SOC Shift Lead
Job Fit Check
Base Career helps you apply smarter for this job.
Role Overview
About Claranet Founded at the beginning of the dot.com bubble in 1996, our CEO Charles Nasser had a light bulb moment to develop a truly customer-focused IT business.
Since then, Claranet has grown from an Internet Service Provider (ISP) in the UK to being one of the leading business modernisation experts, who deliver solutions across 11+ countries.
At Claranet, we’re experienced in implementing progressive technology solutions which help our customers solve their epic business challenges.
We’re committed to understanding their problems, delivering answers quickly, and making a lasting impact to their business.
We are agile, focused and experienced in business modernisation.
Our approach helps customers make genuine, significant shifts in their business strategy, to deliver financial savings, boost innovation, and create a resilient business.
We continually invest in our people and the latest technologies, so our customers get peace of mind knowing that they have access to the best talent and services.
In the UK we have over 500 staff working in London, Gloucester, Warrington and Leeds, or as homeworkers.
Working For Claranet Here at Claranet we pride ourselves on going the extra mile for and with our employees (yes, we really mean with).
We offer an extensive benefits package that you can tailor to your needs, inclusive of a matching contribution pension scheme, healthcare, insurance, dental, discounted gyms and app supported benefit access.
But what we think makes us different is ‘Team Claranet,’ our dedicated internal part of the business that supports you with matters close to your heart.
We proudly support local charities in each of our office locations, support employees with paid charity leave, organise key charity fundraising event per year and have a dedicated committee responsible for supporting employee’s fundraising efforts.
Our Vision Our vision is to become the most trusted technology solutions partner; renowned for being the best and brightest, having lasting impact with our customers and delivering exceptional returns to our stakeholders.
Full Job Posting
Position Summary
About Claranet Founded at the beginning of the dot.com bubble in 1996, our CEO Charles Nasser had a light bulb moment to develop a truly customer-focused IT business.
Since then, Claranet has grown from an Internet Service Provider (ISP) in the UK to being one of the leading business modernisation experts, who deliver solutions across 11+ countries.
At Claranet, we’re experienced in implementing progressive technology solutions which help our customers solve their epic business challenges.
We’re committed to understanding their problems, delivering answers quickly, and making a lasting impact to their business.
We are agile, focused and experienced in business modernisation.
Our approach helps customers make genuine, significant shifts in their business strategy, to deliver financial savings, boost innovation, and create a resilient business.
We continually invest in our people and the latest technologies, so our customers get peace of mind knowing that they have access to the best talent and services.
In the UK we have over 500 staff working in London, Gloucester, Warrington and Leeds, or as homeworkers.
Working For Claranet Here at Claranet we pride ourselves on going the extra mile for and with our employees (yes, we really mean with).
We offer an extensive benefits package that you can tailor to your needs, inclusive of a matching contribution pension scheme, healthcare, insurance, dental, discounted gyms and app supported benefit access.
But what we think makes us different is ‘Team Claranet,’ our dedicated internal part of the business that supports you with matters close to your heart.
We proudly support local charities in each of our office locations, support employees with paid charity leave, organise key charity fundraising event per year and have a dedicated committee responsible for supporting employee’s fundraising efforts.
Our Vision Our vision is to become the most trusted technology solutions partner; renowned for being the best and brightest, having lasting impact with our customers and delivering exceptional returns to our stakeholders.
Essential Roles & Responsibilities
As a SOC Shift Lead, you build on your solid experience as a SOC Analyst by supervising and guiding a team of SOC Analysts during your assigned shift.
You ensure quality and consistency across all alerts and incidents handled by the team while serving as the primary point of escalation.
In this role, you support team development, drive process improvements, and maintain clear, customer-centric communication with all stakeholders.
You also lead quality assurance efforts and ensure that service-level agreements (SLAs) are met.
