SOC Lead

Super · Spain · Other

Posted 2026-10-01

Apply for this role →

SOC Lead

The Security Operations Centre (SOC) is the front line of Super Technologies' security organisation, monitoring, triaging and providing first response to alerts around the clock, with an on-call rotation covering extended hours. As SOC Lead, you'll own alert monitoring, triage, first-line incident response and major-incident coordination across the organisation, building the team's coverage model, runbooks and metrics whilst working closely with Detection Engineering, Forensics, Security Platform Engineering and VulnOps. This is a hands-on leadership role, combining team management with staying close to the operational work — shift coverage, incident ownership and the tooling needed to contain threats quickly.

What the role involves

Monitoring, triage and first response

Own alert monitoring, triage and first-line response across all detection sources, on an extended-hours shift pattern with out-of-hours on-call.

Define SOC runbooks, coverage metrics and SLAs for alert acknowledgement and triage, and feed alert-noise data back to Detection Engineering for tuning.

Logging and detection coverage

Ensure logging coverage exists across the organisation, so Detection Engineering and Forensics have what they need to work from.

Incident ownership

Own incidents end-to-end — enrich, validate, contain and close — escalating to Forensics once confirmed, whilst building the capability to contain any incident anywhere in the organisation within seconds.

Major incident coordination

Coordinate major security incidents across SOC, Infrastructure, Cloud, Identity and business teams, and own major-incident tabletop exercises across Security, IT, business, Legal and Communications.

Capture lessons learned and drive updates to IR playbooks, escalation paths and decision-making procedures.

IR playbooks and testing

Own IR playbooks and work with the pentest team to test alerting coverage and the SOC's reaction time.

What we are looking for

Proven experience running or leading a SOC or equivalent detection-and-response function, including shift-based or extended-hours coverage models and on-call rotations.

Strong hands-on incident response background — triage, containment and coordination of multi-team incidents under time pressure.

Experience building or maturing SOC processes: runbooks, SLAs, escalation paths and metrics (MTTA, MTTR/triage time, escalation accuracy).

Comfort working across a dependency-heavy environment — partnering with Detection Engineering, Forensics, Security Platform Engineering and VulnOps rather than owning every input yourself.

Experience designing or running tabletop exercises with cross-functional stakeholders (IT, business, Legal, Communications).

People leadership experience, ideally managing senior/principal-level engineers.

Clear communicator, comfortable escalating to and coordinating with technical and business stakeholders during live incidents.

What we offer

Medical / Health Insurance

Open Annual Leave

Employee Assistance Programme

Training & Learning Development

Apply for this role →

← Back to all jobs