Role: SOC Shift Lead – London
Location: London
Salary: Competitive salary and package dependent on experience
Career Level: Associate Manager
Please Note: Any offer of employment is subject to satisfactory BPSS and the candidate being granted a level of security clearance which typically requires 10 years continuous UK address history, usually including no periods of 30 consecutive days or more spent outside of the UK, and a declaration of being a British passport holder with no dual nationality at the point of application.
Note: The above information relates to a specific client requirement
Role Description: SOC Shift Lead – London provides advanced investigation and analysis, acting as the escalation point for complex or high‑severity incidents. They conduct root‑cause analysis, guide L1 analysts, and support incident containment and remediation efforts. The role is part of a high‑performance compute operations team operating 24/7, with shift teams paid a premium for unsociable shift hours.
Key Responsibilities
- Investigate escalated incidents to determine attack vectors, scope, and potential impact.
- Correlate events across multiple data sources to build a comprehensive incident narrative.
- Execute containment, eradication, and recovery activities in coordination with IT/OT stakeholders.
- Lead response for medium to high‑severity incidents and document detailed investigation reports.
- Conduct tuning of detection rules and thresholds in collaboration with the Security Content Engineer.
- Support continuous improvement by identifying gaps in detection coverage and playbooks.
- Mentor and provide technical guidance to L1 Analysts.
- Participate in periodic SOC exercises and simulated incident response drills.
- Be part of a 24/7 SOC Team, working in shifts.
- As a shift lead you will be responsible for handling escalations of the Technology Operations Centre in that particular shift. You will be accountable in the absence of a SOC manager or NOC lead.
Role Requirements
- Education: Bachelor’s degree in Cybersecurity, Computer Science, or related field.
- Experience: 7–10 years in SOC, Incident Response, or Threat Analysis roles.
- Certifications (preferred): GCIA, GCIH, CompTIA CySA+, Microsoft SC‑200, or Splunk Certified Power User.
Essential Skills
- Strong analytical mindset, in-depth knowledge of SIEM/EDR tools, malware behaviour, and incident handling methodologies.
#J-18808-Ljbffr
SOC Shift Lead employer: 慨正橡扯
At Third Bridge, we are not just offering a job; we are providing a career launchpad in a vibrant and fast-paced environment. With a strong focus on employee growth, our Client Services Associate role allows you to develop essential skills while working with top-tier clients, all within a supportive culture that values work-life balance and personal development. Join us to accelerate your career and enjoy comprehensive benefits, including generous vacation days and the flexibility to work from anywhere for a month each year.