SOC Shift Lead

慨正橡扯

Greater London

On-site

GBP 60,000 - 80,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

慨正橡扯 is seeking a SOC Shift Lead to oversee incident investigation and analysis in London. This role involves leading teams in responding to high-severity incidents and mentoring analysts.

The ideal candidate will possess 7–10 years of experience in SOC or Incident Response and hold a relevant Bachelor’s degree. Key skills include in-depth knowledge of SIEM/EDR tools and strong analytical capabilities. The position requires working in shifts and provides competitive compensation.

Qualifications

  • 7–10 years in SOC, Incident Response, or Threat Analysis roles.
  • GCIA, GCIH, CompTIA CySA+, Microsoft SC‑200 or Splunk Certified Power User preferred.

Responsibilities

  • Investigate escalated incidents to determine attack vectors and potential impact.
  • Correlate events across multiple data sources for incident narratives.
  • Execute containment and recovery activities with stakeholders.
  • Lead response for medium to high‑severity incidents.
  • Conduct tuning of detection rules in collaboration with the Security Content Engineer.
  • Mentor L1 Analysts and provide technical guidance.
  • Participate in SOC exercises and simulated incident response drills.

Skills

Analytical mindset
Knowledge of SIEM/EDR tools
Malware behaviour understanding
Incident handling methodologies

Education

Bachelor’s degree in Cybersecurity, Computer Science, or related field

Tools

SIEM tools
EDR tools

Job description

Role: SOC Shift Lead – London

Location: London

Salary: Competitive salary and package dependent on experience

Career Level: Associate Manager

Please Note: Any offer of employment is subject to satisfactory BPSS and the candidate being granted a level of security clearance which typically requires 10 years continuous UK address history, usually including no periods of 30 consecutive days or more spent outside of the UK, and a declaration of being a British passport holder with no dual nationality at the point of application.

Note: The above information relates to a specific client requirement

Role Description: SOC Shift Lead – London provides advanced investigation and analysis, acting as the escalation point for complex or high‑severity incidents. They conduct root‑cause analysis, guide L1 analysts, and support incident containment and remediation efforts. The role is part of a high‑performance compute operations team operating 24/7, with shift teams paid a premium for unsociable shift hours.

Key Responsibilities
  • Investigate escalated incidents to determine attack vectors, scope, and potential impact.
  • Correlate events across multiple data sources to build a comprehensive incident narrative.
  • Execute containment, eradication, and recovery activities in coordination with IT/OT stakeholders.
  • Lead response for medium to high‑severity incidents and document detailed investigation reports.
  • Conduct tuning of detection rules and thresholds in collaboration with the Security Content Engineer.
  • Support continuous improvement by identifying gaps in detection coverage and playbooks.
  • Mentor and provide technical guidance to L1 Analysts.
  • Participate in periodic SOC exercises and simulated incident response drills.
  • Be part of a 24/7 SOC Team, working in shifts.
  • As a shift lead you will be responsible for handling escalations of the Technology Operations Centre in that particular shift. You will be accountable in the absence of a SOC manager or NOC lead.
Role Requirements
  • Education: Bachelor’s degree in Cybersecurity, Computer Science, or related field.
  • Experience: 7–10 years in SOC, Incident Response, or Threat Analysis roles.
  • Certifications (preferred): GCIA, GCIH, CompTIA CySA+, Microsoft SC‑200, or Splunk Certified Power User.
Essential Skills
  • Strong analytical mindset, in-depth knowledge of SIEM/EDR tools, malware behaviour, and incident handling methodologies.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Shift Lead - London
SOC Shift Lead - London

Accenture • Greater London

On-site
GBP 90,000 - 150,000
Security Operations Team Lead / Incident Response Lead
Security Operations Team Lead / Incident Response Lead

Anson McCade • Greater London

On-site
GBP 90,000 - 130,000
Senior SOC Analyst
Senior SOC Analyst

Anson McCade • Greater London

On-site
GBP 70,000 - 110,000
Security Operations Center Analyst
Security Operations Center Analyst

Anson McCade • City Of London

On-site
GBP 76,000 - 92,000
Shift allowance
Onsite role
Senior SOC Analyst
Senior SOC Analyst

慨正橡扯 • Greater London

On-site
GBP 50,000 - 70,000
SOC Shift Lead (Cyber)
SOC Shift Lead (Cyber)

Searchability • Hemel Hempstead

On-site
GBP 70,000 - 86,000
Senior SOC Shift Lead - 24/7 Incident Response (London)
Senior SOC Shift Lead - 24/7 Incident Response (London)

Accenture UK • Greater London

On-site
GBP 80,000 - 110,000
London SOC Shift Lead & Incident Response Mentor
London SOC Shift Lead & Incident Response Mentor

Accenture • Greater London

On-site
GBP 90,000 - 150,000
SOC Shift Leader
SOC Shift Leader

Fynity • Farnborough

On-site
GBP 65,000 - 90,000
Lead SOC Analyst
Lead SOC Analyst

Anson McCade • Greater London

On-site
GBP 70,000 - 100,000