SOC SME

London
1 week ago
Create job alert

Job Title

Lead SOC Subject Matter Expert (Future-State Security Operations)

Position Overview

We are seeking a Lead Security Operations Centre (SOC) Subject Matter Expert to spearhead the transformation of Security Operations from a traditional, reactive defence model into an AI-enabled, human-driven SecOps capability.

In this role, you will lead the shift away from manual alert triage toward security platform optimisation, proactive threat anticipation, and autonomous defensive controls. You will shape both the technology strategy and the operating model, ensuring humans remain firmly in control while leveraging AI at scale.

Key Responsibilities

Strategic Platform & Automation Leadership

Lead and support the selection, design, and transition from fragmented security tooling to a unified SIEM platform and security data lake.
Drive a fundamental shift from incident-focused, task-based workflows to preventative security activities and platform optimisation.
Proactive Threat Focus

Guide the evolution from reactive alert handling to proactive threat hunting and investigation.
Leverage AI and advanced analytics across diverse data sets to uncover hidden patterns and anomalies before exploitation occurs.
Attack Path Modelling & Autonomous Hardening

Support the specification, design, and implementation of an attacker-centric defence strategy.
Use AI and threat intelligence to visualise lateral movement paths and chokepoints.
Oversee autonomous hardening capabilities that automatically patch systems and update configurations based on predicted attack paths.
AI Safety & Governance

Assist in defining and deploying controls to manage enterprise AI risks, including prompt injection, data poisoning, and model theft.
Deploy and monitor “guardian agents” to provide real-time detection of malicious behaviour within AI systems.
Incident Response & Resilience

Guide the development, testing, and maintenance of advanced incident response plans, with a focus on high-impact threats such as human-operated ransomware.
Ensure rapid isolation of affected assets and credential revocation to minimise blast radius.
Identity & Cloud Security

Enforce phishing-resistant MFA and oversee the security of workload identities (applications, services, scripts).
Address the growing threat of cloud identity abuse by sophisticated adversaries.
Cross-Functional Alignment

Partner with IT operations and business leaders to ensure security evolution aligns with business objectives and board-level risk management.

Required Skills & Qualifications

Advanced Threat Intelligence Expertise
Deep knowledge of modern attacker TTPs, including nation-state actors, infostealers, and cloud identity abuse.
Proven SOC Transformation Delivery
Demonstrated leadership of SOC operations with at least five successful SOC builds or rapid rebuilds, delivered from inception to live operation within 6–12 months, ideally in regulated or high-availability environments.
End-to-End Programme Ownership
Full lifecycle ownership of major initiatives including MDR consolidation, SIEM, SOAR, and security data lake deployments, delivering measurable business outcomes.
Formal RFP & Vendor Management Expertise
Proven experience authoring RFPs, evaluating vendors, and overseeing complex onboarding and integration.
Battle-Tested Incident Response
Hands-on expertise in detection, response, and automation — with a clear understanding of what succeeds (and fails) under real-world pressure.
Vendor-Neutral Technical Leadership
Ability to navigate and apply leading MDR, SIEM, SOAR, and data lake technologies agnostically to the problem being solved.
AI & Automation Proficiency
Practical experience implementing agentic assistance and managing semi-autonomous security systems.
Security Architecture Mindset
Strong commitment to Zero Trust principles and an assume-breach philosophy.
Executive-Level Communication
Ability to translate complex technical risk into business-focused metrics (e.g. response times, patch latency) for the C-suite and Board.
Mentorship & Team Evolution
Proven ability to upskill teams, fostering a culture where humans provide critical oversight and quality control over automated processes.
Analytical Rigor
Expertise in behaviour-based analytics and the use of AI to synthesise 100 trillion+ security signals into actionable intelligence.

The Future of the Role

As Lead SOC SME, you recognise that the most successful security teams are not those that automate the most, but those that empower analysts most effectively. Your goal is to build a future-state SOC where AI accelerates insight and response, while skilled practitioners retain ownership, judgement, and strategic control

Related Jobs

View all jobs

Platform Engineer (Security & AI)

Senior SOC Analyst

Cloud Security Pre-Sales Consultant - AWS, Azure

Trainee Cyber Security Assistant - Training Course

Security Automation Engineer

Senior Security Administrator - Palo Alto

Subscribe to Future Tech Insights for the latest jobs & insights, direct to your inbox.

By subscribing, you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

How Many Cloud Computing Tools Do You Need to Know to Get a Cloud Job?

If you are aiming for a role in cloud computing, it can feel like the skills list never ends. One job advert asks for AWS, Terraform and Kubernetes. Another mentions Azure DevOps, PowerShell and ARM templates. A third throws in Docker, Python, Linux, CI/CD, monitoring tools and security frameworks. It is no surprise that many cloud job seekers feel overwhelmed before they even apply. Here is the reality most cloud hiring managers agree on: they are not hiring you because you know every cloud tool. They are hiring you because you understand cloud concepts, can design reliable systems, manage costs, keep things secure and support real workloads. Tools matter, but only when they support outcomes. So how many cloud computing tools do you actually need to know to get a job? For most roles, the answer is far fewer than you think. This article explains what employers really expect, which tools are essential, which are role-specific, and how to focus your learning so you look capable and employable rather than scattered.

What Hiring Managers Look for First in Cloud Computing Job Applications (UK Guide)

anding a job in cloud computing can be highly competitive — especially in the UK market where demand far outpaces supply in many segments. Whether you’re aiming for roles in Cloud Engineering, DevOps, Site Reliability, Cloud Architecture, Security, Data/Analytics, or Platform Operations, hiring managers screen applications quickly and with specific priorities in mind. Hiring managers don’t read every detail at first; they scan for critical signals in the first 10–20 seconds. These early signals determine whether your CV gets read more closely, whether your LinkedIn profile gets clicked, and whether you’re invited to interview. This guide breaks down, in practical terms, exactly what hiring managers look for first in cloud computing applications — and what you should emphasise in your CV, cover letter and portfolio to stand out on www.cloudcomputingjobs.co.uk .

The Skills Gap in Cloud Computing Jobs: What Universities Aren’t Teaching

Cloud computing underpins almost every modern digital service. From financial systems and healthcare platforms to AI, e-commerce, government infrastructure and cybersecurity, the cloud is now the default operating environment for UK organisations. Demand for cloud professionals has grown rapidly, with roles spanning architecture, engineering, security, DevOps, platform operations and cost optimisation. Salaries remain high, and vacancies remain stubbornly difficult to fill. Yet despite a growing number of graduates with computer science, IT and software engineering degrees, employers across the UK report a persistent problem: Too many candidates are not job-ready for real cloud computing roles. This is not a question of intelligence or motivation. It is a structural skills gap between what universities teach and what cloud jobs actually require. This article explores that gap in depth: what universities do well, what they consistently miss, why the gap exists, what employers genuinely want, and how jobseekers can bridge the divide to build sustainable careers in cloud computing.