As a Product Manager in Cybersecurity & Technology Controls, you will lead the end-to-end product lifecycle for a blockchain detection and prevention capability serving our SOC. You will translate SOC needs into a prioritized roadmap and backlog, partner closely with engineering and threat SMEs, and ensure detections are accurate, explainable, and operationally effective. Success means improving time-to-detect and time-to-respond while managing false positives and meeting reliability and resiliency expectations. Job Responsibilities Define product vision, strategy, and roadmap for SOC-focused blockchain detection and prevention Lead discovery with SOC analysts and incident responders: workflows, pain points, alert usability, escalation paths, and runbooks Own and refine the backlog: detection use cases, requirements, acceptance criteria, and prioritization tradeoffs Partner with engineering/threat teams to deliver end-to-end capability: signal ingestion, enrichment, alerting, triage experience, and response automation where appropriate Establish and track success metrics (e.g., precision/false positive rate, coverage, latency, time-to-detect/time-to-respond, alert volume, reliability/SLA) and drive continuous improvement Drive launch readiness: documentation, training, operational handoffs, and feedback loops with the SOC Required Qualifications, Capabilities, and Skills Product management experience delivering security detections, SOC tooling, or data/analytics products Strong understanding of SOC operations (alert lifecycle, triage, escalations, incident response) Background in blockchain fundamentals and common threat patterns/abuse cases Ability to use data to prioritize, measure detection efficacy, and manage false positives Preferred Experience with SIEM/SOAR and detection engineering programs Experience operating in a highly matrixed, complex organization
27/07/2026
Full time
As a Product Manager in Cybersecurity & Technology Controls, you will lead the end-to-end product lifecycle for a blockchain detection and prevention capability serving our SOC. You will translate SOC needs into a prioritized roadmap and backlog, partner closely with engineering and threat SMEs, and ensure detections are accurate, explainable, and operationally effective. Success means improving time-to-detect and time-to-respond while managing false positives and meeting reliability and resiliency expectations. Job Responsibilities Define product vision, strategy, and roadmap for SOC-focused blockchain detection and prevention Lead discovery with SOC analysts and incident responders: workflows, pain points, alert usability, escalation paths, and runbooks Own and refine the backlog: detection use cases, requirements, acceptance criteria, and prioritization tradeoffs Partner with engineering/threat teams to deliver end-to-end capability: signal ingestion, enrichment, alerting, triage experience, and response automation where appropriate Establish and track success metrics (e.g., precision/false positive rate, coverage, latency, time-to-detect/time-to-respond, alert volume, reliability/SLA) and drive continuous improvement Drive launch readiness: documentation, training, operational handoffs, and feedback loops with the SOC Required Qualifications, Capabilities, and Skills Product management experience delivering security detections, SOC tooling, or data/analytics products Strong understanding of SOC operations (alert lifecycle, triage, escalations, incident response) Background in blockchain fundamentals and common threat patterns/abuse cases Ability to use data to prioritize, measure detection efficacy, and manage false positives Preferred Experience with SIEM/SOAR and detection engineering programs Experience operating in a highly matrixed, complex organization
London, United Kingdom Posted on 20/07/2026 Engagement: Inside IR35 Start Date: ASAP Overview We are supporting a leading investment banking client in London who is seeking an experienced Cyber Technical Delivery Manager to join a large-scale Cyber Security Transformation Programme. This role will be responsible for the successful delivery of complex cyber security initiatives across multiple technology domains, including Identity & Access Management (IAM), Security Operations, Cloud Security, Vulnerability Management, Data Protection, and Regulatory Compliance. The successful candidate will act as the bridge between technical engineering teams, cyber security stakeholders, business leaders, and third party vendors, ensuring projects are delivered on time, within budget, and in line with regulatory and security requirements. Key Responsibilities Lead the end to end delivery of cyber security projects and workstreams. Develop and maintain project plans, milestones, RAID logs, budgets, and resource plans. Ensure delivery aligns with business objectives, security standards, and regulatory requirements. Manage dependencies across multiple technology and business teams. Drive project governance and reporting activities. Cyber Security Delivery Deliver initiatives across: Identity & Access Management (IAM) Privileged Access Management (PAM) Security Operations (SOC) SIEM Platforms Cloud Security Vulnerability Management Data Protection and DLP Security Monitoring and Threat Detection Secure File Transfer and Encryption Programmes Coordinate technical teams to ensure successful implementation of security controls and technologies. Stakeholder Management Engage with senior stakeholders across Cyber Security, Infrastructure, Cloud, Risk, Compliance, and Business Functions. Provide regular programme updates to senior management and governance forums. Manage relationships with third party suppliers and technology vendors. Facilitate workshops, steering committees, and technical review sessions. Identify, manage, and mitigate project risks and issues. Ensure compliance with internal security policies and regulatory frameworks. Support audit, risk, and compliance activities. Track and report programme KPIs and delivery metrics. Requirements Required Skills & Experience Cyber Security Experience Strong understanding of enterprise cyber security principles and controls. IAM and Access Governance PAM Solutions SIEM and Security Monitoring Vulnerability Management Data Protection Security Compliance Programmes Familiarity with security frameworks and standards such as: NIST ISO 27001 CIS Controls Cyber Essentials Regulatory requirements within Financial Services Technical Knowledge Good understanding of: Microsoft Azure AWS Active Directory / Entra ID Security Monitoring Platforms Identity Management Solutions Network and Infrastructure Security Ability to engage effectively with technical architects, engineers, and security specialists. Delivery Management Proven experience delivering complex technology or cyber programmes within large enterprise environments. Strong project and programme management experience. Experience managing multiple workstreams simultaneously. Excellent RAID management and governance skills. Strong budget and financial management experience. Previous experience working within Investment Banking, Banking, or Financial Services. Experience delivering cyber security transformation programmes. Experience operating within regulated environments. Strong stakeholder management skills with the ability to engage at Executive and C Level. Experience managing third party suppliers and system integrators. Experience with: Microsoft Sentinel Splunk SailPoint CyberArk Okta CrowdStrike Microsoft Defender Suite Knowledge of DevSecOps practices. Exposure to cloud migration and security transformation programmes. Experience supporting regulatory remediation initiatives. Qualifications & Certifications One or more of the following would be advantageous: PMP CISSP CISM CISA CRISC Personal Attributes Strong leadership and organisational skills. Excellent communication and presentation abilities. Ability to influence stakeholders at all levels. Strong analytical and problem solving mindset. Ability to operate effectively in fast paced, complex environments. Self motivated with a strong focus on delivery and outcomes. Successful delivery of cyber security projects and workstreams. Effective management of risks, issues, and dependencies. Timely implementation of security controls and technologies. Improved cyber security posture and compliance alignment. High quality governance reporting and stakeholder engagement.
23/07/2026
Full time
London, United Kingdom Posted on 20/07/2026 Engagement: Inside IR35 Start Date: ASAP Overview We are supporting a leading investment banking client in London who is seeking an experienced Cyber Technical Delivery Manager to join a large-scale Cyber Security Transformation Programme. This role will be responsible for the successful delivery of complex cyber security initiatives across multiple technology domains, including Identity & Access Management (IAM), Security Operations, Cloud Security, Vulnerability Management, Data Protection, and Regulatory Compliance. The successful candidate will act as the bridge between technical engineering teams, cyber security stakeholders, business leaders, and third party vendors, ensuring projects are delivered on time, within budget, and in line with regulatory and security requirements. Key Responsibilities Lead the end to end delivery of cyber security projects and workstreams. Develop and maintain project plans, milestones, RAID logs, budgets, and resource plans. Ensure delivery aligns with business objectives, security standards, and regulatory requirements. Manage dependencies across multiple technology and business teams. Drive project governance and reporting activities. Cyber Security Delivery Deliver initiatives across: Identity & Access Management (IAM) Privileged Access Management (PAM) Security Operations (SOC) SIEM Platforms Cloud Security Vulnerability Management Data Protection and DLP Security Monitoring and Threat Detection Secure File Transfer and Encryption Programmes Coordinate technical teams to ensure successful implementation of security controls and technologies. Stakeholder Management Engage with senior stakeholders across Cyber Security, Infrastructure, Cloud, Risk, Compliance, and Business Functions. Provide regular programme updates to senior management and governance forums. Manage relationships with third party suppliers and technology vendors. Facilitate workshops, steering committees, and technical review sessions. Identify, manage, and mitigate project risks and issues. Ensure compliance with internal security policies and regulatory frameworks. Support audit, risk, and compliance activities. Track and report programme KPIs and delivery metrics. Requirements Required Skills & Experience Cyber Security Experience Strong understanding of enterprise cyber security principles and controls. IAM and Access Governance PAM Solutions SIEM and Security Monitoring Vulnerability Management Data Protection Security Compliance Programmes Familiarity with security frameworks and standards such as: NIST ISO 27001 CIS Controls Cyber Essentials Regulatory requirements within Financial Services Technical Knowledge Good understanding of: Microsoft Azure AWS Active Directory / Entra ID Security Monitoring Platforms Identity Management Solutions Network and Infrastructure Security Ability to engage effectively with technical architects, engineers, and security specialists. Delivery Management Proven experience delivering complex technology or cyber programmes within large enterprise environments. Strong project and programme management experience. Experience managing multiple workstreams simultaneously. Excellent RAID management and governance skills. Strong budget and financial management experience. Previous experience working within Investment Banking, Banking, or Financial Services. Experience delivering cyber security transformation programmes. Experience operating within regulated environments. Strong stakeholder management skills with the ability to engage at Executive and C Level. Experience managing third party suppliers and system integrators. Experience with: Microsoft Sentinel Splunk SailPoint CyberArk Okta CrowdStrike Microsoft Defender Suite Knowledge of DevSecOps practices. Exposure to cloud migration and security transformation programmes. Experience supporting regulatory remediation initiatives. Qualifications & Certifications One or more of the following would be advantageous: PMP CISSP CISM CISA CRISC Personal Attributes Strong leadership and organisational skills. Excellent communication and presentation abilities. Ability to influence stakeholders at all levels. Strong analytical and problem solving mindset. Ability to operate effectively in fast paced, complex environments. Self motivated with a strong focus on delivery and outcomes. Successful delivery of cyber security projects and workstreams. Effective management of risks, issues, and dependencies. Timely implementation of security controls and technologies. Improved cyber security posture and compliance alignment. High quality governance reporting and stakeholder engagement.
Senior Cloud Security Engineer (London, Bracknell or Bristol) We are HealthHero, Europe's largest digital clinic. Join us at a pivotal moment as we scale our digital healthcare platform across Europe - giving you the chance to shape security at the heart of a fast-growing, AI-driven business. We are recruiting an exciting Senior Cloud Security Engineer on an initial 12 month fixed term contract, with a view to becoming permanent - based in either our London or Bristol office two days per week. About the role This role will form a fundamental part of a growing Platform Security function, where the team covers application security, cloud security, security operations, culture and risk management. As a tech-centric organisation the Information Security team will play a critical part in embedding a security-first mindset into application development and continuous application monitoring. This role will co-own the cloud security posture and tooling across HealthHero's AWS and Azure estates and have the opportunity to tackle cloud security with an international scope. The role will be supported by a multidisciplinary force of Infrastructure, Data Governance and Engineering team leads with a security focus as part of their remit. The role has a focus on infrastructure and cloud networking when it comes to security posture. As an experienced Cloud Security Engineer, your working day will include but not be limited to: DevSecOps & SDLC Champion integration of security testing into CI/CD pipelines across all development teams and usage of automated security gates: SAST, DAST, dependency scanning, secrets detection Enable self-serve security tooling for development teams Ability to set up development environment Cloud Security Own cloud security posture management using Wiz (or similar CSPM) Define and enforce cloud security baselines, guardrails, and policies in AWS Implement and maintain IaC security scanning for Terraform Manage IAM policies, network segmentation, and secrets management Configure and tune SIEM (or similar) for cloud-focused detection Establish logging, monitoring, and alerting requirements based on threat modelling Investigate and respond to cloud security events Risk & Compliance Identify, articulate, and escalate security risks to senior leadership with mitigation plans Track and remediate vulnerabilities across infrastructure Manage customer initiatives related to due diligence when required to Support and develop annual programme of Penetration Testing and associated remediations Stakeholder Engagement Partner with internal and stakeholder management to support any requirements from the security function - particularly governance and accreditation requirements across different countries Provide expertise on emerging threats and vulnerabilities Support response to customer/client due diligence requests with timely and accurate information regarding vulnerability exposure Key Skills and Experience Essential Proven experience in application security, DevSecOps, or cloud security Strong understanding of cloud networking Experience securing cloud environments (AWS, Azure) Ability to read and write IAC (Terraform) code, comfortable with IAC lifecycles Familiarity with container security and Kubernetes Understanding of secure coding, penetration testing techniques, SIEM, and vulnerability management Strong technical skills relevant to Information Security such as secure coding standards, ethical hacking techniques, network security and risk analysis Understanding of managing Secure Development Lifecycle and Vulnerability Management. Understanding and practical experience of ISO27001:2022 controls and audit processes Desirable AWS Security Specialty or similar certification Experience in regulated environments (healthcare, financial services) Familiarity with NHS DSPT Technical knowledge of GDPR and data protection requirements Hands-on with CI/CD security tooling and pipeline integration Interest in learning other countries health and security regulations (France / UK / IR / DE) About us We exist to simplify healthcare and improve lives by making care feel instant, intelligent and human. HealthHero is Europe's largest digital health provider , delivering 4 million consultations per year. But we're just getting started. We've built a seamless digital clinic that brings body and mind together - from GP appointments and mental health support to long-term condition management. By sitting behind the world's leading insurers and employers and supporting public health systems, we make it easier for millions of people to get the care they need, exactly when they need it. We are a high-growth, capital-backed business with a sophisticated scale strategy. Our team is a unique blend of those with strong digital experience, management consultants, creatives and industry-leading clinical experts. We aren't just digitising appointments; we're building the next generation of healthcare. We're creating an AI-powered, always-on ecosystem that learns from every interaction to shift the needle from reactive treatment to proactive, sustainable health. At HealthHero, we are digital when it should be and human where it counts. Join us, and help build a next generation health system the world is waiting for. What we offer A full induction training programme, which will be undertaken via Microsoft Teams. An opportunity to work as part of an experienced team who are passionate in their field, supportive, diverse and dynamic. 25 days leave. Bank Holidays and your birthday off as leave. Regular 1-2-1s with your line Manager. 24/7 on-call staff support. Auto-enrolment pension scheme. Health Scheme and access to our Employee Assistance Programme. Life Insurance Scheme. Hybrid: London, Bracknell or Bristol (There is a requirement to work in the office for a minimum of two days per week) Additional information Please note that we are unfortunately unable to offer a sponsor licence to candidates who require sponsorship from their employer.
