UK remote
SOC and Incident Response Lead
About this role
The Role As an experienced SOC and Incident Response Lead at ASOS, you will provide hands-on technical leadership across security monitoring, detection, engineering, incident response, and threat-led investigations. You will lead the SOC and Incident Response team, ensure security incidents are investigated and resolved effectively, and maintain a strong operating relationship with our external MSSP. The ideal candidate will combine deep technical expertise with proven experience leading analysts, improving operational capability, managing stakeholders, and making sound decisions under pressure.
The role will act as the bridge between wider technology teams, the cyber security team, and third-party partners, ensuring a coordinated and consistent response to cyber security incidents. This role reports to the Head of Security Operations. Responsibilities Lead the SOC and Incident Response team day to day, providing technical direction, coaching analysts, maintaining effective operations, and ensuring the team has clear priorities, strong morale, and the capability to respond to complex security incidents.
Own and improve the SOC detection lifecycle, including reviewing detection coverage, tuning noisy or low-value alerts, creating new detections from threat intelligence and incident learnings, and mapping coverage against relevant attack techniques and critical business assets. Establish and maintain incident response processes, procedures, and documentation, ensuring they align with industry best practices. Strong hands-on experience with SIEM, EDR, cloud security, identity, email security, and forensic analysis tooling, with the ability to investigate incidents, validate detections, and guide analysts through complex technical findings.
Define incident response metrics, dashboards, track and report on key performance indicators (KPIs) to senior management, suggesting improvements as needed. Delegate unassigned newly submitted tickets to analysts keeping in mind current workloads and availability. Conduct regular incident response training and drills to enhance team readiness and improve response times. Lead incident post-mortem analysis to identify root causes, lessons learned, and recommend measures for prevention or improvement.