Embedded Cyber Detection and Response Deputy Team Lead

Control Risks

Greater London

On-site

GBP 90,000 - 120,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Control Risks is seeking a Cyber Detection and Response Deputy Team Lead to serve as the operational second-in-command of the DART. You will bridge hands-on cyber operations with leadership, supporting the Team Lead in maturing detection and response capabilities for clients.

The role entails threat detection, incident response, threat hunting, and detection engineering, with supervisory responsibilities and escalation duties across day-to-day security operations, including out-of-hours coverage.

Qualifications

  • 7+ years in cybersecurity with incident response or SOC operations.
  • Mentoring analysts and leading investigations or serving as a technical lead.
  • Hands-on with SIEM/EDR/IDS/IPS and cloud security tech.
  • Familiarity with Splunk, Sentinel, CrowdStrike and related tools.
  • Knowledge of MITRE ATT&CK, NIST CSF and IR best practices.
  • Experience in 24/7 operations and on-call rotations.
  • Strong analytical and problem-solving skills.
  • Ability to communicate complex concepts to diverse audiences.

Responsibilities

  • Serve as primary escalation point during shifts and after-hours.
  • Lead investigations into high-severity cyber incidents, ensuring containment and remediation.
  • Oversee triage across endpoint, network, cloud, and identity environments.
  • Conduct advanced threat hunting to identify emerging threats and gaps in coverage.
  • Support incident response with forensic analysis and remediation planning.
  • Collaborate with Security Engineering to improve detection logic and tooling.
  • Act as Team Lead during absences or out-of-hours coverage.
  • Review investigation quality and reporting standards.
  • Provide performance feedback and development planning.

Skills

Incident response
SOC operations
Threat hunting
Technical lead
SIEM & EDR
Cloud security
Automation mindset
Team mentoring
Communication

Tools

Splunk
Microsoft Sentinel
CrowdStrike
SentinelOne
Palo Alto
Microsoft Defender

Job description

The Cyber Detection and Response Deputy Team Lead serves as the operational second-in-command of the Cyber Detection and Response Team (DART), bridging the gap between hands‑on cyber operations and team leadership. The role supports the Team Lead in the ongoing development, maturation, and delivery of the client’s detection and response capabilities, while providing technical leadership and operational oversight across day‑to‑day security operations.

This position remains actively involved in threat detection, incident response, threat hunting, and detection engineering activities while also assuming supervisory and coordination responsibilities. The Deputy Team Lead acts as the designated escalation point for analysts, leads operational activities during off‑hours, and assumes Team Lead responsibilities during periods of absence, ensuring continuous delivery of a high‑quality detection and response service.

This role will be part of a 24/7 team and cover Monday-Friday: 9:00 am-5:00 pm London Time

Responsibilities
  • Serve as the primary escalation point for Cyber Detection and Response Analysts during assigned shifts and out‑of‑hours operations.
  • Lead and coordinate investigations into high‑severity cyber security incidents, ensuring timely containment, remediation, and reporting.
  • Oversee the triage and investigation of security events across endpoint, network, cloud, and identity environments.
  • Conduct advanced threat hunting activities to identify emerging threats, undetected adversary activity, and gaps in detection coverage.
  • Support incident response activities including forensic analysis, root cause determination, remediation planning, and post‑incident reviews.
  • Collaborate with Security Engineering to improve detection logic, automate workflows, and optimize security tooling.
  • Act as Team Lead during periods of absence, leave, or out‑of‑hours coverage.
  • Review investigation quality, reporting standards, and analyst outputs to ensure consistency and operational excellence.
  • Contribute to performance feedback discussions and professional development planning.
  • Support the Team Lead in implementing new detection and response initiatives, technologies, and operational improvements.
  • Assist with establishing and refining SOPs, playbooks, escalation frameworks, and response processes.
  • Participate in planning activities with Security Engineering and client stakeholders to improve overall security posture.
  • Identify opportunities to enhance team effectiveness through automation, workflow optimization, and process improvements.
  • Support the Team Lead in maintaining strong relationships with client security, technology, and business stakeholders.
  • Provide operational updates and incident briefings to internal and client stakeholders as required.
  • Ensure clear communication and documentation throughout investigations and response activities.
Qualifications
  • 7+ years of experience in cybersecurity, with significant experience in incident response, SOC operations, threat hunting, or cyber defense.
  • Demonstrated experience mentoring analysts, leading investigations, or serving as a technical lead within a security operations environment.
  • Strong hands‑on experience with SIEM, EDR/XDR, SOAR, IDS/IPS, log management, and cloud security technologies.
  • Experience with platforms such as Splunk, Microsoft Sentinel, CrowdStrike, SentinelOne, Palo Alto, Microsoft Defender, or equivalent technologies.
  • Strong understanding of incident response methodologies, digital forensics principles, malware analysis, and threat hunting techniques.
  • Working knowledge of the MITRE ATT&CK Framework, NIST Cybersecurity Framework, and incident response best practices.
  • Experience supporting operational improvement initiatives, tool implementations, or security program maturity efforts.
  • Strong analytical, troubleshooting, and problem‑solving skills.
  • Ability to communicate technical concepts effectively to both technical and non‑technical audiences.
  • Experience working within a 24/7 operational environment and participating in on‑call or escalation rotations.
  • Preferred certifications include CISSP, GCIH, GCIA, GCFA, GSOM, CISM, or equivalent.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Detection & Response Deputy Team Lead (24/7)
Cyber Detection & Response Deputy Team Lead (24/7)

Control Risks • Greater London

On-site
GBP 90,000 - 120,000
Senior Manager – Associate Director Technical Incident Responder, Cyber Incident Response
Senior Manager – Associate Director Technical Incident Responder, Cyber Incident Response

Cyber UK • Greater London, Manchester

On-site
GBP 60,000 - 80,000
Lead Detection & Response Engineer
Lead Detection & Response Engineer

Lloyds • City of Edinburgh

Hybrid
GBP 90,000 - 140,000
Holiday allowance
Flexible working
Private medical insurance
+2
Senior Detection and Response Engineer
Senior Detection and Response Engineer

Jobtailor • Cambridge

On-site
GBP 65,000 - 95,000
Response Engineer - Cloudflare Managed Defense Center (CMDC)
Response Engineer - Cloudflare Managed Defense Center (CMDC)

Cloudflare, Inc. • Greater London

Hybrid
GBP 70,000 - 105,000
SOC Team Lead
SOC Team Lead

Jobtailor • Greater London

On-site
GBP 90,000 - 120,000
Cyber Threat Operations Specialist
Cyber Threat Operations Specialist

Morson Edge • Stevenage

On-site
GBP 65,000 - 90,000
Incident Response Lead - Global Security
Incident Response Lead - Global Security

EasyPark • Greater London

On-site
GBP 90,000 - 120,000
Security Monitoring & Detection Engineering Lead
Security Monitoring & Detection Engineering Lead

Aj Bell • Manchester

On-site
GBP 90,000 - 120,000
24 x 7 Security Analyst
24 x 7 Security Analyst

LRQA Group Limited 2021 • Birmingham

On-site
GBP 45,000 - 65,000