Senior SecOps Lead: Incident Response & Detection

Teya Solutions

Greater London

Hybrid

GBP 63,000 - 103,000

Full time

11 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Health insurance
25 days annual leave
Friday lunch in the office
High-end work equipment
Mental health support

Job summary

Teya is hiring for a full-time Security Engineering role based in London or Porto with a hybrid work mode. You will lead end-to-end investigations of complex security incidents, act as the L3 escalation point, and coordinate with Security, Engineering, IT, Cloud, Legal and Compliance during incidents.

You will maintain playbooks, drive post-incident reviews, and improve detection and automation across SIEM, EDR, and vulnerability tooling.

Qualifications

  • 7+ years in SOC, incident response, detection engineering, or security engineering.
  • Experience leading complex security incidents end-to-end.
  • Strong hands-on experience with SIEM, EDR, and security tooling.
  • Experience building and tuning detections and queries.
  • Experience with log onboarding, telemetry pipelines, and data quality issues.
  • Strong vulnerability management and remediation experience.
  • Solid understanding of attack techniques, cloud, endpoint, identity, and network security.
  • Hands-on scripting and automation experience with Python, PowerShell, Bash, or similar.
  • Experience with APIs, integrations, and automation workflows.
  • Familiarity with Git and engineering practices including testing, review, and deployment.
  • Experience using Jira or similar tools for operational delivery.
  • Strong communication and documentation skills.
  • Ability to work independently and make decisions under pressure.
  • Fintech or regulated industry experience is a nice-to-have.
  • AWS or cloud-native security experience is a nice-to-have.
  • Experience with tools like Exabeam, Splunk, CrowdStrike, or Okta is a nice-to-have.
  • SOAR or security automation experience is a nice-to-have.
  • Threat hunting, purple teaming, or detection-as-code experience is a nice-to-have.
  • CI/CD, IaC, or DevSecOps exposure is a nice-to-have.
  • REST APIs, OAuth, or secrets management experience is a nice-to-have.
  • Security certifications such as GCIA, GCIH, or CISSP are a nice-to-have.

Responsibilities

  • Lead end-to-end investigation and response of complex security incidents.
  • Act as the L3 escalation point for SOC analysts and our MSSP.
  • Coordinate across Security, Engineering, IT, Cloud, Legal, and Compliance during incidents.
  • Make clear, risk-based decisions under pressure with strong documentation.
  • Maintain playbooks, runbooks, and incident workflows.
  • Drive post-incident reviews and ensure improvements and follow-ups are completed.
  • Support incident metrics such as MTTD, MTTR, and recurrence.
  • Operate and improve SIEM, EDR, email security, case management, and vulnerability tools.
  • Monitor health, coverage, data quality, and integrations.
  • Troubleshoot ingestion, parsing, API, and configuration issues.
  • Build and maintain integrations between security tools and internal systems.
  • Manage upgrades, changes, access reviews, and documentation.
  • Apply engineering practices such as version control, testing, peer review, and rollback.
  • Reduce operational toil through automation and simplification.
  • Analyse and prioritise vulnerabilities based on risk and exploitability.
  • Work with Engineering and IT to drive remediation.
  • Track fixes, validate resolution, and escalation high-risk issues.
  • Improve vulnerability workflows and automation.
  • Identify recurring issues and recommend preventative controls.
  • Build, test, and maintain detection rules, queries, and correlation logic.
  • Manage the full detection lifecycle from build to retire.
  • Use version control and detection-as-code where possible.
  • Reduce false positives and improve detection quality and coverage.
  • Map detections to threat behaviours such as MITRE ATT&CK.
  • Validate detections through testing, incidents, and simulations.
  • Onboard and maintain log sources across cloud, identity, endpoint, network, and SaaS.
  • Ensure logs are complete, reliable, and usable for detection and investigation.
  • Troubleshoot ingestion, parsing, schema, and data quality issues.
  • Build validation and monitoring for telemetry pipelines.
  • Offboard unused sources safely with documented impact.
  • Improve telemetry coverage by working with engineering teams.
  • Monitor threats, vulnerabilities, and attacker techniques.
  • Translate intelligence into detections, investigations, and remediation actions.
  • Assess relevance to our environment and risk profile.
  • Share actionable insights with relevant teams.
  • Improve security posture using trends and intelligence.
  • Gather and utilise intelligence for Shadow AI use cases.
  • Partner with Engineering and Platform teams on security requirements.
  • Manage security work in Jira with clear scope and ownership.
  • Support security projects involving tooling, integrations, telemetry, and controls.
  • Contribute to technical design discussions.
  • Produce clear technical documentation and workflows.
  • Communicate effectively with technical and non-technical stakeholders.
  • Automate SOC and security operations workflows.
  • Build scripts, integrations, and event-driven automations using APIs and cloud services.
  • Apply secure engineering practices including testing, logging, secrets management, and error handling.
  • Use version control and peer review for automation and detection content.
  • Monitor and improve automation reliability.
  • Explore AI and automation opportunities to reduce manual effort.
  • Define and track operational and security metrics.

