About this role
SOC Shift Lead – London (24/7 Shift Operations)
We are supporting a global technology organisation in building a new high-performance Security Operations capability supporting secure sovereign AI infrastructure.
As a SOC Shift Lead, you will take ownership of SOC operations during your assigned shift, acting as the senior escalation point for complex security incidents and providing technical leadership to analysts within a critical 24/7 environment.
This role is suited to an experienced SOC professional who has progressed beyond individual contribution and has experience leading teams, mentoring analysts and driving improvements across security operations.
Key Responsibilities
- Lead SOC operations during assigned shifts, acting as the escalation point for high-priority incidents.
- Investigate and manage complex security incidents, identifying attack vectors, scope and business impact.
- Lead incident response activities including containment, eradication and recovery.
- Perform advanced threat analysis and root cause investigations.
- Coordinate responses across security, infrastructure and technology teams.
- Provide coaching, mentoring and technical development for SOC analysts.
- Support threat hunting activities and identify opportunities to improve detection coverage.
- Review and enhance SOC processes, playbooks and operational procedures.
- Act as the accountable lead in the absence of SOC management.
What we’re looking for
- 7+ years’ experience within SOC, incident response, threat analysis or security operations.
- Proven experience leading SOC teams, mentoring analysts or delivering technical coaching.
- Strong experience handling complex security incidents and investigations.
- Experience with threat hunting and/or incident response activities.
- Strong understanding of SIEM, EDR and security monitoring technologies.
- Ability to make decisions under pressure within a fast-paced operational environment.
Additional Requirements
- Must be a sole British National (no dual nationality).
- Must be eligible to obtain UK Security Clearance.
- Ability to work onsite as part of a 24/7 shift pattern.
- Previous experience leading, teaching or upskilling junior SOC analysts is essential.
About cyber security & digital forensics roles for ex-police
Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.
See all cyber security & digital forensics jobs in London →Why this fits a police background
- Police experience explicitly valued
- Incident command & response
- Investigative casework
- Security operations
- Training & coaching delivery
What cyber security & digital forensics roles pay ex-police
Advertised UK ranges, editorial estimates reviewed July 2026
| Digital forensics analyst | £32,000–£45,000 |
| DFIR consultant | £45,000–£65,000 |
| Senior forensics / IR specialist | £60,000–£80,000 |
| Threat-intelligence specialist | £55,000–£80,000 |