{"id":1422637,"url":"https://alion.io/job/pa-consulting-security-operations-manager","title":"Security Operations Manager","company":{"id":6225,"name":"PA Consulting","domain":"paconsulting.com","url":"https://alion.io/company/pa-consulting","size_band":"501-1000","is_staffing_agency":false,"employer_type":"services","is_intermediary":false,"listed_via":null,"ats_vendor":"SmartRecruiters","truth_index":{"grade":"A","score":85,"open_postings":61,"ghost_share":0,"stale_share":0.59,"repost_share":0,"time_to_fill_p50_days":24,"computed_at":"2026-09-30T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"senior","employment_type":"full_time","work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Belfast, United Kingdom"],"countries":["GB"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":70000,"max_usd":139000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":17},"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"Crowdstrike","optional":false},{"name":"GCP","optional":false},{"name":"Microsoft Defender","optional":false},{"name":"Microsoft Sentinel","optional":false},{"name":"Microsoft Teams","optional":false},{"name":"SIEM","optional":false},{"name":"Splunk","optional":false},{"name":"ISO 27001","optional":true},{"name":"MITRE ATT&CK","optional":true},{"name":"NIST CSF","optional":true}],"status":"closed","first_seen_at":"2026-09-28T09:13:45Z","employer_posted_date":"2026-09-28","last_verified_at":"2026-09-30T07:59:48Z","board_verified":false,"closed_at":"2026-09-30T07:59:48Z","days_open":1,"trust":{"level":"not_scored","repost_count":null,"flags":[],"days_open":1},"description":"We believe in the power of ingenuity to build a positive human future.\nAs strategies, technologies, and innovation collide, we create opportunity from complexity.\nOur teams of interdisciplinary experts combine innovative thinking and breakthrough technologies to progress further, faster. Our clients adapt and transform, and together we achieve enduring results.\nWe are over 4,000 strategists, innovators, designers, consultants, digital experts, scientists, engineers, and technologists. And we have deep expertise in consumer and manufacturing, defence and security, energy and utilities, financial services, government and public services, health and life sciences, and transport.\nOur teams operate globally from offices across the UK, Ireland, US, Nordics, and Netherlands.\nPA. Bringing Ingenuity to Life.\n We are looking for a Security Operations Manager to join our Digital Trust & Cyber Security practice. Working on behalf of our clients, you will lead Security Operations Centre (SOC) analysts and incident response specialists.\nYou will combine hands-on operational leadership with advisory work. This means managing live incident containment and day-to-day SOC operations, while helping enterprise and public sector clients modernise their security operations, improve their SIEM, SOAR and EDR capabilities, and build stronger cyber resilience.\nWhy consider joining our Digital & Data community?\nJoin our Digital & Data team and work alongside cyber security, product, design and technology specialists in cross-disciplinary teams to solve complex client challenges and bring ideas to life. \nBuild a flexible and distinctive career in a trust-based, inclusive environment that values excellence, innovation and curiosity. You can progress through a technical career track without needing to follow the Partner career track if that does not align with your ambitions. \nWork across a broad range of Security Operations engagements, client environments and technology stacks spanning seven sectors. No two projects are the same. \nJoin a supportive and collaborative cyber and technology community, with knowledge sharing, peer support, coaching and mentoring from other specialists. \nDeepen your expertise through our culture of learning and growth, with access to a development budget for technical and non-technical training and professional certifications. \nBenefit from a hybrid working approach, with an expectation of being in the office or on a client site for a minimum of two days per week, depending on the role and assignment. \nWhat you'll do\nLead and develop SOC analysts and incident response specialists, providing clear operational direction, coaching and support across day-to-day security operations. \nTake a hands-on leadership role during cyber security incidents, coordinating investigation, containment, eradication, recovery, stakeholder communications and post-incident reviews. \nHelp enterprise and public sector clients assess and improve their Security Operations capabilities, identifying gaps across people, processes and technology and translating these into practical improvements. \nAdvise on the evolution and optimisation of SIEM, SOAR, EDR and threat-detection tooling to improve visibility, reduce noise and strengthen detection and response capabilities. \nDevelop and maintain incident playbooks, standard operating procedures, automated response workflows and proactive tabletop exercises. \nSupport the development of modern Security Operations services and ways of working, sharing your expertise across our Digital Trust & Cyber Security community through coaching, mentoring and knowledge sharing. \nSecurity technologies you'll work with\nWe advocate using the right technology for the right task. Depending on the client environment and engagement, you can expect to work across technologies including:\nSIEM and security analytics platforms, such as Microsoft Sentinel and Splunk. \nSOAR and security automation technologies used for enrichment, triage and response orchestration. \nEndpoint Detection and Response (EDR/XDR) platforms, such as Microsoft Defender for Endpoint and CrowdStrike Falcon. \nThreat intelligence, detection engineering, investigation and incident response technologies. \nCloud security monitoring across Microsoft Azure, AWS and GCP environments. \nWhat