SOC MANAGER
Cyber Security Operations Manager
Remote | Contract | Inside IR35
CCL Global is currently recruiting for a Cyber Security Operations Manager to lead and develop a Security Operations Centre within a high-security, technology-focused environment.
This is a senior leadership position responsible for overseeing SOC operations, managing a team of 8+ cyber security professionals and driving the continuous improvement of security monitoring, incident response and threat detection capabilities.
The successful candidate will work across security operations, threat intelligence, incident management, stakeholder engagement and supplier management. The role is suited to an experienced SOC Manager, Security Operations Lead or senior Cyber Security Manager with a strong background in enterprise or high-security environments.
Key responsibilities
- Lead, manage and mentor a team of cyber security analysts.
- Oversee the detection, triage, escalation and resolution of cyber security incidents.
- Act as a senior escalation point for critical security alerts and incidents.
- Develop and improve SOC monitoring capabilities, detection rules, use cases and playbooks.
- Support proactive threat hunting and intrusion detection activities.
- Use threat intelligence, including OSINT and commercial intelligence, to identify emerging threats.
- Define cyber security metrics, KPIs and performance targets.
- Produce management reports on incidents, trends, risks and operational performance.
- Lead post-incident reviews and drive continuous service improvement.
- Manage relationships with MSSPs, vendors and technology partners.
- Oversee SLAs, KPIs and supplier performance.
- Work closely with internal stakeholders and wider security teams to improve organisational resilience.
Essential experience
- Proven experience leading or managing a SOC or cyber security operations function.
- Demonstrable experience managing and developing cyber security teams.
- Strong knowledge of incident management, response and escalation processes.
- Experience delivering and improving security monitoring capabilities.
- Practical experience with SIEM platforms and associated security monitoring tools.
- Knowledge of threat intelligence, proactive threat hunting and intrusion detection.
- Experience managing MSSPs, vendors or external technology partners.
- Strong understanding of SLAs, KPIs, service management and operational reporting.
- Ability to communicate technical risks and security information to senior stakeholders.
- Experience working within enterprise, government, defence or another high-security environment.
Desirable qualifications and experience
- CISSP, CISM or an equivalent cyber security certification.
- Experience with cloud security, particularly AWS or Azure.
- ITIL Foundation or an equivalent service management qualification.
- Experience working with government or regulated-sector security operations.
- Knowledge of recognised cyber security frameworks and best-practice standards.