Salary: £36,000 - 76,000 per year Requirements: Advanced Threat Intelligence Expertise: Deep knowledge of modern attacker TTPs, including nation-state actors, infostealers, and cloud identity abuse. Proven SOC Transformation Delivery: Demonstrated leadership of SOC operations with at least five successful SOC builds or rapid rebuilds, delivered from inception to live operation within 6–12 months, ideally in regulated or high-availability environments. End-to-End Programme Ownership: Full lifecycle ownership of major initiatives including MDR consolidation, SIEM, SOAR, and security data lake deployments, delivering measurable business outcomes. Formal RFP & Vendor Management Expertise: Proven experience authoring RFPs, evaluating vendors, and overseeing complex onboarding and integration. Battle-Tested Incident Response: Hands-on expertise in detection, response, and automation with a clear understanding of what succeeds (and fails) under real-world pressure. Vendor-Neutral Technical Leadership: Ability to navigate and apply leading MDR, SIEM, SOAR, and data lake technologies agnostically to the problem being solved. AI & Automation Proficiency: Practical experience implementing agentic assistance and managing semi-autonomous security systems. Security Architecture Mindset: Strong commitment to Zero Trust principles and an assume-breach philosophy. Executive-Level Communication: Ability to translate complex technical risk into business-focused metrics (e.g. response times, patch latency) for the C-suite and Board. Mentorship & Team Evolution: Proven ability to upskill teams, fostering a culture where humans provide critical oversight and quality control over automated processes. Analytical Rigor: Expertise in behaviour-based analytics and the use of AI to synthesise 100 trillion security signals into actionable intelligence. Responsibilities: Lead and support the selection, design, and transition from fragmented security tooling to a unified SIEM platform and security data lake. Drive a fundamental shift from incident-focused, task-based workflows to preventative security activities and platform optimisation. Guide the evolution from reactive alert handling to proactive threat hunting and investigation. Leverage AI and advanced analytics across diverse data sets to uncover hidden patterns and anomalies before exploitation occurs. Support the specification, design, and implementation of an attacker-centric defence strategy. Use AI and threat intelligence to visualise lateral movement paths and chokepoints. Oversee autonomous hardening capabilities that automatically patch systems and update configurations based on predicted attack paths. Assist in defining and deploying controls to manage enterprise AI risks, including prompt injection, data poisoning, and model theft. Deploy and monitor guardian agents to provide real-time detection of malicious behaviour within AI systems. Guide the development, testing, and maintenance of advanced incident response plans, focusing on high-impact threats such as human-operated ransomware. Ensure rapid isolation of affected assets and credential revocation to minimise blast radius. Enforce phishing-resistant MFA and oversee the security of workload identities (applications, services, scripts). Address the growing threat of cloud identity abuse by sophisticated adversaries. Partner with IT operations and business leaders to ensure security evolution aligns with business objectives and board-level risk management. Technologies: AI Cloud Support Security More: We are seeking a Lead Security Operations Centre (SOC) Subject Matter Expert to spearhead the transformation of Security Operations from a traditional, reactive defence model into an AI-enabled, human-driven SecOps capability. In this role, you will lead the shift away from manual alert triage toward security platform optimisation, proactive threat anticipation, and autonomous defensive controls. You will have the opportunity to shape both the technology strategy and the operating model within a collaborative team environment. last updated 9 week of 2026