Second Line Team Lead (Manager) - Expert Team
Networks | Security | Escalations | Projects | Cloud | Automation
Role Purpose
Why the Second Line Team Exists
The Second Line Team is Ello Technology’s Expert Team.
It exists to own the complex technical work that sits beyond First Line support and to deliver the technical changes that strengthen, secure, modernise and improve our clients’ environments.
The team is responsible for:
Complex escalations from First Line
Networking reliability, performance and architecture
Cybersecurity controls and continuous risk reduction
Complex incident response and root-cause prevention
Infrastructure projects, migrations and implementations
Cloud adoption, migration and optimisation
Automation and process improvement
Technical standards, documentation and quality assurance
Repeatable technical delivery that scales across the client base
As Second Line Team Lead, you are accountable for turning complex technical work into predictable, secure, documented and commercially sound outcomes.
You build a team that remains calm when production is under pressure, delivers projects without chaos, solves root causes rather than symptoms, and continuously improves the technical environments we manage.
90-Day Mission
Definition of Done
By Day 90, the Second Line Team operates as a structured, accountable Expert Team:
Clear First Line → Second Line escalation rules are implemented and followed
Complex incidents are triaged quickly and driven through to root-cause resolution
Network and security standards are consistently applied
Active projects have clear scope, ownership, timelines, risks and sign-off criteria
Change control and rollback planning are enforced for high-risk work
Cloud and automation delivery follows defined technical standards
Repeat incidents and unnecessary escalations are reducing
Project rework and post-project issues are reducing
Documentation, runbooks, diagrams and configurations are current and usable
Monitoring and alerting are meaningful and actionable
Engineers have clear ownership, expectations and development plans
Scorecards are visible and reviewed consistently
Technical scope and BOM handoffs support accurate quoting, procurement and invoicing
The team is increasingly proactive rather than permanently reactive
Primary Outcomes
Operational Excellence
Reduced repeat escalations and recurring technical issues
Faster resolution of complex and high-severity incidents
Stable and reliable client infrastructure
Improved network performance and availability
Stronger client security posture
Reduced reactive workload through root-cause prevention
Clear ownership of complex technical problems from escalation through resolution
Project & Technical Delivery
Projects delivered predictably against agreed time, scope and quality
Clean project planning, change control and technical execution
Reduced project rework and post-project incidents
Complete handovers into ongoing support
Clear communication with clients and internal stakeholders
Repeatable delivery methods for common project types
Cloud & Automation
Cloud solutions are implemented securely and according to defined standards
Automations deliver measurable operational or client value
Automations are tested, documented and supportable
Client adoption, training and handover are completed
Outcomes such as time saved, reduced manual work or improved processes are measured where possible
Security & Risk
Security controls are consistently implemented and improved
High-risk findings are identified, prioritised and remediated
Security incidents are contained and resolved effectively
Security improvements are converted into structured client roadmaps where appropriate
Change risk is actively managed
Leadership
Clear roles and accountability across the Second Line Team
Strong technical ownership and decision-making
Engineers are coached and continuously upskilled
SOP and documentation discipline is embedded into daily work
Performance expectations are clear and measurable
The team develops deeper technical capability and reduces dependency on individual "heroes"
Commercial
Technical scopes and BOMs are accurate and complete
Scope creep is controlled through formal change management
Billable work is accurately captured
Commercial handoffs are clear and timely
Project delivery protects expected gross profit
Revenue leakage caused by poor technical handoffs is eliminated
Key Responsibilities
1. Escalations & Complex Incident Leadership
Own the First Line → Second Line escalation pathway, including entry criteria, priority and exit criteria
Ensure escalations contain the minimum required troubleshooting and documentation before acceptance
Prioritise and assign complex technical work according to impact and urgency
Ensure rapid triage of high-severity incidents
Drive incidents through to proper resolution rather than relying on temporary workarounds
Lead root-cause analysis and preventive actions
Maintain escalation SOPs and provide feedback and training to First Line
Run post-incident reviews for significant incidents
Build and maintain a prevention backlog based on recurring technical problems
2. Networking & Infrastructure
Own technical standards for switching, routing, Wi-Fi, firewalls and associated infrastructure
Ensure client network documentation and diagrams remain current
Drive proactive improvements to network stability, resilience and performance
Review and approve high-risk infrastructure changes
Ensure appropriate change control, testing and rollback planning
Identify infrastructure risks and ensure remediation plans are established
Standardise common network configurations and deployment methods
3. Security Operations
Own baseline security standards and continuous security improvement within the Second Line function
Ensure agreed patching, vulnerability remediation, endpoint, identity and access standards are enforced
Lead technical incident response for security events
Coordinate containment, remediation, recovery and technical reporting
Maintain security runbooks and response procedures
Identify recurring security risks and develop improvement plans
Support the development of client security roadmaps where required
4. Project Delivery
Own the technical project pipeline within the Second Line Team
Prioritise projects and allocate technical resources
Ensure every project has an approved scope, owner, plan, timeline, risks and completion criteria
Run regular project reviews and remove delivery blockers
Ensure risky changes include testing, change control and rollback planning
Monitor project delivery against agreed scope and timelines
Manage technical stakeholder and client communication
Ensure projects are formally signed off and handed over
Prevent uncontrolled scope creep and unapproved work
5. Technical Scoping & Commercial Handoffs
Produce accurate technical scopes, BOMs and implementation requirements
Ensure technical assumptions, dependencies and exclusions are clearly documented
Confirm scope approval before delivery begins
Identify scope changes early and enforce the change-control process
Provide clean technical handoffs to the BU Sales Consultant for quoting, procurement and invoicing
Ensure billable technical work is accurately recorded and traceable
Review quoted versus delivered effort to identify margin or scoping issues
6. Cloud & Automation Delivery
Own technical standards for cloud implementations and automation
Ensure appropriate naming, permissions, security and documentation standards are followed
Ensure automations and cloud solutions are properly tested before production deployment
Ensure automations are supportable and monitored where required
Maintain reusable templates and deployment standards
Ensure client training, adoption and handover are completed
Track measurable outcomes where possible, including time saved, manual steps removed or operational improvements
7. Monitoring, Alerting & Proactive Management
Ensure monitoring produces meaningful and actionable alerts
Reduce unnecessary alert noise
Define clear ownership and response procedures
Track response and resolution performance
Identify recurring alerts and convert them into prevention work
Use monitoring data to identify client risks before they become major incidents
8. Quality Assurance & Documentation
Documentation is a required part of delivery.
