SOC Operations Technical Lead (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
SOC Operations Technical Lead (Cybersecurity): Lead a 24/7 team of SOC analysts in threat detection, incident response, and security operations for multi-client MSSP environments with an accent on technical leadership, process optimization, and client consulting. Focus on advanced threat hunting, tuning detections, developing custom rules, and driving continuous SOC improvements.
Location: Birmingham, UK (onsite, B37 7ES)
Company
is a leading global assurance provider delivering managed security services and supporting clients' security posture.
What you will do
- Lead day-to-day SOC analyst activities across 24/7 shifts, manage scheduling, handovers, and coverage.
- Provide technical guidance on alert triage, threat hunting, incident response, and escalations.
- Drive improvements in SOC processes, playbooks, detection rules, and automation to reduce false positives and accelerate responses.
- Evaluate and optimize SOC tools like SIEM, EDR/XDR, SOAR across client environments.
- Mentor analysts through training, workshops, and performance management.
- Act as technical consultant to clients, delivering reviews, analyses, and recommendations.
Requirements
- 7+ years in Security Operations, 3–4 years in senior/lead SOC role (MSSP/multi-client preferred)
- Hands-on expertise with SIEM (Microsoft Sentinel, CrowdStrike), EDR/XDR (CrowdStrike, Microsoft Defender, Carbon Black), SOAR, threat intelligence tools
- Experience in threat hunting, detection rule tuning, automation, and multi-tenant environments
- Consulting skills for client communication and strategic advice
- Ability to work in fast-paced 24/7 environment with on-call rotations
Nice to have
- Certifications: CISSP, GIAC (GCIH, GCIA, GREM), SC-200, SC-300
- Cloud security operations experience
- Background in professional services or MSSP delivery
- Familiarity with ITIL, NIST, ISO27001 frameworks
Culture & Benefits
- High-trust, high-performance security team environment
- Collaboration with Threat Intelligence, Engineering, and Incident Response teams
- Focus on diversity, inclusion, and professional development
- Pre-employment checks including right to work, background screening
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →