Azure security functions work as security controls as well as detection tools to protect large cloud estates; Produce content and playbooks on Sentinal to detect security breaches and recognise the importance of threat led Use Cases.
  • Knowledge of SIEM/SOAR tools (Sentinel at a minimum) and other appropriate tooling e.g. SOAR, Threat Intelligence, traffic analysis tools etc. to identify signs of an intrusion, and advise where new/improved tooling could enhance the SOC operation
  • Deep knowledge and experience of operational ICT service delivery management.
  • Working with a range of security tooling/technology
  • Strong understanding of security architecture, in particular networking
  • Detailed understanding of threat intelligence and threat actors, TTPs and operationalising threat intelligence.
  • Understand TCP/IP component layers to identify normal and abnormal traffic
  • Experience of undertaking SOC Analyst activities would be beneficial
  • Experience developing wider SIEM/SOAR content highly desirable

 

Non-technical

  • Client side consulting, including stakeholder engagement and the ability to communicate insights and concepts to others (including briefing skills and report writing)
  • Team Leadership
  • Coaching mindset – help and mentor team
  • Security process development
  • Able to understand and adapt to different cultures and hierarchical structures.
  • Self-starter and capable of independent working
  • Team player and adept at working in multi-disciplinary and diverse teams

 

Why BAE Systems?

This is a place where you’ll be able to make a real difference. You’ll be part of an inclusive culture that values diversity, rewards integrity, and merit, and where you’ll be empowered to fulfil your potential. We welcome candidates from all backgrounds and particularly from sections of the community who are currently underrepresented within our industry, including women, ethnic minorities, people with disabilities and LGBTQ+ individuals.

We also want to make sure that our recruitment processes are as inclusive as possible. If you have a disability or health condition (for example dyslexia, autism, an anxiety disorder etc.) that may affect your performance in certain assessment types, please speak to your recruiter about potential reasonable adjustments.”

PLEASE NOTE: You're expected to have completed 12 months in role prior to applying for an advertised vacancy and you should also discuss the internal opportunity with your line manager to ensure sustained business continuity and to further support your career development. We know there may be individual circumstances that impact this, so please discuss this with your line manager or HR Business Partner (HRBP). If you don't feel you can talk to your line manager, you can contact your HRBP.

Should you be invited for interview, you will be giving consent for the Recruitment team to contact you and your line manager regarding your application for this opportunity.

 

This vacancy is eligible for the UK Employee Referral Scheme. Amount: £5000

 

Life at BAE Systems Digital Intelligence 

We are embracing Hybrid Working. This means you and your colleagues may be working in different locations, such as from home, another BAE Systems office or client site, some or all of the time, and work might be going on at different times of the day.

By embracing technology, we can interact, collaborate and create together, even when we’re working remotely from one another. Hybrid Working allows for increased flexibility in when and where we work, helping us to balance our work and personal life more effectively, and enhance well-being.

Diversity and inclusion are integral to the success of BAE Systems Digital Intelligence. We are proud to have an organisational culture where employees with varying perspectives, skills, life experiences and backgrounds – the best and brightest minds – can work together to achieve excellence and realise individual and organisational potential.

Division overview: Government

At BAE Systems Digital Intelligence, we pride ourselves in being a leader in the cyber defence industry, and Government contracts are an area we have many decades of experience in. Government and key infrastructure networks are critical targets to defend as the effects of these networks being breached can be devastating.

As a member of the Government business unit, you will defend the connected world and ensure the protection of nations. We all have a role to play in defending our clients, and this is yours.

 

 

Locations

  • London, United Kingdom

Salary

Estimated Salary Rangemedium confidence

70,000 - 90,000 GBP / yearly

Source: ai estimated

* This is an estimated range based on market data and may vary based on experience and qualifications.

Skills Required

  • Strong knowledge of Azure security functionsintermediate
  • Knowledge of SIEM/SOAR toolsintermediate
  • Operational ICT service delivery managementintermediate
  • Security architecture understandingintermediate
  • Threat intelligence and TTPs knowledgeintermediate
  • TCP/IP component layers understandingintermediate
  • Client side consulting and stakeholder engagementintermediate
  • Team Leadershipintermediate
  • Coaching and mentoringintermediate
  • Security process developmentintermediate
  • Cultural adaptabilityintermediate
  • Self-starter and independent workingintermediate
  • Team player in multi-disciplinary teamsintermediate

