SOC Team Lead
Location: This position is ideally in Leeds/Hybrid
The schedule will be a Panama schedule: (slow rotating shift pattern that uses 4 teams and two 12-hour shifts to provide 24/7 coverage. The working and non-working days follow this pattern: 2 days on, 2 days off, 3 days on, 2 days off, 2 days on, 3 days off). Every 4 weeks, it will change from the day to the night shift
.
BlueVoyant is looking for Security Operations Center (SOC) Team Lead to help our global customers manage their IT security. You will be part of a fast-paced team that helps customers to reduce the impact of security incidents and ensures that critical business operations continue unhindere
d.
BlueVoyant SOC Team Leads are the first line leaders tasked with enabling efficient, world-class teams to defend clients from adversaries. As a technical expert and defensive strategist, you’ll be instrumental in guiding analysts through active intrusions, aiding clients in taking action, and building a culture of client-first detection and respon
se.
Key Responsibili
tiesAs a team lead the success of the team relies on your expertise to spot and respond to attacks before adversaries gain a foothold. Your visibility over incoming alerts allows you to spot trends, prioritize analysis work, and define the gold standard of analyst w
ork.
As a Team Lead, you’ll directly supervise analysts on your shift, providing mentorship, workflow assistance, quality and performance reviews, and provide excellent customer ser
* vice.Supervise and mentor Security Analysts during a standard working team/shift which includes scheduling, PTO, and working with peers to ensure adequate cov
* erageManage analyst workload and workflows while acting as an escalation point for your
* teamCommunicate with BlueVoyant clients throughout incident escalations and service delivery questions or con
* cernsSupervise operations in deterring, identifying, monitoring, investigating, and analyzing at
* tacksSupport analyst alert triage to identify whether appropriate escalations occurred, and monitor for patterns indicating late-stage incident lifecycle alerts requiring incident res
* ponseProvide quality control and feedback for analyst investiga
* tionsParticipate in the response, investigation, and resolution of security inci
* dentsEnsure teams are aware of operating procedures and any changes or addi
* tionsAid in keeping operational documentation up to
* dateProvide incident investigation, handling, and response, including incident document
* ationServe as the technical escalation point and mentor for your analyst
* teamPerform triage of incoming issues (assess the priority, determine
* risk)Maintain a strong awareness of the current threat land
scape
Basic Qualific
ationsPeople S
* kills:Strong teamwork and interpersonal skills, including the ability to work effectively with a globally distribute
* d teamAble and willing to work in a 24/7/365 environment, including nights and weekends, on a rotating shift sc
* heduleExperience managing technical individual contributors, including providing feedback, monitoring quality, and prioritizin
* g workStrong customer communications skills, including articulating complex or urgent technical data and scenarios to non-technical aud
* iencesAbility to handle high pressure situations in a productive and professional
manner
Tech
* Skills:Knowledge of and experience with intrusion detection/prevention systems and SIEM s
* oftwareAdvanced knowledge and understanding of network protocols and d
* evices.Advanced experience with Mac OS, Windows, and Unix s
* ystems.Ability to analyze event logs and recognize signs of cyber intrusions/
* attacksAdvanced written and verbal communication skills and the ability to present complex technical topics in clear and easy-to-understand l
* anguageFamiliarity with tools such as Malware Sandboxes, Sentinel, Splunk, EDR so
* lutionsStrong knowledge of the fol
* lowing:Enterprise Cloud Solutions (Azure, GC
* P, AWS)Modern authentication systems and attacks (SSO, OATH, Entra
*, etc.)SIEM workflows (preferably Sentinel and
* Splunk)Packet A
* nalysisMalware Detection, to include dynamic and light static a
* nalysisNetwork Monitoring metadata (web logs, firewall logs, W
* AF/IDS)Email Security and common business email compromise
* attacksVulnerability Identification and correlation to attacker b
ehavior
Preferred Qualif
* icationsExperience in network/host vulnerability analysis, intrusion analysis, digital forensics, penetration testing, or relat
* ed areas5+ years of hands-on SOC/TOC/NOC ex
* perienceGIAC certification(s) strongly preferred. CISSP, Security +, Network +, CEH, RHCA, RHCE, MCSA, MCP, or MCSE p
* referredFamiliarity with technologies such as Sentinel, Splunk, Microsoft Defender suites, Crowdstrike Falcon, Sen
* tinelOneFamiliarity with Group Policy, Intune, Virtualization, and other IT Infrastructu
* re toolsUnderstanding and/or experience with one or more of the following programming languages: JavaScript, Python, Lua, Ruby, GoLa
ng, Rust
* EducationMinimum bachelor’s degree in Information Security, Computer Science, or other IT-related field or equivalent e
xperience
About
BlueVoyantAt BlueVoyant, we recognize that effective cyber security requires active prevention and defense across both your organization and supply chain. Our proprietary data, analytics, and technology, coupled with deep expertise, works as a force multiplier to secure your full ecosystem. Accuracy! Actionability! Timeliness! Sc
alability!
Led by CEO, Jim Rosenthal, BlueVoyant’s highly skilled team includes former government cyber officials with extensive frontline experience in responding to advanced cyber threats on behalf of the National Security Agency, Federal Bureau of Investigation, Unit 8200, and GCHQ, together with private sector experts. BlueVoyant services utilize large real-time datasets with industry leading analytics and te
chnologies.
Founded in 2017 by Fortune 500 executives, including Executive Chairman, Tom Glocer, and former Government cyber officials, BlueVoyant is headquartered in New York City and has offices in Maryland, Tel Aviv, San Francisco, London, Budapest, and La
tin America.
All employees must be authorized to work in the United Kingdom. BlueVoyant provides equal employment opportunities to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability or genetics. In addition to federal law requirements, BlueVoyant complies with applicable state and local laws governing non-discrimination in employment in every location in which the company ha
s facilities.