At Serco, you'll join a global organisation delivering essential public services that improve the lives of millions of people. Our values of Trust, Care, Innovation, and Pride guide everything we do. Committed to creating an inclusive workplace. Encourages applications from Aboriginal and Torres Strait Islander peoples, LGBTQIA+ communities, veterans, and people with disabilities.
Cyber Security Operations & CTI Lead
Location
United Kingdom
Posted
9 days ago
Salary
£77K - £90K / year
Seniority
Lead
No structured requirement data.
Job Description
Cyber Security Operations & CTI Lead
Serco Plc
Role Description Serco is building out its in-house cyber security capability, and this is a rare opportunity to shape it from the ground up. Around 18 months ago we made a long-term commitment to bringing more security expertise in-house — this new role is a key part of that plan. You'll provide senior technical leadership across Security Operations and Threat Intelligence, ensuring threats are identified, analysed, and translated into action. This is a hands-on technical role: monitoring, threat hunting, detection engineering, and incident response — strengthening how Serco detects and responds to evolving cyber threats. We're a small team with large ambitions, globalising this service, and you'll play a central role in shaping its future. - Provide technical leadership across Security Operations — alert triage, investigation, and escalation — and act as senior escalation point for complex investigations - Design, build, and evolve a new Cyber Threat Intelligence capability, integrating it into SOC workflows, detection logic, and incident response - Analyse and track threat actors and campaigns, mapping adversary TTPs to MITRE ATT&CK and translating intelligence into detection improvements - Develop, tune, and optimise detection rules based on threat intelligence and incident learnings - Lead hypothesis-driven threat hunting, feeding outcomes back into detection engineering - Lead cyber incidents end-to-end, producing high-quality incident reports with root cause analysis and lessons learned - Author and maintain incident response playbooks and SOC/CTI processes - Task-manage a team of analysts day-to-day, with around four direct reports as the function grows - Participate in an on-call rota supporting incident escalations Qualifications - 7+ years' experience in cyber security roles, in-house or within an MSSP - Strong experience within a SOC environment, including incident response end-to-end - Proven experience building or integrating a Cyber Threat Intelligence function - Strong knowledge of SIEM, EDR, and SOAR tooling, and the MITRE ATT&CK framework - Demonstrated detection engineering and intelligence-led threat hunting experience - Clear communication skills, technical and non-technical, and the ability to operate under pressure during incidents - Eligibility for BPSS clearance Requirements - Desirable: CISSP - Relevant SANS certifications (e.g. SEC503, FOR572) - Relevant Microsoft certifications (e.g. SC200) - Blue Team Level 2 (BTL2) Benefits - Company car - Private healthcare - Bonus scheme of up to 30% - Flexible working considered - Pension – 6% - Chance to contribute to innovation in the public services - A company passionate about diversity and inclusion - Serco discounts which include cinema, merlin entertainment and online shopping discounts, and discounts on mobile phone plans and leisure centre memberships - A range of benefits to support the health and wellbeing of you and your family such as Employee Assistance Programme, Simply Health Cash Plans, and more - A wealth of career development training to suit your future aspirations - A safe and supportive culture
Related Guides
Related Categories
Related Job Pages
More Security Operations Jobs
Forward Deployed Engineer – AI SOC
Thinkahead Consultant Psychologist Pty LtdWe get to the heart of the matter.....real people......real solutions
• Serve as the technical lead for deploying and operationalizing security and AI solutions in customer or enterprise environments • Translate business, operational, and security requirements into deployable architectures and implementation plans • Partner with internal and external stakeholders to ensure solutions are aligned to operational goals, compliance requirements, and long-term platform strategy • Act as a trusted advisor during onboarding, implementation, rollout, and optimization phases • Design and implement integrations across SIEM, XDR, SOAR, case management, data platforms, and AI-enabled tooling • Build and configure cloud-native data ingestion, normalization, and enrichment pipelines for security telemetry • Integrate APIs, webhooks, message queues, and automation workflows across identity, endpoint, cloud, network, and application ecosystems • Develop reusable deployment patterns, templates, and technical assets to accelerate future implementations • Operationalize AI and automation use cases within security workflows, including alert enrichment, triage support, summarization, clustering, playbook selection, and analyst copilots • Work with detection engineering and data teams to support the implementation of behavioral analytics, anomaly detection, risk scoring, and other AI-assisted security use cases • Help define data requirements, feedback loops, and operational guardrails needed to support effective AI outcomes in production environments • Ensure deployed solutions are practical, measurable, and aligned to analyst workflows and response objectives • Implement secure and governed automation for investigation and response use cases across heterogeneous environments • Support resiliency, observability, performance, and scale requirements for deployed solutions • Troubleshoot integration issues, deployment blockers, and production challenges in partnership with platform, cloud, and security teams • Improve reliability and maintainability through documentation, testing, monitoring, and standardized engineering practices • Collaborate across Security Operations, Security Engineering, Detection Engineering, Data Science, Infrastructure, and product or customer teams • Communicate technical concepts clearly to both technical and non-technical stakeholders • Mentor engineers and contribute to best practices for implementation, delivery, and technical solution design • Provide field feedback to influence platform roadmap, product direction, and architectural standards.
• Monitor security alerts and events across Box’s environment using SIEM and other detection tools. • Lead and coordinate the end-to-end response to security incidents. • Conduct in-depth forensic analysis of endpoints, logs, and network traffic. • Develop and refine incident response playbooks, runbooks, and procedures. • Collaborate with Engineering, Legal, and Compliance teams. • Identify trends and patterns in security data to proactively surface emerging threats. • Contribute to threat intelligence programs by researching adversary tactics, techniques, and procedures (TTPs).
Director of IT – Security Operations
RealTime eClinical SolutionsBetter research. Better business. Better outcomes.
• Owns the security, availability, and compliance of the systems. • Operate and evidence the controls required for SOC 2 Type 2 and HIPAA. • Maintain the risk register and run an annual risk assessment. • Enforce least privilege access across corporate and production systems. • Manage cloud hosting vendors and environment changes. • Monitor the security of corporate and cloud environments. • Manage the team providing technical support to employees. • Design and manage the disaster-recovery and business-continuity process.
Security Engineer – Incident Response
AsymmetricEarly stage capital for disruptive technology companies.
• Serve as Incident Commander for SIRN-related security cases • Lead incident triage efforts • Coordinate with internal AR teams and external Solana ecosystem stakeholders • Develop, tune, and triage telemetry signals • Identify gaps in current detection coverage • Author, maintain, and continuously improve incident runbooks • Provide operational and logistical support to the SIRN project team • Escalate to AR Engineering and Consulting leads as appropriate


