Join one of Canada's Best Workplaces

SOC Lead

Location
Nova Scotia
Department
Cyber Security
Salary
To be discussed
Closing Date
10/19/2026
Apply now

Note: This vacancy is a remote role intended for Atlantic Canadian and Ontario residents.

About Admiral

Admiral is one of the UK's leading financial services companies, serving more than 9 million customers through insurance, lending, and other products. Since opening in Halifax in 2007, Admiral Canada has grown to nearly 400 colleagues and become an important part of Admiral's global operations, supporting customer, technology, and cyber security functions across the Group.

Cyber Security at Admiral

Cyber Security plays a critical role in protecting our customers, colleagues, data, and technology platforms. As a global financial services organisation, we operate in a complex and constantly evolving threat landscape, making security a key business priority.

Our Canadian Cyber Security team is part of a 24/7 global operation, working alongside colleagues across multiple regions to detect threats, respond to incidents, strengthen security controls, and improve cyber resilience across the business.

Since establishing our Cyber Security function in Canada in 2022, we've built a growing team of specialists across Security Operations, Incident Response, Security Engineering, and Threat Intelligence. Together, they help safeguard a business serving millions of customers while continuing to strengthen Admiral's global security capabilities.

About the Job – Security Operations Centre Lead

As part of a 24/7 Global Security Operations Centre, the SOC Lead is responsible for leading and developing a team of Security Operations Analysts while ensuring the consistent delivery of high-quality security operations.

Working closely with colleagues across multiple regions, you will help oversee threat monitoring, investigation, and response activities, support effective operational handovers, and maintain the standards and processes that underpin a mature Security Operations function.

This role combines people leadership with strong security operations expertise. You will mentor and develop analysts, identify growth opportunities, strengthen team capability, and help create a culture of continuous learning and accountability. At the same time, you will provide technical guidance during investigations, support escalations, and act as a trusted leader within the SOC.

Success in this role requires strong leadership skills, sound security judgement, excellent communication, and the ability to balance operational excellence with the ongoing development of a high-performing team.

Key Responsibilities

Operational Leadership & Coordination

  • Lead, mentor, and develop SOC analysts across three countries, ensuring consistent quality and performance across all regions.
  • Oversee day-to-day SOC monitoring activities, ensuring 24/7 operational coverage and seamless handovers across time zones.
  • Provide expert guidance during investigations, escalations, and complex security incidents.
  • Ensure all security events are triaged, investigated, documented, and remediated in accordance with SOC processes.
  • Maintain a high level of situational awareness across all regional teams.

Strategic Direction & Continuous Improvement

  • Contribute to the long-term SOC strategy, including capability growth, tooling advancement, and enhancements to the global operating model.
  • Drive maturity improvements aligned with frameworks such as MITRE ATT&CK, the Cyber Kill Chain, and defence-in-depth principles.
  • Identify and implement opportunities to enhance analyst effectiveness through improvements to processes, playbooks, tooling, and governance.
  • Lead annual and quarterly SOC roadmap planning and execution.

AI, Automation & Engineering Collaboration

  • Drive adoption of AI-assisted automated triage and machine-learning-based threat analysis.
  • Partner with engineering teams to enhance SIEM/SOAR pipelines, enrich data sources, and reduce manual workload through targeted automation.
  • Oversee the tuning and optimisation of detection rules across monitoring platforms.

Incident Response & Threat Analysis

  • Support incident investigations with technical leadership, rapid decision-making, and timely updates to stakeholders.
  • Ensure lessons learned from incidents and threat intelligence activities are captured and integrated into processes and playbooks.

Stakeholder Management & Reporting

  • Act as the SOC technical point of contact for internal stakeholders, including security leadership, technology teams, and business functions.
  • Communicate technical threats clearly to non-technical audiences, including senior management.
  • Lead regular SOC operational reviews, presenting insights into service performance, trends, risks, and improvement plans.

SOC Metrics, Performance & Quality Assurance

  • Develop and maintain SOC KPIs and OKRs across all three regions.
  • Track metrics such as MTTD, MTTR, alert volumes, false positives, automation utilisation, analyst productivity, and rule effectiveness.
  • Ensure continuous performance monitoring and drive improvements in SOC throughput and quality.
  • Conduct case reviews, root-cause analyses, and trend reporting to strengthen detection and response capabilities.

People Leadership & Development

  • Build a culture of technical excellence, collaboration, and accountability across global teams.
  • Coach and mentor analysts, identifying training needs, certification pathways, and career development opportunities.
  • Conduct performance reviews and support the professional development of junior and senior SOC analysts.
  • Foster an inclusive, high-trust, globally aligned team environment.

Experience and Qualifications Required

Required

4+ years' experience in SOC operations and security monitoring.

  • Minimum 3 years' experience leading and developing high-performing teams.
  • Strong understanding of SIEM platforms.
  • Proven knowledge of MITRE ATT&CK, the Cyber Kill Chain, and modern threat actor behaviours.
  • Strong communication, report-writing, presentation, and stakeholder-facing skills.

Highly Desirable

  • Experience with SOAR technologies.
  • Experience with detection content and playbooks.
  • Familiarity with cloud environments (Azure, GCP) and cloud security practices.
  • Background in AI/ML security tools or LLM integration within SOC workflows.
  • Relevant certifications (e.g., GCIH, GCIA, GCFE, GDAT, GCDA, GISP) are considered an asset.
  • Experience in global follow-the-sun SOC operations.

Salary, Benefits, and Work-Life Balance

We offer a competitive salary and total rewards package that reflects the experience, skills, and expertise of the successful candidate. We welcome applications from qualified candidates and are happy to discuss compensation details throughout the recruitment process.

At Admiral, we know that great people do their best work when they're supported both professionally and personally. That's why we offer a comprehensive benefits package and are proud to be consistently recognized as one of the best workplaces in Canada and globally.

Admiral colleagues are eligible for five weeks of paid vacation annually, plus statutory holidays. Vacation entitlement increases with length of service, giving you even more time to rest, recharge, and enjoy life outside of work.

Leann more about our employee benefits here: https://joinadmiral.ca/employee-benefits/

Our Commitment to You

Admiral is committed to building a diverse and inclusive workplace. We are proud to be an equal opportunity employer and do not discriminate based on race, national origin, gender, gender identity, sexual orientation, disability, age, family status, or any other protected characteristic. We believe all qualified applicants should receive fair and equal consideration for employment.