Skip to content

Open nowPosted 3 days ago

Team Lead - Principal Security Detection & Response Analyst Team Lead, German Speaking

twh43 open roles

Where
United Kingdom
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowTeam Lead - Principal Security Detection & Response Analyst Team Lead, German Speakingtwh · United Kingdom
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on twh's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 3 days ago

The posting

LevelBlue reduces risk and builds lasting resilience so organizations can innovate and advance their mission with confidence. As the world’s most analyst-recognized and largest pure-play managed security services provider, LevelBlue elevates client outcomes that matter: stronger defense, faster response, and sustained business continuity. LevelBlue combines AI-powered security operations, advanced threat intelligence, and elite human expertise to provide the most comprehensive portfolio of strategic advisory, managed security, offensive security, and incident response services. UK BASED ONLY- Employment Contract

We are looking for an experienced, hands-on cybersecurity professional to join our Global Security Operations team as a Senior or Principal Security Detection & Response Analyst and EU SOC Team Lead. 

This is primarily a hands-on technical role with additional Team Lead responsibilities. You will operate as a Tier 2 or Tier 3 Security Detection & Response Analyst while providing day-to-day support, coordination, coaching and technical leadership to other analysts within the EU SOC.    Working Schedule: The working hours are 08:00–16:00 or 9:00–17:00 local time in the UK, depending on daylight saving time. The position follows a rotating working-day schedule that includes weekend coverage. Working days may rotate between Tuesday–Saturday and Sunday–Thursday, according to the team rotation. .   We are currently requiring candidates with Fluent German along with fluent English for this role. French language skills would be a plus.

  As an analyst, you will investigate and respond to sophisticated security threats, act as an escalation point for other analysts, participate in threat hunting and incident response, and work directly with customers to protect their environments. 

  As Team Lead, you will help the EU SOC operate effectively on a day-to-day basis by supporting analysts, coordinating activity, monitoring workload and raising operational or resourcing concerns to SOC leadership. You will work closely with the EU SOC Director and other regional teams as part of our global follow-the-sun operating model. 

The LevelBlue Global SOC provides 24/7 active monitoring and proactive threat hunting services, delivering fast identification, response and analysis of threats to help keep our customers safe from today's and tomorrow's adversaries. 

Key Responsibilities

Security Analysis & Incident Response · Perform hands-on security analysis and investigation of complex endpoint and security alerts across MDR and MXDR environments. · Act as a technical escalation point for Tier 1 and Tier 2 analysts. · Piece together attack chains across complex customer environments including endpoint, cloud, identity, email and network technologies. · Participate in all stages of incident investigations, including taking decisive action in response to active breaches. · Conduct proactive threat hunting across customer environments to identify attackers, suspicious activity or remnants of compromise. · Research new and emerging attacks, threat actors, malware and attacker tactics, techniques and procedures (TTPs). · Collect, process and exploit OSINT to support investigations, improve threat-hunting queries and contribute to Threat Alerts. · Engage directly with customers during investigations and escalations, communicating effectively with stakeholders ranging from SOC analysts to C-suite executives. · Remain actively involved in the analyst workload, supporting operational investigations and escalations as required. Team Lead Responsibilities Alongside your analyst responsibilities, you will provide day-to-day support and leadership to the EU SOC team. · Provide coaching, mentoring and technical guidance to EU SOC analysts. · Act as a first point of contact for analysts requiring support with technical or operational issues. · Help coordinate day-to-day activity across the team and ensure work is appropriately prioritised. · Maintain awareness of team workload and operational coverage, raising potential capacity or coverage concerns with SOC leadership. · Support analysts with complex investigations and customer escalations. · Encourage collaboration, knowledge sharing and consistent working practices across the team. · Help ensure Global SOC policies, procedures and operational processes are understood and followed. · Support the monitoring of service delivery, SLOs, SLAs and operational metrics, highlighting potential issues to SOC leadership. · Identify opportunities to improve investigation processes, methodologies and ways of working. · Support onboarding and development of new analysts. · Provide feedback to SOC leadership on team development, operational challenges and areas for improvement.

What we are looking for:- We are looking for someone who combines strong technical security expertise with the ability and desire to support and develop others. · Significant experience working within a SOC, MDR, incident response or similar cybersecurity environment. · Technical capability appropriate to a Senior/Tier 2 or Principal/Tier 3 Security Analyst position. · Strong hands-on security investigation and incident-response skills. · Experience in at least two of the following areas: Endpoint security, Malware analysis, Threat hunting / threat intelligence, Incident response, Penetration testing, Reverse engineering and Digital forensics · Strong knowledge of modern operating systems, particularly Windows; knowledge of macOS and Linux is advantageous. · Solid understanding of networking protocols and network architecture. Familiarity with common security tools, technologies and frameworks. · Experience with scripting languages such as Python, Bash or PowerShell is advantageous. · Previous Team Lead or people-management experience, ability to balance Team Lead responsibilities with an active technical workload. · Ability to explain complex technical issues to both technical and non-technical audiences. · Strong customer-facing skills and confidence engaging with senior stakeholders. · Excellent English reading, writing and speaking skills. · Additional European languages, particularly French or German, are required for this role. Why it Matters: Joining our team means becoming a vital part of a market-leading force dedicated to safeguarding critical assets, solving complex security challenges, and delivering innovative services that meet the security needs of our global customer base. Why You Will Love It: Exceptional Team: Lead a highly skilled team and collaborate with experienced leaders in cybersecurity who share your passion for delivering market-leading Managed Security Services. Global Exposure: Gain insight into various aspects of the Managed Security Services business, with your leadership and actions directly impacting the security of organizations worldwide. Ownership and Impact: Assume responsibility for defining and executing processes that consistently deliver outstanding results. Desired Experience:

7 or more years of information security or networking experience. Previous operational experience as an analyst, engineer, or team lead. Excellent customer service skills. Strong analytical thinking and problem-solving skills. Strong oral and written communication skills. Self-managed and team-oriented, with the ability to coach and teach. Responsive, collaborative, and highly motivated. Leadership and management experience.

Preferred:

Bachelor's/Master's Degree in Information Technology or a similar area of study. At least 7 years of experience in Information Security or Networking. Certification in a security-related industry, vendor, or professional certification

  Why Join LevelBlue?At LevelBlue, you’re not just an employee—you’re part of a team making a real difference in the world of cybersecurity. We foster a culture of innovation and creativity where your contributions are valued, and you’ll have the support and resources to grow and thrive.   This role is open to candidates legally authorized to work in the UK. At LevelBlue, we support flexible work and bring people together in person for key moments based on role, team, and business needs. LevelBlue is committed to a culture of respect, inclusion, and equal opportunity. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status, age, or any other status protected under applicable law. To all agencies: Please do not contact LevelBlue employees outside of the Talent Acquisition team. LevelBlue’s policy is to only accept resumes from agencies through its approved agency process and with a valid agreement in place. Any resume submitted outside this process will be considered the property of LevelBlue, and no fee will be paid if a candidate is hired from such a submission.   #LI-KD1

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against twh's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on twh's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    twh's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.