SOC Shift Lead
Listed on 2026-07-17
-
IT/Tech
Cybersecurity, Security Management & Operations
Lead the Defenders. Hunt the Threats. Protect What Matters.
Cyber threats don't sleep – and neither do the teams that stop them.
At Sopra Steria, our Security Operations Centre stands on the front line of cyber defence, protecting some of the UK's most critical organisations. As we continue to grow our managed security services, we're looking for an experienced Lead SOC Analyst to take charge of a high‑performing team and help shape the future of our 24/7 Cyber Security Operations capability.
This is more than a leadership role. You'll remain hands‑on in the fight against cyber threats, leading investigations, driving incident response, mentoring analysts, and strengthening our detection and response capabilities across multiple complex client environments. Whether you're already leading a SOC team or you're a senior analyst ready to take the next step, this is your opportunity to make a real impact in a mission‑critical security environment.
Office based:
Hemel Hempstead OR Farnborough
Clearance:
Eligible for SC and DV Clearance
Shift based: 2 x 6am to 6pm; 2 x 6pm to 6am; 4 days off.
What You'll Be Doing:- Lead and inspire a team of SOC Analysts within a fast‑paced 24/7 Security Operations Centre.
- Take ownership of major security incidents, acting as the primary escalation point for high‑priority threats.
- Hunt, investigate and respond to sophisticated cyber attacks across client environments.
- Analyse network traffic, endpoint activity, logs and alerts to uncover malicious behaviour.
- Drive continuous improvement of detection capabilities aligned to the MITRE ATT&CK framework.
- Enhance SOC processes, tooling, playbooks and operational effectiveness.
- Mentor and develop analysts, helping build the next generation of cyber security talent.
- Represent the SOC in operational discussions with stakeholders, partners and customers.
- Proven experience working within a Security Operations Centre (SOC).
- Strong incident detection, investigation and response experience.
- Deep understanding of network and host‑based attack techniques.
- Hands‑on experience with SIEM technologies such as Microsoft Sentinel or Splunk.
- Experience leading, coaching or mentoring analysts in an operational security environment.
- Detection engineering or threat‑informed defence experience.
- MITRE ATT&CK framework knowledge.
- Python, Power Shell or Bash scripting skills.
- Malware analysis or reverse engineering exposure.
- CREST, Blue Team Level 1 or similar cyber security certifications.
Employment Type:
Permanent
Location:
Hemel Hempstead OR Farnborough
Security Clearance Level: Eligible for DV and SC Clearance.
Internal Recruiter:
Jane
Salary:
Up to £65K + shift allowance
Benefits: 25 days annual leave with the choice to buy additional holiday days, health cash plan, life assurance, and pension.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: