Skip to main content
AfterDuty

SOC Shift Lead

Anson McCade · London, Greater London

Type
Full-time
Posted
24 days ago

Overview

Your incident command and crisis management experience from policing translate to leading high-severity incident response.

About this role

SOC Shift Lead | London | £70,000–£84,900 + 25% Shift Premium

London | 24/7 SOC | Permanent | Security Clearance Required

I’m currently supporting a major transformation programme focused on sovereign AI and next-generation high-performance computing infrastructure, and I’m looking for an experienced SOC Shift Lead to join a 24/7 security operation in Central London.

This is not a traditional SOC Analyst position. You’ll be the senior technical escalation point on shift, leading incident response activity, supporting analysts and taking ownership of complex and high-severity security incidents.

What you’ll be doing

  • Lead the response to medium and high-severity security incidents
  • Act as the escalation point for complex investigations and provide technical direction on shift
  • Investigate attack vectors, scope and potential impact across multiple data sources
  • Perform root cause analysis and coordinate containment, eradication and recovery
  • Correlate events across SIEM, EDR and other security tooling to build a clear incident narrative
  • Identify detection gaps and support improvements to rules, thresholds and playbooks
  • Mentor and provide technical guidance to L1 SOC Analysts
  • Produce detailed investigation and incident reports
  • Participate in SOC exercises and incident response simulations
  • Take operational accountability for the SOC during your shift in the absence of the SOC Manager / NOC Lead

What we’re looking for

You’ll ideally bring 7+ years’ experience across SOC, Incident Response or Threat Analysis, with proven experience leading a SOC team or acting as a senior escalation point.

You should have strong hands-on knowledge of

  • SIEM and EDR technologies
  • Incident response and investigation
  • Threat analysis and malware behaviour
  • Detection engineering / tuning
  • Incident containment and remediation
  • Leading or mentoring SOC Analysts

Certifications such as GCIH, GCIA, SC-200, CySA+ or Splunk are advantageous but not essential.

Why consider it?

  • £70,000–£84,900 basic salary
  • 25% shift premium
  • Central London
  • 24/7 SOC operation
  • Opportunity to work within a highly secure, next-generation AI compute environment
  • Genuine SOC leadership responsibility rather than purely hands-on monitoring
  • Exposure to some of the most advanced high-density compute infrastructure being developed in the UK

If you’re currently a SOC Team Lead, SOC Shift Lead, Senior SOC Analyst or Incident Response Lead and are looking for your next step into a high-profile, security-critical environment, I’d be keen to speak.

Bradley Collings

Senior Technology Recruitment Consultant

Bradley.Collings@ansonmccade.com

https://www.linkedin.com/in/bradley-collings-amc/

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in London

Why this fits a police background

  • Police experience explicitly valued
  • Incident command & response
  • Investigative casework
  • Training & coaching delivery
  • Team & shift leadership

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Security Architect - (Active SC Clearance Required)

    Sanderson Government & Defence · London

    Contract

    £500 – £550 a dayEstimated

    Your experience managing risk and applying security standards in policing gives you a strong foundation for security architecture.

    Posted Yesterday

  • Your evidence handling, chain of custody, and investigative discipline from policing are directly applicable to digital forensic investigations.

    Posted 6 days ago

  • Information Security Analyst

    Howard Kennedy LLP · London

    Full-time

    Your incident response and investigative discipline from policing directly apply to triaging and managing security alerts.

    Posted 6 days ago

  • SOC Team Lead

    Methods Business and Digital Technology · London

    Full-time

    £45,000 – £50,000Estimated

    Your incident command and crisis management experience translates directly to leading a SOC under pressure.

    Posted 8 days ago