20/07/2026
Contractor
Senior Cloud Security Engineer (London, Bracknell or Bristol) We are HealthHero, Europe's largest digital clinic. Join us at a pivotal moment as we scale our digital healthcare platform across Europe - giving you the chance to shape security at the heart of a fast-growing, AI-driven business. We are recruiting an exciting Senior Cloud Security Engineer on an initial 12 month fixed term contract, with a view to becoming permanent - based in either our London or Bristol office two days per week. About the role This role will form a fundamental part of a growing Platform Security function, where the team covers application security, cloud security, security operations, culture and risk management. As a tech-centric organisation the Information Security team will play a critical part in embedding a security-first mindset into application development and continuous application monitoring. This role will co-own the cloud security posture and tooling across HealthHero's AWS and Azure estates and have the opportunity to tackle cloud security with an international scope. The role will be supported by a multidisciplinary force of Infrastructure, Data Governance and Engineering team leads with a security focus as part of their remit. The role has a focus on infrastructure and cloud networking when it comes to security posture. As an experienced Cloud Security Engineer, your working day will include but not be limited to: DevSecOps & SDLC Champion integration of security testing into CI/CD pipelines across all development teams and usage of automated security gates: SAST, DAST, dependency scanning, secrets detection Enable self-serve security tooling for development teams Ability to set up development environment Cloud Security Own cloud security posture management using Wiz (or similar CSPM) Define and enforce cloud security baselines, guardrails, and policies in AWS Implement and maintain IaC security scanning for Terraform Manage IAM policies, network segmentation, and secrets management Configure and tune SIEM (or similar) for cloud-focused detection Establish logging, monitoring, and alerting requirements based on threat modelling Investigate and respond to cloud security events Risk & Compliance Identify, articulate, and escalate security risks to senior leadership with mitigation plans Track and remediate vulnerabilities across infrastructure Manage customer initiatives related to due diligence when required to Support and develop annual programme of Penetration Testing and associated remediations Stakeholder Engagement Partner with internal and stakeholder management to support any requirements from the security function - particularly governance and accreditation requirements across different countries Provide expertise on emerging threats and vulnerabilities Support response to customer/client due diligence requests with timely and accurate information regarding vulnerability exposure Key Skills and Experience Essential Proven experience in application security, DevSecOps, or cloud security Strong understanding of cloud networking Experience securing cloud environments (AWS, Azure) Ability to read and write IAC (Terraform) code, comfortable with IAC lifecycles Familiarity with container security and Kubernetes Understanding of secure coding, penetration testing techniques, SIEM, and vulnerability management Strong technical skills relevant to Information Security such as secure coding standards, ethical hacking techniques, network security and risk analysis Understanding of managing Secure Development Lifecycle and Vulnerability Management. Understanding and practical experience of ISO27001:2022 controls and audit processes Desirable AWS Security Specialty or similar certification Experience in regulated environments (healthcare, financial services) Familiarity with NHS DSPT Technical knowledge of GDPR and data protection requirements Hands-on with CI/CD security tooling and pipeline integration Interest in learning other countries health and security regulations (France / UK / IR / DE) About us We exist to simplify healthcare and improve lives by making care feel instant, intelligent and human. HealthHero is Europe's largest digital health provider , delivering 4 million consultations per year. But we're just getting started. We've built a seamless digital clinic that brings body and mind together - from GP appointments and mental health support to long-term condition management. By sitting behind the world's leading insurers and employers and supporting public health systems, we make it easier for millions of people to get the care they need, exactly when they need it. We are a high-growth, capital-backed business with a sophisticated scale strategy. Our team is a unique blend of those with strong digital experience, management consultants, creatives and industry-leading clinical experts. We aren't just digitising appointments; we're building the next generation of healthcare. We're creating an AI-powered, always-on ecosystem that learns from every interaction to shift the needle from reactive treatment to proactive, sustainable health. At HealthHero, we are digital when it should be and human where it counts. Join us, and help build a next generation health system the world is waiting for. What we offer A full induction training programme, which will be undertaken via Microsoft Teams. An opportunity to work as part of an experienced team who are passionate in their field, supportive, diverse and dynamic. 25 days leave. Bank Holidays and your birthday off as leave. Regular 1-2-1s with your line Manager. 24/7 on-call staff support. Auto-enrolment pension scheme. Health Scheme and access to our Employee Assistance Programme. Life Insurance Scheme. Hybrid: London, Bracknell or Bristol (There is a requirement to work in the office for a minimum of two days per week) Additional information Please note that we are unfortunately unable to offer a sponsor licence to candidates who require sponsorship from their employer.
Manchester, Glasgow, London or Newbury/Hybrid A bit about us At Gamma, we're a dynamic, forward-thinking team revolutionizing the way businesses connect and communicate. We provide voice, data, and mobile solutions to businesses across the UK, Germany, Spain, and the Benelux region. We're expanding rapidly to bring digital automation and Gamma-powered services to Enterprise, Public Sector and Small to medium businesses, both direct and through a growing network of channel partners. We move fast with a start up mindset, but we have the stability of a leading European business. Our team thrives on collaboration, innovation, and the belief that diverse perspectives make us stronger. Join us, and you'll have the opportunity to make an impact, grow your career, and be part of a company that celebrates inclusivity and fresh ideas. Who are we looking for? We are seeking a skilled and client focused Security Engineer with strong expertise in Vulnerability Management and Network Security engineering. This role operates within a managed service provider environment, delivering security services to enterprise clients, with a primary focus on risk based vulnerability management alongside network security, firewall optimisation and access control. The successful candidate will be responsible for identifying, assessing, prioritising and driving remediation of vulnerabilities across complex enterprise environments. In addition, they will contribute to strengthening overall cyber resilience by aligning vulnerability management with Managed Detection and Response (MDR) operations, supporting Secure Access Service Edge (SASE) frameworks and advancing Zero Trust security models across network, identity and access control layers. This is a hands on engineering role requiring deep technical expertise across vulnerability management and network security, combined with strong stakeholder engagement. The role ensures security risks are proactively reduced, controls are optimised and remediation is delivered in line with contractual SLAs and cyber security best practices. What will you be doing day to day? Key Responsibilities Vulnerability Management Services Deliver end to end vulnerability management services to clients, including discovery, assessment, prioritisation, reporting and remediation tracking Operate and maintain vulnerability scanning tools (e.g. Qualys, Nessus, Rapid7) across multiple client environments Perform regular vulnerability scans, validation and re testing to ensure remediation effectiveness Analyse vulnerability data, eliminate false positives and provide actionable remediation guidance tailored to client environments Prioritise vulnerabilities using risk based methodologies (CVSS, exploitability, business impact, threat intelligence) Track remediation activities and ensure closure within agreed SLAs and service metrics Produce client facing reports, dashboards and service reviews, highlighting risk posture, trends and key improvement areas Act as a trusted advisor to clients, providing best practice recommendations on vulnerability and risk reduction strategies Security Engineering & Detection Support deployment and optimisation of Microsoft Sentinel and SIEM/XDR platforms Contribute to detection engineering (use case development, rule tuning, alert optimisation) Onboard and integrate telemetry across network, endpoint, cloud and identity sources Support threat detection across SIEM, NDR and identity platforms Collaborate with SOC teams to improve detection coverage and reduce false positives Align vulnerability insights with MDR workflows and threat detection use cases Network Security & Remediation Identify, analyse and manage network and system vulnerabilities across enterprise environments Collaborate with infrastructure, cloud and application teams to drive remediation activities to completion Troubleshoot and resolve network/security issues linked to vulnerabilities and access controls Support secure network architecture and ensure adherence to security and compliance standards Support SASE architectures (e.g. Prisma, Cisco Secure) and secure connectivity models Contribute to Zero Trust implementation, including least privilege and identity controls Strengthen security posture across hybrid environments (network, cloud, SaaS, identity) Support pre sales activities, including solution design and vulnerability management offerings Provide SME input into RFPs, bids and technical workshops Assist with onboarding clients and transitioning services into BAU Build strong client relationships and act as a trusted technical advisor Support service adoption and continuous improvement initiatives Governance, Reporting & Documentation Maintain accurate records of vulnerabilities, remediation plans and audit evidence Support client audits, compliance requirements and security assessments Contribute to service improvement initiatives, automation and process optimisation Ensure adherence to ITIL based service management practices where applicable Breach Attack Simulation (BAS) Design, implement and maintain BAS scenarios to continuously validate the effectiveness of security controls across the enterprise Configure and operate BAS platforms to simulate real world threat actor techniques (MITRE ATT&CK aligned) and identify control gaps Analyse BAS results to prioritise vulnerabilities, misconfigurations and detection gaps, feeding findings into the vulnerability management lifecycle What you'll need: Strong experience in delivering vulnerability management services, ideally within a managed service or consultancy environment Deep understanding of vulnerability lifecycle management (discovery / assessment / remediation / validation / reporting) Hands on experience with Tufin (SecureTrack / SecureChange) or similar tools such as Palo Alto Panorama or Cisco Defense Orchestrator Proficiency with vulnerability scanning tools (Qualys, Nessus, Rapid7) Solid knowledge of network security principles (firewalls, VPNs, segmentation, protocols) Experience working with client stakeholders and managing competing priorities Ability to translate technical vulnerabilities into business risk and remediation actions Strong analytical, troubleshooting and communication skills Nice to haves Certifications such as CCNA / Security+ / CEH / CISSP (or working towards) Experience in multi client or managed security service provider (MSSP) environments Familiarity with multi vendor firewalls (Cisco, Palo Alto, Check Point) Knowledge of compliance frameworks (ISO 27001, NIST, CIS, PCI DSS) Exposure to risk based vulnerability management and threat intelligence integration Understanding of ITIL service delivery and SLA driven environments Experience with SASE, Zero Trust, MDR/XDR platforms Experience with RSA Authentication Manager or similar IAM solutions What do we offer you? At Gamma, we believe in work life balance, which is why we offer 25 days of annual leave, plus an extra day off for your birthday. Giving back is important to us, so we also provide a volunteer day to support a charity that matters to you. Family matters, too. With enhanced maternity and paternity pay and childcare vouchers, we're here to support you as a parent and help you thrive in your career. We care about your future, so our pension plan helps you save for the years ahead with contributions of 4.59% from Gamma, alongside your own contributions. Your well being is our priority. We offer group income protection and life assurance (four times your salary) to ensure peace of mind for you and your loved ones. We want you to share in our success. That's why we offer tax efficient share save and share incentive plans, giving you the opportunity to benefit from Gamma's growth. We're committed to health, both physical and mental, and provide private medical insurance through Vitality, which extends to your immediate family. And, because we care about the environment, we offer an Electric Vehicle scheme through Octopus and a Cycle to Work scheme, making it easier to get around sustainably. A few things to note Unfortunately, we can't offer visa sponsorship or relocation support for this role. This role is hybrid but with 3 days a week onsite at either our Manchester, Glasgow, London or Newbury sites. If you feel you could be a good fit for Gamma but do not think that you meet all the requirements, we still encourage you to apply as you could be the person that we are looking for! Gamma is an equal opportunity employer. We care about inclusion and believe in having diverse teams where everyone can be their true authentic selves. We value each person and their range of backgrounds and actively encourage people from underrepresented backgrounds to apply. We don't discriminate based on any protected characteristics e.g., race, colour, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, marital status, disability or age. We are a family friendly employer with a culture based on trust, autonomy and flexibility to help you create a work life balance and enjoy working here at Gamma. . click apply for full job details
20/07/2026
Full time
Manchester, Glasgow, London or Newbury/Hybrid A bit about us At Gamma, we're a dynamic, forward-thinking team revolutionizing the way businesses connect and communicate. We provide voice, data, and mobile solutions to businesses across the UK, Germany, Spain, and the Benelux region. We're expanding rapidly to bring digital automation and Gamma-powered services to Enterprise, Public Sector and Small to medium businesses, both direct and through a growing network of channel partners. We move fast with a start up mindset, but we have the stability of a leading European business. Our team thrives on collaboration, innovation, and the belief that diverse perspectives make us stronger. Join us, and you'll have the opportunity to make an impact, grow your career, and be part of a company that celebrates inclusivity and fresh ideas. Who are we looking for? We are seeking a skilled and client focused Security Engineer with strong expertise in Vulnerability Management and Network Security engineering. This role operates within a managed service provider environment, delivering security services to enterprise clients, with a primary focus on risk based vulnerability management alongside network security, firewall optimisation and access control. The successful candidate will be responsible for identifying, assessing, prioritising and driving remediation of vulnerabilities across complex enterprise environments. In addition, they will contribute to strengthening overall cyber resilience by aligning vulnerability management with Managed Detection and Response (MDR) operations, supporting Secure Access Service Edge (SASE) frameworks and advancing Zero Trust security models across network, identity and access control layers. This is a hands on engineering role requiring deep technical expertise across vulnerability management and network security, combined with strong stakeholder engagement. The role ensures security risks are proactively reduced, controls are optimised and remediation is delivered in line with contractual SLAs and cyber security best practices. What will you be doing day to day? Key Responsibilities Vulnerability Management Services Deliver end to end vulnerability management services to clients, including discovery, assessment, prioritisation, reporting and remediation tracking Operate and maintain vulnerability scanning tools (e.g. Qualys, Nessus, Rapid7) across multiple client environments Perform regular vulnerability scans, validation and re testing to ensure remediation effectiveness Analyse vulnerability data, eliminate false positives and provide actionable remediation guidance tailored to client environments Prioritise vulnerabilities using risk based methodologies (CVSS, exploitability, business