Skills

SOC expertise
Incident response
Detection engineering
Security tooling
Scripting
Python
PowerShell
Bash
Git
Jira
Communication
Independent decisions
Threat hunting

Tools

Splunk
Exabeam
CrowdStrike
Okta
Jira

Job description

Teya is hiring for a full-time Security Engineering role based in London or Porto with a hybrid work mode. You will lead end-to-end investigations of complex security incidents, act as the L3 escalation point, and coordinate with Security, Engineering, IT, Cloud, Legal and Compliance during incidents.

You will maintain playbooks, drive post-incident reviews, and improve detection and automation across SIEM, EDR, and vulnerability tooling.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior SecOps Specialist
Senior SecOps Specialist

Teya Solutions • Greater London

Hybrid
GBP 63,000 - 103,000
Health insurance
25 days annual leave
Friday lunch in the office
+2
Senior SecOps Architect: Detection, IR & Automation
Senior SecOps Architect: Detection, IR & Automation

Jobtailor • Greater London

On-site
GBP 120,000 - 170,000
Senior Security Engineer, Detection & Response Lead
Senior Security Engineer, Detection & Response Lead

Mixpanel • Greater London

On-site
GBP 103,000 - 140,000
Comprehensive Medical, Vision, and…
Mental Wellness Benefit
Generous Vacation Policy & Additional…
+3
Senior SOC Incident Lead & Detection Engineer
Senior SOC Incident Lead & Detection Engineer

Xact Placements Limited • Reading

Hybrid
GBP 50,000 - 60,000
Hybrid work arrangement
Competitive salary
Senior L3 SOC Analyst: Threat Hunting & Incident Response
Senior L3 SOC Analyst: Threat Hunting & Incident Response

Inchcape Motors Finland Oy • Greater London

Hybrid
GBP 70,000 - 120,000
Security Operations Architect – Hybrid (Next-Gen Detection & Response)
Security Operations Architect – Hybrid (Next-Gen Detection & Response)

Searchability • Greater London

Hybrid
GBP 68,000 - 83,000
Tailored professional development
Hybrid working arrangements
Access to industry experts
+1
Senior Detection Engineer for SOC Automation
Senior Detection Engineer for SOC Automation

Infosec • Basingstoke

Hybrid
GBP 56,000 - 80,000
Salary up to £80,000
Bonuses
Hybrid work
Lead Security Engineer: Own Cloud & Incident Response
Lead Security Engineer: Own Cloud & Incident Response

Understanding Recruitment • Greater London

Hybrid
GBP 110,000 - 150,000
Hybrid working
London office access
Autonomy and ownership
+2
Senior SOC Analyst - Incident Response & IAM Lead (Hybrid)
Senior SOC Analyst - Incident Response & IAM Lead (Hybrid)

TalentHawk • Greater London

Hybrid
GBP 39,000 - 65,000
Senior Security Engineer: Detection & Automation Consultant
Senior Security Engineer: Detection & Automation Consultant

InfoSec People Ltd • Basingstoke

Hybrid
GBP 70,000 - 100,000
Hybrid working model
Comprehensive employee benefits