The Team Lead must:
Maintain SOPs for recurring Second Line activities
Establish QA gates for technical changes and projects
Implement peer review where appropriate
Ensure testing and sign-off checklists are used
Ensure client documentation is updated following changes
Maintain runbooks, diagrams, configurations and technical guides
Ensure project documentation is complete before closure
Audit documentation and SOP compliance
Build reusable technical and project templates
No project or complex technical change is considered complete until the required documentation and handover are complete.
9. People Leadership & Technical Development
Set clear roles, ownership and performance expectations for Second Line engineers
Run regular 1:1s
Establish individual skills and development plans
Coach engineers on troubleshooting, technical decision-making and client communication
Develop engineers across networking, security, cloud, automation and project delivery
Conduct peer reviews and technical knowledge-sharing sessions
Address performance or quality issues promptly
Support recruitment, interviews and technical assessments where required
Build succession and capability within the team
10. Cross-BU Collaboration
First Line
Maintain clear escalation and handover standards
Provide technical coaching where recurring escalation issues are identified
Ensure completed work is handed back with sufficient documentation for ongoing support
Customer Acquisition / Sales
Provide accurate technical scope and BOM information
Identify risks, dependencies and assumptions before quoting
Support technical discovery where required
BU Sales Consultant
Provide clean scope and BOM handoffs
Support quote → procurement → delivery → invoicing flow
Ensure variations and additional work are commercially captured
The objective is one continuous delivery process - not isolated departments handing problems to one another.
KPIs / Scorecard
Monthly - Ver2.0
Escalations & Incident Management
Escalations received vs resolved
Repeat escalation rate
Critical incident MTTA
Critical incident MTTR
Repeat incident/root-cause rate
Prevention backlog completed
Networks & Infrastructure
Network incident count
Client downtime minutes where measurable
Network standards compliance
Change failure rate
Recurring infrastructure issues resolved
Security
High-risk findings opened vs remediated
Patch/remediation SLA adherence
Security incidents by severity
Security incident containment time
Security baseline/control coverage where applicable
Project Delivery
Projects delivered on time
Projects delivered on scope
Project cycle time
Project rework rate
Post-project incident rate
Client/project sign-off rate
Change failure rate
Cloud & Automation
Cloud/automation initiatives delivered
Automation adoption and handover completion
Automation/project rework rate
Measurable impact achieved where applicable
Documentation and support readiness
Quality & Documentation
Documentation completeness score
SOP compliance audit score
QA/peer review pass rate
Ticket quality
Runbook/diagram/configuration compliance
Handover completeness
Commercial
Scope/BOM handoff quality
Missed billable/revenue leakage incidents - target: zero
Project quoted vs delivered variance
Project GP variance within agreed threshold
Unapproved scope-creep incidents - target: zero
People & Leadership
1:1 completion
Skills development progress
Training/certification progress where applicable
Team scorecard performance
Recurring quality/performance issues
Knowledge-sharing and cross-training completed
Non-Negotiables
Behavioural Rules
Calm and decisive under pressure
Root cause over temporary workaround
No project starts without clear scope and approval
No high-risk change without change control and rollback planning
No project closes without documentation and handover
Documentation is part of the work - not optional administration
Scope creep is managed through change control, not goodwill
No hero culture: systems, standards and teamwork beat individual dependency
Technical decisions must consider security, operational and commercial impact
Strong handoffs between First Line, Second Line, Sales and the BU Sales Consultant
SOP compliance is enforced
Reporting must be factual and scorecard-driven
Problems must be surfaced early - not hidden until they become emergencies
30 / 60 / 90-Day Plan
Days 0-30: Stabilise & Build the Operating System
Focus
Understand the current technical environment, stabilise urgent issues and establish one operating rhythm for the newly merged Second Line Team.
