TRCI-26-05211
Interim Cyber Defence Lead (SOC & Incident Response)
Interim Cyber Defence Lead to provide operational leadership and continuity for Cyber Defence while the manager is on parental leave. You will lead and coordinate SOC operations, drive incident management and threat follow-up (including P1/major incidents, potentially outside office hours), and improve MTTR, monitoring/detection coverage, and timely follow-up of incidents, threats, and vulnerabilities. The role requires strong stakeholder communication, the ability to translate technical findings into clear actions and reporting, and hands-on experience with Microsoft XDR, Microsoft Sentinel, and Palo Alto in a cyber defence/SOC environment.
Position summary
- Location
- Sweden
- Workplace
- Remote
- Employment
- Contract
- Experience
- Minimum 5 years and Maximum 10 years
Role overview
Why This Role Matters.
Interim Cyber Defence Lead to provide operational leadership and continuity for Cyber Defence while the manager is on parental leave. You will lead and coordinate SOC operations, drive incident management and threat follow-up (including P1/major incidents, potentially outside office hours), and improve MTTR, monitoring/detection coverage, and timely follow-up of incidents, threats, and vulnerabilities. The role requires strong stakeholder communication, the ability to translate technical findings into clear actions and reporting, and hands-on experience with Microsoft XDR, Microsoft Sentinel, and Palo Alto in a cyber defence/SOC environment.
Your Impact
Deliver Enterprise Value
Help organisations solve complex business problems through modern technology, consulting expertise and measurable outcomes.
Collaboration
Work Across Teams
Collaborate with consultants, architects, engineers and client stakeholders throughout the project lifecycle.
Growth
Learn Continuously
Gain exposure to enterprise technologies, certifications, mentoring and real-world project experience.
Career Path
Grow With Ubique
Build a long-term consulting career with opportunities to take on greater responsibility and leadership over time.
Responsibilities
What You'll Be Doing.
Every role at Ubique contributes directly to solving meaningful business challenges for our clients.
Lead and coordinate Security Operations (SOC)
Drive incident management and threat follow-up
Support the team on operational security matters
Help lead P1 and major incidents when needed (might be outside office hours)
Follow up actions, risks and security improvements
Coordinate with internal teams and service providers- act as SME Key priorities
Improve MTTR (Mean Time to Respond/Recover)
Increase security monitoring and detection coverage
Ensure timely follow-up of incidents, threats and vulnerabilities
high skills in communication, stakeholder mgmt
Strong background in SOC, Incident Response and Cyber Defence
Technology stack
Tools & Technologies.
The platforms and technologies you'll use to build modern, enterprise-grade solutions.
SOC
Security Operations
Incident Response
Incident Management
Major Incident
P1 incident
Threat Management
Threat Follow-up
Security Monitoring
Detection Coverage
MTTR
Vulnerability Management
Identity Security
Non-human identity
Microsoft Sentinel
Microsoft XDR
Palo Alto
Cyber Defence
Requirements
Skills & Experience.
We value curiosity, collaboration and continuous learning. If you don't meet every requirement but believe you can make an impact, we'd still love to hear from you.
Essential
Required Qualifications
SOC operations leadership and coordination
Incident management and incident response (including P1/major incidents)
Threat management and threat follow-up
Security monitoring and detection engineering/coverage improvement
Vulnerability management and follow-up
Identity security (including modern identity risks)
Stakeholder management and strong communication skills
Ability to translate technical findings into clear actions and reporting
Microsoft Sentinel
Microsoft XDR
Palo Alto (security platform)
Cyber defence operations
Preferred
Nice to Have
Experience coordinating with external service providers (MSSP/partners)
Experience improving MTTR via process/operational metrics and runbooks
Ability to support on-call/out-of-hours major incident leadership
What you'll gain
More Than Just A Job.
We're committed to helping every team member grow professionally, personally and technically while working on meaningful projects.
Global Exposure
Collaborate with international clients and multicultural teams on enterprise programmes.
Continuous Learning
Expand your expertise through mentoring, certifications and hands-on project experience.
Career Growth
Take ownership, develop leadership skills and grow your consulting career over time.
Flexible Working
Hybrid and remote collaboration designed around trust and delivering exceptional outcomes.
People First
Join a supportive culture where collaboration, respect and long-term relationships come first.
Enterprise Projects
Work on meaningful technology initiatives for leading organisations across industries.
Apply
Apply for Interim Cyber Defence Lead (SOC & Incident Response)
One page, about two minutes. We only ask for what we actually need to have a first conversation.