impact, threat intelligence) Track remediation activities and ensure closure within agreed SLAs and service metrics Produce client facing reports, dashboards and service reviews, highlighting risk posture, trends and key improvement areas Act as a trusted advisor to clients, providing best practice recommendations on vulnerability and risk reduction strategies Security Engineering & Detection Support deployment and optimisation of Microsoft Sentinel and SIEM/XDR platforms Contribute to detection engineering (use case development, rule tuning, alert optimisation) Onboard and integrate telemetry across network, endpoint, cloud and identity sources Support threat detection across SIEM, NDR and identity platforms Collaborate with SOC teams to improve detection coverage and reduce false positives Align vulnerability insights with MDR workflows and threat detection use cases Network Security & Remediation Identify, analyse and manage network and system vulnerabilities across enterprise environments Collaborate with infrastructure, cloud and application teams to drive remediation activities to completion Troubleshoot and resolve network/security issues linked to vulnerabilities and access controls Support secure network architecture and ensure adherence to security and compliance standards Support SASE architectures (e.g. Prisma, Cisco Secure) and secure connectivity models Contribute to Zero Trust implementation, including least privilege and identity controls Strengthen security posture across hybrid environments (network, cloud, SaaS, identity) Support pre sales activities, including solution design and vulnerability management offerings Provide SME input into RFPs, bids and technical workshops Assist with onboarding clients and transitioning services into BAU Build strong client relationships and act as a trusted technical advisor Support service adoption and continuous improvement initiatives Governance, Reporting & Documentation Maintain accurate records of vulnerabilities, remediation plans and audit evidence Support client audits, compliance requirements and security assessments Contribute to service improvement initiatives, automation and process optimisation Ensure adherence to ITIL based service management practices where applicable Breach Attack Simulation (BAS) Design, implement and maintain BAS scenarios to continuously validate the effectiveness of security controls across the enterprise Configure and operate BAS platforms to simulate real world threat actor techniques (MITRE ATT&CK aligned) and identify control gaps Analyse BAS results to prioritise vulnerabilities, misconfigurations and detection gaps, feeding findings into the vulnerability management lifecycle What you'll need: Strong experience in delivering vulnerability management services, ideally within a managed service or consultancy environment Deep understanding of vulnerability lifecycle management (discovery / assessment / remediation / validation / reporting) Hands on experience with Tufin (SecureTrack / SecureChange) or similar tools such as Palo Alto Panorama or Cisco Defense Orchestrator Proficiency with vulnerability scanning tools (Qualys, Nessus, Rapid7) Solid knowledge of network security principles (firewalls, VPNs, segmentation, protocols) Experience working with client stakeholders and managing competing priorities Ability to translate technical vulnerabilities into business risk and remediation actions Strong analytical, troubleshooting and communication skills Nice to haves Certifications such as CCNA / Security+ / CEH / CISSP (or working towards) Experience in multi client or managed security service provider (MSSP) environments Familiarity with multi vendor firewalls (Cisco, Palo Alto, Check Point) Knowledge of compliance frameworks (ISO 27001, NIST, CIS, PCI DSS) Exposure to risk based vulnerability management and threat intelligence integration Understanding of ITIL service delivery and SLA driven environments Experience with SASE, Zero Trust, MDR/XDR platforms Experience with RSA Authentication Manager or similar IAM solutions What do we offer you? At Gamma, we believe in work life balance, which is why we offer 25 days of annual leave, plus an extra day off for your birthday. Giving back is important to us, so we also provide a volunteer day to support a charity that matters to you. Family matters, too. With enhanced maternity and paternity pay and childcare vouchers, we're here to support you as a parent and help you thrive in your career. We care about your future, so our pension plan helps you save for the years ahead with contributions of 4.59% from Gamma, alongside your own contributions. Your well being is our priority. We offer group income protection and life assurance (four times your salary) to ensure peace of mind for you and your loved ones. We want you to share in our success. That's why we offer tax efficient share save and share incentive plans, giving you the opportunity to benefit from Gamma's growth. We're committed to health, both physical and mental, and provide private medical insurance through Vitality, which extends to your immediate family. And, because we care about the environment, we offer an Electric Vehicle scheme through Octopus and a Cycle to Work scheme, making it easier to get around sustainably. A few things to note Unfortunately, we can't offer visa sponsorship or relocation support for this role. This role is hybrid but with 3 days a week onsite at either our Manchester, Glasgow, London or Newbury sites. If you feel you could be a good fit for Gamma but do not think that you meet all the requirements, we still encourage you to apply as you could be the person that we are looking for! Gamma is an equal opportunity employer. We care about inclusion and believe in having diverse teams where everyone can be their true authentic selves. We value each person and their range of backgrounds and actively encourage people from underrepresented backgrounds to apply. We don't discriminate based on any protected characteristics e.g., race, colour, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, marital status, disability or age. We are a family friendly employer with a culture based on trust, autonomy and flexibility to help you create a work life balance and enjoy working here at Gamma. . click apply for full job details
Protect identities at global scale. We're hiring a hands-on Senior Identity Protection Engineer/Specialist to lead detection, investigation, and response for identity-based threats across Microsoft Entra ID/Azure AD, on prem Active Directory, and connected SaaS/IaaS. You'll serve as the enterprise SME/administrator for CrowdStrike Identity Protection, tune high-fidelity detections, integrate dark web intelligence, and orchestrate automation that measurably reduces MTTD/MTTR and risk.What you'll doLead identity threat monitoring and triageOperate and tune CrowdStrike Identity Protection; monitor SIEM/UEBA and identity telemetry for risks like impossible travel, atypical sign ins, MFA fatigue, and session hijackingValidate true/false positives, prioritize by business impact, and escalate per playbooks/SLAsDrive rapid containment and remediationExecute containment actions (disable accounts, revoke sessions/tokens, isolate hosts)Coordinate remediation with IAM/Endpoint/Infrastructure; verify risk reduction to closureOwn identity-focused incident responseLead IR for credential compromise, privilege escalation, directory persistence, and lateral movementEnsure evidence handling, root cause analysis, post incident reviews, and lessons learnedEngineer detections and hunt for threatsBuild and refine detections and hunts across SIEM/EDR/identity platforms using KQL/SQL/regex/Sigma aligned to MITRE ATT&CKClose visibility gaps, reduce false positives, and expand privileged activity monitoringStrengthen privileged access controlsDetect anomalous privileged behavior via SIEM/UEBA and Netskope telemetryRecommend/enforce JIT, break glass patterns, and mover/leaver privilege hygiene with IAMRespond to dark web/credential exposureIntegrate sources like CyberInt; assess exposure and targeted campaignsOrchestrate takedowns, forced resets, token revocation, and Conditional Access updatesAdminister platforms and sustain hygieneMaintain coverage/health for identity monitoring; manage upgrades and changes via CABKeep operational runbooks, SOPs, and playbooks currentAutomate and orchestrate at scaleUse PowerShell/Python and REST/Graph/CrowdStrike APIs (and SOAR where applicable) to automate enrichment and response, standardize workflows, and improve signal fidelityShape identity policy and controlsAdvise on Conditional Access, MFA exceptions, SSO/SCIM patterns, and session controls under the shared responsibility model with IAMReport outcomes and support auditsProduce executive-ready dashboards and KPIs (identity incident volume, MTTD/MTTR, CA/MFA efficacy, exposure/takedown cycle time)Maintain audit-ready evidence and support internal/external auditsWhat you'll bringBachelor's degree in Cybersecurity, Computer Science, IT, or related field; or equivalent practical experience8+ years in IT/cybersecurity, including 3+ years focused on identity security/operations (Entra ID/Azure AD, on prem AD, MFA, Conditional Access, SSO/SCIM)Hands-on enterprise experience administering/operating CrowdStrike Identity ProtectionProficiency with SIEM/UEBA (Splunk preferred) and cloud security platforms (e.g., Netskope) for identity telemetry, detection, and investigationsDemonstrated experience in identity centric IR, threat hunting, and detection engineering (KQL/SQL/regex/Sigma)Scripting/automation with PowerShell and Python; experience with REST/Graph/CrowdStrike APIs and SOARClear communication and documentation skills; comfortable producing executive ready reports and audit evidenceOperates effectively within change control/CAB and under pressure during high severity incidentsBonus pointsCertifications: Microsoft SC 200/SC 300; Okta Certified Administrator/Professional; CISSP, SSCP, Security+; GIAC (GMON, GCIH, GCDA) or equivalentDeep knowledge of identity attack paths and protocols (Kerberos/NTLM), token/session abuse, and persistence techniques (e.g., Golden/Silver Ticket, DCShadow)Experience with JIT/JEA, PAM concepts, and global on call rotationsLocation, work style, and travelOpportunities in the United States, United Kingdom, and DenmarkOnsite or hybrid depending on location and business needsOccasional on call coverage may be requiredWhy you'll love it hereOwn a mission critical identity defense stack and make measurable impact on MTTD/MTTR and privilege hygieneSolve complex problems from dark web exposure to directory persistence and lateral movementCollaborate with experienced global teams and leading vendors to continuously raise the barGrow your career in a modern, data driven security operations environmentThis is a global position that will support all our FUJIFILM Biotechnologies sites. This position can be based at any of our locations around the globe. Benefits and compensation will be governed by the location that you are based from and considered your home site.As part of any recruitment process, FUJIFILM Diosynth Biotechnologies collects and processes personal data relating to job applicants. The organization is committed to being transparent about how it collects and uses that data and to meeting its data protection obligations and may share this as part of the global recruitment process with hiring managers in Europe and the United States.Please, no phone calls or emails to any employee of FUJIFILM about this requisition. All resumes submitted by search firms/employment agencies to any employee at FUJIFILM via-email, the internet or in any form and/or method will be deemed the sole property of FUJIFILM, unless such search firms/employment agencies were engaged by FUJIFILM for this requisition and a valid agreement with FUJIFILM is in place. In the event a candidate who was submitted outside of the FUJIFILM agency engagement process is hired, no fee or payment of any kind will be paid.
19/07/2026
Full time
Protect identities at global scale. We're hiring a hands-on Senior Identity Protection Engineer/Specialist to lead detection, investigation, and response for identity-based threats across Microsoft Entra ID/Azure AD, on prem Active Directory, and connected SaaS/IaaS. You'll serve as the enterprise SME/administrator for CrowdStrike Identity Protection, tune high-fidelity detections, integrate dark web intelligence, and orchestrate automation that measurably reduces MTTD/MTTR and risk.What you'll doLead identity threat monitoring and triageOperate and tune CrowdStrike Identity Protection; monitor SIEM/UEBA and identity telemetry for risks like impossible travel, atypical sign ins, MFA fatigue, and session hijackingValidate true/false positives, prioritize by business impact, and escalate per playbooks/SLAsDrive rapid containment and remediationExecute containment actions (disable accounts, revoke sessions/tokens, isolate hosts)Coordinate remediation with IAM/Endpoint/Infrastructure; verify risk reduction to closureOwn identity-focused incident responseLead IR for credential compromise, privilege escalation, directory persistence, and lateral movementEnsure evidence handling, root cause analysis, post incident reviews, and lessons learnedEngineer detections and hunt for threatsBuild and refine detections and hunts across SIEM/EDR/identity platforms using KQL/SQL/regex/Sigma aligned to MITRE ATT&CKClose visibility gaps, reduce false positives, and expand privileged activity monitoringStrengthen privileged access controlsDetect anomalous privileged behavior via SIEM/UEBA and Netskope telemetryRecommend/enforce JIT, break glass patterns, and mover/leaver privilege hygiene with IAMRespond to dark web/credential exposureIntegrate sources like CyberInt; assess exposure and targeted campaignsOrchestrate takedowns, forced resets, token revocation, and Conditional Access updatesAdminister platforms and sustain hygieneMaintain coverage/health for identity monitoring; manage upgrades and changes via CABKeep operational runbooks, SOPs, and playbooks currentAutomate and orchestrate at scaleUse PowerShell/Python and REST/Graph/CrowdStrike APIs (and SOAR where applicable) to automate enrichment and response, standardize workflows, and improve signal fidelityShape identity policy and controlsAdvise on Conditional Access, MFA exceptions, SSO/SCIM patterns, and session controls under the shared responsibility model with IAMReport outcomes and support auditsProduce executive-ready dashboards and KPIs (identity incident volume, MTTD/MTTR, CA/MFA efficacy, exposure/takedown cycle time)Maintain audit-ready evidence and support internal/external auditsWhat you'll bringBachelor's degree in Cybersecurity, Computer Science, IT, or related field; or equivalent practical experience8+ years in IT/cybersecurity, including 3+ years focused on identity security/operations (Entra ID/Azure AD, on prem AD, MFA, Conditional Access, SSO/SCIM)Hands-on enterprise experience administering/operating CrowdStrike Identity ProtectionProficiency with SIEM/UEBA (Splunk preferred) and cloud security platforms (e.g., Netskope) for identity telemetry, detection, and investigationsDemonstrated experience in identity centric IR, threat hunting, and detection engineering (KQL/SQL/regex/Sigma)Scripting/automation with PowerShell and Python; experience with REST/Graph/CrowdStrike APIs and SOARClear communication and documentation skills; comfortable producing executive ready reports and audit evidenceOperates effectively within change control/CAB and under pressure during high severity incidentsBonus pointsCertifications: Microsoft SC 200/SC 300; Okta Certified Administrator/Professional; CISSP, SSCP, Security+; GIAC (GMON, GCIH, GCDA) or equivalentDeep knowledge of identity attack paths and protocols (Kerberos/NTLM), token/session abuse, and persistence techniques (e.g., Golden/Silver Ticket, DCShadow)Experience with JIT/JEA, PAM concepts, and global on call rotationsLocation, work style, and travelOpportunities in the United States, United Kingdom, and DenmarkOnsite or hybrid depending on location and business needsOccasional on call coverage may be requiredWhy you'll love it hereOwn a mission critical identity defense stack and make measurable impact on MTTD/MTTR and privilege hygieneSolve complex problems from dark web exposure to directory persistence and lateral movementCollaborate with experienced global teams and leading vendors to continuously raise the barGrow your career in a modern, data driven security operations environmentThis is a global position that will support all our FUJIFILM Biotechnologies sites. This position can be based at any of our locations around the globe. Benefits and compensation will be governed by the location that you are based from and considered your home site.As part of any recruitment process, FUJIFILM Diosynth Biotechnologies collects and processes personal data relating to job applicants. The organization is committed to being transparent about how it collects and uses that data and to meeting its data protection obligations and may share this as part of the global recruitment process with hiring managers in Europe and the United States.Please, no phone calls or emails to any employee of FUJIFILM about this requisition. All resumes submitted by search firms/employment agencies to any employee at FUJIFILM via-email, the internet or in any form and/or method will be deemed the sole property of FUJIFILM, unless such search firms/employment agencies were engaged by FUJIFILM for this requisition and a valid agreement with FUJIFILM is in place. In the event a candidate who was submitted outside of the FUJIFILM agency engagement process is hired, no fee or payment of any kind will be paid.
