ASOS Logo

ASOS

SOC and Incident Response Lead

Posted Yesterday
Be an Early Applicant
Hybrid
London, England, GBR
Expert/Leader
Hybrid
London, England, GBR
Expert/Leader
Leads the SOC and Incident Response team, providing technical direction across security monitoring, detection engineering, incident investigation, threat-led analysis, and response operations. Owns detection lifecycle improvements, incident response processes, metrics, training, drills, post-mortems, and threat simulations. Partners with an external MSSP and internal technology and security teams while managing stakeholders, coaching analysts, and guiding responses to complex cyber incidents.
The summary above was generated by AI
Company Description

We’re ASOS, the online retailer for fashion lovers all around the world.  

We exist to give our customers the confidence to be whoever they want to be, and that goes for our people too. At ASOS, you’re free to be your true self without judgement, and channel your creativity into a platform used by millions.  

But how are we showing up? We’re proud members of Inclusive Companies, are Disability Confident Committed and have signed the Business in the Community Race at Work Charter and we placed 8th in the Inclusive Top 50 Companies Employer list.   

Everyone needs some help showing up as their best self. Let our Talent team know if you need any adjustments throughout the process in whatever way works best for you.  

Job Description

The Role 

As an experienced SOC and Incident Response Lead at ASOS, you will provide hands-on technical leadership across security monitoring, detection, engineering, incident response, and threat-led investigations. You will lead the SOC and Incident Response team, ensure security incidents are investigated and resolved effectively, and maintain a strong operating relationship with our external MSSP. The ideal candidate will combine deep technical expertise with proven experience leading analysts, improving operational capability, managing stakeholders, and making sound decisions under pressure. 

The role will act as the bridge between wider technology teams, the cyber security team, and third-party partners, ensuring a coordinated and consistent response to cyber security incidents. 

This role reports to the Head of Security Operations. 

Responsibilities 

  • Lead the SOC and Incident Response team day to day, providing technical direction, coaching analysts, maintaining effective operations, and ensuring the team has clear priorities, strong morale, and the capability to respond to complex security incidents. 
  • Own and improve the SOC detection lifecycle, including reviewing detection coverage, tuning noisy or low-value alerts, creating new detections from threat intelligence and incident learnings, and mapping coverage against relevant attack techniques and critical business assets. 
  • Establish and maintain incident response processes, procedures, and documentation, ensuring they align with industry best practices. 
  • Strong hands-on experience with SIEM, EDR, cloud security, identity, email security, and forensic analysis tooling, with the ability to investigate incidents, validate detections, and guide analysts through complex technical findings. 
  • Define incident response metrics, dashboards, track and report on key performance indicators (KPIs) to senior management, suggesting improvements as needed. 
  • Delegate unassigned newly submitted tickets to analysts keeping in mind current workloads and availability. 
  • Conduct regular incident response training and drills to enhance team readiness and improve response times. 
  • Lead incident post-mortem analysis to identify root causes, lessons learned, and recommend measures for prevention or improvement. 
  • Conduct periodic threat simulation activities to evaluate the adequacy of deployed detective/preventative controls. 

Qualifications

About you

  • Proficiency in incident response tooling, including SIEM, EDR, cloud security, threat intelligence and forensic analysis platforms.
  • Demonstrable experience leading and coordinating responses to complex cyber security incidents, acting as a technical lead during high-pressure situations.
  • Proven experience managing, mentoring and developing SOC Analysts and Incident Responders within a Security Operations environment.
  • Strong analytical and problem-solving abilities, with the capability to rapidly assess, contain and remediate security threats.
  • Ability to make effective decisions under pressure whilst managing multiple incidents, priorities and stakeholders simultaneously.
  • Experience working with cloud security technologies and environments, particularly Azure and/or AWS.
  • Experience building, tuning and improving security monitoring, detection engineering and threat detection capabilities.
  • Strong stakeholder management and communication skills, with the ability to translate technical security issues into clear business risk and impact for senior leadership.
  • Experience conducting incident post-mortems, root cause analysis, tabletop exercises and crisis response testing to drive continuous improvement.
  • Working knowledge of UK security and compliance frameworks, including PCI-DSS, GDPR, NIST, ISO 27001 and Cyber Essentials.

Additional Information

BeneFITS’ 

  • Employee discount (hello ASOS discount!) 
  • Employee sample sales 
  • 25 days paid annual leave + an extra celebration day for a special moment 
  • Discretionary bonus scheme 
  • Private medical care scheme 
  • Flexible benefits allowance - which you can choose to take as extra cash, or use towards other benefits 
  • Opportunity for personalised learning and in-the-moment experiences that enable you to thrive and excel in your role 

HQ

ASOS London, England Office

Hampstead Rd, London, United Kingdom, NW1 7FB

ASOS Watford, England Office

Hercules Way, Leavesden, Watford, United Kingdom, WD25 7GR

Similar Jobs

38 Minutes Ago
Easy Apply
Hybrid
City of London, City and County of the City of London, England, GBR
Easy Apply
Senior level
Senior level
Cloud • Information Technology • Security • Software • Cybersecurity
Own an enterprise UK territory focused on acquiring net-new logos and expanding existing accounts with 5,000–40,000 employees. Build customer business cases, generate pipeline through field marketing and channel partners, collaborate with sales and technical teams, and manage disciplined sales cycles. The role requires quota-carrying UK sales experience, consistent net-new performance, channel partnership expertise, team-selling ability, and familiarity with AI/ML and security or SaaS solutions.
Top Skills: Ai-Powered Sales Intelligence ToolsAi/MlCloud SecurityConversational AiPredictive Pipeline AnalyticsSaaSSaseZscaler Zero Trust Exchange
46 Minutes Ago
Hybrid
London, Greater London, England, GBR
Entry level
Entry level
Information Technology
Manages the technical relationship for managed services customers, serving as a trusted advisor and technical escalation point. Owns technical roadmaps, lifecycle and risk management, incident and problem resolution, service improvement, governance reviews, and optimization initiatives. Translates business needs into technical recommendations across cloud, security, infrastructure, workplace, and lifecycle services. Collaborates with delivery teams, vendors, architects, and commercial stakeholders to support transitions, proposals, renewals, and service expansion.
Top Skills: Amazon Web Services (Aws)ItilMicrosoft 365AzureSalesforceServicenow
46 Minutes Ago
Hybrid
Entry level
Entry level
Information Technology
Serves as the primary technical advisor for managed services customers, overseeing technical roadmaps, lifecycle risks, incident and problem resolution, service improvement, governance, and optimization. The role translates business needs into technical recommendations, leads reviews and root-cause analyses, coordinates internal and vendor teams, supports solution expansion, and promotes adoption of cloud, security, infrastructure, workplace, and professional services capabilities.
Top Skills: Amazon Web Services (Aws)Microsoft 365AzureSalesforceServicenow

What you need to know about the London Tech Scene

London isn't just a hub for established businesses; it's also a nursery for innovation. Boasting one of the most recognized fintech ecosystems in Europe, attracting billions in investments each year, London's success has made it a go-to destination for startups looking to make their mark. Top U.K. companies like Hoptin, Moneybox and Marshmallow have already made the city their base — yet fintech is just the beginning. From healthtech to renewable energy to cybersecurity and beyond, the city's startups are breaking new ground across a range of industries.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account