Cybersecurity Defense SOC Lead

Posted 4 Days Ago
Be an Early Applicant
London, Greater London, England, GBR
In-Office
Expert/Leader
Insurance
The Role
Lead a 24x7 SOC: triage/escalate incidents, act as incident commander, manage MSSP and global SOC teams, develop detection content and playbooks, maintain SIEM/log sources, mentor analysts, and support red/purple/blue team exercises.
Summary Generated by Built In

This is an opportunity to join Ascot Group - one of the world’s preeminent specialty risk underwriting organizations.

Designed as a modern-era company operating through an ecosystem of interconnected global operating platforms, we’re bound by a common mission and purpose: One Ascot. Our greatest strength is a talented team who flourish in a collaborative, inclusive, and entrepreneurial culture, steeped in underwriting excellence, integrity, and a passion to find a better way, The Ascot Way.

The Ascot Way guides our people and our organization. Our underwriting platforms collaborate to find creative ways to deploy our capital in a true cross-product and cross-platform approach. These platforms work as one, deploying our capital creatively through our unique Fusion Model: Client Centric, Risk Centric, Technology Centric.

Built to be resilient, Ascot maximizes client financial security while delivering bespoke products and world class service — both pre- and post-claims. Ascot exists to solve for our clients’ brightest tomorrow, through agility, collaboration, resilience, and discipline.


Job Summary:

As part of our 24x7 Cyber Defence function, the Security Operations Center Lead will be responsible for triaging, escalating, and managing cybersecurity events for Ascot, improving detection content and supporting the overall monitoring, detecting and cybersecurity incident response activities. 

Acting as an escalation point for L1/L2/L3 SOC analysts, this resource will work within an expanding cybersecurity team, collaborating with cybersecurity managers, IT Infrastructure, and Deskside Support Teams.  

You must be detail-oriented, diligent, and capable of managing multiple aspects of the incident response lifecycle simultaneously. You will be supporting a 24X7 Cybersecurity Defence function, that includes overseeing and managing a Managed Security Services Provider (MSSP), and teams across multiple time zones. You will be required to work in shifts that will vary based on operational needs to support the global footprint across the UK, US and Bermuda time zones and other regions as part of our expansion. 

This resource will additionally be responsible for the overall day-to-day management of our SOC, maintaining detection content on the detection tool, (detection rules, log ingestion, parsers, forwarders), maintaining playbooks, SOC documentation and supporting integrations and log sources associated with the overall Cyber Defence solution. This role will be in the office with a hybrid work schedule and overseeing/managing a global team of resources. 


Responsibilities: 

  • Monitor our security tools to triage and respond to suspicious events and abnormal activities, capable of performing deep-dive incident investigations. 

  • Serve as a point of escalation for the L1, L2, L3 SOC Analysts, MSSP, and other vendors, coordinating response efforts with other groups and stakeholders with varying technical expertise, such as IT, Legal, business etc.  

  • Stay current with evolving threats, vulnerabilities, tools, technologies and threat actor TTPs to help improve detection and response capabilities.  

  • Provide oversight and governance over the daily operations of the MSSP and SOC team at a global level.  

  • Mentor and provide training to junior SOC team members.  

  • Oversee the incident response process, ensuring rapid identification, containment, eradication, and recovery from security incidents.

  • Develop and refine standard operating procedures in the form of run books and playbooks for incident response and threat detection. Create and make improvements to procedures and playbooks. 

  • Conduct technical analysis, log reviews, and assessments of cybersecurity incidents throughout the incident management lifecycle.  

  • Act as an Incident Commander during cybersecurity incidents working across incident confirmation, containment, and communicating to internal and external stakeholders. 

  • Work with end users, vendors, and MSSP where appropriate on security related incident through closure. 

  • Manage and create incident reports, identify improvements to detect and prevent similar incidents from occurring in the future. 

  • Document and manage incident cases to utilize information for stakeholder engagement to provide insight, intelligent recommendations, risk reporting and lessons learned.

  • Work in scheduled shift patterns when required.  

  • Conduct in-depth security investigations, log analysis, network/email traffic assessment, and evaluate other data sources to identify root causes, assess impact, and gather evidence for response and mitigating actions. 

  • Implement detection use cases within our SIEM for our expanding estate using appropriate scripting languages. 

  • Manage log sources, log ingestion volumes, detection content and overall SIEM solution system health, maintenance, and upgrades. 

  • Assist with additional ad hoc projects as required.

  • Run and coordinate annual cybersecurity tabletop exercises, that spread across both technical and non-technical areas and testing. 

  • Support Red, Purple and Blue Teaming exercises, prioritizing findings and overseeing the implementation of recommendations. 

 

Requirements:

  • Cybersecurity related degree (Bachelor’s and/or Master’s) or related work experience.

  • Minimum of 10 years of experience in a security operations role, SOC engineering and or a cybersecurity technical engineering role.

  • Exposure to building and migrating log sources onto a new SIEM platform, creating detection content, log parsers and detection engineering. Alternatively, candidates that have worked in senior technical roles in a Managed Security Service Provider (MSSP) will be preferred. 

  • Preference will be given to candidates who also have additional technical and cyber-risk certifications covering both defensive and offensive security such as CompTIA Security+, Certified SOC Analyst (CSA), Certified Ethical Hacker (CEH), CySA+, CISSP, GSEC, GCIH, CCSP, Microsoft SC-200, CISSP-ISSMP, CTIA, OSCP  

  • Candidates must have solid experience and knowledge of typical enterprise technologies. On-premises and cloud base Windows and Linux operating systems, Microsoft Azure, M365 and the ability to detect signs of compromise in these systems.

