SOC Shift Lead

Claranet

Leeds

On-site

GBP 55,000 - 75,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Pension scheme
Healthcare coverage
Discounted gym memberships
Wellbeing support
25 days annual leave (plus birthday)

Job summary

Claranet in Leeds is seeking a SOC Shift Lead to supervise a team of SOC Analysts and oversee shift operations. You ensure high-quality incident handling, escalation, and customer‑centric communication, while driving process improvements and QA across tickets and procedures.

You will mentor the team, support certifications, and contribute to service improvements, threat hunting, and monthly reporting. The role emphasizes leadership, collaboration, and continuous growth within a UK security

Qualifications

  • Minimum 3+ years of SOC operational experience with alert triage, incident analysis and escalation.
  • Willingness to pursue intermediate cybersecurity certifications (e.g. SBT BTL2, CREST).
  • Proficiency with SIEM platforms, endpoint security tools and ticketing systems under pressure.
  • Strong teamwork and mentoring abilities to continuously enhance the team.

Responsibilities

  • Shift Leadership and Team Coordination – run shift operations, ensure SLAs, set shift agendas, balance workloads and address staffing issues; maintain customer-centric communication with internal teams, customers and partner responders.
  • Incident Triage and Investigation – review alerts, own high-priority incidents, escalate properly to customers and Senior SOC Analysts, make data-driven triage decisions.
  • Quality Assurance and Documentation – conduct QA of tickets, ensure SOC procedures and documentation standards, provide feedback to improve skills and workflow.
  • Collaboration and Mentorship – mentor SOC Analysts, offer feedback on triage processes, encourage training and certifications for career progression.
  • Service Improvement – participate in threat hunting, tune rules, support monthly reporting and post-incident reviews for process improvements.

Skills

SOC operations
Team leadership
Incident triage
Data-driven decisions
Customer-centric communication

Tools

SIEM platforms
Endpoint security tools
Ticketing systems

Job description

As a SOC Shift Lead, you build on your solid experience as a SOC Analyst by supervising and guiding a team of SOC Analysts during your assigned shift. You ensure quality and consistency across all alerts and incidents handled by the team while serving as the primary point of escalation. In this role, you support team development, drive process improvements, and maintain clear, customer‑centric communication with all stakeholders. You also lead quality assurance efforts and ensure that service‑level agreements (SLAs) are met.

Objectives & Key Results
Key Responsibilities
  • Shift Leadership and Team Coordination – You run shift operations, ensuring compliance with SLAs and maintaining high‑quality incident handling. You set shift agendas, balance workloads, and promptly address any process or staffing issues. You also maintain effective, customer‑centric communication with internal teams (including Security Optimisation and Engineering), customers, and their incident response partners
  • Incident Triage and Investigation – You review and prioritise new alerts, taking initial ownership of high‑priority or complex incidents, and ensure proper escalation to customers and Senior SOC Analysts. You make sound, data‑driven decisions to facilitate effective triage, investigation, and escalation in line with operational standards
  • Quality Assurance and Documentation – You conduct regular quality assurance (QA) of tickets to ensure SOC procedures and documentation standards are met, providing clear, constructive feedback to team members to improve technical skills and workflow consistency
  • Collaboration and Mentorship – You mentor SOC Analysts in your team by offering regular, constructive feedback on triage processes and best practices. You encourage targeted training initiatives, including relevant certifications, to support career progression within the SOC
  • Service Improvement – You contribute to ongoing service improvement through participation in supporting threat hunting activity led by Senior SOC Analysts, rule tuning, and process refinement initiatives. You assist in monthly reporting and post‑incident reviews to drive improvements that reflect our commitment to transparent and reliable performance

In addition to the duties performed by a SOC Analyst:

  • Monitor shift activity and ensure all alerts, incidents, and tickets meet established SLAs
  • Document shift activities, decisions, and process improvements accurately
  • Lead regular shift briefings and debriefings (e.g. daily standups, shift handovers) to communicate updates, review performance, and reinforce best practices
Required Qualifications & Experience
  • You may be required to hold or obtain UK Non‑Police Personnel Vetting (NPPV) and/or a Security Check (SC) clearance as part of this role
  • A minimum of 3+ years of SOC operational experience, demonstrating a strong background in alert triage, incident analysis, and escalation
  • Willingness to work towards or obtain intermediate cybersecurity certifications (e.g. SBT BTL2, CREST Registered Intrusion Analyst)
  • Proficiency with SIEM platforms, endpoint security tools, and ticketing systems, with an ability to make clear, data‑driven decisions under pressure
  • Proven teamwork and mentoring abilities, ensuring that technical and operational skills are continuously enhanced within the team
Critical Competencies – Technical Fit
  • Operating Systems - Possess detailed knowledge of Windows and Linux system architectures, with a clear understanding of how event logs (e.g., Windows Event Viewer, Syslog) reflect system security posture
  • Networking and Protocols - Have a comprehensive understanding of TCP/IP, DNS, DCHP, VPNs, SSL/TLS, and network forensics concepts to validate network‑based alerts and anomalies
  • Cybersecurity Frameworks - Deeply understand and be able to articulate the elements of the MITRE ATT&CK framework, and Cyber Kill Chain; know how adversary tactics and techniques translate into observable indicators
  • SIEM and Security Tools - Know the theoretical underpinnings of SIEM operations, including alert correlation, the design of automated detection rules, and the interpretation of aggregated security data
  • Incident Triage - Understand the principles behind effective triage, including the rationale for using standardised playbooks and the criteria for escalating incidents without undertaking complex forensic analysis
  • Threat Intelligence Integration - Be knowledgeable about the role and structure of threat intelligence – how feeds are sourced, what constitutes actionable information, and how malware indicators are defined
  • Scripting and Automation - Understand the concepts behind using scripting for automating regular data extraction and log analysis, and the benefits such tools being to maintaining consistency in alert handling
Professional Development & Career Progression

