402,911open jobs
14,044companies
78,108added this week
Browse all
Salary
$89k – $173k per year (Estimated)
Location
In office (London)
Seniority
Staff
Employment
Contractor
Overview
Company
Impact
Profile match
Control Risks is a global specialist risk and strategic consulting firm focused on political, security, and integrity risks. Founded in 1975 and headquartered in London, the company assists organizations in understanding and navigating complex operational challenges, geopolitical volatility, and crisis management across hostile or high-risk environments worldwide. Its comprehensive suite of services includes corporate investigations, cyber risk assessment, due diligence, and on-the-ground protective support for multinational enterprises and institutions.

The Cyber Detection and Response Deputy Team Lead serves as the operational second-in-command of the Cyber Detection and Response Team (DART), bridging the gap between hands-on cyber operations and team leadership. The role supports the Team Lead in the ongoing development, maturation, and delivery of the client's detection and response capabilities, while providing technical leadership and operational oversight across day-to-day security operations.

This position remains actively involved in threat detection, incident response, threat hunting, and detection engineering activities while also assuming supervisory and coordination responsibilities. The Deputy Team Lead acts as the designated escalation point for analysts, leads operational activities during off-hours, and assumes Team Lead responsibilities during periods of absence, ensuring continuous delivery of a high-quality detection and response service.

This role will be a part of a 24/7 team and cover Monday-Friday: 9:00 am-5:00 pm London Time

Requirements

Responsibilities

  • Serve as the primary escalation point for Cyber Detection and Response Analysts during assigned shifts and out-of-hours operations.
  • Lead and coordinate investigations into high-severity cyber security incidents, ensuring timely containment, remediation, and reporting.
  • Oversee the triage and investigation of security events across endpoint, network, cloud, and identity environments.
  • Conduct advanced threat hunting activities to identify emerging threats, undetected adversary activity, and gaps in detection coverage.
  • Support incident response activities including forensic analysis, root cause determination, remediation planning, and post-incident reviews.
  • Collaborate with Security Engineering to improve detection logic, automate workflows, and optimize security tooling.
  • Act as Team Lead during periods of absence, leave, or out-of-hours coverage.
  • Review investigation quality, reporting standards, and analyst outputs to ensure consistency and operational excellence.
  • Contribute to performance feedback discussions and professional development planning.
  • Support the Team Lead in implementing new detection and response initiatives, technologies, and operational improvements.
  • Assist with establishing and refining SOPs, playbooks, escalation frameworks, and response processes.
  • Participate in planning activities with Security Engineering and client stakeholders to improve overall security posture.
  • Identify opportunities to enhance team effectiveness through automation, workflow optimization, and process improvements.
  • Support the Team Lead in maintaining strong relationships with client security, technology, and business stakeholders.
  • Provide operational updates and incident briefings to internal and client stakeholders as required.
  • Ensure clear communication and documentation throughout investigations and response activities.

Qualifications

  • 7+ years of experience in cybersecurity, with significant experience in incident response, SOC operations, threat hunting, or cyber defense.
  • Demonstrated experience mentoring analysts, leading investigations, or serving as a technical lead within a security operations environment.
  • Strong hands-on experience with SIEM, EDR/XDR, SOAR, IDS/IPS, log management, and cloud security technologies.
  • Experience with platforms such as Splunk, Microsoft Sentinel, CrowdStrike, SentinelOne, Palo Alto, Microsoft Defender, or equivalent technologies.
  • Strong understanding of incident response methodologies, digital forensics principles, malware analysis, and threat hunting techniques.
  • Working knowledge of the MITRE ATT&CK Framework, NIST Cybersecurity Framework, and incident response best practices.
  • Experience supporting operational improvement initiatives, tool implementations, or security program maturity efforts.
  • Strong analytical, troubleshooting, and problem-solving skills.
  • Ability to communicate technical concepts effectively to both technical and non-technical audiences.
  • Experience working within a 24/7 operational environment and participating in on-call or escalation rotations.
  • Preferred certifications include CISSP, GCIH, GCIA, GCFA, GSOM, CISM, or equivalent.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
402,911 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
London
Remote • Bachelor's Degree
PowerShell
Python
DevOps
Ansible
Azure
CI/CD
Configuration Management
Datadog
GCP
GitLab
GitLab CI
IAM
Incident Management
OpenTelemetry
SigNoz
Terraform
VMWare
Windows Server
Cybersecurity
Crowdstrike
GDPR
HashiCorp Vault
ISO 27001
Okta
Qualys Cloud Platform
Tines
Cryptography
Vault
Management
Power Automate
Marketing
LinkedIn
Apply
$112k – $140k per year • In office
Java
TypeScript
DevOps
AWS
AWS Lambda
Azure
CI/CD
GitLab
GitLab CI
Jenkins
Cybersecurity
FedRAMP
NIST 800-53
SBOM
SonarQube
STRIDE
Threat Modeling
Apply
DevOps Engineer 15 min ago
In office • Full-Time • Bachelor's Degree • Santiago
Python
DevOps
ArgoCD
AWS
Bitbucket
CI/CD
Docker
GCP
Grafana
Helm
Jenkins
Kubernetes
Spinnaker
Terraform
Apply
$99k – $220k per year (Estimated) • Remote/Hybrid • Bachelor's Degree • Chicago
SQL
Databases
BigQuery
Google BigQuery
DevOps
CI/CD
GCP
Analytics
ETL/ELT
Management
Jira
SharePoint
Marketing
LinkedIn
Apply
$101k – $133k per year • Remote • Bachelor's Degree
JavaScript
Node JS
TypeScript
Databases
PostgreSQL
Frontend
React.js
DevOps
CI/CD
GCP
Git
Kubernetes
Rest API
Shift-Left
Cybersecurity
Shift-Left Security
Management
Confluence
Jira
Apply
GSOC Shift Lead 5 days ago
In office • Full-Time • Bachelor's Degree • Singapore
Apply
$121k – $270k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Singapore
DevOps
Amazon ECS
Apply
In office • Full-Time • Bachelor's Degree • Baghdad
Apply
GSOC Analyst 5 days ago
$47k – $106k per year (Estimated) • In office • Contractor • Bachelor's Degree • Singapore
Apply
In office • Full-Time • Basra
Apply
In office • London
Apply
In office • London
Apply
Content Strategist 1 day ago
$80k – $120k per year • In office • Full-Time • 3+ years exp • London
Marketing
LinkedIn
Apply
Marketing Lead 1 day ago
$80k – $130k per year • In office • Full-Time • 3+ years exp • London
Apply
Operations 1 day ago
$35k – $50k per year • In office • Full-Time • London
Apply
See all jobs
This is one of many
402,911 more open roles from verified company boards, updated every day.