SOC Team Lead

SOC Team Lead

£45,000–£50,000 DOE
Fully Remote – Must Be UK Based
Monday–Friday, 8.30am–5.30pm

Are you an experienced SOC Analyst ready to take your first step into leadership, or an existing Team Lead looking for a role where you can help shape a growing security function?

Can you explain technical security issues clearly, build confidence with clients and keep people informed when an incident needs attention?

Would you enjoy developing other analysts while building your own career towards senior SOC leadership?

We are recruiting for a SOC Team Lead to join a growing technology consultancy with an established Security Operations team supporting customers across a variety of industries, including financial services and real estate.

This is a hands-on leadership opportunity combining security operations, people management and regular client interaction. Within a wider team of approximately 15, you will take day-to-day management responsibility for most of the SOC team.

Excellent communication is central to this role. You will lead client conversations, explain findings to people with different levels of technical understanding and provide clear, timely updates during investigations.

We are open to an existing SOC Team Lead or an experienced SOC Analyst who has started mentoring colleagues, taking ownership of escalations and demonstrating the potential to lead. You do not need to have mastered every aspect of formal people management; there is scope to develop these skills.

What will you be doing?

You will coordinate the team’s day-to-day activities, support analysts with investigations and maintain the quality of the security service delivered to customers.

Your responsibilities will include:

  • Prioritising security alerts, investigations and escalations, ensuring work progresses effectively.

  • Acting as the SOC escalation point during UK working hours, reviewing and signing off escalation reports and supporting more advanced investigations when needed.

  • Remaining involved in threat detection, investigation and incident response.

  • Leading client service reviews and incident-related calls, explaining findings and recommended actions clearly.

  • Producing and reviewing useful, accurate security reports.

  • Coaching and mentoring analysts, helping them build technical knowledge and confidence.

  • Planning rotas, contributing to recruitment and taking responsibility for appraisals and performance management as your experience develops.

  • Maintaining consistent standards for ticket management, documentation, handovers and response quality.

  • Improving investigation procedures, playbooks and operational processes.

  • Contributing to threat intelligence research and reporting, with the team looking to use AI to support initial research and analysis.

What are we looking for?

  • Commercial experience working within a SOC.

  • Practical experience investigating security alerts and responding to incidents.

  • Hands-on experience with a SIEM platform and familiarity with endpoint security tools.

  • Some exposure to Microsoft 365 environments.

  • Excellent written and verbal communication, including the ability to explain technical findings clearly to non-technical audiences.

  • Confidence speaking with clients, managing expectations and keeping them informed.

  • Experience supporting, mentoring or guiding colleagues, with the ambition to develop your people management skills.

  • A calm, organised approach to competing priorities and escalations.

  • Sound judgement about when to take ownership and when to involve specialist support.

  • The ability to work effectively within a remote team.

Experience within an MSP, MSSP or another environment supporting multiple customers would be particularly useful.

Technical experience that would be useful

The team uses Microsoft Sentinel and Microsoft Defender XDR, but experience with these specific platforms is desirable rather than essential. We welcome applicants who have worked with other SIEM technologies.

The following would also strengthen your application:

  • KQL or similar query languages used to investigate security events.

  • Threat hunting and the use of threat intelligence within investigations.

  • Familiarity with MITRE ATT&CK and common attacker techniques.

  • Improving detection rules, investigation playbooks or response workflows.

  • Relevant certifications, such as Microsoft SC-200, CompTIA Security+ or equivalent practical knowledge.

Working hours

The usual working pattern is Monday–Friday, 8.30am–5.30pm, working fully remotely from within the UK.

As a point of escalation, you may very occasionally be required to take a call outside these hours, including overnight.

Why consider this role?

You will have the opportunity to take meaningful responsibility within an established SOC, develop other analysts and build strong relationships with customers.

For an experienced analyst, this could be your first formal leadership appointment, with scope to learn areas such as appraisals and performance management. For an existing Team Lead, it offers the opportunity to influence how the team works and develops.

Longer term, there is potential to progress towards Global Head of SOC, as your capabilities and the security function grow.

If you combine practical SOC experience with excellent communication and the ambition to develop as a leader, we would be pleased to have a confidential conversation.

Job Details

Company
Constant Recruitment Ltd
Location
Folkestone, Kent, United Kingdom
Hybrid / Remote Options
Employment Type
Permanent
Salary
£45000 - £50000/annum
Posted