UK remote
Team Lead, Cybersecurity Engineering
About this role
As a member of the Cybersecurity Department, the Cybersecurity Team Lead will provide hands- on technical leadership for the UK Security Operations Centre (SOC) team while collaborating closely with SOC leadership and peer team leads across the wider organisation. This role will partner with ServiceDesk, Engineering, and business stakeholders to strengthen security across data, systems, networks, applications, and client environments.
The UK SOC Team Lead will guide daily security operations, support analyst development, coordinate incident response and security initiatives, and help ensure consistent global SOC processes, communication, and service delivery across time zones. Responsibilities Lead day-to-day UK SOC operations, prioritising work, coordinating escalations,supporting shift handovers, and ensuring timely delivery of security services and commitments.
Provide technical guidance, coaching, and mentorship to Security Analysts, helping build capability, consistency, and accountability across the team. Collaborate with SOC managers and peer team leads in India and the US to align priorities, share operational context, maintain consistent processes, and support follow-the-sun security operations. Oversee security tools, platforms, and operational processes including MDR, endpoint detection and response, identity management, email filtering, firewalls, application control, threat intelligence, incident tickets and security documentation.
Coordinate response to escalated security support tickets and incidents, including triage, investigation, containment, communication, and follow-up actions; occasional out-of- hours work may be required. Manage and maintain multiple security solutions and appliances, ensuring appropriate configuration, monitoring, lifecycle management, and operational effectiveness. Partner with information security leadership to develop operational plans, enforce security requirements, address identified risks, and report on team progress, risks, and improvement opportunities.
Monitor vulnerability intelligence and emerging threats, assess business and clien impact, and coordinate remediation activity with ServiceDesk, Engineering, and other technical teams. Review and improve security operations documentation, runbooks, procedures, and knowledge articles to support consistent execution and audit readiness. Communicate effectively with management, clients, peers, technical stakeholders, and geographically distributed SOC leaders, translating security risks and recommendations into clear business language.