Required Qualifications

  • Strong knowledge of Azure security functions as security controls and detection tools (experience)
  • Knowledge of SIEM/SOAR tools, particularly Sentinel (experience)
  • Deep knowledge and experience of operational ICT service delivery management (experience)
  • Strong understanding of security architecture, particularly networking (experience)
  • Detailed understanding of threat intelligence, threat actors, TTPs, and operationalising threat intelligence (experience)
  • Understanding of TCP/IP component layers to identify normal and abnormal traffic (experience)
  • Existing SC clearance (experience)

Preferred Qualifications

  • Experience of undertaking SOC Analyst activities (experience)
  • Experience developing wider SIEM/SOAR content (experience)
  • Client side consulting experience (experience)
  • Team Leadership experience (experience)
  • Coaching mindset (experience)

Responsibilities

  • Document platforms and feed back lessons learned to evolve the customer SOC capability
  • Work with technical project managers, engineers, solution architects, and end-customer senior stakeholders
  • Oversee deployment and implementation activities ensuring entry criteria are met
  • Develop, test, and deploy updated and new content across the monitored estate
  • Take playbooks from SOC teams, develop technical aspects, seek approval, and deploy
  • Maintain existing detection content to ensure it remains current and relevant
  • Assess the effectiveness of new/updated rules and analytics
  • Review and approve required documentation as part of releases or changes
  • Oversee maintenance of underlying Azure and off-Azure infrastructure related to the SOC
  • Obtain authorisation for implementing releases and changes through the Change Management process

Benefits

  • general: Hybrid and flexible working arrangements
  • general: Inclusive culture that values diversity and rewards integrity
  • general: Employee Referral Scheme with a £5,000 bonus
  • general: Support for career development and internal opportunities

Target Your Resume for "SOC Engineering Lead" , BAE Systems

Get personalized recommendations to optimize your resume specifically for SOC Engineering Lead. Takes only 15 seconds!

AI-powered keyword optimization
Skills matching & gap analysis
Experience alignment suggestions

Check Your ATS Score for "SOC Engineering Lead" , BAE Systems

Find out how well your resume matches this job's requirements. Get comprehensive analysis including ATS compatibility, keyword matching, skill gaps, and personalized recommendations.

ATS compatibility check
Keyword optimization analysis
Skill matching & gap identification
Format & readability score

Tags & Categories

Digital IntelligenceConsultingExperienced professionalsDigital IntelligenceConsultingExperienced professionals

Answer 10 quick questions to check your fit for SOC Engineering Lead @ BAE Systems.

Quiz Challenge
10 Questions
~2 Minutes
Instant Score

Related Books and Jobs

No related jobs found at the moment.

BAE Systems logo

SOC Engineering Lead

BAE Systems

Software and Technology Jobs

SOC Engineering Lead

full-timePosted: Jan 7, 2026

Job Description

 

Location(s): UK, Europe & Africa : UK : London || UK, Europe & Africa : UK : Leeds 

 

BAE Systems Digital Intelligence is home to 4,500 digital, cyber and intelligence experts. We work collaboratively across 10 countries to collect, connect and understand complex data, so that governments, nation states, armed forces and commercial businesses can unlock digital advantage in the most demanding environments.
 

 

Job Title: SOC Engineering Lead

Requisition ID: 122577

Location: London We offer a range of hybrid and flexible working arrangements – please speak to your recruiter about the options for this particular role.

Grade: GG11

Referral Bonus: £5,000

 

SOC Engineering Lead

 

Role description

 

BAE Systems are bidding to undertake the day to day operation of (and incremental improvement of) a dedicated Security Operations Centre (SOC) to support the defence of a major UK CNI organisation.  The networks protected are predominantly hosted in Azure cloud platforms, with many systems within these environments that must be protected.  The customer is committed to development of this improved SOC to be a benchmark of best practice and excellence in reflection of the significant threat that the protected systems are subject to.

The SOC will be staffed by a blend of customer and BAE Systems staff, based in multiple locations, but with the day to day operations both remotely and in the customer’s premises.

These roles require a minimum of SC clearance.  Due to timelines for the start of operations, it will not be possible to sponsor new clearances so candidates must have existing clearances.

The SOC Engineering lead is responsible for planning and managing development, testing and implementation activities for both day to day activities – delivering new / updated rules and analytics for the Azure SIEM and SOAR platforms, and production of playbooks leading the Analytics and Rules (A&R) Teams prioritising and coordinating their activities across the various projects / releases – as well as long term improvement upgrades and activities.

The day-to-day focus of the Engineering team which you will manage day to day is working with the Protective Monitoring, Threat Intelligence and wider SOC operations Teams to scope and define the requirements for tuning existing security use cases and creating new detection content. This includes planning each release and overseeing all design, development, testing and implementation activities.

