Hamilton Barnes π³
SOC Shift Lead

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
SOC Shift Lead
π Leeds (hybrid) | 4 on / 4 off / 4 nights rotating | Β£38,500 + 20% shift allowance
Ready to step up from analyst to leader?
We're a leading managed services and cyber security provider, trusted by organisations across the UK and Europe to keep their most critical systems secure. Our Security Operations Centre sits at the heart of that promise β a modern, tooling-rich environment where analysts are developed, not just deployed. We invest heavily in our people, our detection capability, and the technology behind both, and we're proud of a culture built on transparency, collaboration, and genuine career progression.
We're now looking for a SOC Shift Lead to guide and elevate a team of analysts across their shift.
The role
Building on your solid grounding as a SOC Analyst, you'll supervise and support a team through your shift β owning quality, consistency, and SLA performance while acting as the primary point of escalation. It's a role that blends hands-on security work with leadership: you'll run the shift, develop your analysts, and drive the improvements that keep our service sharp.
What you'll be doing
- Leading shift operations β setting agendas, balancing workloads, and resolving process or staffing issues as they arise
- Taking ownership of high-priority and complex incidents, making sound, data-driven escalation decisions in line with operational standards
- Running QA on tickets and giving clear, constructive feedback that raises the technical bar across the team
- Mentoring and coaching analysts, supporting their progression through targeted training and certifications
- Chairing shift briefings, standups and handovers, and contributing to threat hunting, rule tuning, reporting and post-incident reviews
- Keeping communication clear and customer-centric across internal teams, customers, and their incident response partners
Reasons to use Rodeo
Iβm in my final year doing Economics and I donβt know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer β it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) donβt need a masters. Letβs look at the ones youβd be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet β that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant β 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
Youβve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon β deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme β client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right β and where to focus when applying.
What you'll bring
- Established, hands-on SOC experience with a strong track record in alert triage, incident analysis, and escalation
- Confidence leading or coordinating others β chairing shift meetings, monitoring SLAs, quality assuring tickets, and mentoring fellow analysts
- Proficiency across SIEM platforms, endpoint security tools, and ITSM/ticketing systems (e.g. ServiceNow), with strong ticket prioritisation and SLA awareness
- Hands-on exposure to Microsoft Sentinel and Defender XDR, and/or SentinelOne (endpoint and AI SIEM)
- Solid grounding in Windows and Linux architectures, networking and protocols (TCP/IP, DNS, DHCP, VPNs, SSL/TLS), and frameworks such as MITRE ATT&CK and the Cyber Kill Chain
- A customer-focused approach and excellent written and verbal communication
- Willingness to work towards intermediate certifications (e.g. SBT BTL2, CREST Registered Intrusion Analyst)


Get help with your application
Your very own career expert that helps elevate your application to the next level.
The shift pattern
This is a 24/7 SOC operating 365 days a year. You'll work a rotating 4 days on, 4 off, 4 nights pattern, with shifts running 7amβ7pm / 7pmβ7am. When a day shift falls on a Monday, Wednesday or Friday, you'll be on-site at our Leeds office; the rest of the rota offers hybrid flexibility.
Please note: you may be required to hold or obtain UK Non-Police Personnel Vetting (NPPV) and/or Security Check (SC) clearance for this role.
Why join us?
You'll be joining an organisation that treats security as a craft and its SOC as a career springboard β with the tooling, mentoring, and progression pathways to match. If you're an experienced analyst ready to take the lead, we'd love to hear from you.
Apply now or reach out for a confidential conversation.
βIt took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what Iβve been looking for.β
Jessica, London
Skills
Location