  • Possess a growth mindset and is willing to learn how to resolve technical security issues. 

  • Demonstrate a working and genuine interest and talent in Cybersecurity  

  • Demonstrate detail orientation and can take a structured approach to procedures and working instructions. 

  • Work and maintain a calm structured mindset even when under pressure. 

  • Possess an aptitude for understanding and analysing data when troubleshooting. 

  • Strong written communication, critical thinking, and analysis skills, including the ability to present potential risks and actual findings to a wide audience. Ability to communicate complex problems to a non-technical audience. 

  • Must have a working understanding of key security concepts and attack types such as phishing, malware, vulnerabilities, Cyber Kill Chain, and attack stages. 

  • A strong analytical mindset, capable of digesting a wide range of information to make practical judgements based on available data and context.  

  • Experience with security tools and technologies, including SIEM, intrusion detection systems, EDR, XDR, log analysis, and malware analysis.  

  • Understand threat actor tactics, techniques and procedures, have familiarity with the MITRE-ATT&CK Framework and different stages of an attack lifecycle. 

  • Maintain a desire to keep learning, with a curious and creative growth mindset.


Please be aware that Ascot Group’s job opportunities will be posted on our official careers page. All official communication comes from @ascotgroup.com email addresses, if you receive a job offer or recruitment communication from Ascot Group that you suspect might be fraudulent, do not hesitate to contact us directly to verify its legitimacy. We will never ask for payment or sensitive personal information during any stage of the recruitment process. Your privacy and trust are of utmost importance to us, and we strive to ensure that you have a positive experience with Ascot Group.


#LI-Hybrid

Skills Required

  • Cybersecurity related degree (Bachelor's and/or Master's) or equivalent work experience
  • Minimum of 10 years experience in security operations, SOC engineering, or cybersecurity technical engineering
  • Experience building and migrating log sources onto a SIEM, creating detection content, log parsers and detection engineering
  • Senior technical experience in a Managed Security Service Provider (MSSP)
  • Experience with enterprise technologies: on-prem and cloud Windows and Linux, Microsoft Azure and Microsoft 365, and detecting compromise in these systems
  • Experience managing or providing oversight/governance of an MSSP and global SOC operations
  • Familiarity with SIEM, intrusion detection systems, EDR, XDR, log analysis, and malware analysis
  • Familiarity with MITRE ATT&CK framework, threat actor TTPs, Cyber Kill Chain and attack lifecycle stages
  • Ability to implement detection use cases in SIEM using scripting languages and manage SIEM system health
  • Strong written communication, critical thinking, and ability to present technical findings to non-technical audiences
  • Willingness to work scheduled shift patterns to support a 24x7 global cybersecurity function (hybrid, in-office)
  • Certifications covering defensive and offensive security (examples: CompTIA Security+, CSA, CEH, CySA+, CISSP, GSEC, GCIH, CCSP, Microsoft SC-200, CTIA, OSCP)

Ascot Group Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Ascot Group and has not been reviewed or approved by Ascot Group.

  • Healthcare Strength Health coverage in the U.S. is characterized as excellent, with indications that individual medical can be employer-paid in some cases. Company materials also highlight comprehensive medical, dental, vision, and wellness resources.
  • Retirement Support A 401(k) with company contributions or match is consistently highlighted, alongside options such as HSAs and FSAs. This points to structured support for longer-term financial security.
  • Leave & Time Off Breadth Generous PTO and paid holidays are emphasized, with additional leaves such as caregiver, adoption, and disability frequently included. Some locations note extras like birthdays off.

Ascot Group Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Bermuda, Bermuda
1,095 Employees

What We Do

Ascot Group is a global specialty insurance and reinsurance group with a record of underwriting excellence and superior claims service. Founded in 2001, Ascot provides a broad range of property and casualty products to customers worldwide through its Lloyd’s and Bermuda market platforms. In the United States, Ascot provides specialized insurance products to small and mid-sized businesses as well as offering underwriting services to high-quality carrier and syndicate partners.

Similar Jobs

Square Logo Square

Account Executive

eCommerce • Fintech • Hardware • Payments • Software • Financial Services
Hybrid
Manchester, Greater Manchester, England, GBR
12000 Employees

Teya Logo Teya

Customer Complaints Agent

Fintech • Payments • Financial Services
In-Office
London, Greater London, England, GBR
1000 Employees

Lansweeper Logo Lansweeper

Development Manager

Cloud • Information Technology • Software
Remote or Hybrid
London, Greater London, England, GBR
404 Employees

Klaviyo Logo Klaviyo

Enterprise Sales Specialist - Customer Agent

Consumer Web • eCommerce • Marketing Tech • Retail • Software • Analytics • Generative AI
Easy Apply
Hybrid
London, Greater London, England, GBR
2400 Employees
82K-123K Annually

Similar Companies Hiring

Globe Life Thumbnail
Insurance • Financial Services
McKinney, TX
3000 Employees
MassMutual India Thumbnail
Big Data • Fintech • Information Technology • Insurance • Financial Services
Hyderabad, Telangana
Granted Thumbnail
Mobile • Insurance • Healthtech • Financial Services • Artificial Intelligence
New York, New York
23 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account