Why we need this role
We are seeking a Tech Lead - SOC Responder. This is an opportunity to meaningfully contribute to a highly visible security operations function with global impact upon Colt, business units, partners, and customers. While working as part of this team, the successful individual will provide world‑class incident response functions to detect, protect, respond, and sustain operations within cyberspace.
This role operates at a Tier 3 level, with the expectation that the individual has undeniable experience handling major and complex cyber incidents, independently leading and managing incidents end to end, delivering clear and effective stakeholder communication, and mentoring other members of the SOC team.
What You Will Do
- Support SOC Manager to deliver SIEM, IR tools platform management including all design, implementation and administration activities.
- Use cases preparation and implementation, connector deployment, maintenance & health checks.
- Responsible for operational activities, technology escalation support, security solution assessment, existing service maturing and build activities.
- Analyse potential infrastructure security incidents to determine if incident qualifies as a legitimate security breach.
- Establish and govern security incident response processes, investigations and security operational processes.
- Maintain and enhance formal service catalogue, service descriptions, targets and performance against these.
- Ensure security services, tools and platforms are adequately maintained.
- Monitor and report on the effectiveness of our security‑enforcing technologies.
- Identify and continuously monitor specific security risks and KPIs; produce management information to ensure Colt receives value from key security investments/services.
- Contribute to design, development and maintenance of security standards and controls.
- Align the team's goals and plan with Colt’s long‑term priorities and strategy.
- Develop and grow the talent and people capability within the security teams.
Key performance indicators
- Takes ownership for understanding what is expected of them/their team and ensures it is delivered.
- Proactively requests leadership for views and opinions; uses this feedback to improve personal performance.
- Reviews working methods regularly to identify ways of improving service delivery – makes recommendations on what improvement can be made and owns delivery of agreed action plan and outcomes.
- Understands cultural differences and utilises this understanding to build rapport across different teams in order to obtain the necessary cooperation.
What We're Looking For
- Information Security Incident Response experience with a focus on detection and response to malicious activity using log data from various sources preferred.
- Strong networking and systems experience, preferably in an enterprise environment.
- Strong understanding of information security and the threat landscape surrounding enterprise systems.
- Strong scripting experience (Python, PowerShell, Unix shell).
- Experience working in all phases of the SDLC.
- Deep understanding and experience using cyber security operations, security monitoring, endpoint (EDR), network, and SIEM tools.
- Prior SOC experience a plus.
- Extensive knowledge of network and server security protocols, technologies, and products.
- Industry‑recognized certifications (CISSP, GCIH, GCFA, OSCP, etc.) preferred.
- Strong oral and written communication skills.
- Relentless curiosity and attention to detail.
- Ability to learn quickly and leverage prior experiences to effectively solve current security challenges.
- Refusing to accept the status quo.
Qualifications
- Combination of the following:
- Degree in Information Technology, Engineering or similar.
- SIEM management – desirable to have advanced certification from SIEM vendors on products such as ArcSight, MS Sentinel or LogRhythm.
Benefits
- Flexible working hours and the option to work from home.
- Extensive induction program with experienced mentors and buddies.
- Opportunities for further development and educational opportunities.
- Global Family Leave Policy.
- Employee Assistance Program.
- Internal inclusion & diversity employee networks.
#J-18808-Ljbffr