Security Operations Manager

  • Full-time

Company Description

We believe in the power of ingenuity to build a positive human future.  

As strategies, technologies, and innovation collide, we create opportunity from complexity. 

Our teams of interdisciplinary experts combine innovative thinking and breakthrough technologies to progress further, faster. Our clients adapt and transform, and together we achieve enduring results. 

We are over 4,000 strategists, innovators, designers, consultants, digital experts, scientists, engineers, and technologists. And we have deep expertise in consumer and manufacturing, defence and security, energy and utilities, financial services, government and public services, health and life sciences, and transport.  

Our teams operate globally from offices across the UK, Ireland, US, Nordics, and Netherlands. 

PA. Bringing Ingenuity to Life. 

Job Description

We are looking for a Security Operations Manager to join our Digital Trust & Cyber Security practice. Working on behalf of our clients, you will lead Security Operations Centre (SOC) analysts and incident response specialists. 

You will combine hands-on operational leadership with advisory work. This means managing live incident containment and day-to-day SOC operations, while helping enterprise and public sector clients modernise their security operations, improve their SIEM, SOAR and EDR capabilities, and build stronger cyber resilience. 

Why consider joining our Digital & Data community? 🤔 

  • Join our Digital & Data team and work alongside cyber security, product, design and technology specialists in cross-disciplinary teams to solve complex client challenges and bring ideas to life. 
  • Build a flexible and distinctive career in a trust-based, inclusive environment that values excellence, innovation and curiosity. You can progress through a technical career track without needing to follow the Partner career track if that does not align with your ambitions. 
  • Work across a broad range of Security Operations engagements, client environments and technology stacks spanning seven sectors. No two projects are the same. 
  • Join a supportive and collaborative cyber and technology community, with knowledge sharing, peer support, coaching and mentoring from other specialists. 
  • Deepen your expertise through our culture of learning and growth, with access to a development budget for technical and non-technical training and professional certifications. 
  • Benefit from a hybrid working approach, with an expectation of being in the office or on a client site for a minimum of two days per week, depending on the role and assignment. 

What you'll do 🌱 

  • Lead and develop SOC analysts and incident response specialists, providing clear operational direction, coaching and support across day-to-day security operations. 
  • Take a hands-on leadership role during cyber security incidents, coordinating investigation, containment, eradication, recovery, stakeholder communications and post-incident reviews. 
  • Help enterprise and public sector clients assess and improve their Security Operations capabilities, identifying gaps across people, processes and technology and translating these into practical improvements. 
  • Advise on the evolution and optimisation of SIEM, SOAR, EDR and threat-detection tooling to improve visibility, reduce noise and strengthen detection and response capabilities. 
  • Develop and maintain incident playbooks, standard operating procedures, automated response workflows and proactive tabletop exercises. 
  • Support the development of modern Security Operations services and ways of working, sharing your expertise across our Digital Trust & Cyber Security community through coaching, mentoring and knowledge sharing. 

Security technologies you'll work with 🚀 

We advocate using the right technology for the right task. Depending on the client environment and engagement, you can expect to work across technologies including: 

  • SIEM and security analytics platforms, such as Microsoft Sentinel and Splunk. 
  • SOAR and security automation technologies used for enrichment, triage and response orchestration. 
  • Endpoint Detection and Response (EDR/XDR) platforms, such as Microsoft Defender for Endpoint and CrowdStrike Falcon. 
  • Threat intelligence, detection engineering, investigation and incident response technologies. 
  • Cloud security monitoring across Microsoft Azure, AWS and GCP environments. 

What you can expect 🌱 

  • Work collaboratively across multiple technical teams and stakeholder groups, using your Security Operations expertise to solve complex client problems and contribute to internal initiatives. 
  • Participate in live, in-person working sessions to investigate incidents, assess operational challenges and design practical improvements, alongside asynchronous collaboration through Microsoft Teams. 
  • Work with the team at client sites or in our offices for a minimum of two days per week. The time you spend and where you work will vary by role and assignment, including the possibility of being on a client site for up to five days per week. 
  • Work in an environment that takes its values seriously and places collaboration, inclusion, learning and client impact at the heart of how teams operate. 

