skip navigation
skip mega-menu

SOC Technical Team Lead - Registers of Scotland - SEO

Government Digital & Data -

Full-time (Permanent)
£48,544 - £57,155 plus Digital, Data and Technology Annual Pay supplement of 20%
Published on
15 January 2026
Deadline
25 January 2026

Location

Relaxed Hybrid and Flexible Working Environment

About the job

Job summary

Registers of Scotland (RoS) 

Join an award-winning organisation recognised for its technology and innovation. RoS is a world-leading pioneer in land and property registration. We work to create data-led, digital solutions for the people of Scotland. Our full-stack teams design, architect, and build all our registration products in-house.  

 

The Role 

We are seeking a technically skilled and people-focused SOC Technical Team Lead to join our Cyber Security team at Registers of Scotland. This role provides both technical leadership and line management for the Security Operations Centre (SOC) team, ensuring the delivery of high-quality threat detection, incident response, and vulnerability management services. 

We’re looking for candidates with at least three years experience in a Security Operations Centre or similar environment, to ensure they bring the hands-on expertise and operational insight needed to lead effective incident response and support a high-performing security team.  

 

As SOC Technical Team Lead, you’ll lead a team of analysts and work closely with cyber engineers to develop and automate threat detection and response playbooks. A key part of the role is ensuring SOC processes are fully integrated with existing ITSM workflows and that service levels are monitored and reported through agreed SLA/OLA metrics and outcome-driven key performance indicators.  


Please note we have partnered with an agency for this position and will be accepting applications via their website.

 

Job description

On a typical day you will… 

  • Provide line management, coaching, and development to SOC analysts and engineers.  
  • Lead the configuration, tuning, and maintenance of core SOC capabilities including log aggregation, alerting, correlation, threat detection, and response tooling.  
  • Collaborate with cyber engineers to develop and automate detection logic and incident response playbooks.  
  • Work with our Technical Product Manager and Security Architect to ensure SOC capabilities align with enterprise security architecture and strategy.  
  • Develop and maintain scenario-based runbooks and technical procedures for incident response.  
  • Engage with project teams to provide security assurance for new and existing services.  
  • Drive continuous improvement in SOC operations, tooling, and team capability.  
  • Monitor and report on SOC performance, including:  
  •   - SLA/OLA adherence and incident handling timelines  
      - Volume and severity of security incidents  
      - Average time to detect (MTTD) and respond (MTTR) to threats  
      - Accuracy and relevance of alerts (e.g. reducing false alarms)  
      - Coverage of threat detection across systems and services  
      - Outcome-focused metrics such as reduced dwell time, successful containment rates, and measurable improvements in security posture  

Person specification

  • Proven experience in a Security Operations Centre or operational security environment.
  • Demonstrable experience managing or leading a technical team or function in an enterprise setting. 
  • Strong background in operating and maintaining SOC capabilities such as log management, alerting, threat detection, and incident response tooling. 
  • Experience in incident response, including leading technical investigations and developing response frameworks. 
  • Proficiency in integrating and operationalising cyber threat intelligence. 
  • Experience working with ITSM systems to manage and prioritise workloads. 
  • Experience reporting on SOC metrics including SLA/OLA performance, MTTD/MTTR, alert accuracy, and outcome-based security improvements. 
  • Excellent interpersonal and communication skills, with the ability to work effectively across technical and non-technical teams. 
  • Experience developing or implementing vulnerability management tools and processes.
  • Familiarity with cloud security monitoring and hybrid infrastructure environments.
  • Knowledge of relevant security frameworks such as NIST CRF, ISO 27001, NCSC CAF, and MITRE ATT&CK.
  • Experience contributing to or leading SOC maturity assessments or improvement programmes.

