SOC Hiring and Retention Challenges in the UK

Shaped by real conversations with SOC leaders across the UK, this article unpacks the hiring and retention challenges facing security teams today.

Written by Tom Sharwood, Recruitment Partner and specialist in SOC recruitment.

30th June 2026

SOC room

The cyber market continues to grow, with over 140,000 professionals now employed nationally, but demand for SOC talent is still outpacing supply. The issue isn’t just a lack of people it’s a mismatch between the skills organisations need and what’s actually available in the market.

Time and time again, I hear that teams can find candidates with certifications, but far fewer with the hands-on experience needed to step straight into a live SOC environment.

Why are experienced SOC analysts still so hard to find

One of the biggest pain points I hear from hiring managers is the shortage of experienced SOC analysts.

Most organisations want people who’ve worked with SIEM tools, handled real incidents, and understand threat detection in practice, not just theory. But a large portion of the candidate market is still early-stage, often coming in with certifications but limited real-world exposure.

What that creates is a very tight mid-level talent pool. The same candidates are being approached again and again, giving them more options, which drags out hiring processes and leaves roles open for longer than teams can really afford.

Rising salaries and the knock-on effect internally

Unsurprisingly, salaries are continuing to rise alongside that demand. As competition for talent intensifies, candidates (particularly those with a few years of SOC experience) are commanding increasingly high salaries. Average SOC salary expectations in the UK are approaching £60k–£70k+, making this fairly typical for internal mid-level SOC roles, with MSSPs sitting closer to £40k–£45k. Shift work often pushes this higher, along with varying annual bonuses and/or certification completion payments, which can vary things further.

The challenge this creates internally is just as important as the attraction piece. I’ve spoken with several businesses where new hires are coming in are demanding higher salaries than existing team members, which naturally leads to frustration and retention risks.

Add budget constraints into the mix, and it’s not unusual to see hiring decisions delayed or scaled back altogether.

The reality of burnout in 24/7 SOC teams

Burnout is probably the most consistent theme that comes up in conversations about SOC retention.

Running a 24/7 operation inevitably means nights, weekends, and long shifts. On top of that, analysts are often dealing with high alert volumes many of which are repetitive or low priority.

Over time, that leads to alert fatigue, disengagement, and people leaving. In a lot of cases, I see analysts moving on within 18–24 months, either stepping into engineering roles or leaving the organisation entirely.

That churn then feeds straight back into the hiring problem.

Why SOC analysts get stuck, and why they move on

A lack of clear progression.

A lot of Tier 1 analysts feel stuck, with no obvious path into more advanced roles. If the work also stays heavily reactive, without opportunities to get involved in things like threat hunting or automation, it becomes even harder to keep people engaged.

At the same time, the external market is always there. Consultancies, MSSPs, and other organisations are actively targeting these individuals with what often looks like better progression and more varied work.

The real cost of SOC vacancies

Something that doesn’t always get enough attention is the cost of leaving these roles unfilled.

From a practical standpoint, when a SOC is understaffed, alerts don’t get triaged quickly, response times slow down, and risk increases.

But beyond the security impact, there’s a knock-on operational and financial cost too. Teams rely heavily on contractors, overwork existing staff, or simply accept reduced coverage.

The “saving” from not filling a role rarely outweighs the risk and inefficiency that comes with it.

How businesses are starting to rethink their approach

After speaking with a number of SOC leaders over the past 12–18 months, I’ve definitely noticed a shift in how organisations are approaching these challenges.

More teams are moving away from rigid requirements around certifications and focusing more on potential, things like problem-solving ability, curiosity, and hands-on aptitude.

I’ve also seen increasing openness to hiring from adjacent areas. People coming from IT support, networking, or infrastructure backgrounds are being brought in and re-trained into SOC roles, which is helping widen the talent pool.

It’s not a perfect solution, but it’s a much more sustainable approach than competing for the same small group of experienced analysts.

Investing in people: development and retention

The organisations that seem to be getting this right are the ones investing properly in development.

That means structured training, clear progression pathways, and giving analysts exposure to more advanced work as they grow. When people can see a path from Tier 1 through to engineering or threat hunting roles, they’re far more likely to stay.

I’m also seeing more focus on reducing burnout, whether that’s through automation, better tooling, or rethinking shift patterns to make roles more sustainable long term.

Are in-house SOCs still viable for everyone?

One question that’s coming up more often now is whether running a fully in-house SOC actually makes sense for every organisation.

When you factor in people, tooling, and infrastructure, the cost and complexity can be significant. For some, that’s leading to a move towards outsourced or hybrid models to maintain 24/7 coverage without carrying the full operational burden.

It’s bigger than hiring

These challenges aren’t just about recruitment anymore, they’re structural.

The organisations that are making progress are the ones thinking more broadly about how they hire, develop, and structure their SOC function.

There’s no quick fix, but the direction of travel is clear: more flexibility in hiring, more investment in people, and more willingness to rethink traditional models.

The organisations making progress are the ones tackling these challenges early, with a more strategic approach to hiring and retention. At InfoSec People, we specialise in SOC recruitment and support teams across the UK facing these exact challenges. If you're reviewing your team or planning to scale, get in touch with Tom Sharwood for an informal chat.
InfoSec People is a UK based boutique cyber and technology recruitment consultancy, built by genuine experts. Whether you’re a cyber security professional looking for a new opportunity or a business looking to build your security team, we are here to help. Contact us as our experienced recruiters are passionate about cyber security and are committed to providing exceptional service.

Call us directly on 01242 507 100 to discuss opportunities or email info@infosecpeople.co.uk.

www.infosecpeople.co.uk