As a Product Manager in Cybersecurity & Technology Controls, you will lead the end-to-end product lifecycle for a blockchain detection and prevention capability serving our SOC. You will translate SOC needs into a prioritized roadmap and backlog, partner closely with engineering and threat SMEs, and ensure detections are accurate, explainable, and operationally effective. Success means improving time-to-detect and time-to-respond while managing false positives and meeting reliability and resiliency expectations. Job Responsibilities Define product vision, strategy, and roadmap for SOC-focused blockchain detection and prevention Lead discovery with SOC analysts and incident responders: workflows, pain points, alert usability, escalation paths, and runbooks Own and refine the backlog: detection use cases, requirements, acceptance criteria, and prioritization tradeoffs Partner with engineering/threat teams to deliver end-to-end capability: signal ingestion, enrichment, alerting, triage experience, and response automation where appropriate Establish and track success metrics (e.g., precision/false positive rate, coverage, latency, time-to-detect/time-to-respond, alert volume, reliability/SLA) and drive continuous improvement Drive launch readiness: documentation, training, operational handoffs, and feedback loops with the SOC Required Qualifications, Capabilities, and Skills Product management experience delivering security detections, SOC tooling, or data/analytics products Strong understanding of SOC operations (alert lifecycle, triage, escalations, incident response) Background in blockchain fundamentals and common threat patterns/abuse cases Ability to use data to prioritize, measure detection efficacy, and manage false positives Preferred Experience with SIEM/SOAR and detection engineering programs Experience operating in a highly matrixed, complex organization Equal Opportunity Statement We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.
19/07/2026
Full time
As a Product Manager in Cybersecurity & Technology Controls, you will lead the end-to-end product lifecycle for a blockchain detection and prevention capability serving our SOC. You will translate SOC needs into a prioritized roadmap and backlog, partner closely with engineering and threat SMEs, and ensure detections are accurate, explainable, and operationally effective. Success means improving time-to-detect and time-to-respond while managing false positives and meeting reliability and resiliency expectations. Job Responsibilities Define product vision, strategy, and roadmap for SOC-focused blockchain detection and prevention Lead discovery with SOC analysts and incident responders: workflows, pain points, alert usability, escalation paths, and runbooks Own and refine the backlog: detection use cases, requirements, acceptance criteria, and prioritization tradeoffs Partner with engineering/threat teams to deliver end-to-end capability: signal ingestion, enrichment, alerting, triage experience, and response automation where appropriate Establish and track success metrics (e.g., precision/false positive rate, coverage, latency, time-to-detect/time-to-respond, alert volume, reliability/SLA) and drive continuous improvement Drive launch readiness: documentation, training, operational handoffs, and feedback loops with the SOC Required Qualifications, Capabilities, and Skills Product management experience delivering security detections, SOC tooling, or data/analytics products Strong understanding of SOC operations (alert lifecycle, triage, escalations, incident response) Background in blockchain fundamentals and common threat patterns/abuse cases Ability to use data to prioritize, measure detection efficacy, and manage false positives Preferred Experience with SIEM/SOAR and detection engineering programs Experience operating in a highly matrixed, complex organization Equal Opportunity Statement We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.
ENEX.AI is an AI-native, automation-first, built-for-scale Managed Detection and Response (MDR) provider. We are a force multiplier for defenders, helping organizations enhance their cybersecurity posture through advanced threat detection, rapid response, and continuous protection. Our team is composed of industry experts with deep experience in cybersecurity, automation and AI-driven solutions. Backed by leading investors, we are rapidly growing and seeking top talent to join our mission of revolutionizing the AI-Native MDR landscape. We're a fast growing startup backed by industry experts and top tier investors led by Crosspoint Capital Partners and also backed by Shield Capital, DTCP (formerly Deutsche Telekom Capital Partners), Deepwork Capital, and the Florida Opportunity Fund. Seed round led by Andreessen Horowitz (a16z). As an early employee, you'll play a meaningful role in defining and building our culture. Get in on the ground floor. We're a small but well-funded team that just raised a substantial round - joining now comes with limited risk and unlimited upside We are seeking a dynamic Customer Engineer (CE) to join our team, reporting to the VP of Customer Engineering. This hybrid role combines the technical expertise of a Pre-Sales Engineer with hands on contributions to Customer Success and Security Operations. As a CE, you will act as a trusted advisor, showcasing TENEX.AI's AI driven security solutions during the pre sales and evaluation processes, ensuring seamless handover to customer onboarding, and supporting rapid onboarding of operational initiatives to enhance security outcomes. This field based role requires up to 50% travel to client sites, with remote work flexibility. The ideal candidate is passionate about cybersecurity, thrives in a fast paced environment, and excels at translating complex technical concepts into compelling business value. Cultivated culture is one of the most important things at TENEX.AI-explore our culture deck at culture.tenex.ai to witness how we embody it, prioritizing the irreplaceable collaboration and community of in person work. Key Responsibilities Sales Engineering Excellence: Partner with the sales team to deliver technical expertise during pre sales. Conduct product demonstrations, proof of concepts (POCs), and security assessments tailored to client needs. Understand and address security concerns, compliance requirements (e.g., GDPR, HIPAA, SOC 2), and risk mitigation strategies to drive deal closures. Meet and exceed individual and team sales targets, consistently achieving and surpassing assigned quotas. Customer Success & Operational Support: Collaborate with Customer Success managers to streamline onboarding of new clients. Review client security architectures and recommend best practices for AI driven security deployments. Support incident response planning and contribute to developing operational tools, processes, and documentation to scale security operations. Thought Leadership: Represent TENEX at industry events, webinars, and conferences as a cybersecurity expert. Create high impact content (e.g., whitepapers, case studies, blog posts) to educate the market on AI driven security trends. Provide actionable customer feedback to influence product roadmap enhancements. Cross Functional Collaboration: Work with all TENEX teams to align on both customer and internal business needs. Share field insights to refine GTM strategies and operational workflows. Work closely with the marketing and technical teams to ensure cohesive messaging. Cloud Security Expertise: Develop and maintain deep knowledge of Google Cloud & Microsoft Azure solutions, aligning with TENEX's strategic partnerships to deliver integrated MDR offerings. Qualifications Experience: 5+ years in cybersecurity, with 5+ years in a customer facing role (e.g., Sales Engineer, Solutions Architect, Consultant). Technical Skills: Strong understanding of cybersecurity principles Familiarity with security operations platforms (e.g., SIEM, SOAR, Threat Intelligence, UEBA). Knowledge of cloud security (e.g., Google Cloud, AWS, Azure) is a plus. Google SecOps or Microsoft Sentinel a strong plus. Soft Skills: Exceptional communication and presentation skills, with the ability to simplify complex security topics for non technical audiences. Strong problem solving skills, customer empathy, and experience engaging executive stakeholders (e.g., CISOs, CTOs). Other: Willingness to travel (up to 50%); valid driver's license required. Must pass a background check and maintain up to date security clearances if applicable. Why Join Us? Opportunity to work with cutting edge AI driven cybersecurity technologies and Google SecOps solutions. Collaborate with a talented and innovative team focused on continuously improving security operations. Competitive salary and benefits package. A culture of growth and development, with opportunities to expand your knowledge in AI, cybersecurity, and emerging technologies.
17/07/2026
Full time
ENEX.AI is an AI-native, automation-first, built-for-scale Managed Detection and Response (MDR) provider. We are a force multiplier for defenders, helping organizations enhance their cybersecurity posture through advanced threat detection, rapid response, and continuous protection. Our team is composed of industry experts with deep experience in cybersecurity, automation and AI-driven solutions. Backed by leading investors, we are rapidly growing and seeking top talent to join our mission of revolutionizing the AI-Native MDR landscape. We're a fast growing startup backed by industry experts and top tier investors led by Crosspoint Capital Partners and also backed by Shield Capital, DTCP (formerly Deutsche Telekom Capital Partners), Deepwork Capital, and the Florida Opportunity Fund. Seed round led by Andreessen Horowitz (a16z). As an early employee, you'll play a meaningful role in defining and building our culture. Get in on the ground floor. We're a small but well-funded team that just raised a substantial round - joining now comes with limited risk and unlimited upside We are seeking a dynamic Customer Engineer (CE) to join our team, reporting to the VP of Customer Engineering. This hybrid role combines the technical expertise of a Pre-Sales Engineer with hands on contributions to Customer Success and Security Operations. As a CE, you will act as a trusted advisor, showcasing TENEX.AI's AI driven security solutions during the pre sales and evaluation processes, ensuring seamless handover to customer onboarding, and supporting rapid onboarding of operational initiatives to enhance security outcomes. This field based role requires up to 50% travel to client sites, with remote work flexibility. The ideal candidate is passionate about cybersecurity, thrives in a fast paced environment, and excels at translating complex technical concepts into compelling business value. Cultivated culture is one of the most important things at TENEX.AI-explore our culture deck at culture.tenex.ai to witness how we embody it, prioritizing the irreplaceable collaboration and community of in person work. Key Responsibilities Sales Engineering Excellence: Partner with the sales team to deliver technical expertise during pre sales. Conduct product demonstrations, proof of concepts (POCs), and security assessments tailored to client needs. Understand and address security concerns, compliance requirements (e.g., GDPR, HIPAA, SOC 2), and risk mitigation strategies to drive deal closures. Meet and exceed individual and team sales targets, consistently achieving and surpassing assigned quotas. Customer Success & Operational Support: Collaborate with Customer Success managers to streamline onboarding of new clients. Review client security architectures and recommend best practices for AI driven security deployments. Support incident response planning and contribute to developing operational tools, processes, and documentation to scale security operations. Thought Leadership: Represent TENEX at industry events, webinars, and conferences as a cybersecurity expert. Create high impact content (e.g., whitepapers, case studies, blog posts) to educate the market on AI driven security trends. Provide actionable customer feedback to influence product roadmap enhancements. Cross Functional Collaboration: Work with all TENEX teams to align on both customer and internal business needs. Share field insights to refine GTM strategies and operational workflows. Work closely with the marketing and technical teams to ensure cohesive messaging. Cloud Security Expertise: Develop and maintain deep knowledge of Google Cloud & Microsoft Azure solutions, aligning with TENEX's strategic partnerships to deliver integrated MDR offerings. Qualifications Experience: 5+ years in cybersecurity, with 5+ years in a customer facing role (e.g., Sales Engineer, Solutions Architect, Consultant). Technical Skills: Strong understanding of cybersecurity principles Familiarity with security operations platforms (e.g., SIEM, SOAR, Threat Intelligence, UEBA). Knowledge of cloud security (e.g., Google Cloud, AWS, Azure) is a plus. Google SecOps or Microsoft Sentinel a strong plus. Soft Skills: Exceptional communication and presentation skills, with the ability to simplify complex security topics for non technical audiences. Strong problem solving skills, customer empathy, and experience engaging executive stakeholders (e.g., CISOs, CTOs). Other: Willingness to travel (up to 50%); valid driver's license required. Must pass a background check and maintain up to date security clearances if applicable. Why Join Us? Opportunity to work with cutting edge AI driven cybersecurity technologies and Google SecOps solutions. Collaborate with a talented and innovative team focused on continuously improving security operations. Competitive salary and benefits package. A culture of growth and development, with opportunities to expand your knowledge in AI, cybersecurity, and emerging technologies.
