Cyber Security Operations & CTI Lead

Cyber Security Operations & CTI Lead

Full-Time 77000 - 90000 £ / year (est.) No working from home possible
Serco Limited

At a Glance

  • Tasks: Lead cyber security operations and shape threat intelligence capabilities from the ground up.
  • Company: Join Serco, a global leader in essential services with a commitment to security.
  • Benefits: Enjoy a competitive salary, private healthcare, flexible working, and a bonus scheme.
  • Other info: Opportunities for career development and a supportive culture await you.
  • Why this job: Make a real impact in cyber security while working with a motivated team.
  • Qualifications: 7+ years in cyber security, strong SOC experience, and excellent communication skills.

The predicted salary is between 77000 - 90000 £ per year.

  • Cyber Security Operations & CTI Lead
  • Full Time, Permanent
  • Band B2 | £77,000 - £90,000 per annum DOE
  • Overview

Serco is building out its in‑house cyber security capability, and this is a rare opportunity to shape it from the ground up.

Around 18 months ago we made a long‑term commitment to bringing more security expertise in‑house - this new role is a key part of that plan.

You’ll provide senior technical leadership across Security Operations and Threat Intelligence, ensuring threats are identified, analysed, and translated into action.

This is a hands‑on technical role: monitoring, threat hunting, detection engineering, and incident response - strengthening how Serco detects and responds to evolving cyber threats.

We’re a small team with large ambitions, globalising this service, and you’ll play a central role in shaping its future.

Responsibilities

  • Provide technical leadership across Security Operations—alert triage, investigation, and escalation—and act as senior escalation point for complex investigations
  • Design, build, and evolve a new Cyber Threat Intelligence capability, integrating it into SOC workflows, detection logic, and incident response
  • Analyse and track threat actors and campaigns, mapping adversary TTPs to MITRE ATT&CK and translating intelligence into detection improvements
  • Develop, tune, and optimise detection rules based on threat intelligence and incident learnings
  • Lead hypothesis‑driven threat hunting, feeding outcomes back into detection engineering
  • Lead cyber incidents end‑to‑end, producing high‑quality incident reports with root cause analysis and lessons learned
  • Author and maintain incident response playbooks and SOC/CTI processes
  • Task‑manage a team of analysts day‑to‑day, with around four direct reports as the function grows
  • Participate in an on‑call rota supporting incident escalations
  • What you’ll need to do the role
  • 7+ years’ experience in cyber security roles, in‑house or within an MSSP
  • Strong experience within a SOC environment, including incident response end‑to‑end
  • Proven experience building or integrating a Cyber Threat Intelligence function
  • Strong knowledge of SIEM, EDR, and SOAR tooling, and the MITRE ATT&CK framework
  • Demonstrated detection engineering and intelligence‑led threat hunting experience
  • Clear communication skills, technical and non‑technical, and the ability to operate under pressure during incidents

You’ll need to be eligible for BPSS clearance.

Desirable

  • CISSP
  • Relevant SANS certifications (e. g. SEC503, FOR572)
  • Relevant Microsoft certifications (e. g. SC200)
  • Blue Team Level 2 (BTL2)
  • Why Serco

Meaningful and vital work: In this position, your work is vital to the business, in terms of decisions and growth.

You will gain a world of opportunity working for a globally operating business delivering essential services across 5 vital sectors, personal growth, achievement and development won’t be hard to find.

You’ll also work with great people.

You’ll find yourself working in a highly motivated, supportive environment where no two days are the same, with experienced colleagues who strive for excellence.

What we offer

  • Company car
  • Private healthcare
  • Bonus scheme of up to 30%
  • Flexible working considered
  • Pension – 6%
  • Chance to contribute to innovation in the public services
  • A company passionate about diversity and inclusion
  • Serco discounts which include cinema, merlin entertainment and online shopping discounts, and discounts on mobile phone plans and leisure centre memberships
  • A range of benefits to support the health and wellbeing of you and your family such as Employee Assistance Programme, Simply Health Cash Plans, and more.
  • A wealth of career development training to suit your future aspirations.

These range from role specific training, leadership coaching, formal study and much more to support you to build your career with Serco.

  • A safe and supportive culture.
  • #J-18808-Ljbffr

Cyber Security Operations & CTI Lead employer: Serco Limited

Serco Limited is an excellent employer, offering a dynamic work environment in Waterlooville where innovation meets national security. With a strong focus on employee development through comprehensive training programs and a generous benefits package including 25 days of holiday and a contributory pension scheme, Serco fosters a culture of collaboration and growth, making it an ideal place for Electronics & Hardware Engineers to thrive and contribute meaningfully to defence technology.

Serco Limited

Contact Details:

Serco Limited Recruitment Team

We think you need these skills to ace Cyber Security Operations & CTI Lead

Cyber Security
Threat Intelligence
Incident Response
Security Operations
Detection Engineering
Threat Hunting
SIEM