Apply Edge Start your job search

SOC Technical Lead

Experis · United Kingdom

Apply & track with Apply Edge
SOC Operations Technical LeadRole objectiveThe purpose of this role is to lead a team of SOC analysts, who are collectively operating on a 24/7/365 basis. Technical and client-oriented SOC Operations Technical Lead role plays a pivotal senior role within our Managed Security Services Provider (MSSP) environment. This role reports to Head of SOC Operations.This hands-on position serves as the senior technical authority for SOC operations, driving excellence in threat detection, incident response, and security operations across a diverse multi-client portfolio.You will combine deep technical proficiency with strong consulting skills to mentor analysts, manage shift rotations, optimise SOC processes and tools, lead complex incident escalations, and act as a trusted advisor.Although you will manage team of SOC analysts, this is not a purely managerial role; you will remain deeply involved in technical work while elevating team capabilities and delivering strategic value to our clients.Team Leadership & Operations OversightLead day-to-day activities of the SOC analysts across all shifts (24/7 operations through and on call rotation).Manage team scheduling, shift handovers, and always ensure proper coverage.Act as the first point of escalation for security events and staff queries during shifts.Aim to ensure high-quality incident triage, investigation, and response by team members, following predefined and agreed SOC processes.Coordinate with other shifts to maintain operational continuity and consistent processes.Lead and Facilitate the Development of the wider monitoring team through technical training courses, workshops and exercises.Applicable department objectives and projects are completed within specification, deadline and budgetary constraints.Ensure completion of all HALO case management on time and with accurate and timely results.Technical Leadership & Operations ExcellenceProvide technical leadership and guidance to SOC analysts on alert triage, investigation, threat hunting, and incident response.Function as the primary technical escalation point for complex, high-severity, or novel security alerts across multiple client environments.Drive continuous improvement of SOC processes, playbooks, detection rules, and automation to enhance efficiency, reduce false positives, and accelerate response times.Evaluate, recommend, and support the implementation and optimization of SOC technologies (SIEM, EDR/XDR, SOAR, threat intelligence platforms) across heterogeneous client stacks.Develop and maintain advanced detection content, custom queries, correlation rules, and use cases tailored to client environments and emerging threats.Consulting & Client EngagementServe as a trusted technical consultant to clients, participating in security reviews, root cause analyses, and recommendations for security posture improvements.Translate complex technical findings and recommendations into clear, actionable insights for both technical and executive client stakeholders.Required Qualifications & Experience7+ years of experience in Security Operations, with at least 3–4 years in a senior/lead technical role within a SOC (preferably in an MSSP or multi-client environment).Strong hands-on expertise with industry-leading tools:SIEM platforms (Microsoft Sentinel, CrowdStrike)EDR/XDR solutions (CrowdStrike, Microsoft Defender, Carbon Black)SOAR, threat intelligence platforms, and network security tools.Proven experience in advanced threat hunting.Solid automation skills to improve SOC efficiency.Experience designing and tuning detection rules, use cases, and correlation logic in multi-tenant environments.Demonstrated consulting skills and ability to communicate effectively with clients, present findings, and provide strategic security advice.