Claranet supports ongoing professional growth. As a SOC Shift Lead you are encouraged to pursue additional training and relevant certifications to further your skills and advance to roles such as Senior SOC Analyst. This may include both technical and leadership certifications.

At Claranet, we go the extra mile with our people—because we believe in building a workplace where everyone feels valued and supported. Our flexible benefits package includes:

  • Pension Scheme: Employer-matched contributions to help you plan for the future.
  • Comprehensive Healthcare Coverage: Access to private medical care for your peace of mind and wellbeing.
  • Discounted Gym Memberships: Prioritise your fitness with exclusive rates at leading gyms.
  • Personalised Wellbeing Support: App‑based resources and services available 24/7
  • Enhanced Annual Leave: 25 days of holiday, increasing to 27 days with service, plus bank holidays and a day off for your birthday.
  • Continuous Learning & Development: Ongoing opportunities to grow your skills and advance your career.

What makes us unique is Team Claranet, our internal community that supports causes close to our employees’ hearts. We offer paid charity leave, support local charities across our offices, and host annual fundraising events, all backed by a dedicated committee.

We’re proud founding members of TC4RE (Technology Community for Racial Equality) working collectively to build a more diverse and inclusive tech industry.

About Claranet

Founded at the beginning of the dot com bubble in 1996, our CEO Charles Nasser had a light bulb moment to develop a truly customer‑focused IT business. Since then, Claranet has grown from an Internet Service Provider (ISP) in the UK to being one of the leading business modernisation experts, who deliver solutions across 11+ countries.

Diversity, equity and inclusion are at the heart of what we value as an organisation. Claranet is an equal opportunities employer and all qualified applicants will receive consideration for employment without regard to race, religion, sex, sexual orientation, age, disability or any other status protected by law. Our recruitment team are happy to support any reasonable adjustments that are needed within the recruitment process.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SOC Shift Lead - Internet Service Provider
SOC Shift Lead - Internet Service Provider

Hamilton Barnes Associates Limited • West Yorkshire

On-site
GBP 39,000 - 55,000
SOC Shift Lead
SOC Shift Lead

慨正橡扯 • Greater London

On-site
GBP 60,000 - 80,000
SOC Shift Lead
SOC Shift Lead

Sopra Steria • Hemel Hempstead, Farnborough

On-site
GBP 39,000 - 65,000
25 days annual leave
Health cash plan
Life assurance
+1
SOC Analyst Level 1
SOC Analyst Level 1

NTT DATA UK Ltd. • Birmingham

On-site
GBP 40,000 - 56,000
Flexible work options
Learning & Development opportunities
Disability Confident Employer
SOC Shift Lead (Cyber)
SOC Shift Lead (Cyber)

Searchability • Hemel Hempstead

On-site
GBP 70,000 - 86,000
SOC Shift Lead
SOC Shift Lead

Searchability NS&D • Watford

On-site
GBP 70,000 - 86,000
Career progression
Technical training & certification
Exposure to critical infrastructure
SOC Shift Lead
SOC Shift Lead

Searchability NS&D • Hemel Hempstead

On-site
GBP 70,000 - 86,000
Career progression
Technical training and certification
Exposure to enterprise infrastructure
SOC Shift Leader
SOC Shift Leader

Fynity • Farnborough

On-site
GBP 65,000 - 90,000
SOC Shift Lead
SOC Shift Lead

Sopra Steria Ltd • Hemel Hempstead

On-site
GBP 59,000 - 72,000
25 days annual leave
Health cash plan
Life assurance
+1
SOC Shift Lead: Lead & Elevate Incident Response
SOC Shift Lead: Lead & Elevate Incident Response

Claranet • Leeds

On-site
GBP 55,000 - 75,000
Pension scheme
Healthcare coverage
Discounted gym memberships
+2