Skip to main content
AfterDuty

Security Operations Team Lead / Incident Response Lead

Anson McCade · London, Greater London

Type
Full-time
Posted
15 days ago

Overview

Your incident command and decision-making under pressure transfer, but deep SOC technical skills require years of specialist retraining.

About this role

SOC Shift Lead – London (24/7 Shift Operations)

We are supporting a global technology organisation in building a new high-performance Security Operations capability supporting secure sovereign AI infrastructure.

As a SOC Shift Lead, you will take ownership of SOC operations during your assigned shift, acting as the senior escalation point for complex security incidents and providing technical leadership to analysts within a critical 24/7 environment.

This role is suited to an experienced SOC professional who has progressed beyond individual contribution and has experience leading teams, mentoring analysts and driving improvements across security operations.

Key Responsibilities

  • Lead SOC operations during assigned shifts, acting as the escalation point for high-priority incidents.
  • Investigate and manage complex security incidents, identifying attack vectors, scope and business impact.
  • Lead incident response activities including containment, eradication and recovery.
  • Perform advanced threat analysis and root cause investigations.
  • Coordinate responses across security, infrastructure and technology teams.
  • Provide coaching, mentoring and technical development for SOC analysts.
  • Support threat hunting activities and identify opportunities to improve detection coverage.
  • Review and enhance SOC processes, playbooks and operational procedures.
  • Act as the accountable lead in the absence of SOC management.

What we’re looking for

  • 7+ years’ experience within SOC, incident response, threat analysis or security operations.
  • Proven experience leading SOC teams, mentoring analysts or delivering technical coaching.
  • Strong experience handling complex security incidents and investigations.
  • Experience with threat hunting and/or incident response activities.
  • Strong understanding of SIEM, EDR and security monitoring technologies.
  • Ability to make decisions under pressure within a fast-paced operational environment.

Additional Requirements

  • Must be a sole British National (no dual nationality).
  • Must be eligible to obtain UK Security Clearance.
  • Ability to work onsite as part of a 24/7 shift pattern.
  • Previous experience leading, teaching or upskilling junior SOC analysts is essential.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in London

Why this fits a police background

  • Police experience explicitly valued
  • Incident command & response
  • Investigative casework
  • Security operations
  • Training & coaching delivery

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Full-time

    Your experience managing operational risk and leading incident reviews translates directly into shaping security culture and resilience.

    Posted 2 days ago

  • Information Security Analyst

    Europa Worldwide Group · London

    Full-time

    £40,000 – £45,000Estimated

    Your experience managing evidence, compliance, and risk under ISO standards translates directly into this security assurance role.

    Posted 2 days ago

  • Cyber Security & Compliance Analyst

    Shivom Consultancy Ltd · London

    Full-time

    Your incident management, evidence handling, and risk assessment from policing transfer directly to this role.

    Posted 2 days ago

  • £570 a dayEstimated

    Your experience managing security incidents and coordinating multi-agency responses transfers directly to this governance role.

    Posted 2 days ago