InternalLocation: UKGlobal Grade: D1 / C2About the job you're consideringOrganisations are facing a sustained increase in cyber risk, regulatory pressure and operational complexity as they modernise their technology landscapes. Cybersecurity is no longer a standalone technical function; it is central to business resilience, digital transformation and customer trust. Senior leaders need pragmatic, commercially grounded advice to embed security into their transformation agendas and make confident, risk informed decisions. Within Capgemini's Cloud Infrastructure Services (CIS) Projects & Consulting, we work with clients across financial services, public and private sectors to shape cybersecurity strategies, design secure transformation pathways and support the mobilisation of complex cyber enabled change. Our work spans early stage maturity assessments and cyber strategy through to the integration of security into large scale cloud, infrastructure and business transformation programmes.We are seeking Manager and Senior Manager level cybersecurity consultants who combine strong advisory capability with deep cyber domain expertise and a track record across consulting, pre sales and delivery. You will play a key role in leading cyber focused engagements, shaping client propositions, supporting go to market activity and helping clients translate cyber ambition into tangible outcomes. This role suits individuals who are credible with senior stakeholders, commercially aware and comfortable operating across advisory, business development and delivery contexts, with cybersecurity as their core specialism.This role requires someone who can:Lead high impact cybersecurity consulting engagements, including maturity assessments, risk reviews, strategy and roadmapsBe part of the team that advises senior stakeholders (e.g. CISO, CTO) on cyber risk, resilience and secure transformation prioritiesIntegrate cybersecurity into wider cloud, infrastructure and digital transformation programmesTranslate complex cyber and risk concepts into clear, actionable recommendations for business leadersIdentify opportunities to extend advisory work into broader transformation, delivery and managed services engagementsSupport and shape go to market propositions in cybersecurity and adjacent domainsContribute to client proposals, bids and credentials, bringing both domain credibility and commercial awarenessEngage proactively with clients to originate and develop opportunitiesProduce high quality, client ready outputs and thought leadership aligned to market trends and Capgemini prioritiesCollaborate effectively with delivery teams, architects and SMEs across CapgeminiHybrid working: The places that you work from day to day will vary according to your role, your needs, and those of the business; it will be a blend of Company offices, client sites, and your home; noting that you will be unable to work at home 100% of the time.Your roleAs a Manager or Senior Manager in the CIS Projects & Consulting Advisory team, you will:Lead and deliver cybersecurity advisory engagements, from problem definition through to recommendations and mobilisationAct as a trusted advisor to client stakeholders, combining consulting judgement with deep cyber expertiseShape engagement scope, approach and deliverables, ensuring outcomes are practical, commercially sound and aligned to risk prioritiesSupport the integration of cybersecurity into broader technology transformation programmes (e.g. cloud, workplace, infrastructure modernisation)Play an active role in business development, including proposition development, client conversations, bids and pipeline growthContribute to thought leadership, market insights and internal capability development in cybersecurityMentor and support junior consultants, helping build a high performing cyber advisory capabilityThe scope of responsibility will vary by grade, with Senior Managers taking greater accountability for client relationships, engagement leadership and go to market contributionYour skills and experienceYou will bring strong consulting foundations alongside credible cybersecurity expertise and commercial experience.Core experience:Experience in a consulting or advisory role at Manager or Senior Manager level within one of the leading consultancies (e.g. Big 4, boutique cybersecurity consultancies, global SIs)Proven ability to lead front end, ambiguous cybersecurity engagements from discovery through to recommendationsExperience across both advisory and delivery, with exposure to large scale transformation programmesTrack record supporting business development, including proposals, bids and client engagementCybersecurity capability (strong experience across some of these areas):Cybersecurity strategy and operating model designCyber risk management, governance and compliance (e.g. ISO 27001, NIST, NIS2, GDPR)Security architecture and secure by design principles in cloud and hybrid environmentsIdentity and access management, security operations or cyber controls engineeringCyber resilience, incident response and operational securityIntegration of security into DevOps and cloud transformationUnderstanding of emerging risks and controls associated with AI and agentic systems, including secure AI adoption, model risk, data protection, and the application of AI within cybersecurity (e.g. threat detection, automation and response)Consulting and commercial skills:Strong stakeholder engagement skills, with the ability to influence at C suite and senior leadership levelExcellent communication and storytelling capability, translating complex cyber topics into clear, compelling narrativesCommercial awareness and the ability to shape propositions and differentiate Capgemini in competitive situationsAbility to operate across industries and adapt to different client environmentsMindset:Intellectually curious, with a strong interest in evolving cyber threats and technologiesComfortable operating across advisory, pre sales and delivery contextsA collaborative team player, able to work across a global, matrix organisationCommitted to continuous learning and staying current in cybersecurity and technology trendsWe are a disability confident employerCapgemini is proud to be a Disability Confident Employer (Level 2) under the UK Government's Disability Confident scheme. As part of our commitment to inclusive recruitment, we will offer an interview to all candidates who:Declare they have a disability, andMeet the minimum essential criteria for the role.Please opt in during the application process.Your security clearance and pre-employment checksIf you are successfully offered this position, you will go through a series of pre-employment checks, including: identity, nationality (single or dual) or immigration status, employment history going back 3 continuous years, and unspent criminal record check (known as Disclosure and Barring Service). To be successfully appointed to this role, it is a requirement to obtain Security Check (SC) clearance. To obtain SC clearance, the successful applicant must have resided continuously within the United Kingdom for the last 5 years, along with other criteria and requirements. Throughout the recruitment process, you will be asked questions about your security clearance eligibility such as, but not limited to, country of residence and nationality. Some posts are restricted to sole UK Nationals for security reasons; therefore, you may be asked about your citizenship in the application process.Make it real - what does that mean for you?We realise a Total Reward package should be more than just compensation. At Capgemini we offer range of core and flexible benefits and have a Peer Recognition Portal called Applaud.You will be encouraged to have a positive work-life balance. Our hybrid-first way of working means we embed hybrid working in all that we do and make flexible working arrangements the day-to-day reality for our people. All UK employees are eligible to request flexible working arrangements.You will be empowered to explore, innovate, and progress. You will benefit from Capgemini's 'learning for life' mindset, meaning you will have countless training and development opportunities from thinktanks to hackathons, and access to 250,000 courses with numerous external certifications from AWS, Microsoft, Harvard ManageMentor, Cybersecurity qualifications and much more.You'll be bringing your unique skills and perspectives to the team, inspiring and taking inspiration from your teammates as you unlock value in everything you do. You'll be joining a professional community of experts, who have got your back and will support you, every step of the way.Capgemini. Make it real.Why you should consider CapgeminiGrowing clients' businesses while building a more sustainable, more inclusive future is a tough ask. When you join Capgemini, you'll join a thriving company and become part of a collective of free-thinkers, entrepreneurs and industry experts. We find new ways technology can help us reimagine what's possible. It's why, together, we seek out opportunities that will transform the world's leading businesses, and it's how you'll gain the experiences and connections you need to shape your future. By learning from each other every day, sharing knowledge, and always pushing yourself to do better, you'll build the skills you want. You'll use your skills to help our clients leverage technology to innovate and grow their business. So, it might not always be easy, but making the world a better place rarely is.About CapgeminiCapgemini is an AI-powered global business and technology transformation partner, delivering tangible business value. We imagine the future of organisations and make it real with AI, technology and people. With our strong heritage of nearly 60 years, we are a responsible and diverse group of over 420 . click apply for full job details
16/07/2026
Full time
InternalLocation: UKGlobal Grade: D1 / C2About the job you're consideringOrganisations are facing a sustained increase in cyber risk, regulatory pressure and operational complexity as they modernise their technology landscapes. Cybersecurity is no longer a standalone technical function; it is central to business resilience, digital transformation and customer trust. Senior leaders need pragmatic, commercially grounded advice to embed security into their transformation agendas and make confident, risk informed decisions. Within Capgemini's Cloud Infrastructure Services (CIS) Projects & Consulting, we work with clients across financial services, public and private sectors to shape cybersecurity strategies, design secure transformation pathways and support the mobilisation of complex cyber enabled change. Our work spans early stage maturity assessments and cyber strategy through to the integration of security into large scale cloud, infrastructure and business transformation programmes.We are seeking Manager and Senior Manager level cybersecurity consultants who combine strong advisory capability with deep cyber domain expertise and a track record across consulting, pre sales and delivery. You will play a key role in leading cyber focused engagements, shaping client propositions, supporting go to market activity and helping clients translate cyber ambition into tangible outcomes. This role suits individuals who are credible with senior stakeholders, commercially aware and comfortable operating across advisory, business development and delivery contexts, with cybersecurity as their core specialism.This role requires someone who can:Lead high impact cybersecurity consulting engagements, including maturity assessments, risk reviews, strategy and roadmapsBe part of the team that advises senior stakeholders (e.g. CISO, CTO) on cyber risk, resilience and secure transformation prioritiesIntegrate cybersecurity into wider cloud, infrastructure and digital transformation programmesTranslate complex cyber and risk concepts into clear, actionable recommendations for business leadersIdentify opportunities to extend advisory work into broader transformation, delivery and managed services engagementsSupport and shape go to market propositions in cybersecurity and adjacent domainsContribute to client proposals, bids and credentials, bringing both domain credibility and commercial awarenessEngage proactively with clients to originate and develop opportunitiesProduce high quality, client ready outputs and thought leadership aligned to market trends and Capgemini prioritiesCollaborate effectively with delivery teams, architects and SMEs across CapgeminiHybrid working: The places that you work from day to day will vary according to your role, your needs, and those of the business; it will be a blend of Company offices, client sites, and your home; noting that you will be unable to work at home 100% of the time.Your roleAs a Manager or Senior Manager in the CIS Projects & Consulting Advisory team, you will:Lead and deliver cybersecurity advisory engagements, from problem definition through to recommendations and mobilisationAct as a trusted advisor to client stakeholders, combining consulting judgement with deep cyber expertiseShape engagement scope, approach and deliverables, ensuring outcomes are practical, commercially sound and aligned to risk prioritiesSupport the integration of cybersecurity into broader technology transformation programmes (e.g. cloud, workplace, infrastructure modernisation)Play an active role in business development, including proposition development, client conversations, bids and pipeline growthContribute to thought leadership, market insights and internal capability development in cybersecurityMentor and support junior consultants, helping build a high performing cyber advisory capabilityThe scope of responsibility will vary by grade, with Senior Managers taking greater accountability for client relationships, engagement leadership and go to market contributionYour skills and experienceYou will bring strong consulting foundations alongside credible cybersecurity expertise and commercial experience.Core experience:Experience in a consulting or advisory role at Manager or Senior Manager level within one of the leading consultancies (e.g. Big 4, boutique cybersecurity consultancies, global SIs)Proven ability to lead front end, ambiguous cybersecurity engagements from discovery through to recommendationsExperience across both advisory and delivery, with exposure to large scale transformation programmesTrack record supporting business development, including proposals, bids and client engagementCybersecurity capability (strong experience across some of these areas):Cybersecurity strategy and operating model designCyber risk management, governance and compliance (e.g. ISO 27001, NIST, NIS2, GDPR)Security architecture and secure by design principles in cloud and hybrid environmentsIdentity and access management, security operations or cyber controls engineeringCyber resilience, incident response and operational securityIntegration of security into DevOps and cloud transformationUnderstanding of emerging risks and controls associated with AI and agentic systems, including secure AI adoption, model risk, data protection, and the application of AI within cybersecurity (e.g. threat detection, automation and response)Consulting and commercial skills:Strong stakeholder engagement skills, with the ability to influence at C suite and senior leadership levelExcellent communication and storytelling capability, translating complex cyber topics into clear, compelling narrativesCommercial awareness and the ability to shape propositions and differentiate Capgemini in competitive situationsAbility to operate across industries and adapt to different client environmentsMindset:Intellectually curious, with a strong interest in evolving cyber threats and technologiesComfortable operating across advisory, pre sales and delivery contextsA collaborative team player, able to work across a global, matrix organisationCommitted to continuous learning and staying current in cybersecurity and technology trendsWe are a disability confident employerCapgemini is proud to be a Disability Confident Employer (Level 2) under the UK Government's Disability Confident scheme. As part of our commitment to inclusive recruitment, we will offer an interview to all candidates who:Declare they have a disability, andMeet the minimum essential criteria for the role.Please opt in during the application process.Your security clearance and pre-employment checksIf you are successfully offered this position, you will go through a series of pre-employment checks, including: identity, nationality (single or dual) or immigration status, employment history going back 3 continuous years, and unspent criminal record check (known as Disclosure and Barring Service). To be successfully appointed to this role, it is a requirement to obtain Security Check (SC) clearance. To obtain SC clearance, the successful applicant must have resided continuously within the United Kingdom for the last 5 years, along with other criteria and requirements. Throughout the recruitment process, you will be asked questions about your security clearance eligibility such as, but not limited to, country of residence and nationality. Some posts are restricted to sole UK Nationals for security reasons; therefore, you may be asked about your citizenship in the application process.Make it real - what does that mean for you?We realise a Total Reward package should be more than just compensation. At Capgemini we offer range of core and flexible benefits and have a Peer Recognition Portal called Applaud.You will be encouraged to have a positive work-life balance. Our hybrid-first way of working means we embed hybrid working in all that we do and make flexible working arrangements the day-to-day reality for our people. All UK employees are eligible to request flexible working arrangements.You will be empowered to explore, innovate, and progress. You will benefit from Capgemini's 'learning for life' mindset, meaning you will have countless training and development opportunities from thinktanks to hackathons, and access to 250,000 courses with numerous external certifications from AWS, Microsoft, Harvard ManageMentor, Cybersecurity qualifications and much more.You'll be bringing your unique skills and perspectives to the team, inspiring and taking inspiration from your teammates as you unlock value in everything you do. You'll be joining a professional community of experts, who have got your back and will support you, every step of the way.Capgemini. Make it real.Why you should consider CapgeminiGrowing clients' businesses while building a more sustainable, more inclusive future is a tough ask. When you join Capgemini, you'll join a thriving company and become part of a collective of free-thinkers, entrepreneurs and industry experts. We find new ways technology can help us reimagine what's possible. It's why, together, we seek out opportunities that will transform the world's leading businesses, and it's how you'll gain the experiences and connections you need to shape your future. By learning from each other every day, sharing knowledge, and always pushing yourself to do better, you'll build the skills you want. You'll use your skills to help our clients leverage technology to innovate and grow their business. So, it might not always be easy, but making the world a better place rarely is.About CapgeminiCapgemini is an AI-powered global business and technology transformation partner, delivering tangible business value. We imagine the future of organisations and make it real with AI, technology and people. With our strong heritage of nearly 60 years, we are a responsible and diverse group of over 420 . click apply for full job details
