Detect Workstream Lead - 6 Month Contract - Inside IR35 - Fully Remote

  • Hamilton Barnes
  • 12/05/2026
Contractor Information Technology Telecommunications

Job Description

Detect Workstream Lead - 6 Month Contract - Inside IR35 - Fully Remote

Contract Type: Initial 6 month contract (Inside IR35)
Rate: £500 per day Inside IR35
Location: Hybrid in London

Role Overview:

We are looking for a Detect Workstream Lead to join on a 6-month hybrid contract based in Gloucester (2 days on-site). The role leads delivery across the Detect function within a major cybersecurity transformation programme, working across SOC, security engineering, platform, and business stakeholders to shape plans, manage dependencies, and drive detection-aligned outcomes. Note: Active SC clearance is desirable; eligibility to obtain clearance is essential.

Key Responsibilities:

  • Lead the Detect workstream across agreed scope, milestones, and delivery outcomes, defining and driving workstream plans, priorities, and implementation sequencing
  • Coordinate stakeholders across SOC, security engineering, platform teams, and wider programme functions, driving delivery across detection, monitoring, tooling integration, and security operations uplift
  • Manage governance, RAID, dependencies, decision points, and escalations, providing clear progress reporting and recommendations to programme leadership
  • Lead use case prioritisation, integration planning, and third-party supplier management aligned to the Detect workstream roadmap
  • Update and maintain associated risk mitigations, ensuring delivery decisions and actions are clearly tracked and communicated

What You Will Ideally Bring:

  • Senior-level programme or workstream leadership experience, with a proven track record of independently driving delivery in complex security transformation environments
  • Strong security operations and detection delivery background, with good working knowledge of NIST CSF 2.0
  • Experience across SOC operations, detection engineering, and security monitoring including use case development and alerting
  • Hands-on knowledge of SIEM platforms such as Microsoft Sentinel, including tooling integration, onboarding, and SOC transformation activities
  • Strong governance and stakeholder management skills - RAID management, dependency tracking, and executive-level progress reporting - SC clearance required or eligibility to obtain