Pen Tester / SOC Analyst

Contract Type:

Location:

 -  

Industry:

Category:

Contact Name:

Contact Email:

Date Published:

04-Oct-2026

About the opportunity

Our client is looking for a security professional who doesn't want to choose between offence and defence. Sitting within its cyber security operations team, this role splits time roughly evenly between authorised penetration testing and Security Operations Centre work.

What makes it different is the feedback loop. The weaknesses you find in testing don't just go into a report; you'll map them to MITRE ATT&CK and use them to validate and improve the telemetry, detections and playbooks the SOC relies on every day. It's a complex, multi-platform environment with a strong Microsoft identity footprint, offering real breadth across applications, infrastructure, identity and cloud.

The role
  • Plan and deliver authorised penetration tests across web apps, APIs, infrastructure, identity services and cloud platforms, under defined Rules of Engagement
  • Monitor and triage alerts across SIEM, EDR and XDR platforms, investigating and escalating confirmed incidents
  • Develop, tune and validate detection rules, use cases, dashboards and response playbooks
  • Run proactive threat hunts using telemetry, threat intelligence and known adversary behaviour
  • Report findings with evidence, risk ratings, remediation advice and re-test outcomes
What you'll bring
  • Proven experience in both penetration testing and security operations within complex enterprise environments
  • Hands-on SIEM, EDR or XDR experience, including triage, incident analysis and escalation
  • Detection engineering experience using KQL, SPL, Sigma or equivalent, and a strong grasp of MITRE ATT&CK
  • Solid knowledge of Active Directory, Entra ID, Microsoft 365, Windows and Linux security
  • A relevant tertiary qualification and current industry security accreditation
Recognised pen testing, SOC, incident response or cloud security certifications are highly regarded, as is Agile delivery experience.

Culture
  • Close collaboration with security engineering, infrastructure, cloud, application, identity, architecture and risk teams
  • A disciplined approach: controlled testing in production under change, escalation and safety requirements
  • An individual contributor role with genuine breadth rather than a narrow specialism
If this sounds like you please apply for the role right away!
APPLY NOW
APPLY NOW
Apply With Button

Share this job

Interested in this job?
Save Job
Create As Alert

Similar Jobs

SCHEMA MARKUP ( This text will only show on the editor. )