Role objective The purpose of this role is to lead a team of SOC analysts, who are collectively operating on a 24/7/365 basis. Technical and client-oriented SOC Operations Technical Lead role plays a pivotal senior role within our Managed Security Services Provider (MSSP) environment. This role reports to Head of SOC Operations. This hands on position serves as the senior technical authority for SOC operations, driving excellence in threat detection, incident response, and security operations across a diverse multi-client portfolio. You will combine deep technical proficiency with strong consulting skills to mentor analysts, manage shift rotations, optimise SOC processes and tools, lead complex incident escalations, and act as a trusted advisor. Although you will manage a team of SOC analysts, this is not a purely managerial role; you will remain deeply involved in technical work while elevating team capabilities and delivering strategic value to our clients. In this role you will be accountable for the effective functioning of your team, ensuring high performance standards while continuously developing their skills as part of a high trust, high performing security service. You will leverage your combined experience in leadership and security operations to enable the smooth delivery of our award winning defensive monitoring service, supporting proactive detection and response for clients across the globe. You will be expected to contribute, hands on, technically where and when needed, including deep dive investigations, incident response escalations, threat hunting, tuning detections, delivering technical training, and driving process and capability improvements. Strong technical knowledge is essential to mentor junior analysts, develop their capabilities, and ensure the team remains at the forefront of security operations. You must proactively initiate actions and work independently to quickly mitigate threats, set an example, maintain operational continuity, make informed decisions, and ensure team efficiency under pressure. The roles and responsibilities are reviewed annually to ensure alignment with current organisational needs, emerging threats, and industry best practice. Collaboration with other teams As SOC Operations Technical Lead, you will be working closely with Threat Intelligence, Engineering and Incident Response teams as this is essential to strengthen the SOC's ability to detect, investigate, and respond to emerging threats. This collaboration ensures timely sharing of actionable intelligence, refinement of detection rules, improvement of security tools, and alignment of operational processes, ultimately enhancing overall organisational security posture. This role drives continuous improvement within the SOC by identifying gaps in processes, detection capabilities, and team performance, and implementing solutions to enhance operational efficiency. The SOC Operations Technical Lead evaluates incidents and alerts to refine triage and response workflows, ensuring lessons learned are translated into updated playbooks and best practices. By monitoring emerging threats, tuning detections, and adopting new tools and techniques, the role strengthens the SOC's proactive defence posture. Team Leadership & Operations Oversight Lead day to day activities of the SOC analysts across all shifts (24/7 operations through and on call rotation). Manage team scheduling, shift handovers, and always ensure proper coverage. Act as the first point of escalation for security events and staff queries during shifts. Aim to ensure high quality incident triage, investigation, and response by team members, following predefined and agreed SOC processes. Coordinate with other shifts to maintain operational continuity and consistent processes. Lead and Facilitate the Development of the wider monitoring team through technical training courses, workshops and exercises. Applicable department objectives and projects are completed within specification, deadline and budgetary constraints. Ensure completion of all HALO case management on time and with accurate and timely results. Technical Leadership & Operations Excellence Provide technical leadership and guidance to SOC analysts on alert triage, investigation, threat hunting, and incident response. Function as the primary technical escalation point for complex, high severity, or novel security alerts across multiple client environments. Drive continuous improvement of SOC processes, playbooks, detection rules, and automation to enhance efficiency, reduce false positives, and accelerate response times. Evaluate, recommend, and support the implementation and optimization of SOC technologies (SIEM, EDR/XDR, SOAR, threat intelligence platforms) across heterogeneous client stacks. Develop and maintain advanced detection content, custom queries, correlation rules, and use cases tailored to client environments and emerging threats. Consulting & Client Engagement Serve as a trusted technical consultant to clients, participating in security reviews, root cause analyses, and recommendations for security posture improvements. Translate complex technical findings and recommendations into clear, actionable insights for both technical and executive client stakeholders. Mentor and coach SOC analysts, fostering technical growth, best practices, and a high performance culture. Conduct technical training sessions, knowledge sharing workshops, and skills assessments. Support performance management, including goal setting and feedback for direct or matrix team members. Strategic & Operational Contributions Identify opportunities to enhance MSSP service offerings through new capabilities, automation, or methodology improvements. Monitor industry trends, threat intelligence, and tool advancements to keep SOC operations at the cutting edge. Ensure compliance with SLAs, internal standards, and relevant regulatory requirements. Required Qualifications & Experience 7+ years of experience in Security Operations, with at least 3-4 years in a senior/lead technical role within a SOC (preferably in an MSSP or multi-client environment). Strong hands on expertise with industry leading tools: SIEM platforms (Microsoft Sentinel, CrowdStrike) EDR/XDR solutions (CrowdStrike, Microsoft Defender, Carbon Black) SOAR, threat intelligence platforms, and network security tools. Proven experience in advanced threat hunting. Solid automation skills to improve SOC efficiency. Experience designing and tuning detection rules, use cases, and correlation logic in multi tenant environments. Demonstrated consulting skills and ability to communicate effectively with clients, present findings, and provide strategic security advice. Preferred Qualifications Relevant certifications: CISSP, GIAC (GCIH, GCIA, GREM), SC 200, SC 300 or equivalent. Experience with cloud security operations environments. Background in professional services, consulting, or MSSP delivery. Familiarity with ITIL, NIST, ISO27001 or other security frameworks in a service provider context. Exceptional technical depth combined with the ability to explain complex concepts simply. Strong problem solving, analytical thinking, and decision making under pressure. Excellent written and verbal communication skills, including client facing presentation abilities. Leadership presence with a collaborative, mentoring approach. Ability to manage multiple priorities and thrive in a fast paced, 24/7 MSSP environment.
15/07/2026
Full time
Role objective The purpose of this role is to lead a team of SOC analysts, who are collectively operating on a 24/7/365 basis. Technical and client-oriented SOC Operations Technical Lead role plays a pivotal senior role within our Managed Security Services Provider (MSSP) environment. This role reports to Head of SOC Operations. This hands on position serves as the senior technical authority for SOC operations, driving excellence in threat detection, incident response, and security operations across a diverse multi-client portfolio. You will combine deep technical proficiency with strong consulting skills to mentor analysts, manage shift rotations, optimise SOC processes and tools, lead complex incident escalations, and act as a trusted advisor. Although you will manage a team of SOC analysts, this is not a purely managerial role; you will remain deeply involved in technical work while elevating team capabilities and delivering strategic value to our clients. In this role you will be accountable for the effective functioning of your team, ensuring high performance standards while continuously developing their skills as part of a high trust, high performing security service. You will leverage your combined experience in leadership and security operations to enable the smooth delivery of our award winning defensive monitoring service, supporting proactive detection and response for clients across the globe. You will be expected to contribute, hands on, technically where and when needed, including deep dive investigations, incident response escalations, threat hunting, tuning detections, delivering technical training, and driving process and capability improvements. Strong technical knowledge is essential to mentor junior analysts, develop their capabilities, and ensure the team remains at the forefront of security operations. You must proactively initiate actions and work independently to quickly mitigate threats, set an example, maintain operational continuity, make informed decisions, and ensure team efficiency under pressure. The roles and responsibilities are reviewed annually to ensure alignment with current organisational needs, emerging threats, and industry best practice. Collaboration with other teams As SOC Operations Technical Lead, you will be working closely with Threat Intelligence, Engineering and Incident Response teams as this is essential to strengthen the SOC's ability to detect, investigate, and respond to emerging threats. This collaboration ensures timely sharing of actionable intelligence, refinement of detection rules, improvement of security tools, and alignment of operational processes, ultimately enhancing overall organisational security posture. This role drives continuous improvement within the SOC by identifying gaps in processes, detection capabilities, and team performance, and implementing solutions to enhance operational efficiency. The SOC Operations Technical Lead evaluates incidents and alerts to refine triage and response workflows, ensuring lessons learned are translated into updated playbooks and best practices. By monitoring emerging threats, tuning detections, and adopting new tools and techniques, the role strengthens the SOC's proactive defence posture. Team Leadership & Operations Oversight Lead day to day activities of the SOC analysts across all shifts (24/7 operations through and on call rotation). Manage team scheduling, shift handovers, and always ensure proper coverage. Act as the first point of escalation for security events and staff queries during shifts. Aim to ensure high quality incident triage, investigation, and response by team members, following predefined and agreed SOC processes. Coordinate with other shifts to maintain operational continuity and consistent processes. Lead and Facilitate the Development of the wider monitoring team through technical training courses, workshops and exercises. Applicable department objectives and projects are completed within specification, deadline and budgetary constraints. Ensure completion of all HALO case management on time and with accurate and timely results. Technical Leadership & Operations Excellence Provide technical leadership and guidance to SOC analysts on alert triage, investigation, threat hunting, and incident response. Function as the primary technical escalation point for complex, high severity, or novel security alerts across multiple client environments. Drive continuous improvement of SOC processes, playbooks, detection rules, and automation to enhance efficiency, reduce false positives, and accelerate response times. Evaluate, recommend, and support the implementation and optimization of SOC technologies (SIEM, EDR/XDR, SOAR, threat intelligence platforms) across heterogeneous client stacks. Develop and maintain advanced detection content, custom queries, correlation rules, and use cases tailored to client environments and emerging threats. Consulting & Client Engagement Serve as a trusted technical consultant to clients, participating in security reviews, root cause analyses, and recommendations for security posture improvements. Translate complex technical findings and recommendations into clear, actionable insights for both technical and executive client stakeholders. Mentor and coach SOC analysts, fostering technical growth, best practices, and a high performance culture. Conduct technical training sessions, knowledge sharing workshops, and skills assessments. Support performance management, including goal setting and feedback for direct or matrix team members. Strategic & Operational Contributions Identify opportunities to enhance MSSP service offerings through new capabilities, automation, or methodology improvements. Monitor industry trends, threat intelligence, and tool advancements to keep SOC operations at the cutting edge. Ensure compliance with SLAs, internal standards, and relevant regulatory requirements. Required Qualifications & Experience 7+ years of experience in Security Operations, with at least 3-4 years in a senior/lead technical role within a SOC (preferably in an MSSP or multi-client environment). Strong hands on expertise with industry leading tools: SIEM platforms (Microsoft Sentinel, CrowdStrike) EDR/XDR solutions (CrowdStrike, Microsoft Defender, Carbon Black) SOAR, threat intelligence platforms, and network security tools. Proven experience in advanced threat hunting. Solid automation skills to improve SOC efficiency. Experience designing and tuning detection rules, use cases, and correlation logic in multi tenant environments. Demonstrated consulting skills and ability to communicate effectively with clients, present findings, and provide strategic security advice. Preferred Qualifications Relevant certifications: CISSP, GIAC (GCIH, GCIA, GREM), SC 200, SC 300 or equivalent. Experience with cloud security operations environments. Background in professional services, consulting, or MSSP delivery. Familiarity with ITIL, NIST, ISO27001 or other security frameworks in a service provider context. Exceptional technical depth combined with the ability to explain complex concepts simply. Strong problem solving, analytical thinking, and decision making under pressure. Excellent written and verbal communication skills, including client facing presentation abilities. Leadership presence with a collaborative, mentoring approach. Ability to manage multiple priorities and thrive in a fast paced, 24/7 MSSP environment.
About Us: Solirius Reply , part of the Reply Group , is a technology consultancy and digital transformation partner that helps organisations solve complex challenges through strategy, design, engineering, and delivery. We work closely with our clients to deliver secure, accessible, user-focused services that evolve with their needs. By combining deep technical expertise with people-centred design, we create solutions that deliver meaningful, lasting impact. Our consultants partner directly with client teams, embedding into organisations to understand their goals, challenges, and users. This collaborative approach enables us to deliver tailored solutions that drive measurable outcomes across public and private sectors. Past and present clients include the Ministry of Justice, Department for Education, Ministry of Housing, Communities and Local Government, UEFA, International Olympic Committee, and Mercedes-Benz. Our services span the full digital delivery lifecycle, including architecture, engineering, delivery management, user-centred design, business analysis, data, DevOps, and AI. We operate as a collaborative and inclusive organisation that empowers our people to take ownership, innovate, and develop their expertise. As an equal opportunities employer, we are committed to encouraging equality, diversity, and social mobility, while creating opportunities for our teams to work on meaningful projects that deliver lasting impact About You: You are a motivated and adaptable professional with a strong analytical mindset and a passion for using technology to solve real-world problems. You enjoy working in collaborative, agile teams and take pride in delivering high-quality solutions that make a tangible impact. With strong communication skills and a consultative approach, you're comfortable engaging with clients, understanding their needs, and translating them into effective outcomes. The Role: We are seeking experienced Security Architects to support our public sector and enterprise clients in delivering secure digital services and technology transformation initiatives. The role involves engaging with multiple stakeholders to understand business objectives, identify security risks, and design security architectures that enable the safe delivery of business outcomes. You will work closely with solution architects, engineering teams, delivery managers, and client leadership to ensure that security is embedded by design and aligned with organisational risk appetites. As a Security Architect, you will operate with a high degree of autonomy, applying your expertise to resolve complex security challenges and providing authoritative guidance across projects and programmes. You will also contribute to the growth of the Security Practice by developing new service offerings, maintaining security standards and artefacts, supporting business development activities, and mentoring junior colleagues. In addition to technical leadership, you will help identify and shape new opportunities by engaging with client stakeholders to understand strategic security objectives and deliver value-driven outcomes. You will be a confident communicator, capable of influencing senior stakeholders, facilitating workshops, and building consensus across multidisciplinary teams. Key Responsibilities: Design end-to-end security architectures that align with business, technical, regulatory, and security requirements. Develop security strategies and controls for cloud-native, hybrid, and on-premise environments. Conduct security architecture reviews and provide recommendations to mitigate identified risks. Translate business and technical requirements into secure, scalable, and resilient designs. Ensure alignment with enterprise security architecture, governance frameworks, and organisational standards. Support Agile delivery teams by embedding security-by-design principles throughout the software development lifecycle. Define and document security patterns, reference architectures, and reusable security artefacts. Lead threat modelling activities and identify appropriate mitigation strategies. Collaborate with stakeholders across business, product, operations, and engineering teams to drive secure decision-making. Advise on identity and access management approaches, including authentication, authorisation, and privileged access controls. Ensure security, privacy, compliance, and risk management requirements are incorporated into solutions. Support security assurance activities, including risk assessments, security testing, and accreditation processes. Contribute to DevSecOps initiatives, promoting automation and continuous security practices. Produce clear architectural documentation, including security views, high-level designs, and security artefacts. Mentor junior team members and contribute to the development of the wider Security Practice. Key Experience: Extensive experience engaging with stakeholders at all levels, including senior leadership and C-suite executives. Proven experience operating within client-facing and/or consultancy environments. Demonstrated experience designing and implementing enterprise security architectures. Strong understanding of security architecture methodologies and frameworks. Experience conducting threat modelling and security risk assessments. Experience supporting security assurance activities within regulated environments. Proven ability to balance security requirements with operational and business objectives. Experience designing secure architectures across cloud and hybrid environments. Strong understanding of security controls for applications, infrastructure, data, and identity. Experience working within Agile delivery environments and integrating security into delivery processes. Familiarity with public sector security requirements and accreditation approaches is highly desirable. Experience supporting compliance initiatives involving standards and regulatory frameworks. Key Skills: Advanced knowledge of cloud security across Microsoft Azure, AWS, Google Cloud Platform (GCP), and Microsoft 365. Expertise in Zero Trust security principles and secure-by-design methodologies. Strong understanding of identity and access management technologies, including federation, SSO, MFA, and privileged access management. Experience with threat modelling methodologies such as STRIDE, PASTA, or equivalent. Knowledge of security frameworks and standards including: - ISO 27001 - NIST Cybersecurity Framework - NIST 800-53 - CIS Controls - SABSA - TOGAF Understanding of security operations concepts, incident response, and detection capabilities. Knowledge of application security principles, including secure coding practices and OWASP guidance. Experience with DevSecOps practices and security automation. Familiarity with container and Kubernetes security. Understanding of encryption, key management, and data protection principles. Strong documentation, communication, and stakeholder management skills. Competitive Salary Bonus Scheme Private Healthcare Insurance 25 Days Annual Leave + Bank Holidays Up to 10 days allocated for development training per year Enhanced Parental Leave Paid Fertility Leave (5 Days) Statutory & Contributory Pension EAP with Gym Membership Benefits Cycle to Work and Electric Vehicle schemes Flexible Working Annual Away Days/Company Socials Diversity and Inclusion As an equal opportunities employer, we are committed to creating a work environment that supports, celebrates, encourages and respects all individuals, where all processes are based on merit, competence and business needs. Encouraging high social mobility is really important to us. We foster an inclusive culture by welcoming different perspectives, enabling equitable opportunities and promoting open dialogue. This commitment is reflected in initiatives such as our gender diversity group and our focus on mental health and wellbeing. Whatever stage you are at, you will find an environment where you can thrive. Should you require further assistance or require any reasonable adjustments to be put in place to better support your application process, please do not hesitate to raise this with us. As a Disability Confident employer, we are committed to ensuring our recruitment process is accessible and inclusive, enabling all candidates to demonstrate their skills, experience and potential.
