Team lead SOC

Il y a 5 heures

Brussels, Brussels, Belgique Barclay Simpson Temps plein
Cybersecurity Team Lead
- Contract We are seeking an experienced Cybersecurity Team Lead to oversee the delivery of security operations within a highly regulated critical infrastructure environment. This is a hands-on leadership position combining team management, incident response, vulnerability management and client-facing service delivery.

Key Responsibilities
- Lead and develop a technical cybersecurity team, managing workload, priorities, on-call coverage and operational continuity.
- Ensure security services are delivered against agreed SLAs, including monitoring, detection, alert triage, log management and security tooling administration.
- Act as Incident Commander during significant security incidents, coordinating containment, recovery, escalation and post-incident reviews.
- Own the vulnerability management lifecycle, from discovery and risk-based prioritisation through to remediation and verification.
- Monitor patching compliance and clearly communicate risks where remediation is delayed.
- Translate threat intelligence into improved detection, hardening and security priorities.
- Coordinate penetration testing, audits and the remediation of resulting findings.
- Serve as the main operational contact between internal security teams, customers and third-party suppliers.
- Produce regular reporting covering incidents, vulnerabilities, KPIs, SLAs, risks and improvement actions.
- Maintain security runbooks, technical documentation and a prioritised service-improvement backlog. Essential Experience
- At least five years of professional cybersecurity experience, including substantial hands-on technical responsibilities.
- Formal experience as a Cybersecurity Team Lead, Security Operations Lead or equivalent.
- Proven leadership of a technical team of three or more.
- Experience delivering managed or outsourced security services against contractual service levels.
- Practical experience leading the response to significant security incidents.
- Strong knowledge of SIEM, EDR/XDR, vulnerability management platforms and network security controls.
- Good understanding of Windows, Linux, networking, directory services, cloud environments, IAM and PAM.
- Ability to analyse logs, packet captures, configurations and other technical evidence directly.
- Excellent spoken and written English. Desirable
- Experience within aviation, defence, finance, energy, rail or another critical infrastructure sector.
- Knowledge of NIS2, EASA Part-IS or wider European cybersecurity regulation.
- Exposure to OT or industrial control system security.
- Scripting or security automation experience.