{bc}
workable

Embedded Cyber Detection and Response Deputy Team Lead

Control Risks
London, GBR
Contract
Senior · 7+ years experience
Onsite
Discovered 2 weeks ago
SIEMEDR/XDRSOARIDS/IPSlog managementSplunk
Free

Job Fit Check

Base Career helps you apply smarter for this job.

?%
Ready to Scan

Key skills for this role

SIEMEDR/XDRSOAR
Smart Apply

Full Job Posting

Requirements

  • Responsibilities
  • Serve as the primary escalation point for Cyber Detection and Response Analysts during assigned shifts and out-of-hours operations.
  • Lead and coordinate investigations into high-severity cyber security incidents, ensuring timely containment, remediation, and reporting.
  • Oversee the triage and investigation of security events across endpoint, network, cloud, and identity environments.
  • Conduct advanced threat hunting activities to identify emerging threats, undetected adversary activity, and gaps in detection coverage.
  • Support incident response activities including forensic analysis, root cause determination, remediation planning, and post-incident reviews.
  • Collaborate with Security Engineering to improve detection logic, automate workflows, and optimize security tooling.
  • Act as Team Lead during periods of absence, leave, or out-of-hours coverage.
  • Review investigation quality, reporting standards, and analyst outputs to ensure consistency and operational excellence.
  • Contribute to performance feedback discussions and professional development planning.
  • Support the Team Lead in implementing new detection and response initiatives, technologies, and operational improvements.
  • Assist with establishing and refining SOPs, playbooks, escalation frameworks, and response processes.
  • Participate in planning activities with Security Engineering and client stakeholders to improve overall security posture.
  • Identify opportunities to enhance team effectiveness through automation, workflow optimization, and process improvements.
  • Support the Team Lead in maintaining strong relationships with client security, technology, and business stakeholders.
  • Provide operational updates and incident briefings to internal and client stakeholders as required.
  • Ensure clear communication and documentation throughout investigations and response activities.
  • Qualifications
  • 7+ years of experience in cybersecurity, with significant experience in incident response, SOC operations, threat hunting, or cyber defense.
  • Demonstrated experience mentoring analysts, leading investigations, or serving as a technical lead within a security operations environment.
  • Strong hands-on experience with SIEM, EDR/XDR, SOAR, IDS/IPS, log management, and cloud security technologies.
  • Experience with platforms such as Splunk, Microsoft Sentinel, CrowdStrike, SentinelOne, Palo Alto, Microsoft Defender, or equivalent technologies.
  • Strong understanding of incident response methodologies, digital forensics principles, malware analysis, and threat hunting techniques.
  • Working knowledge of the MITRE ATT&CK Framework, NIST Cybersecurity Framework, and incident response best practices.
  • Experience supporting operational improvement initiatives, tool implementations, or security program maturity efforts.
  • Strong analytical, troubleshooting, and problem-solving skills.
  • Ability to communicate technical concepts effectively to both technical and non-technical audiences.
  • Experience working within a 24/7 operational environment and participating in on-call or escalation rotations.
  • Preferred certifications include CISSP, GCIH, GCIA, GCFA, GSOM, CISM, or equivalent.

Apply for this job in 1 click

Skip the repetitive application forms

Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.

Sarah M.James T.Maya R.

Trusted by over 500,000 job seekers on Base Career

Start Free Today

More from this employer

More jobs at Control Risks