Key Responsibilities
- Shift Leadership and Team Coordination – You run shift operations, ensuring compliance with SLAs and maintaining high-quality incident handling. You set shift agendas, balance workloads, and promptly address any process or staffing issues. You also maintain effective, customer-centric communication with internal teams (including Security Optimisation and Engineering), customers, and their incident response partners
- Incident Triage and Investigation – You review and prioritise new alerts, taking initial ownership of high-priority or complex incidents, and ensure proper escalation to customers and Senior SOC Analysts. You make sound, data-driven decisions to facilitate effective triage, investigation, and escalation in line with operational standards
- Quality Assurance and Documentation – You conduct regular quality assurance (QA) of tickets to ensure SOC procedures and documentation standards are met, providing clear, constructive feedback to team members to improve technical skills and workflow consistency
- Collaboration and Mentorship – You mentor SOC Analysts in your team by offering regular, constructive feedback on triage processes and best practices. You encourage targeted training initiatives, including relevant certifications, to support career progression within the SOC
- Service Improvement – You contribute to ongoing service improvement through participation in supporting threat hunting activity led by Senior SOC Analysts, rule tuning, and process refinement initiatives. You assist in monthly reporting and post-incident reviews to drive improvements that reflect our commitment to transparent and reliable performance
Essential Duties In addition to the duties performed by a SOC Analyst:
- Monitor shift activity and ensure all alerts, incidents, and tickets meet established SLAs
- Document shift activities, decisions, and process improvements accurately
- Lead regular shift briefings and debriefings (e.g. daily standups, shift handovers) to communicate updates, review performance, and reinforce best practices
Required Qualifications & Experience
- You may be required to hold or obtain UK Non-Police Personnel Vetting (NPPV) and/or a Security Check (SC) clearance as part of this role
- A minimum of 3+ years of SOC operational experience, demonstrating a strong background in alert triage, incident analysis, and escalation
- Willingness to work towards or obtain intermediate cybersecurity certifications (e.g. SBT BTL2, CREST Registered Intrusion Analyst)
- Proficiency with SIEM platforms, endpoint security tools, and ticketing systems, with an ability to make clear, data-driven decisions under pressure
- Proven teamwork and mentoring abilities, ensuring that technical and operational skills are continuously enhanced within the team
Technical Knowledge
- Operating Systems - Possess detailed knowledge of Windows and Linux system architectures, with a clear understanding of how event logs (e.g., Windows Event Viewer, Syslog) reflect system security posture
- Networking and Protocols - Have a comprehensive understanding of TCP/IP, DNS, DCHP, VPNs, SSL/TLS, and network forensics concepts to validate network-based alerts and anomalies
- Cybersecurity Frameworks - Deeply understand and be able to articulate the elements of the MITRE ATT&CK framework, and Cyber Kill Chain; know how adversary tactics and techniques translate into observable indicators
- SIEM and Security Tools - Know the theoretical underpinnings of SIEM operations, including alert correlation, the design of automated detection rules, and the interpretation of aggregated security data
- Incident Triage - Understand the principles behind effective triage, including the rationale for using standardised playbooks and the criteria for escalating incidents without undertaking complex forensic analysis
- Threat Intelligence Integration - Be knowledgeable about the role and structure of threat intelligence – how feeds are sourced, what constitutes actionable information, and how malware indicators are defined
- Scripting and Automation - Understand the concepts behind using scripting for automating regular data extraction and log analysis, and the benefits such tools being to maintaining consistency in alert handling
Behavioural & Professional Competencies
- Communication - Provide clear, timely updates to internal teams and customers during incidents, ensuring stakeholders are informed of progress, risks, and next steps without unnecessary technical jargon. Lead shift handovers and briefings, reinforcing priorities, SLAs, and lessons learned from previous shifts
- Leadership - Foster a collaborative shift environment by delegating tasks fairly, addressing knowledge gaps through real-time coaching, and resolving interpersonal conflicts constructively. Advocate for Associate and SOC Analysts’ development by identifying training opportunities and providing actionable feedback during/post-shift reviews
- Decision Making - Prioritise incidents based on severity, SLA deadlines, and resource availability, ensuring alignment with established playbooks and escalation protocols. Authorise deviations from standard procedures only when justified by immediate risk to customer operations, documenting rationale for post-incident review
- Adaptability - Dynamically reallocate analysts and tools during surges in alert volume or critical incidents, balancing speed and accuracy to maintain SLA compliance. Proactively identify and address gaps in shift workflows, such as repetitive false positives or tool misconfigurations, escalating systemic issues to Senior Analysts
- Problem Solving - Resolve ambiguities in alert classification or escalation paths by synthesising inputs from analysts, historical tickets, and playbook guidelines. Guide junior analysts through troubleshooting steps during complex triage scenarios, ensuring adherence to documentation standards
- Customer Focus - Uphold SLAs by monitoring ticket resolution times, validating customer communications for clarity, and escalating delays to Senior Analysts promptly. Translate technical findings into business-impact summaries for stakeholders, highlighting risks to continuity or compliance
- Attention to Detail - Conduct rigorous QA checks on tickets, ensuring evidence, timelines, and conclusions meet SOC standards and support seamless escalations. Identify recurring process inefficiencies (e.g., misprioritised alerts) and contribute to post-shift improvement discussions
Professional Development & Career Progression Claranet supports ongoing professional growth.
As a SOC Shift Lead you are encouraged to pursue additional training and relevant certifications to further your skills and advance to roles such as Senior SOC Analyst.
This may include both technical and leadership certifications.
About Claranet
Privately owned managed service provider helping organizations modernize and protect cloud, cybersecurity, data, and workplace systems.
Visit company websiteJobs and hiring trendsApply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
More jobs at Claranet
Change Technical Lead
Gloucester, GBR
Account Manager
London, GBR
Accounts Payable Analyst
, IND
Level 4 Network Operations Engineer - Player/Coach
Gloucester, GBR
IT Support & Information Security Engineer
, IND
Senior Finance Business Partner - Commercial
Gloucester, GBR
Penetration Tester
London, GBR
Connectivity Product Manager
, GBR