CSOC Lead
// Role Summary
Lead and develop a Cyber Security Operations Centre (CSOC) team in Cheltenham, combining technical cyber expertise with leadership to protect critical operations and shape future defence strategies.
// Key Responsibilities
- Lead a team of cyber threat analysts, providing direction and operational oversight.
- Manage security operations across the EMEA region, including monitoring, triage, and incident response.
- Drive advanced threat hunting and digital forensic investigations.
- Collaborate globally to enhance cyber defence capabilities and strategy.
- Communicate cyber risk updates to senior stakeholders and leadership.
// Role Specification
CSOC Lead
Northrop Grumman UK is seeking an experienced cyber defender and people leader to head their Cyber Security Operations Centre (CSOC) team based in Cheltenham. This is a unique opportunity to blend deep technical cyber expertise with significant leadership responsibilities. You will guide a team of skilled cyber threat analysts in safeguarding Northrop Grumman's UK and EMEA operations. Your role will involve direct participation in threat hunting, incident response, digital forensics, and broader cyber defence activities.
As part of a worldwide cybersecurity organisation, you will work collaboratively with colleagues across the UK, Europe, and the United States. Your contributions will help shape cyber defence strategies and continually improve the organisation's capacity to identify, investigate, and respond to evolving threats. If you are driven by protecting critical business operations, influencing cyber strategy, and leading talented security professionals, this role offers a chance to make a substantial impact daily.
What You'll Do
- Lead, mentor, and develop a team of cyber threat analysts, offering direction, coaching, and day-to-day operational supervision.
- Oversee security operations for the EMEA region, ensuring effective execution of cyber monitoring, triage, investigation, and response tasks.
- Act as the Incident Response Lead for significant cyber security incidents, coordinating technical investigations, containment, and remediation efforts.
- Spearhead advanced threat hunting and digital forensic investigations utilising SIEM, EDR, network telemetry, and threat intelligence resources.
- Collaborate closely with global CSOC teams to enhance cyber defence capabilities, operational processes, and detection methodologies.
- Deliver clear and actionable cyber risk updates, technical briefings, and executive summaries to senior stakeholders and leadership.
- Represent Northrop Grumman UK in government, industry, and security forums, fostering collaboration and information exchange.
- Promote cyber resilience through exercises, post-incident reviews, and continuous improvement initiatives.
What We're Looking For
Essential Experience
- Experience leading or managing a Security Operations Centre (SOC) or Cyber Security Operations Centre (CSOC).
- Demonstrated success in leading teams, projects, or operational cyber security functions.
- Strong expertise in incident response, cyber threat hunting, and digital forensics.
- Experience with commercial SIEM, EDR, and network analysis platforms.
- A solid understanding of network protocols and traffic analysis across the OSI model.
- Experience with cyber threat intelligence methodologies and frameworks.
- Ability to articulate complex technical issues clearly to both executive and non-technical audiences.
- Proficient stakeholder management, decision-making, and problem-solving skills.
- Proficiency across Windows, Linux, and Unix environments, including scripting with PowerShell and Bash.
Desirable Experience
- Existing established relationship with the UK National Cyber Security Centre (NCSC).
- Experience operating within highly regulated, defence, or high-classification environments.
- Familiarity with NCSC CAF, DEFSTAN, DCC, and comparable national security frameworks.
- Experience assessing and responding to sophisticated nation-state and cyber espionage activities.
- Relevant technical certifications (e.g., GCIH, GCIA, GCFA, CEH) or equivalent.
- A Bachelor's degree or higher in Cyber Security, Computer Science, or a related field.
Above all, we seek a leader passionate about cyber defence, driven by continuous improvement, and committed to developing both people and capabilities within a dynamic threat landscape. We encourage applications even if you don't meet every single requirement, as your experience, potential, and perspective could be invaluable to our team.
Security Clearance
Due to the sensitive nature of our work, candidates must be UK nationals and capable of obtaining and maintaining UK Government security clearance relevant to the role.
Benefits
Northrop Grumman UK offers a comprehensive and flexible benefits package designed to support your well-being, career progression, and lifestyle. This includes flexible working options, private healthcare, life assurance, a pension scheme, a flexible benefits package, a holiday buy/sell scheme, and robust career development and learning programmes. An annual performance incentive is also available.
Why Join Northrop Grumman UK?
A Mission to Believe In
Contribute daily to building a more secure and connected world. You will collaborate with industry-leading cybersecurity professionals, defending critical technologies and supporting vital missions. Engage with employee networks, STEM programmes, and community initiatives that create positive societal impact.
A Place to Belong and Thrive
We foster an environment where diverse experiences, perspectives, and backgrounds drive innovation. Every voice is valued, and we are committed to creating an inclusive space for all to contribute, grow, and succeed.
Your Career, Your Way
Whether your goals involve deepening technical expertise, developing leadership skills, or influencing global cybersecurity strategy, we provide the necessary support, mentoring, and development opportunities.