Flexa
Discover companiesFind a jobResourcesSign in/up
For employers
< Back to search
ASOS

SOC and Incident Response Lead

Location:  London, United Kingdom
Location flexibility:  3 office days / week – may vary across teams (tech teams 3 days at home)
View company profile
Apply

Job Description

Company Description

We’re ASOS, the online retailer for fashion lovers all around the world.

We exist to give our customers the confidence to be whoever they want to be, and that goes for our people too. At ASOS, you’re free to be your true self without judgement, and channel your creativity into a platform used by millions.

But how are we showing up? We’re proud members of Inclusive Companies, are Disability Confident Committed and have signed the Business in the Community Race at Work Charter and we placed 8th in the Inclusive Top 50 Companies Employer list.

Everyone needs some help showing up as their best self. Let our Talent team know if you need any adjustments throughout the process in whatever way works best for you.

Job Description

The Role

As an experienced SOC and Incident Response Lead at ASOS, you will provide hands-on technical leadership across security monitoring, detection, engineering, incident response, and threat-led investigations. You will lead the SOC and Incident Response team, ensure security incidents are investigated and resolved effectively, and maintain a strong operating relationship with our external MSSP. The ideal candidate will combine deep technical expertise with proven experience leading analysts, improving operational capability, managing stakeholders, and making sound decisions under pressure.

The role will act as the bridge between wider technology teams, the cyber security team, and third-party partners, ensuring a coordinated and consistent response to cyber security incidents.

This role reports to the Head of Security Operations.

Responsibilities

  • Lead the SOC and Incident Response team day to day, providing technical direction, coaching analysts, maintaining effective operations, and ensuring the team has clear priorities, strong morale, and the capability to respond to complex security incidents.
  • Own and improve the SOC detection lifecycle, including reviewing detection coverage, tuning noisy or low-value alerts, creating new detections from threat intelligence and incident learnings, and mapping coverage against relevant attack techniques and critical business assets.
  • Establish and maintain incident response processes, procedures, and documentation, ensuring they align with industry best practices.
  • Strong hands-on experience with SIEM, EDR, cloud security, identity, email security, and forensic analysis tooling, with the ability to investigate incidents, validate detections, and guide analysts through complex technical findings.
  • Define incident response metrics, dashboards, track and report on key performance indicators (KPIs) to senior management, suggesting improvements as needed.
  • Delegate unassigned newly submitted tickets to analysts keeping in mind current workloads and availability.
  • Conduct regular incident response training and drills to enhance team readiness and improve response times.
  • Lead incident post-mortem analysis to identify root causes, lessons learned, and recommend measures for prevention or improvement.
  • Conduct periodic threat simulation activities to evaluate the adequacy of deployed detective/preventative controls.

Qualifications

About you

  • Proficiency in incident response tooling, including SIEM, EDR, cloud security, threat intelligence and forensic analysis platforms.
  • Demonstrable experience leading and coordinating responses to complex cyber security incidents, acting as a technical lead during high-pressure situations.
  • Proven experience managing, mentoring and developing SOC Analysts and Incident Responders within a Security Operations environment.
  • Strong analytical and problem-solving abilities, with the capability to rapidly assess, contain and remediate security threats.
  • Ability to make effective decisions under pressure whilst managing multiple incidents, priorities and stakeholders simultaneously.
  • Experience working with cloud security technologies and environments, particularly Azure and/or AWS.
  • Experience building, tuning and improving security monitoring, detection engineering and threat detection capabilities.
  • Strong stakeholder management and communication skills, with the ability to translate technical security issues into clear business risk and impact for senior leadership.
  • Experience conducting incident post-mortems, root cause analysis, tabletop exercises and crisis response testing to drive continuous improvement.
  • Working knowledge of UK security and compliance frameworks, including PCI-DSS, GDPR, NIST, ISO 27001 and Cyber Essentials.

Additional Information

BeneFITS’

  • Employee discount (hello ASOS discount!)
  • Employee sample sales
  • 25 days paid annual leave + an extra celebration day for a special moment
  • Discretionary bonus scheme
  • Private medical care scheme
  • Flexible benefits allowance - which you can choose to take as extra cash, or use towards other benefits
  • Opportunity for personalised learning and in-the-moment experiences that enable you to thrive and excel in your role
Apply

Other jobs you might like

Tesco

Security Analyst III - SOC

Welwyn Garden City, UK

Tesco

Senior Incident Responder (DFIR)

Welwyn Garden City, UK

Vodafone

Security Expert

Bucuresti, RO

#1 MOST LOVED - ENTERPRISE COMPANIES

Working at ASOS

3 office days / week – may vary across teams (tech teams 3 days at home)

A little flex time

Company benefits

25 days annual leave + bank holidays
401K
Accrued annual leave – Max 5 days to carry over
Adoption leave – 26 weeks enhanced pay
Annual bonus
Annual pay rises
Bike parking
Birthday off
Buy or sell annual leave
Cinema discounts
Coffee discounts
Company freebies
Compassionate leave
Critical Illness Insurance
Dental coverage
Early finish Fridays
Emergency leave
Employee assistance programme
Employee discounts
Enhanced maternity leave – 26 weeks enhanced pay
Enhanced paternity leave – 8 weeks enhanced pay
Enhanced pension match/contribution
Enhanced sick days
Enhanced sick pay
Eye Care Support
Faith rooms
Family health insurance
Fertility benefits
Financial coaching
Further education support
Gym membership
Hackathons
Health insurance
Hertility subscription
In house training
On-site catering
On-site massages
On-site workout classes
On-site yoga classes
Learning platform
Life assurance
Mental health first aiders
Mental health platform access – Access to EAP (Unum)
Mentoring
Neonatal leave – 16 weeks leave
On-site gym
On-site wellness room
Open to compressed hours
Open to part time work for some roles
Open to part-time employees
Personal development days
Pregnancy loss leave – 10 days paid leave
Private GP service
Professional subscriptions
Referral bonus
Religious celebration leave
Restaurant discounts
Sabbaticals
Salary sacrifice
Shared parental leave – 26 weeks enhanced pay
Skilled worker visas
Study support
Teambuilding days
Time off in-lieu
Travel loan
Volunteer days
Summer hours
Secure on-site parking
Modern office
Private booths
Collaboration spaces
On-site barista
On-site shower
On-site personal trainer
Carer’s leave
Fertility treatment leave
Women’s health leave
Menopause support

Awards & Accreditations

2nd – Most loved - Medium companies

2nd – Most loved - Medium companies

Flexa awards 2026
Apply
Flex spring

Join the mailing list

Get the latest insights and expert guidance on job hunting, career progression, and creating thriving workplaces.

Enter your email
  • About us
  • Contact us
  • FAQs
  • Info for employers
  • Join Flexa
  • Legal
  • Live feed
  • Resources
  • Sign in/up
  • The Flexa awards
Flexa

BAE Systems

Lead SOC Architect

Guildford, United Kingdom

EY UK

Cyber Defense Incident Responder - Assistant Director

Manchester, UK

#2 MOST INCLUSIVE COMPANY

Company employees:

3,000

Gender diversity (m:f):

35:65

Hiring in countries

United Kingdom

Office Locations