Skip to main content
AfterDuty

SOC Shift Lead

Anson McCade · London, Greater London

Type
Full-time
Posted
11 days ago

Overview

Your incident command and crisis management experience from policing translate to leading high-severity incident response.

About this role

SOC Shift Lead | London | £70,000–£84,900 + 25% Shift Premium

London | 24/7 SOC | Permanent | Security Clearance Required

I’m currently supporting a major transformation programme focused on sovereign AI and next-generation high-performance computing infrastructure, and I’m looking for an experienced SOC Shift Lead to join a 24/7 security operation in Central London.

This is not a traditional SOC Analyst position. You’ll be the senior technical escalation point on shift, leading incident response activity, supporting analysts and taking ownership of complex and high-severity security incidents.

What you’ll be doing

  • Lead the response to medium and high-severity security incidents
  • Act as the escalation point for complex investigations and provide technical direction on shift
  • Investigate attack vectors, scope and potential impact across multiple data sources
  • Perform root cause analysis and coordinate containment, eradication and recovery
  • Correlate events across SIEM, EDR and other security tooling to build a clear incident narrative
  • Identify detection gaps and support improvements to rules, thresholds and playbooks
  • Mentor and provide technical guidance to L1 SOC Analysts
  • Produce detailed investigation and incident reports
  • Participate in SOC exercises and incident response simulations
  • Take operational accountability for the SOC during your shift in the absence of the SOC Manager / NOC Lead

What we’re looking for

You’ll ideally bring 7+ years’ experience across SOC, Incident Response or Threat Analysis, with proven experience leading a SOC team or acting as a senior escalation point.

You should have strong hands-on knowledge of

  • SIEM and EDR technologies
  • Incident response and investigation
  • Threat analysis and malware behaviour
  • Detection engineering / tuning
  • Incident containment and remediation
  • Leading or mentoring SOC Analysts

Certifications such as GCIH, GCIA, SC-200, CySA+ or Splunk are advantageous but not essential.

Why consider it?

  • £70,000–£84,900 basic salary
  • 25% shift premium
  • Central London
  • 24/7 SOC operation
  • Opportunity to work within a highly secure, next-generation AI compute environment
  • Genuine SOC leadership responsibility rather than purely hands-on monitoring
  • Exposure to some of the most advanced high-density compute infrastructure being developed in the UK

If you’re currently a SOC Team Lead, SOC Shift Lead, Senior SOC Analyst or Incident Response Lead and are looking for your next step into a high-profile, security-critical environment, I’d be keen to speak.

Bradley Collings

Senior Technology Recruitment Consultant

Bradley.Collings@ansonmccade.com

https://www.linkedin.com/in/bradley-collings-amc/

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in London

Why this fits a police background

  • Police experience explicitly valued
  • Incident command & response
  • Investigative casework
  • Training & coaching delivery
  • Team & shift leadership

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • £35,000 – £40,000Estimated

    Your risk assessment and incident management skills from policing are directly applicable to this GRC role.

    Posted 4 days ago

  • Full-time

    Your incident command and multi-agency coordination experience translates directly to operational resilience and third-party oversight.

    Posted 4 days ago

  • Full-time

    Your investigative mindset and evidence-handling discipline from policing transfer directly to digital forensics and incident response.

    Posted 5 days ago

  • GRC Manager - 6 month FTC

    Trayport · London

    Full-time

    Your experience managing risk, policy, and regulatory compliance under frameworks like PACE transfers directly to GRC.

    Posted 7 days ago