The strategic focus of the Engineering Lead is to ensure that the detection and monitoring technology remains optimised, current and tailored to the changing threat landscape, authority risk position and technology in use.

The SOC Engineering Lead is an IT and cyber technical specialist with deep knowledge of the Cyber Monitoring technologies and cyber threat tools, tactics, techniques and procedures and demonstrable experience of prior SOC Engineering roles of a similar nature, with clear understanding of how engineering impacts the people and process aspects of a SOC.

 

 

Responsibilities

 

  • You will help grow and evolve the customer SOC capability by documenting the platforms, feeding back lessons learned and working with the wider team in establishing best practices and repeatable engineering processes.  You will feed back requirements that you have captured during the project continually to appropriate customer and BAE Systems management teams to help to steer the SOC roadmap.
  • You will work with technical project managers, engineers, solution architects, as well as the end-customer senior stakeholders. Given the CNI client focus of this role, flexibility in our designs and delivery methodologies is essential to ensure timely and potentially safety complaint delivery to the customer’s satisfaction.
  • Oversee deployment / implementation activities ensuring that entry criteria are met, all planned activities are completed and that rollback plans are initiated where required.
  • Develop, test and deploy updated and new content across the monitored estate in liaison with the Operations teams.
  • Take playbooks from the wider SOC teams, develop technical aspects, seek approval, and deploy – sometimes directly and sometimes as am mentor to the team.
  • Accountable for the maintenance of existing detection content to ensure it remains current and relevant to the monitored estate.
  • Assess the effectiveness of new / updated rules and analytics to feed into future development activities.
  • Review and approve all required documentation as part of a release or change including design, deployment, configuration and administration guides.
  • Oversee and remain responsible for the maintenance of underlying Azure and off-Azure infrastructure related to the SOC.
  • Obtain authorisation for implementing releases and changes through the Change Management process for ICT and SOC component changes.

 

Requirements

 

Technical

 

  • Strong knowledge of how Azure security functions work as security controls as well as detection tools to protect large cloud estates; Produce content and playbooks on Sentinal to detect security breaches and recognise the importance of threat led Use Cases.
  • Knowledge of SIEM/SOAR tools (Sentinel at a minimum) and other appropriate tooling e.g. SOAR, Threat Intelligence, traffic analysis tools etc. to identify signs of an intrusion, and advise where new/improved tooling could enhance the SOC operation
  • Deep knowledge and experience of operational ICT service delivery management.
  • Working with a range of security tooling/technology
  • Strong understanding of security architecture, in particular networking
  • Detailed understanding of threat intelligence and threat actors, TTPs and operationalising threat intelligence.
  • Understand TCP/IP component layers to identify normal and abnormal traffic
  • Experience of undertaking SOC Analyst activities would be beneficial
  • Experience developing wider SIEM/SOAR content highly desirable

 

Non-technical

  • Client side consulting, including stakeholder engagement and the ability to communicate insights and concepts to others (including briefing skills and report writing)
  • Team Leadership
  • Coaching mindset – help and mentor team
  • Security process development
  • Able to understand and adapt to different cultures and hierarchical structures.
  • Self-starter and capable of independent working
  • Team player and adept at working in multi-disciplinary and diverse teams

 

Why BAE Systems?

This is a place where you’ll be able to make a real difference. You’ll be part of an inclusive culture that values diversity, rewards integrity, and merit, and where you’ll be empowered to fulfil your potential. We welcome candidates from all backgrounds and particularly from sections of the community who are currently underrepresented within our industry, including women, ethnic minorities, people with disabilities and LGBTQ+ individuals.

We also want to make sure that our recruitment processes are as inclusive as possible. If you have a disability or health condition (for example dyslexia, autism, an anxiety disorder etc.) that may affect your performance in certain assessment types, please speak to your recruiter about potential reasonable adjustments.”

PLEASE NOTE: You're expected to have completed 12 months in role prior to applying for an advertised vacancy and you should also discuss the internal opportunity with your line manager to ensure sustained business continuity and to further support your career development. We know there may be individual circumstances that impact this, so please discuss this with your line manager or HR Business Partner (HRBP). If you don't feel you can talk to your line manager, you can contact your HRBP.

Should you be invited for interview, you will be giving consent for the Recruitment team to contact you and your line manager regarding your application for this opportunity.

