Overview
In this role you lead a Security Operations Centre (SOC) team to protect client systems and accelerate security maturity. You combine hands-on incident response with advisory work to strengthen SIEM, SOAR and EDR capabilities across enterprise and public sector clients. You’ll guide operations, improve detection, and shape modern security services within a collaborative Digital Trust & Cyber Security community. This is a hands-on leadership role with a strong focus on impact, scalability, and client outcomes.
Pay / Benefits
- Private healthcare for you and your family
- 25 days annual leave (+ Christmas Eve half day)
- Generous pension
- Annual performance-based bonus
- PA share ownership
- Tax efficient benefits (cycle to work)
Responsibilities
- Lead and develop SOC analysts and incident responders, providing clear direction and coaching
- Coordinate live cyber incident responses including containment, eradication, recovery, and post-incident reviews
- Assess and improve clients’ Security Operations capabilities by identifying gaps in people, processes and technology
- Advise on evolution and optimisation of SIEM, SOAR, EDR and threat-detection tooling to enhance visibility and reduce noise
- Develop and maintain incident playbooks, SOPs, automated response workflows and tabletop exercises
- Support development of modern Security Operations services and share expertise through coaching and knowledge sharing
Key requirements
- SOC Leadership: experience leading a SOC, CSOC or Incident Response team
- Incident Response: hands-on live incident management (ransomware, account takeovers, supply chain breaches)
- Technical Stack: direct experience with SIEM/SOAR tools and EDR/XDR platforms (e.g., Microsoft Sentinel, Splunk, Defender for Endpoint, CrowdStrike Falcon)
- Security Frameworks: knowledge of MITRE ATT&CK, NIST CSF, NCSC Caf v4.0 and ISO 27001
- Communication: ability to write concise incident reports and brief engineers and leaders
- clear communication
- coaching and mentoring
- cross-functional collaboration
- SIEM
- SOAR
- EDR/XDR
…
