About The Role
At EDF, success is personal. Here you’ll develop a career that’s unique to you. Whether you want to move horizontally, deepen your specialty, or advance through the levels — it’s your journey, powered by us.
The Opportunity
The SOC Operations Manager is responsible for overseeing the daily operations of the SOC, ensuring the effective monitoring, detection, and response to cybersecurity incidents. This role involves leading a team of security analysts, developing and implementing security policies and procedures, and coordinating with other departments to ensure comprehensive security measures. The SOC Operations Manager also conducts regular assessments and audits of SOC activities, manages incident response efforts and leads on SOC management reporting.
Pay, Benefits And Culture
Alongside a salary of £75,000 (DOE) and a market-leading pension scheme, your package will include a range of benefits, from the big and formal to the small and personal.
We’re talking about everything from
enhanced parental leave to
electric vehicle leasing, health insurance to
product discounts, critical illness insurance to
technology vouchers, gym membership to
season ticket loans.
At EDF UK, we embrace flexibility while recognising that everyone's working needs are different. Whether you're in our office spaces, on site, or working remotely, we promote an environment that supports collaboration, connection, and comfort. No matter where you are, our priority is to make sure you feel safe, valued, and celebrated.
Here, we do right by each other and everyone’s welcome. We’re on an action-oriented journey, championing equity, diversity, and inclusion. We’d like our future workforce to have an equal gender balance, represent a broad mix of people from minority ethnic backgrounds, LGBTQ+, those with a disability and supporting social mobility.
We’re a disability confident employer and we’ll do all we can to help with your application. Please let us know if you need to request reasonable adjustments.
We take pride in fostering a dynamic and inclusive environment, where the diverse backgrounds and experiences of our employees drive fresh thinking and innovation. We understand that success means different things to different people. We believe there are multiple definitions of what it means to succeed. That’s why we support you to pursue a career that’s unique to you. Because success is personal.
What You’ll Be Doing
Team Leadership
- Lead and manage the SOC team, including hiring, training, performance reviews, and career development.
- Define and oversee SOC policies, procedures, and playbooks to improve efficiency and effectiveness.
- Coordinate with InfoSec teams to ensure consistent and aligned security controls across EDF.
- Build and maintain strong relationships with internal stakeholders, IT, assurance teams, and external partners.
Incident Management
- Response: Oversee security incident response, ensuring effective playbooks and automation are in place. Collaborate with SecOps and SOAR teams to optimise response capabilities.
- Analysis: Lead the analysis of security events using data from SIEM, XDR, and other sources. Foster a culture of deep, high-quality analytical investigation.
- Tracking & Reporting: Ensure incidents are properly tracked, documented, and reported using standardised templates. Provide regular dashboards and insights on incident trends and response.
- Tooling: Act as a key advisor on EDR/XDR tools and MDR services. Ensure incident response needs are reflected in security tools and drive continuous improvement with engineering teams.
Monitoring & Detection
- Data Collection: Ensure relevant log sources are collected in the SIEM. Assess value and remove redundant data where appropriate.
- Detection Use Cases: Develop detection logic and use cases aligned with business needs and regulatory requirements as a CNI organisation.
- System Health: Monitor the health and coverage of SOC tools and sensors. Hold IT support partners accountable for meeting performance and availability standards.
Stakeholder Engagement
- Reporting: Deliver clear, actionable reports and briefings to demonstrate SOC performance and value to leadership.
- Compliance: Work with GRC teams to align SOC activities with regulatory standards (e.g. NCSC CAF, ONR SyAPs, ISO27001).
- Crisis Support: Provide expert SOC support during major incidents and exercises, including analysis and threat hunting.
Who You Are
We’re looking for a strong leader with proven experience in a SOC environment, ready to take on more responsibility. You’ll bring solid knowledge of SOC/SIEM/XDR technologies, strong M365 expertise, and cloud experience with Azure and/or AWS.
You understand how to run an efficient SOC, engage stakeholders effectively, and clearly communicate security value through business-aligned reporting.
Key Skills & Experience:
- Hands-on experience with SOC/SIEM/XDR platforms in enterprise environments
- Deep understanding of M365 security tools and operations
- Skilled in stakeholder engagement and value-driven reporting
- Up to date with the latest security threats and trends
- Committed to fostering a culture of service excellence
If this sounds like you, then we’d love to hear from you!
Closing date for applications: 31st August 2025
Location: Gloucester/London/Hove/Doxford (Hybrid - Flexible)
Success is personal. It's your journey, powered by us. Join us and we'll help Britain achieve Net Zero together.