SOC Manager
GCS
Job Description
A leading gaming sector organisation undergoing a significant cybersecurity transformation. The SOC has recently transitioned from a third-party MSSP to a fully in-house 24/7 operation. Operating under strict Gaming Commission oversight, this is one of the UK's most highly regulated environments, with a strong focus on resilience, compliance, and operational excellence.
Key responsibilities β’ Lead, mentor, and develop a team of SOC analysts in a 24/7 operational environment across a three-shift rotation β’ Own and enhance incident detection and response capabilities β’ Act as senior decision-maker during major incidents and crisis situations β’ Develop and implement SOC use cases aligned to the MITRE ATT&CK framework β’ Drive continuous improvement across SOC processes, tooling, and playbooks β’ Collaborate with Security Engineering to optimise detection pipelines β’ Build strong relationships with stakeholders across technology and the wider business β’ Partner with the Major Incident Manager on critical security events β’ Support regulatory compliance, audit requirements, and contribute to strategic direction Experience β’ Proven experience managing SOC or security operations teams β’ Strong background in incident response and crisis management β’ Background in highly regulated environments (Gaming, Financial Services, Utilities) Technical skills β’ Demonstrated ability to operate effectively in high-pressure situations Technical skills β’ SIEM platforms β Sentinel, Splunk, Elastic or similar β’ SOC operations, detection engineering, and security tooling β’ MITRE ATT&CK framework and use case development β’ Demonstrated ability to operate effectively in high-pressure situations β’ Security pipelines, integrations, and emerging AI/LLM in cybersecurity Soft skills β’Strong leadership and people development capabilities β’ Confident and decisive under pressure β’ Excellent stakeholder management and communication β’ Collaborative, personable, and resilient mindset Technical environment β’ SIEM platforms β Microsoft Sentinel, Splunk, Elastic (SIEM transition in progress; training provided) β’ Modern security operations tooling and detection engineering practices β’ Emerging focus on AI/LLM applications within security operations Working arrangements β’ Hybrid model β minimum 1 day per week onsite in Warrington β’ Flexibility offered, with initial emphasis on building strong in-person relationships β’ New state-of-the-art office and dedicated SOC facility opening May/June 2026