Security Operations Center Analyst
SOC Shift Lead – London
Location: London
Salary: £70,000 - £84,900 + package + shift premium
Working Pattern: 24/7 shifts
Level: Associate Manager / Consultant
A leading global consultancy is looking for a SOC Shift Lead to join a new 24/7 security operation supporting next-generation AI compute infrastructure in the UK.
This is a great opportunity for an experienced SOC, Cyber Defence or Incident Response professional looking to take on more technical leadership and ownership within a highly secure, cutting-edge environment.
The Role
As a SOC Shift Lead, you'll be the senior technical escalation point on your shift, taking ownership of complex and high-severity security incidents.
You'll investigate incidents, identify attack vectors and impact, lead containment and remediation, and provide technical guidance to junior analysts.
You'll be responsible for:
- Leading investigations into medium and high-severity security incidents
- Analysing and correlating data across SIEM, EDR and other security sources
- Leading containment, eradication and recovery activities
- Conducting root-cause analysis and producing incident reports
- Supporting detection rule and threshold tuning
- Identifying gaps in detection coverage and response processes
- Mentoring and supporting SOC Analysts
- Acting as the senior escalation point during your shift
- Supporting SOC exercises and incident response simulations
What we're looking for
We're particularly interested in candidates with:
- 5–10 years' experience across SOC, Incident Response or Threat Analysis
- Strong experience with SIEM and EDR technologies
- Hands-on experience investigating and responding to security incidents
- Knowledge of threat detection, containment and remediation
- Experience acting as a technical escalation point or mentoring junior analysts
- Strong analytical and investigative skills
Experience with Splunk, Microsoft Sentinel, Microsoft Defender, CrowdStrike or similar would be beneficial.
Relevant certifications such as GCIH, GCIA, CySA+, SC-200 or Splunk certifications are desirable but not essential.
The Opportunity
This isn't simply a SOC monitoring role. You'll be leading incident investigations, making decisions during high-severity events and providing technical leadership across your shift.
You'll also be working within a highly secure, next-generation AI infrastructure environment, giving you exposure to some of the latest technology and security challenges.
Please note: This is a 24/7 shift-based position with a shift premium. The role is subject to BPSS and the required level of security clearance, including 10 years' continuous UK address history.
If this sounds like the right fit for you, please contact erin.robinson@ansonmccade.com