The AI SOC Lead will be responsible for leading day-to-day security monitoring, detection, investigation and incident response activities within a 24×7 Security Operations Centre. The role will provide technical leadership to SOC analysts, handle complex escalations, improve detection capabilities and ensure consistent quality of incident analysis and response.
The role will also drive the practical adoption of AI-assisted security operations and automation to improve alert triage, investigation, threat hunting and analyst productivity. This includes evaluating AI-enabled capabilities within security platforms and identifying appropriate opportunities for automation while maintaining analyst validation and operational controls.
Key Responsibilities
- Lead security event monitoring, investigation and incident response activities across the SOC, acting as the technical escalation point for complex or high-severity incidents.
- Manage, tune and optimise SIEM capabilities, including correlation rules, detection logic, filters, alerts and use cases based on evolving threats and business requirements.
- Perform and guide deep-dive investigations, threat hunting, malware analysis and root-cause analysis for escalated security incidents.
- Lead SOC shifts and allocate work across analysts while ensuring timely investigation, escalation and closure of security incidents.
- Review analyst investigations, incident documentation and response actions to maintain investigation quality and adherence to established processes and SLAs.
- Identify gaps and recommend improvements across security controls such as EDR/XDR, IDS/IPS, DLP, vulnerability management and other security monitoring technologies.
- Apply AI-assisted investigation, alert enrichment and summarisation capabilities where they can improve SOC efficiency without compromising investigation accuracy or security controls.
- Identify opportunities to automate repetitive SOC workflows using SOAR, scripting and platform-native automation, including enrichment, triage and response activities.
- Work with SOC management to develop and improve operational procedures, playbooks, detection use cases and incident response processes.
- Serve as a key operational and technical contact for clients/stakeholders, providing incident updates, investigation findings and recommendations.
Skills & Experience
- 5+ years of relevant experience in SOC operations, security monitoring, incident detection and response, with experience providing technical guidance or leading SOC activities.
- Strong understanding of security event analysis, incident investigation, threat hunting and common attacker techniques.
- Hands-on experience with enterprise SIEM platforms; Securonix, Splunk, Microsoft Sentinel, IBM QRadar
- Working knowledge of EDR/XDR, IDS/IPS, firewalls, DLP, vulnerability management and other security monitoring/control technologies.
- Experience developing and tuning SIEM correlation rules, detection logic, alerts and security use cases.
- Understanding of network, endpoint, identity and authentication logs and their use during security investigations.
- Familiarity with threat intelligence, IOC analysis and frameworks such as MITRE ATT&CK for investigation and detection engineering.
- Practical understanding of SOAR, security workflow automation and scripting for repetitive investigation or response activities.
- Familiarity with AI-assisted capabilities in modern security operations platforms, including their appropriate use and limitations in investigation and triage.
- Strong incident documentation, analytical, communication and client/stakeholder management skills.
Preferred Qualifications
- Certifications such as CISSP, CISM, GIAC, CEH, Security+ or relevant vendor‑specific SIEM/SOC certifications are preferred.
- Experience working in an MSSP, managed SOC or large enterprise SOC environment.
- Exposure to SOAR platforms, security automation, detection engineering or AI-enabled SOC capabilities will be an advantage.