Security Operations Centre Team Leader
We’re Civica and we make software that helps deliver critical services for citizens all around the world. From local to state government, to education, to health and care, over 5,000 public bodies across the globe use our software to help provide critical services to over 100 million citizens. Our aspiration is to be a GovTech champion everywhere we work around the globe, supporting the needs of citizens and those that serve them every day. Building on 21 years of continuous growth and success, we're at a pivotal point on our journey to realise that aspiration. As a company, we’re passionate about what we do and the citizens we help to serve. If you too would like to help champion the use of technology in public services, to improve outcomes for citizens and public sector organisations, then Civica is the right place for you. We will help you unlock the best version of yourself, achieve growth in your career whilst making a real difference to people and communities. Why you'll love this role as a SOC Team Leader at Civica If you're passionate about cyber security, thrive on solving complex threats, and enjoy developing high-performing teams, this is the perfect opportunity for you. As our SOC Team Lead, you'll combine hands-on technical expertise with leadership responsibility, playing a pivotal role in protecting our customers and business. In this role, you'll lead from the front, acting as the senior technical authority for incident response, guiding Security Analysts through complex investigations, and driving operational excellence across the SOC. You'll have the opportunity to mentor and develop junior analysts, shape security processes, and continuously elevate the capability of the team. Unlike purely managerial positions, you'll remain deeply involved in the technical work, dedicating part of your time to Level III SOC Analyst responsibilities. This means you'll be actively investigating sophisticated threats, responding to critical incidents, and working with cutting-edge security technologies alongside your team. You'll enjoy a collaborative environment where your expertise is valued, your leadership makes a visible impact, and your contributions directly strengthen our security posture while helping others grow their careers in cyber security. Your key responsibilities include: Lead, coach, and support a team of SOC Analysts to deliver high-quality security operations. Act as the senior escalation point for complex security incidents and investigations. Ensure operational excellence through quality reviews, feedback, and continuous improvement. Drive analyst capability development through mentoring and knowledge sharing. Maintain and enhance SOC processes, procedures, and incident response playbooks. Lead proactive threat hunting and support the assessment of emerging threats and vulnerabilities. Collaborate with internal security teams and business stakeholders to support effective threat management and remediation. Contribute to SOC operations by performing Level III Analyst responsibilities alongside the team. Requirements What you will need to be successful in this role 5+ years of hands-on experience in a Security Operations Centre (SOC) environment, with demonstrated experience in incident response. Proven experience in a senior or lead analyst role, with a passion for mentoring others. Deep technical expertise with core security technologies, including SIEM (e.g., Elastic SIEM, Splunk, Sentinel, QRadar), EDR, and network security tools. Strong understanding of incident response methodologies, cyber kill chain, and frameworks like the MITRE ATT&CK® framework. Excellent analytical, critical thinking, and problem-solving skills, with the ability to perform calmly under pressure. Strong communication skills, capable of clearly explaining complex technical issues to team members.
Nice to Haves: Professional cybersecurity certifications such as GIAC (GCIH, GCFA), CISSP, OSCP etc. Experience with scripting or automation (e.g., Python, PowerShell) to improve SOC efficiency. Experience working in a Managed Security Service Provider (MSSP) environment. Experience with security orchestration, automation, and response (SOAR) platforms. Knowledge of cybersecurity standards related to incident response, such as NIST SP800-61r1, SP800-61r2, SANS PICERL, etc. Exposure and good working knowledge supporting LANs/WLANs Experience in operationalizing and developing SOC specific processes (procedures, work instructions, etc.). Previous experience with raw log file review, data correlation, and analysis, as well as with network security tools, network traffic analysers, firewall logs, network flows, intrusion detection systems, system logs, memory dumps, vulnerability management, SOAR platforms, SIEM, especially Elastic SIEM, and other Enterprise / Open Source equivalents. Previous experience in malware investigations, incident response, and threat hunting Benefits Why you'll love working with us. We know that when our people are happy, they will work better and have greater work satisfaction. Here's what you can expect: We're all different - and we love this about us. We provide an inclusive, safe, and welcoming environment to all Civicans - there are heaps of opportunities to enable you to grow and be your best. Giving culture - we encourage you to "give back" with benefits such as our Days of Difference leave where you can volunteer for a charity of your choice. Flexible Work - we have comprehensive flexibility options including part-time work, adjusted hours, staggered shifts, and hybrid or remote working, supporting work–life balance based on individual needs. Apply for this job - Become part of something special Do you see yourself in this role? If so, then we would love to hear from you.