12/07/2026
Full time
About Us: Solirius Reply , part of the Reply Group , is a technology consultancy and digital transformation partner that helps organisations solve complex challenges through strategy, design, engineering, and delivery. We work closely with our clients to deliver secure, accessible, user-focused services that evolve with their needs. By combining deep technical expertise with people-centred design, we create solutions that deliver meaningful, lasting impact. Our consultants partner directly with client teams, embedding into organisations to understand their goals, challenges, and users. This collaborative approach enables us to deliver tailored solutions that drive measurable outcomes across public and private sectors. Past and present clients include the Ministry of Justice, Department for Education, Ministry of Housing, Communities and Local Government, UEFA, International Olympic Committee, and Mercedes-Benz. Our services span the full digital delivery lifecycle, including architecture, engineering, delivery management, user-centred design, business analysis, data, DevOps, and AI. We operate as a collaborative and inclusive organisation that empowers our people to take ownership, innovate, and develop their expertise. As an equal opportunities employer, we are committed to encouraging equality, diversity, and social mobility, while creating opportunities for our teams to work on meaningful projects that deliver lasting impact About You: You are a motivated and adaptable professional with a strong analytical mindset and a passion for using technology to solve real-world problems. You enjoy working in collaborative, agile teams and take pride in delivering high-quality solutions that make a tangible impact. With strong communication skills and a consultative approach, you're comfortable engaging with clients, understanding their needs, and translating them into effective outcomes. The Role: We are seeking experienced Security Architects to support our public sector and enterprise clients in delivering secure digital services and technology transformation initiatives. The role involves engaging with multiple stakeholders to understand business objectives, identify security risks, and design security architectures that enable the safe delivery of business outcomes. You will work closely with solution architects, engineering teams, delivery managers, and client leadership to ensure that security is embedded by design and aligned with organisational risk appetites. As a Security Architect, you will operate with a high degree of autonomy, applying your expertise to resolve complex security challenges and providing authoritative guidance across projects and programmes. You will also contribute to the growth of the Security Practice by developing new service offerings, maintaining security standards and artefacts, supporting business development activities, and mentoring junior colleagues. In addition to technical leadership, you will help identify and shape new opportunities by engaging with client stakeholders to understand strategic security objectives and deliver value-driven outcomes. You will be a confident communicator, capable of influencing senior stakeholders, facilitating workshops, and building consensus across multidisciplinary teams. Key Responsibilities: Design end-to-end security architectures that align with business, technical, regulatory, and security requirements. Develop security strategies and controls for cloud-native, hybrid, and on-premise environments. Conduct security architecture reviews and provide recommendations to mitigate identified risks. Translate business and technical requirements into secure, scalable, and resilient designs. Ensure alignment with enterprise security architecture, governance frameworks, and organisational standards. Support Agile delivery teams by embedding security-by-design principles throughout the software development lifecycle. Define and document security patterns, reference architectures, and reusable security artefacts. Lead threat modelling activities and identify appropriate mitigation strategies. Collaborate with stakeholders across business, product, operations, and engineering teams to drive secure decision-making. Advise on identity and access management approaches, including authentication, authorisation, and privileged access controls. Ensure security, privacy, compliance, and risk management requirements are incorporated into solutions. Support security assurance activities, including risk assessments, security testing, and accreditation processes. Contribute to DevSecOps initiatives, promoting automation and continuous security practices. Produce clear architectural documentation, including security views, high-level designs, and security artefacts. Mentor junior team members and contribute to the development of the wider Security Practice. Key Experience: Extensive experience engaging with stakeholders at all levels, including senior leadership and C-suite executives. Proven experience operating within client-facing and/or consultancy environments. Demonstrated experience designing and implementing enterprise security architectures. Strong understanding of security architecture methodologies and frameworks. Experience conducting threat modelling and security risk assessments. Experience supporting security assurance activities within regulated environments. Proven ability to balance security requirements with operational and business objectives. Experience designing secure architectures across cloud and hybrid environments. Strong understanding of security controls for applications, infrastructure, data, and identity. Experience working within Agile delivery environments and integrating security into delivery processes. Familiarity with public sector security requirements and accreditation approaches is highly desirable. Experience supporting compliance initiatives involving standards and regulatory frameworks. Key Skills: Advanced knowledge of cloud security across Microsoft Azure, AWS, Google Cloud Platform (GCP), and Microsoft 365. Expertise in Zero Trust security principles and secure-by-design methodologies. Strong understanding of identity and access management technologies, including federation, SSO, MFA, and privileged access management. Experience with threat modelling methodologies such as STRIDE, PASTA, or equivalent. Knowledge of security frameworks and standards including: - ISO 27001 - NIST Cybersecurity Framework - NIST 800-53 - CIS Controls - SABSA - TOGAF Understanding of security operations concepts, incident response, and detection capabilities. Knowledge of application security principles, including secure coding practices and OWASP guidance. Experience with DevSecOps practices and security automation. Familiarity with container and Kubernetes security. Understanding of encryption, key management, and data protection principles. Strong documentation, communication, and stakeholder management skills. Competitive Salary Bonus Scheme Private Healthcare Insurance 25 Days Annual Leave + Bank Holidays Up to 10 days allocated for development training per year Enhanced Parental Leave Paid Fertility Leave (5 Days) Statutory & Contributory Pension EAP with Gym Membership Benefits Cycle to Work and Electric Vehicle schemes Flexible Working Annual Away Days/Company Socials Diversity and Inclusion As an equal opportunities employer, we are committed to creating a work environment that supports, celebrates, encourages and respects all individuals, where all processes are based on merit, competence and business needs. Encouraging high social mobility is really important to us. We foster an inclusive culture by welcoming different perspectives, enabling equitable opportunities and promoting open dialogue. This commitment is reflected in initiatives such as our gender diversity group and our focus on mental health and wellbeing. Whatever stage you are at, you will find an environment where you can thrive. Should you require further assistance or require any reasonable adjustments to be put in place to better support your application process, please do not hesitate to raise this with us. As a Disability Confident employer, we are committed to ensuring our recruitment process is accessible and inclusive, enabling all candidates to demonstrate their skills, experience and potential.
Duco is empowering financial services to transform the work undertaken in Operations by automating manual work and elevating humans from task workers to decision makers. We do this with a combination of proprietary technique, innovative cloud computing, artificial intelligence technology, and deep subject matter expertise. Our agentic Operations platform gives firms the ability to unlock full end-to-end reconciliation, data trust and automation of their data, regardless of source, format or structure. By partnering with the industry's leading firms, we are helping to rethink operating models, increase efficiency, strengthen governance and regulatory compliance, reduce risk, streamline processes and build the workforce of the future. More than 10,000 users across 30+ countries process billions of data records every week using the platform. Duco is headquartered in London, with offices in New York, Wroclaw, Antwerp and Singapore. Customers include global banks, investment managers, exchanges and insurance firms, such as CIBC Mellon, ING and Man Group. The role We are looking for a Head of Information Security to own our end-to-end security posture, govern our risk and compliance programme, and lead our IT Operations function. This is a VP Level role with company wide scope. With approximately 200 employees across London, New York, Wroclaw, Antwerp, and Singapore, we move fast, build with purpose, and hold ourselves to a high bar. As we scale, information security, governance, and IT operations sit at the heart of that ambition. What you will be doing Security architecture and engineering Define security architecture standards and lead threat modelling across the organisation Establish and maintain long term security architecture aligned to business strategy and regulatory requirements Guide technology decisions at an enterprise level, including cloud strategy and zero trust adoption Oversee penetration testing, DLP, and advanced threat detection programmes Own the vulnerability management programme Implement enterprise frameworks including IAM, SIEM, and data classification Anticipate emerging threats, leverage AI/ML for predictive security, and set the technology vision Lead the Security Incident Response Programme Governance, risk, and compliance (GRC) Define and own the GRC programme, including the ISMS, policy framework, risk registers, and audit readiness Implement and maintain compliance with ISO 27001, SOC 1, SOC 2, NIST CSF, GDPR, and relevant financial services regulations Understand the GRC landscape, implement appropriate controls, and adapt as the threat and regulatory environment shifts Own execution of GRC strategy across the organisation; ensure frameworks are scalable and adaptable Own the Third Party Risk Management (TRPM) programme, including vendor assessments and ongoing oversight IT operations Define and own the IT Operations programme, setting strategy and standards for the function Own execution of IT Operations strategy; ensure frameworks are scalable and adaptable as Duco grows Ensure operational excellence across infrastructure, tooling, and end user support Leadership and stakeholder management Lead, mentor, and develop a high performing team across InfoSec, GRC, and IT Ops Build strategic relationships with clients, regulators, and internal stakeholders Engage effectively with large, complex, and multi national enterprise clients that have mission critical operations requirements, building trust and credibility at the most senior levels Recognise, influence, and resolve critical issues that may affect company direction Create strategies that cross organisational boundaries to achieve broad business goals Work with industry peers and working groups to develop solutions that benefit the wider market Enterprise Client Assurance: Act as a key partner to Duco's Client Success and Pre Sales teams. This involves speaking directly with the CISOs and security teams of global financial institutions to assure them of Duco's risk management and data privacy practices Core Competencies Technical leadership: Proven track record of strategic impact at company wide and industry wide levels; recognised internally and externally as an InfoSec expert, with evidence of exceptional technical and people leadership End to end ownership: Develop proven solutions and replicate them across teams; design systems and frameworks built to last; own execution of security, GRC, and IT Ops strategy; ensure frameworks are scalable, adaptable, and aligned to business strategy and executive level risk expectations Market knowledge: Deep understanding of the security and risk landscape across fintech and beyond; evaluate and integrate advanced security technologies and GRC best practices; act as a recognised industry leader through regulatory advisory groups and industry events Scope and influence: Operate across all departments; build sponsorship for strategic initiatives and drive them through; influence executive peers, board decisions, and global regulatory compliance strategy What We Are Looking For 8+ years of progressive experience in information security, with at least 3 years in a senior or leadership role Hands on experience owning ISO 27001 and SOC 1 and SOC 2 programmes, not just supporting them Demonstrated experience managing security incidents end to end, including client and regulatory communications Strong understanding of cloud security, particularly AWS, including IAM, logging, and observability infrastructure Experience operating in a B2B SaaS or fintech environment, with exposure to enterprise client security requirements Track record of building and managing TPRM programmes at scale Excellent stakeholder management skills; comfortable presenting to the board and to client security teams in equal measure Ability to make pragmatic decisions based on company culture and risk appetite Strong written communication skills: able to translate complex security topics into clear, plain language communications for non technical audiences Experience leading and developing a small, high performing team Familiarity with AI governance and the security implications of agentic AI systems Beneficial Experience Experience with DLP, SIEM, or SOC build outs Relevant certifications such as CISSP, CISM, or ISO 27001 Lead Implementer Experience in capital markets, asset management, or securities services
11/07/2026
Full time
Duco is empowering financial services to transform the work undertaken in Operations by automating manual work and elevating humans from task workers to decision makers. We do this with a combination of proprietary technique, innovative cloud computing, artificial intelligence technology, and deep subject matter expertise. Our agentic Operations platform gives firms the ability to unlock full end-to-end reconciliation, data trust and automation of their data, regardless of source, format or structure. By partnering with the industry's leading firms, we are helping to rethink operating models, increase efficiency, strengthen governance and regulatory compliance, reduce risk, streamline processes and build the workforce of the future. More than 10,000 users across 30+ countries process billions of data records every week using the platform. Duco is headquartered in London, with offices in New York, Wroclaw, Antwerp and Singapore. Customers include global banks, investment managers, exchanges and insurance firms, such as CIBC Mellon, ING and Man Group. The role We are looking for a Head of Information Security to own our end-to-end security posture, govern our risk and compliance programme, and lead our IT Operations function. This is a VP Level role with company wide scope. With approximately 200 employees across London, New York, Wroclaw, Antwerp, and Singapore, we move fast, build with purpose, and hold ourselves to a high bar. As we scale, information security, governance, and IT operations sit at the heart of that ambition. What you will be doing Security architecture and engineering Define security architecture standards and lead threat modelling across the organisation Establish and maintain long term security architecture aligned to business strategy and regulatory requirements Guide technology decisions at an enterprise level, including cloud strategy and zero trust adoption Oversee penetration testing, DLP, and advanced threat detection programmes Own the vulnerability management programme Implement enterprise frameworks including IAM, SIEM, and data classification Anticipate emerging threats, leverage AI/ML for predictive security, and set the technology vision Lead the Security Incident Response Programme Governance, risk, and compliance (GRC) Define and own the GRC programme, including the ISMS, policy framework, risk registers, and audit readiness Implement and maintain compliance with ISO 27001, SOC 1, SOC 2, NIST CSF, GDPR, and relevant financial services regulations Understand the GRC landscape, implement appropriate controls, and adapt as the threat and regulatory environment shifts Own