More jobs at Government Digital & Data

Interaction Designer - GDS
Full-time (Permanent)
Test Engineer - GDS - SEO
£46,725 - £50,220 (London) / £42,893 - £45,653 (National) plus additional allowance
Full-time (Permanent)
Head of Service Management - FCDO - G7
£58,209 - £66,877 Plus location allowance £1,750
Full-time (Permanent)
Senior Software Developer (Service Now) - FCDO - SEO
£48,801 - £53,697 Location allowance £1750
Full-time (Permanent)
Inquiries Archivist - Cabinet Office - HEO
£37,922 - £41,992
Full-time (Temporary)
Senior Public Inquiries Archivist - Cabinet Office - SEO
£43,760 - £47,413
Full-time (Temporary)
Senior Project Manager - FCDO - G7
£58,209 - £66,877 Plus location allowance £1750
Full-time (Permanent)
Lead Security Architect - FCDO - SEO
£48,801 - £53,697 Plus location allowance £1750
Full-time (Permanent)
Lead Technical Architect - HMRC - G6
National - Minimum £71,725 - Maximum £79,481 London - Minimum £78,988 - Maximum £87,612
Full-time (Permanent)
Director Platform Engineering, Resilience & Cyber - DSIT - SCS2
£100,000 - £163,000
Full-time (Permanent)
Senior Data Architect - DWP - G7
£57,946 - £83,917
Full-time (Permanent)
Senior Security Architect - DWP - G7
£57,946 - £83,917
Full-time (Permanent)
Test Engineer - Welsh Revenue Authority - HEO
£37,111 - £45,378 plus additional DDaT allowance
Full-time (Permanent)
Senior Test Engineer - Infected Blood Compensation Authority - SEO
£47,258 plus additional £3,544 after completing probation
Full-time (Permanent)
Lead Interaction Designer - Crown Prosecution Service - G7
£58,330 - £67,450 (National) / £62,820 - £73,520 + £3,150 RRA (London)
Full-time (Permanent)
Service Transition Manager - Welsh Government - HEO
£37,111
Full-time (Permanent)
Software Developer - HMRC - HEO
National £37,682 - £40,705. London £42,631 - £46,077
Full-time (Permanent)
Lead Software Developer - Crown Prosecution Service - G7
National - £58,330 - £67,450 London - £62,820 - £73,520 + £3150 RRA
Full-time (Permanent)
Senior Security Architect - DWP - G7
£57,946 - £83,917
Full-time (Permanent)
Lead DevOps Engineer - Insolvency Service - G7
National: £57,367 - £63,319 London: £59,463 - £66,290 up to £5,150 allowance
Full-time (Permanent)
Senior DevOps Engineer - Insolvency Service - SEO
National: £48,429 - £52,222 London: £51,661 - £54,686 plus £5,150 allowance
Full-time (Permanent)
Senior Infrastructure Manager - HMRC - SEO
£45,544 - £49,523
Full-time (Permanent)
Deputy Director DDaT in HO Digital Enterprise Services Technology - Home Office - SCS1
£81,000 - £91,000
Full-time (Permanent)
£55,575
£55,575 plus allowances. London offers an additional £4,218
Full-time (Permanent)
Test Assurance Analyst - National Crime Agency - HEO
£45,326 plus additional allowance. London additional £4,218
Full-time (Permanent)
Supporting Services Senior Officer - National Crime Agency - HEO
£45,326 plus an additional £4,218 for London
Full-time (Permanent)
Senior Dynamics Developer - Intellectual Property Office - SEO
£47,766 up to £58,575 with additional pay allowance
Full-time (Permanent)
Senior IT Service Manager - Government Digital Service - G7
£55,403. Offers made above this will be made up with a specialist pay allowance.
Full-time (Permanent)
Senior Enterprise Architect (Data Analytics) - HMRC - G7
£58,541 - £64,624
Full-time (Permanent)
Test Engineer - Welsh Revenue Authority - HEO
£37,111 - £45,378
Full-time (Permanent)
Senior Test Engineer - Infected Blood Compensation Authority - SEO
£47,258 plus additional £3,544 after probationary period
Full-time (Permanent)
Lead Services Manager - Office for Standards in Education, Children's Services and Skills - G7
£68,635 per annum. Rising to £69,322 per annum on successful completion of probation.
Full-time (Permanent)
Software Developer - Ministry of Housing, Communities and Local Government - SEO
£49,548 (London), £45,928 (National) may also qualify for additional allowance
Full-time (Permanent)
Lead Developer - Department for Transport - G7
Base pay £57,515 plus an additional allowance up to £22,885
Full-time (Permanent)
Lead Technical Architect - Home Office - G7
National £62,109 London £66,229 plus up to £18,291 additional allowance
Full-time (Permanent)
Senior Technical Architect - Crown Commercial Service - G7
£59,877 - £66,869 plus up to £9,000 technical allowance
Full-time (Permanent)
Principal Technical Architect, Networks & Infrastructure - Home Office - G6
National £76,117 London £80,237 plus up to £19,483 additional allowance
Full-time (Permanent)
Senior DevOps Engineer - UK Health Security Agency - SEO
£41,983 - £52,113 This role attracts a Market Pay Supplement of up to £5,000.
Full-time (Permanent)
IT Ops Student Placement - HM Land Registry - EO
£32,114
Full-time (Permanent)

Subscribe to our newsletter

Sign up here