Haystack
← Back to Jobs
Other
AM

SOC Shift Lead

Anson McCadelondon, london🇬🇧United KingdomPosted 20 Aug 2026

Quick Overview

Salary
£70k - £84.9k/yr
Work Type
Hybrid
Level
Mid Senior

Job Description

SOC Shift Lead | London | £70,000–£84,900 + 25% Shift Premium

London | 24/7 SOC | Permanent | Security Clearance Required


I’m currently supporting a major transformation programme focused on sovereign AI and next-generation high-performance computing infrastructure , and I’m looking for an experienced SOC Shift Lead to join a 24/7 security operation in Central London.


This is not a traditional SOC Analyst position. You’ll be the senior technical escalation point on shift , leading incident response activity, supporting analysts and taking ownership of complex and high-severity security incidents.


What you’ll be doing

  • Lead the response to medium and high-severity security incidents
  • Act as the escalation point for complex investigations and provide technical direction on shift
  • Investigate attack vectors, scope and potential impact across multiple data sources
  • Perform root cause analysis and coordinate containment, eradication and recovery
  • Correlate events across SIEM, EDR and other security tooling to build a clear incident narrative
  • Identify detection gaps and support improvements to rules, thresholds and playbooks
  • Mentor and provide technical guidance to L1 SOC Analysts
  • Produce detailed investigation and incident reports
  • Participate in SOC exercises and incident response simulations
  • Take operational accountability for the SOC during your shift in the absence of the SOC Manager / NOC Lead


What we’re looking for

You’ll ideally bring 7+ years’ experience across SOC, Incident Response or Threat Analysis , with proven experience leading a SOC team or acting as a senior escalation point .


You should have strong hands-on knowledge of:

  • SIEM and EDR technologies
  • Incident response and investigation
  • Threat analysis and malware behaviour
  • Detection engineering / tuning
  • Incident containment and remediation
  • Leading or mentoring SOC Analysts


Certifications such as GCIH, GCIA, SC-200, CySA+ or Splunk are advantageous but not essential.


Why consider it?

  • £70,000–£84,900 basic salary
  • 25% shift premium
  • Central London
  • 24/7 SOC operation
  • Opportunity to work within a highly secure, next-generation AI compute environment
  • Genuine SOC leadership responsibility rather than purely hands-on monitoring
  • Exposure to some of the most advanced high-density compute infrastructure being developed in the UK


If you’re currently a SOC Team Lead, SOC Shift Lead, Senior SOC Analyst or Incident Response Lead and are looking for your next step into a high-profile, security-critical environment, I’d be keen to speak.


Bradley Collings

Senior Technology Recruitment Consultant

Skills

Splunk
Root Cause Analysis

Similar jobs