 

This vacancy is eligible for the UK Employee Referral Scheme. Amount: £5000

 

Life at BAE Systems Digital Intelligence 

We are embracing Hybrid Working. This means you and your colleagues may be working in different locations, such as from home, another BAE Systems office or client site, some or all of the time, and work might be going on at different times of the day.

By embracing technology, we can interact, collaborate and create together, even when we’re working remotely from one another. Hybrid Working allows for increased flexibility in when and where we work, helping us to balance our work and personal life more effectively, and enhance well-being.

Diversity and inclusion are integral to the success of BAE Systems Digital Intelligence. We are proud to have an organisational culture where employees with varying perspectives, skills, life experiences and backgrounds – the best and brightest minds – can work together to achieve excellence and realise individual and organisational potential.

Division overview: Government

At BAE Systems Digital Intelligence, we pride ourselves in being a leader in the cyber defence industry, and Government contracts are an area we have many decades of experience in. Government and key infrastructure networks are critical targets to defend as the effects of these networks being breached can be devastating.

As a member of the Government business unit, you will defend the connected world and ensure the protection of nations. We all have a role to play in defending our clients, and this is yours.

 

 

Locations

  • London, United Kingdom

Salary

Estimated Salary Rangemedium confidence

70,000 - 90,000 GBP / yearly

Source: ai estimated

* This is an estimated range based on market data and may vary based on experience and qualifications.

Skills Required

  • Strong knowledge of Azure security functionsintermediate
  • Knowledge of SIEM/SOAR toolsintermediate
  • Operational ICT service delivery managementintermediate
  • Security architecture understandingintermediate
  • Threat intelligence and TTPs knowledgeintermediate
  • TCP/IP component layers understandingintermediate
  • Client side consulting and stakeholder engagementintermediate
  • Team Leadershipintermediate
  • Coaching and mentoringintermediate
  • Security process developmentintermediate
  • Cultural adaptabilityintermediate
  • Self-starter and independent workingintermediate
  • Team player in multi-disciplinary teamsintermediate

Required Qualifications

  • Strong knowledge of Azure security functions as security controls and detection tools (experience)
  • Knowledge of SIEM/SOAR tools, particularly Sentinel (experience)
  • Deep knowledge and experience of operational ICT service delivery management (experience)
  • Strong understanding of security architecture, particularly networking (experience)
  • Detailed understanding of threat intelligence, threat actors, TTPs, and operationalising threat intelligence (experience)
  • Understanding of TCP/IP component layers to identify normal and abnormal traffic (experience)
  • Existing SC clearance (experience)

Preferred Qualifications

  • Experience of undertaking SOC Analyst activities (experience)
  • Experience developing wider SIEM/SOAR content (experience)
  • Client side consulting experience (experience)
  • Team Leadership experience (experience)
  • Coaching mindset (experience)

Responsibilities

  • Document platforms and feed back lessons learned to evolve the customer SOC capability
  • Work with technical project managers, engineers, solution architects, and end-customer senior stakeholders
  • Oversee deployment and implementation activities ensuring entry criteria are met
  • Develop, test, and deploy updated and new content across the monitored estate
  • Take playbooks from SOC teams, develop technical aspects, seek approval, and deploy
  • Maintain existing detection content to ensure it remains current and relevant
  • Assess the effectiveness of new/updated rules and analytics
  • Review and approve required documentation as part of releases or changes
  • Oversee maintenance of underlying Azure and off-Azure infrastructure related to the SOC
  • Obtain authorisation for implementing releases and changes through the Change Management process

Benefits

  • general: Hybrid and flexible working arrangements
  • general: Inclusive culture that values diversity and rewards integrity
  • general: Employee Referral Scheme with a £5,000 bonus
  • general: Support for career development and internal opportunities

Target Your Resume for "SOC Engineering Lead" , BAE Systems

Get personalized recommendations to optimize your resume specifically for SOC Engineering Lead. Takes only 15 seconds!

AI-powered keyword optimization
Skills matching & gap analysis
Experience alignment suggestions

Check Your ATS Score for "SOC Engineering Lead" , BAE Systems

Find out how well your resume matches this job's requirements. Get comprehensive analysis including ATS compatibility, keyword matching, skill gaps, and personalized recommendations.

ATS compatibility check
Keyword optimization analysis
Skill matching & gap identification
Format & readability score

Tags & Categories

Digital IntelligenceConsultingExperienced professionalsDigital IntelligenceConsultingExperienced professionals

Answer 10 quick questions to check your fit for SOC Engineering Lead @ BAE Systems.

Quiz Challenge
10 Questions
~2 Minutes
Instant Score

Related Books and Jobs

No related jobs found at the moment.