Lead Information Security Analyst
The Lead Information Security Analyst plays a critical role in leading and delivering the organisation’s information security roadmap through both technical IR expertise and operational leadership. This role combines hands-on security operations with team leadership responsibilities, acting as the primary technical focal point for SOC and Incident Response activities. The Lead will be responsible for managing team priorities, overseeing sprint planning and execution, and ensuring high-quality delivery of security operations. Working in a dynamic environment, you will provide technical leadership, guidance, and consultancy across the business, helping strengthen the organisation’s security posture while ensuring efficient and consistent service delivery. You will collaborate closely with Security Architecture, Engineering, Governance, Risk & Compliance, IT, and business stakeholders to drive continuous improvement across monitoring, detection, and response capabilities.
- Serve as the technical focal point for SOC and Incident Response activities, leading complex investigations and acting as the primary escalation point for operational and technical issues.
- Provide technical leadership, mentorship, and guidance to SOC analysts and IR team members to strengthen team capabilities and promote knowledge sharing.
- Manage SOC and IR operations, including workload distribution, task prioritization, sprint planning, execution, follow-ups, and tracking of team performance to ensure efficient delivery.
- Oversee and continuously improve security monitoring, detection, logging, alerting, and incident response capabilities, driving enhancements in automation and orchestration.
- Lead and support vulnerability management activities across the organisation, ensuring timely identification, prioritization, and remediation of security risks.
- Develop, maintain, and optimise security processes, playbooks, and runbooks to enhance operational effectiveness and response consistency.
- Collaborate with Security Architecture, Engineering, GRC, Delivery, Product, and Planning teams to define security requirements and align security initiatives with business objectives and risk appetite.
- Provide strategic security expertise by advising stakeholders on emerging threats, security risks, mitigation strategies, and opportunities to strengthen the organisation's overall security posture.
- Proven experience in SOC and Incident Response (IR) operations, including hands-on leadership of complex security investigations and operational activities (required).
- Strong technical expertise with security technologies, including EDR/XDR solutions (e.g., Microsoft Defender for Endpoint), SIEM/SOAR platforms (e.g., Splunk), and threat detection, investigation, and response methodologies (required).
- Demonstrated experience in proactive threat hunting, hypothesis-driven investigations, and identifying emerging threats across enterprise environments (required).
- Solid understanding of cloud and endpoint security, with practical experience securing AWS and Azure environments and managing Microsoft security technologies (required).
- Strong leadership, stakeholder management, and communication skills, with experience managing team priorities, sprint execution, technical decision-making, and familiarity with security frameworks such as NIST 800 and ISO 27001 (required).
- Industry-leading maternity and paternity leave and paid time off if you have caring responsibilities.
- Discounts at a range of high-street retailers.
- Financial compensation, pension, and bonus schemes.
- Tools and services to help support your well-being, including support with mental health and financial education.
- Gym discounts and our cycle to work scheme.
- Hybrid working Our employees can work from home up to 80% of the time with 20% of office time built in to ensure we get some face-to-face collaborative team time - and the chance for a coffee and a catch-up!
William Hill is one of the UK's best-known bookmakers, founded by its namesake in 1934 taking bets around Birmingham. It has since grown into an international, multi-brand betting and gaming business spanning online and retail. The company is now part of evoke plc (formerly 888 Holdings), one of the world's leading online betting and gaming groups. Headquartered in London, William Hill operates sports betting and gaming products across multiple markets.