Actions
Audit all active Second Line escalations and projects
Identify the top 20 recurring escalations
Identify the top 10 client technical/security risks
Review active and overdue projects
Define First Line → Second Line escalation criteria
Establish project prioritisation and resource planning
Implement technical scoping and project templates
Implement change-control requirements
Establish documentation baseline standards
Review monitoring and identify unnecessary alert noise
Establish the monthly Second Line scorecard
Start post-incident reviews for critical events
Define roles and ownership within the merged team
Identify immediate skills gaps and single points of technical dependency
Deliverables by Day 30
Second Line escalation SOP
First Line escalation checklist
Active project and escalation register
Second Line monthly scorecard live
Technical documentation standard published
Project scope, risk, change and handover templates implemented
Team ownership structure defined
Top client risks and recurring technical problems identified
Days 31-60: Improve Quality, Speed & Predictability
Focus
Move the team from reactive problem-solving toward structured delivery and prevention.
Actions
Implement QA gates and peer review
Establish network and security baselines
Reduce repeat escalations through root-cause remediation
Implement formal change-control discipline
Improve incident triage and ownership
Establish skills development plans for engineers
Formalise monitoring and alert response rules
Standardise cloud and automation delivery
Improve project communication and sign-off
Build a prioritised prevention backlog
Address the most common causes of project rework
Begin cross-training to reduce individual technical dependency
Deliverables by Day 60
Visible reduction in repeat escalations
Network/security baseline rollout underway
Improved incident response performance
Monitoring and response rules formalised
QA and peer-review process operating
Cloud and automation standards implemented
Lower project rework trend
Individual development plans active
Days 61-90: Scale the Expert Team
Focus
Build a predictable technical delivery engine that improves client environments rather than simply responding to problems.
Actions
Mature incident response and post-incident learning
Reduce reactive workload through prevention
Standardise recurring project types
Tighten technical scope/BOM and commercial handoffs
Improve project forecasting and resource planning
Ensure billing capture and scope discipline
Measure cloud and automation outcomes
Build the Second Line technical playbook
Establish reusable runbooks and implementation standards
Continue reducing single-person technical dependencies
Use scorecard trends to drive continuous improvement
Deliverables by Day 90
Second Line operating predictably as one Expert Team
Reduced repeat escalations and incidents
Improved project delivery performance
Reduced project rework
Reliable network/security standards
Prevention engine operating
Cloud and automation delivery standards embedded
Clean technical-to-commercial handoffs
Reliable reporting for capacity and operational planning
Second Line playbook established
Clear skills and succession roadmap for the team
Benefits
Earning Potential
Your income should grow when your leadership creates stronger client environments, better delivery and measurable commercial impact.
This is a leadership role where your impact on uptime, security, project delivery, automation and technical quality directly contributes to business performance.
This is how we do that at Ello:
Competitive, market-related salary aligned to leadership responsibility
A role built around ownership and measurable outcomes
Opportunity to increase your value as the Expert Team's capability and impact grow
Performance Recognition
Not just activity. We recognise technical leadership that produces measurable results.
At Ello Technology, we value leaders who solve difficult problems while building systems that prevent those problems from returning.
This is how we do that at Ello:
We recognise strong technical and delivery leadership
We value calm decision-making under pressure
We recognise improvements in uptime, security and project performance
We value reductions in repeat incidents and rework
We make meaningful contributions visible and appreciated
Career Growth
This role provides broad ownership across technical operations and delivery.
You will lead a function spanning escalations, infrastructure, security, projects, cloud and automation.
This is how we do that at Ello:
Exposure to broad technical and operational leadership
Involvement in architecture, security, cloud and automation decisions
Increasing ownership as the Second Line function matures
Opportunity to grow into broader technical, operations or architecture leadership
A performance-led environment where responsibility grows with demonstrated capability
Coaching & Development
Good engineers solve difficult technical problems.
Great technical leaders build teams and systems capable of solving those problems consistently without depending on one person.
This role gives you the opportunity to develop beyond technical execution into technical, people and operational leadership.
This is how we do that at Ello:
Hands-on leadership of a high-impact technical team
Exposure to incident, project, security and cloud leadership
Experience building technical standards, QA systems and scorecards
Continuous learning through complex real-world environments
Direct, practical feedback designed to improve leadership and execution
Meaningful Work & Culture
High standards. Strong ownership. Real impact.
The Second Line Team is Ello Technology's Expert Team. It owns the technical challenges and changes that have the greatest impact on our clients' environments.
This is how we do that at Ello:
You solve complex problems that directly affect client operations
You protect and strengthen client environments
You deliver projects that create meaningful business improvement
You use cloud and automation to improve efficiency
You build systems that reduce recurring problems
You develop engineers into stronger technical professionals
You help create a technical business that is stable, secure, scalable and trusted