you can expect\nWork collaboratively across multiple technical teams and stakeholder groups, using your Security Operations expertise to solve complex client problems and contribute to internal initiatives. \nParticipate in live, in-person working sessions to investigate incidents, assess operational challenges and design practical improvements, alongside asynchronous collaboration through Microsoft Teams. \nWork with the team at client sites or in our offices for a minimum of two days per week. The time you spend and where you work will vary by role and assignment, including the possibility of being on a client site for up to five days per week. \nWork in an environment that takes its values seriously and places collaboration, inclusion, learning and client impact at the heart of how teams operate. \n Essential requirements\nEven if you don’t meet every requirement below, feel free to still apply as we are often hiring for similar roles which your background might be better suited to.\nSOC Leadership: Experience running or supervising a SOC, CSOC, or Incident Response team.\n Incident Response: Practical experience managing live cyber incidents (such as ransomware, account takeovers, or supply chain breaches).\n Technical Stack: Direct experience working with major SIEM/SOAR tools (e.g., Microsoft Sentinel, Splunk) and EDR/XDR platforms (e.g., Microsoft Defender for Endpoint, CrowdStrike Falcon).\nSecurity Frameworks: Solid understanding of MITRE ATT&CK, NIST CSF, NCSC Caf v4.0 and ISO 27001.\nCommunication: Ability to write concise incident reports and speak comfortably with both engineers and business leaders.\nDesirable\nExperience working in management consulting, managed services (MSSP), or client-facing advisory roles.\nExperience in regulated UK environments (such as Central Government, Defence, or Critical National Infrastructure).\nHands-on familiarity with cloud security monitoring in AWS, Azure, or GCP.\nPlease be aware that some of our UK roles at PA Consulting require a UK security clearance.\nAll PA people are required to undergo background checks and to achieve the Baseline Personnel Security Standard however, some UK roles also require higher levels of National Security Vetting, where applicants must have at least 5 years of continuous residency in the UK.\nWe therefore ask that you only apply if you meet the residency requirements (i.e. you are a British citizen or have been resident in the UK for the past 5 years), as this is the prerequisite for a security clearance. If you're unsure about your eligibility, we encourage you to review the UK Government’s guidance on security vetting before applying.\n Assessment process\nPlease note that the interview stages may be subject to change based on the specific requirements of the role.\nQuick call with one of our Tech Recruiters - to discuss your application, the role and PA \nRound 1: Either a competency or technical interview (60 mins) \nRound 2: Either a competency or technical interview, whichever you didn’t do at first round (60 mins) \nFinal round : Meeting with a PA leader - a mini case study and discussion around your client-centricity (60 mins) \nLife At PA encompasses our peoples' experience at PA. It's about how we enrich peoples’ working lives by giving them access to unique people and growth opportunities and purpose led meaningful work.\nOur purpose guides how we work with our clients and our teams, and support our communities, to deliver insight and impact, solving the world’s most complex challenges. We're focused on building a workplace that values human difference and diverse mindsets, and a culture of inclusion and equality that unlocks the potential in our people so everyone can be their best self.\nFind out more about Life at PA here.\nWe are dedicated to supporting the physical, emotional, social and financial well-being of our people. Check out some of our extensive benefits:\nHealth and lifestyle perks accompanying private healthcare for you and your family \n25 days annual leave (plus a bonus half day on Christmas Eve) with the opportunity to buy 5 additional days \nGenerous company pension scheme \nOpportunity to get involved with community and charity-based initiatives \nAnnual performance-based bonus \nPA share ownership \nTax efficient benefits (cycle to work, give as you earn) \nWe’re committed to advancing equality. We recruit, retain, reward and develop our people based solely on their abilities and contributions and without reference to their age, background, disability, genetic information, parental or family status, religion or belief, race, ethnicity, nationality, sex, sexual orientation, gender identity (or expression), political belief, veteran status, any other range of human difference brought about by identity and experience. We welcome applications from underrepresented groups.\nAdjustments or accommodations - Should you need any adjustments or accommodations to the recruitment process, at either application or interview, please contact us on ","description_format":"text","description_chars":9365,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[{"language":"English","level":"All levels","optional":false}]},"benefits":["Annual leave","Growth opportunities","Hybrid work"],"hiring_locations":[{"name":"United Kingdom","iso":"GB","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Government","Professional Services","Incident Response","Management Consulting"],"lifecycle":[{"event":"open","at":"2026-09-28T22:54:09Z"},{"event":"close","at":"2026-09-30T07:59:48Z"}],"liveness":null,"pay":null,"html_url":"https://alion.io/job/pa-consulting-security-operations-manager","json_url":"https://alion.io/job/pa-consulting-security-operations-manager.json","meta":{"generated_at":"2026-10-01T01:43:32Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1228,"day_limit":5000,"remaining_today":3772,"minute_limit":60,"resets_at":"2026-10-02T00:00:00Z"}}}