SOC Architect
Datasource London, United KingdomSOC Architect
Introduction
Our client is one of the most recognised names in digital and technology consultancy - a firm operating at serious scale, with a cyber practice of over 450 specialists in the UK alone, sitting inside a Technology and Transformation business of 7,500 people. You'll be joining a team that's passionate about cyber security, comfortable working at pace, and focused on solving the toughest security challenges facing major organisations today.
The work spans Next-Gen Detection and Response, operating model design, SIEM and SOAR tooling, and everything in between. you'll need deep hands-on experience in security operations architecture, a solid grasp of architecture frameworks like TOGAF, and real-world exposure to SIEM and SOAR platforms.
Working Patterns and location - Hybrid - 2-3 days on site per week
Key responsibilities
• Design and continuously improve Next-Gen Detection and Response capabilities for clients.
• Define architectural blueprints to guide engineers on implementation and tooling.
• Lead threat detection and response strategies, deciding the best course of action against threats.
• Develop processes, governance and ways of working to support the target operating model.
• Collaborate with Engineers and Threat Hunters to analyse dashboard data and drive continuous improvement.
• Lead migration and implementation strategies and plans for security solutions.
• Research emerging tools and approaches to keep detection and response capabilities cutting edge.
• Support clients in evolving their security operating models and refining tooling selection.
Skills & experience
• Strong experience in Security Operations architecture and Next-Gen Detection and Response design.
• Solid understanding of Security Operations Centres and working within or alongside a SOC.
• Experience producing High Level Design and Low Level Design documentation for security solutions.
• Experience working with architecture frameworks, ideally TOGAF.
• Hands-on experience with multiple SIEM and SOAR platforms, preferably Google SecOps.
• Experience with EDR, XDR and NDR tooling such as CrowdStrike, Corelight or Microsoft Defender XDR.
• Experience working across hyperscaler cloud environments.
• Strong written, verbal and presentation skills - comfortable engaging from end users to board level.
The client would also like to see some of the below, but this is not essential:
• Experience working within Agile, DevOps or Kanban delivery environments.
• Professional Cloud Architect Certification from a major hyperscaler provider.
• Experience in a consultancy or client-facing advisory environment.
• Relevant cyber security qualifications such as CISSP, CISM or equivalent.
Additional benefits
• 26 days Annual Leave plus Bank Holidays.
• Pension contribution matched up to 8%.
• Private Medical Insurance.
• Overseas Working Policy - If you have the right to work in another country, can request up to 20 days each year to work remotely.
• Yearly On Target Bonus.
• Season Ticket Loans.
• Paid professional subscription.
• Life Assurance.
Our client is committed to providing a diverse and inclusive workplace and welcomes applications from all backgrounds.
Part-time opportunities/flexible working is available to suit individual needs.
RECOMMEND A FRIEND: If you have professional friends/colleagues who would be interested in one of our roles and our excellent levels of service too, we'd like to recognise your recommendations with a 'thank you' of our own. For every friend you refer who then starts a role through Datasource either Contract or Permanent, we will send you £200 of Love to Shop Gift Vouchers & gift your friend £100 in Love to Shop Gift Vouchers as well!
You will be required to hold a minimum of SC Clearance. If you do not hold an active SC Clearance, please familiarise yourself with the vetting process before applying.
(c) Copyright Datasource Computer Employment Limited 2026.