University College London
Detection and Response Lead
Job Description
Salary: £39,000 - 62,000 per year
Requirements:- Significant experience leading or managing security operations, SOC, detection and response, or incident response services in a complex organisation.
- Strong knowledge of security monitoring, alert triage, investigation workflows, incident declaration, incident response coordination, and post-incident improvement.
- Experience with relevant security tools and platforms, such as SIEM, SOAR, EDR, NDR, identity protection, CSPM, CTEM, and specialist incident response or forensic tools.
- Experience developing and improving incident response plans, playbooks, runbooks, exercises, and operational process documentation.
- Ability to provide calm, decisive, evidence-based leadership during security incidents and make timely decisions when information is incomplete.
- Experience leading, developing, and supporting multidisciplinary technical teams, setting clear objectives, and building capability, resilience, and a culture of continuous improvement.
- Strong stakeholder management and communication skills, including the ability to explain technical security issues, operational impacts, and risks to technical and non-technical audiences.
- Experience using metrics, evidence, and operational data to improve services, prioritise risk, and report outcomes to senior stakeholders.
- Ability to collaborate across internal teams, external suppliers, and specialist partners to resolve telemetry, tooling, process, and capability gaps.
- Lead our Detection and Response function, including security monitoring, alert triage, investigations, and security incident response.
- Provide calm and accountable leadership during security incidents.
- Develop our teams capabilities and ensure effective processes, tooling, metrics, and escalation arrangements are in place.
- Identify and address gaps in our detection and response capability with colleagues across Security Operations and the wider university.
- Maintain and improve our incident response plans and playbooks, and coordinate exercises to test our readiness.
- Build trusted relationships with senior stakeholders, service providers, government bodies, and law enforcement.
- Translate complex technical issues into clear operational and risk-based advice.
- Cloud
- Support
- Security
- UX UI Design
- DevOps
More:
We are UCLs Information Services Division (ISD), the primary provider of IT services to UCL. We support and enhance learning, teaching, research, and administration for more than 50,000 staff and students at UCL and associated institutions. Our ambition is to lead IT services in the higher education sector. We are modernising our technology foundations, digitising university processes, and developing capability in experience and UX, agile development, security, cloud, service management, and partnering. This role is within our Information Security Group and its Security Operations team, responsible for security monitoring, incident response, vulnerability management, and threat intelligence. We offer 41 days of holiday, an annual leave purchase scheme, a CARE pension scheme, cycle-to-work and season-ticket loans, an immigration loan, relocation support for certain posts, an on-site nursery and gym, enhanced family leave pay, an employee assistance programme, and discounted medical insurance. Based in London, we are committed to equality, diversity, and inclusion, and particularly encourage applications from candidates underrepresented in our workforce.
last updated 39 week of 2026
Interested in this role?
Submit your application now
How to Apply
About University College London
University College London
London
IT
Skills & Technologies
Inferred from job description
Salary Insight
£50,500
This role
£85,000
UK median
This salary is 41% below the UK median for Lead roles (£85,000/yr).
Based on 2024–2025 UK technology sector benchmarks