Qualifications

Essential requirements ✅ 

Even if you don’t meet every requirement below, feel free to still apply as we are often hiring for similar roles which your background might be better suited to. 

  • SOC Leadership: Experience running or supervising a SOC, CSOC, or Incident Response team.
  • Incident Response: Practical experience managing live cyber incidents (such as ransomware, account takeovers, or supply chain breaches).
  • Technical Stack: Direct experience working with major SIEM/SOAR tools (e.g., Microsoft Sentinel, Splunk) and EDR/XDR platforms (e.g., Microsoft Defender for Endpoint, CrowdStrike Falcon).
  • Security Frameworks: Solid understanding of MITRE ATT&CK, NIST CSF, NCSC Caf v4.0 and ISO 27001.
  • Communication: Ability to write concise incident reports and speak comfortably with both engineers and business leaders.

Desirable

  • Experience working in management consulting, managed services (MSSP), or client-facing advisory roles.
  • Experience in regulated UK environments (such as Central Government,  Defence, or Critical National Infrastructure).
  • Hands-on familiarity with cloud security monitoring in AWS, Azure, or GCP.

 

Please be aware that some of our UK roles at PA Consulting require a UK security clearance.

All PA people are required to undergo background checks and to achieve the Baseline Personnel Security Standard however, some UK roles also require higher levels of National Security Vetting, where applicants must have at least 5 years of continuous residency in the UK.

We therefore ask that you only apply if you meet the residency requirements (i.e. you are a British citizen or have been resident in the UK for the past 5 years), as this is the prerequisite for a security clearance. If you're unsure about your eligibility, we encourage you to review the UK Government’s guidance on security vetting before applying.

Additional Information

Assessment process ⚖️ 

Please note that the interview stages may be subject to change based on the specific requirements of the role. 

  • Quick call with one of our Tech Recruiters – to discuss your application, the role and PA 
  • Round 1: Either a competency or technical interview (60 mins) 
  • Round 2: Either a competency or technical interview, whichever you didn’t do at first round (60 mins) 
  • Final round 🎉: Meeting with a PA leader - a mini case study and discussion around your client-centricity (60 mins) 

Life At PA encompasses our peoples' experience at PA. It's about how we enrich peoples’ working lives by giving them access to unique people and growth opportunities and purpose led meaningful work. 

Our purpose guides how we work with our clients and our teams, and support our communities, to deliver insight and impact, solving the world’s most complex challenges. We're focused on building a workplace that values human difference and diverse mindsets, and a culture of inclusion and equality that unlocks the potential in our people so everyone can be their best self. 

Find out more about Life at PA here. 

We are dedicated to supporting the physical, emotional, social and financial well-being of our people. Check out some of our extensive benefits: 

  • Health and lifestyle perks accompanying private healthcare for you and your family 
  • 25 days annual leave (plus a bonus half day on Christmas Eve) with the opportunity to buy 5 additional days 
  • Generous company pension scheme 
  • Opportunity to get involved with community and charity-based initiatives 
  • Annual performance-based bonus 
  • PA share ownership 
  • Tax efficient benefits (cycle to work, give as you earn) 

We’re committed to advancing equality. We recruit, retain, reward and develop our people based solely on their abilities and contributions and without reference to their age, background, disability, genetic information, parental or family status, religion or belief, race, ethnicity, nationality, sex, sexual orientation, gender identity (or expression), political belief, veteran status, any other range of human difference brought about by identity and experience. We welcome applications from underrepresented groups. 

Adjustments or accommodations - Should you need any adjustments or accommodations to the recruitment process, at either application or interview, please contact us on [email protected] 

#LI-IC2

By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply

Privacy Notice