Cyber SOC Technical Lead

Nottingham Trent House (95002), United Kingdom, Nottingham, Nottinghamshire

At Capital One, we're building a leading information-based technology company. Still founder-led by Chairman and Chief Executive Officer Richard Fairbank, Capital One is on a mission to help our customers succeed by bringing ingenuity, simplicity, and humanity to banking. We measure our efforts by the success our customers enjoy and the advocacy they exhibit. We are succeeding because they are succeeding.

Guided by our shared values, we thrive in an environment where collaboration and openness are valued. We believe that innovation is powered by perspective and that teamwork and respect for each other lead to superior results. We elevate each other and obsess about doing the right thing. Our associates serve with humility and a deep respect for their responsibility in helping our customers achieve their goals and realize their dreams. Together, we are on a quest to change banking for good.

Cyber SOC Technical Lead

Capital One is hiring for a seasoned Cyber Security professional to identify and block cyber threats and attacks against Capital One enterprise applications, networks, and services by investigating indicators of suspicious and malicious activity, and proactively discovering threats to Capital One.

Your mission is to take a technical lead role, supporting the SOC Analysts to find the threat actors attempting to attack Capital One infrastructure, root out and stop any malicious actors who make it past our defences, and develop solutions that increase the ability to automatically detect or respond to malicious events. You will also be responsible for driving escalated investigations to conclusion, for initiating your own investigations to locate malicious activity, and for delivering improvements to the defensive posture of the organisation.

In addition to the technical skills, you will need to be a leader, someone who enjoys training and mentoring teammates, and a person who can encourage and elevate the team.

The Cyber SOC Technical Lead will ensure the effective operations of the SOC through the following:

  • Proactively search for active intrusions in the Capital One environment, recognising potential, successful, and unsuccessful intrusion attempts and compromises thorough reviews and analyses of relevant event detail and summary information
  • Work closely with escalation points to close out complex investigations
  • Conducting holistic, investigative analysis and rating the risk associated with observed activity
  • Review investigation escalations from SOC Analysts to ensure accurate analysis and provide advice/mentorship
  • Refine and develop dashboards, queries and reports to continuously improve security situational awareness
  • Maintain SOC documentation, procedures, processes and hardware and software inventory detail


Extensive experience in a Cybersecurity Operations role, ideally in a global enterprise organisation, including hands-on experience in the following technical skills:
  • Conducting Cybersecurity investigations into network and application activity
  • Leveraging core security and infrastructure technologies during investigations (e.g. firewall logs, network security tools, malware detonation devices, proxies, IPS/IDS)
  • Analysing common application and network based attacks
  • Working with or investigating *nix and Windows operating systems
  • Interpreting, and identifying abuse in, routed and routing protocols and application traffic
  • Carrying out PCAP analysis, including extracting files, identifying and extracting compressed data and identifying obfuscated content within a data stream

Preferred Qualifications:
  • Bachelor's Degree in Information Technology, Cyber Security, Computer Science, or equivalent experience
  • SANS GIAC 503 or 504, Splunk Power User Certifications
  • Extensive experience in a Security Operations Centre (SOC) with SIEM technology
  • Proven experience conducting Cyber Security investigations in a Cloud environment
  • Proven experience coordinating and supporting incident handling and remediation
  • Experience writing scripts or programs in Python, Javascript, or Bash
  • Experience writing and tuning SIEM rules
  • Experience tuning security appliance signatures (e.g. IDS rules)
  • Experience developing and delivering technical coaching and mentoring programmes

Capital One is committed to diversity in the workplace.

If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at 1-800-304-9102 or via email at All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.

For technical support or questions about Capital One's recruiting process, please send an email to

Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.

Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).

Back to top