execution of GRC strategy across the organisation; ensure frameworks are scalable and adaptable Own the Third Party Risk Management (TRPM) programme, including vendor assessments and ongoing oversight IT operations Define and own the IT Operations programme, setting strategy and standards for the function Own execution of IT Operations strategy; ensure frameworks are scalable and adaptable as Duco grows Ensure operational excellence across infrastructure, tooling, and end user support Leadership and stakeholder management Lead, mentor, and develop a high performing team across InfoSec, GRC, and IT Ops Build strategic relationships with clients, regulators, and internal stakeholders Engage effectively with large, complex, and multi national enterprise clients that have mission critical operations requirements, building trust and credibility at the most senior levels Recognise, influence, and resolve critical issues that may affect company direction Create strategies that cross organisational boundaries to achieve broad business goals Work with industry peers and working groups to develop solutions that benefit the wider market Enterprise Client Assurance: Act as a key partner to Duco's Client Success and Pre Sales teams. This involves speaking directly with the CISOs and security teams of global financial institutions to assure them of Duco's risk management and data privacy practices Core Competencies Technical leadership: Proven track record of strategic impact at company wide and industry wide levels; recognised internally and externally as an InfoSec expert, with evidence of exceptional technical and people leadership End to end ownership: Develop proven solutions and replicate them across teams; design systems and frameworks built to last; own execution of security, GRC, and IT Ops strategy; ensure frameworks are scalable, adaptable, and aligned to business strategy and executive level risk expectations Market knowledge: Deep understanding of the security and risk landscape across fintech and beyond; evaluate and integrate advanced security technologies and GRC best practices; act as a recognised industry leader through regulatory advisory groups and industry events Scope and influence: Operate across all departments; build sponsorship for strategic initiatives and drive them through; influence executive peers, board decisions, and global regulatory compliance strategy What We Are Looking For 8+ years of progressive experience in information security, with at least 3 years in a senior or leadership role Hands on experience owning ISO 27001 and SOC 1 and SOC 2 programmes, not just supporting them Demonstrated experience managing security incidents end to end, including client and regulatory communications Strong understanding of cloud security, particularly AWS, including IAM, logging, and observability infrastructure Experience operating in a B2B SaaS or fintech environment, with exposure to enterprise client security requirements Track record of building and managing TPRM programmes at scale Excellent stakeholder management skills; comfortable presenting to the board and to client security teams in equal measure Ability to make pragmatic decisions based on company culture and risk appetite Strong written communication skills: able to translate complex security topics into clear, plain language communications for non technical audiences Experience leading and developing a small, high performing team Familiarity with AI governance and the security implications of agentic AI systems Beneficial Experience Experience with DLP, SIEM, or SOC build outs Relevant certifications such as CISSP, CISM, or ISO 27001 Lead Implementer Experience in capital markets, asset management, or securities services
Role Summary Sophos is seeking an experienced MDR Manager to support its Managed Detection and Response customers. The successful candidate will lead MDR analysts and day-to-day operations, ensuring operational quality, timely incident handling, effective customer communication, consistent reporting, and continuous service improvement. As part of the Managed Detection and Response team, you will help deliver best-in-class monitoring, detection, and response services that proactively defend customer environments. You will guide investigations, review quality, coach analysts, manage escalations, and use operational insights to improve team performance, investigation consistency, and customer outcomes. What you will do Lead day-to-day MDR operations, overseeing case queues, analyst workloads, SLA performance, escalations, and resource allocation to ensure consistent service delivery. Guide and review incident investigations, validating findings, assessing business impact, recommending response actions, and ensuring appropriate escalation management. Serve as a key point of coordination during customer and internal escalations, providing clear updates, risk assessments, recommendations, and resolution plans. Coach, mentor, and develop MDR analysts through case reviews, feedback, skills development, and performance management. Conduct quality reviews of investigations, customer communications, documentation, and calls to drive operational excellence and continuous improvement. Analyse operational metrics and dashboards to identify trends, risks, capacity constraints, and opportunities to improve service quality, efficiency, and customer outcomes. Develop and maintain SOPs, playbooks, workflows, and knowledge-base content to improve consistency and operational readiness. Provide technical leadership in intrusion analysis, incident response, digital forensics, malware investigations, and threat hunting activities. Lead response efforts during significant security incidents, ensuring effective coordination, decision-making, and ownership through resolution. Stay current on threat actor tactics, techniques, and procedures (TTPs), leveraging threat intelligence to enhance investigations, detections, and response capabilities. Partner with Engineering, Labs, and Content teams to improve detection quality, reduce false positives, and address recurring investigation gaps. What you will bring Up to 12 years of total work experience. 5+ years of experience in cybersecurity, with a minimum of 2-3 years leading, mentoring, or coordinating analysts in a SOC, MDR, Incident Response, or similar environment. Bachelor's degree in Information Technology, Computer Science, or a related field, or equivalent practical experience. Hands on experience in security operations, including threat detection, incident investigation, and response. Strong understanding of endpoint and network security technologies, including IDS/IPS, EDR, ATP, malware protection, and monitoring platforms. Experience with threat hunting methodologies and familiarity with the MITRE ATT&CK framework preferred. Working knowledge of incident response processes, adversary tactics and techniques, and cyber threat intelligence. Strong technical expertise in Windows environments, including host artefacts, endpoint telemetry, event log analysis, and operating system security events; exposure to macOS and Linux is a plus. Solid understanding of network fundamentals, including TCP/IP, routing, switching, and traffic analysis. Experience with SIEM platforms and enterprise security data management; database querying skills are advantageous. Working knowledge of PowerShell and Python for automation and investigation support. Strong analytical, troubleshooting, and decision making skills, with the ability to prioritise effectively in high pressure situations. Excellent written and verbal communication skills, including the ability to produce clear reports, case summaries, operational updates, and executive ready communications. Experience performing quality reviews and providing actionable feedback that improves investigation outcomes and analyst performance. Proven ability to build team capability through coaching, onboarding, training, and knowledge sharing. Strong stakeholder management and customer facing skills, with the capability to explain technical findings, risks, and recommendations to both technical and non technical audiences. Advanced cybersecurity certifications are preferred but not required. Equal Opportunity Employer All applicants will be treated in a fair and equal manner and in accordance with the law regardless of gender, sex, gender reassignment, marital status, race, religion or belief, color, age, military veteran status, disability, pregnancy, maternity or sexual orientation. Data Protection If you choose to explore an opportunity, and subsequently share your CV or other personal details with Sophos, these details will be held by Sophos for 12 months in accordance with our Privacy Policy and used by our recruitment team to contact you regarding this or other relevant opportunities at Sophos. If you would like Sophos to delete or update your details at any time, please follow the steps set out in the Privacy Policy describing your individual rights. For more information on Sophos' data protection practices, please consult our Privacy Policy.
10/07/2026
Full time
Role Summary Sophos is seeking an experienced MDR Manager to support its Managed Detection and Response customers. The successful candidate will lead MDR analysts and day-to-day operations, ensuring operational quality, timely incident handling, effective customer communication, consistent reporting, and continuous service improvement. As part of the Managed Detection and Response team, you will help deliver best-in-class monitoring, detection, and response services that proactively defend customer environments. You will guide investigations, review quality, coach analysts, manage escalations, and use operational insights to improve team performance, investigation consistency, and customer outcomes. What you will do Lead day-to-day MDR operations, overseeing case queues, analyst workloads, SLA performance, escalations, and resource allocation to ensure consistent service delivery. Guide and review incident investigations, validating findings, assessing business impact, recommending response actions, and ensuring appropriate escalation management. Serve as a key point of coordination during customer and internal escalations, providing clear updates, risk assessments, recommendations, and resolution plans. Coach, mentor, and develop MDR analysts through case reviews, feedback, skills development, and performance management. Conduct quality reviews of investigations, customer communications, documentation, and calls to drive operational excellence and continuous improvement. Analyse operational metrics and dashboards to identify trends, risks, capacity constraints, and opportunities to improve service quality, efficiency, and customer outcomes. Develop and maintain SOPs, playbooks, workflows, and knowledge-base content to improve consistency and operational readiness. Provide technical leadership in intrusion analysis, incident response, digital forensics, malware investigations, and threat hunting activities. Lead response efforts during significant security incidents, ensuring effective coordination, decision-making, and ownership through resolution. Stay current on threat actor tactics, techniques, and procedures (TTPs), leveraging threat intelligence to enhance investigations, detections, and response capabilities. Partner with Engineering, Labs, and Content teams to improve detection quality, reduce false positives, and address recurring investigation gaps. What you will bring Up to 12 years of total work experience. 5+ years of experience in cybersecurity, with a minimum of 2-3 years leading, mentoring, or coordinating analysts in a SOC, MDR, Incident Response, or similar environment. Bachelor's degree in Information Technology, Computer Science, or a related field, or equivalent practical experience. Hands on experience in security operations, including threat detection, incident investigation, and response. Strong understanding of endpoint and network security technologies, including IDS/IPS, EDR, ATP, malware protection, and monitoring platforms. Experience with threat hunting methodologies and familiarity with the MITRE ATT&CK framework preferred. Working knowledge of incident response processes, adversary tactics and techniques, and cyber threat intelligence. Strong technical expertise in Windows environments, including host artefacts, endpoint telemetry, event log analysis, and operating system security events; exposure to macOS and Linux is a plus. Solid understanding of network fundamentals, including TCP/IP, routing, switching, and traffic analysis. Experience with SIEM platforms and enterprise security data management; database querying skills are advantageous. Working knowledge of PowerShell and Python for automation and investigation support. Strong analytical, troubleshooting, and decision making skills, with the ability to prioritise effectively in high pressure situations. Excellent written and verbal communication skills, including the ability to produce clear reports, case summaries, operational updates, and executive ready communications. Experience performing quality reviews and providing actionable feedback that improves investigation outcomes and analyst performance. Proven ability to build team capability through coaching, onboarding, training, and knowledge sharing. Strong stakeholder management and customer facing skills, with the capability to explain technical findings, risks, and recommendations to both technical and non technical audiences. Advanced cybersecurity certifications are preferred but not required. Equal Opportunity Employer All applicants will be treated in a fair and equal manner and in accordance with the law regardless of gender, sex, gender reassignment, marital status, race, religion or belief, color, age, military veteran status, disability, pregnancy, maternity or sexual orientation. Data Protection If you choose to explore an opportunity, and subsequently share your CV or other personal details with Sophos, these details will be held by Sophos for 12 months in accordance with our Privacy Policy and used by our recruitment team to contact you regarding this or other relevant opportunities at Sophos. If you would like Sophos to delete or update your details at any time, please follow the steps set out in the Privacy Policy describing your individual rights. For more information on Sophos' data protection practices, please consult our Privacy Policy.
About Us Solirius Reply, part of the Reply Group, is a technology consultancy and digital transformation partner that helps organisations solve complex challenges through strategy, design, engineering, and delivery. We work closely with our clients to deliver secure, accessible, user-focused services that evolve with their needs. By combining deep technical expertise with people-centred design, we create solutions that deliver meaningful, lasting impact. Our consultants partner directly with client teams, embedding into organisations to understand their goals, challenges, and users. This collaborative approach enables us to deliver tailored solutions that drive measurable outcomes across public and private sectors. Past and present clients include the Ministry of Justice, Department for Education, Ministry of Housing, Communities and Local Government, UEFA, International Olympic Committee, and Mercedes Benz. Our services span the full digital delivery lifecycle, including architecture, engineering, delivery management, user centred design, business analysis, data, DevOps, and AI. We operate as a collaborative and inclusive organisation that empowers our people to take ownership, innovate, and develop their expertise. As an equal opportunities employer, we are committed to encouraging equality, diversity, and social mobility, while creating opportunities for our teams to work on meaningful projects that deliver lasting impact. About You You are a motivated and adaptable professional with a strong analytical mindset and a passion for using technology to solve real-world problems. You enjoy working in collaborative, agile teams and take pride in delivering high-quality solutions that make a tangible impact. With strong communication skills and a consultative approach, you're comfortable engaging with clients, understanding their needs, and translating them into effective outcomes. The Role We are seeking experienced Security Architects to support our public sector and enterprise clients in delivering secure digital services and technology transformation initiatives. The role involves engaging with multiple stakeholders to understand business objectives, identify security risks, and design security architectures that enable the safe delivery of business outcomes. You will work closely with solution architects, engineering teams, delivery managers, and client leadership to ensure that security is embedded by design and aligned with organisational risk appetites. As a Security Architect, you will operate with a high degree of autonomy, applying your expertise to resolve complex security challenges and providing authoritative guidance across projects and programmes. You will also contribute to the growth of the Security Practice by developing new service offerings, maintaining security standards and artefacts, supporting business development activities, and mentoring junior colleagues. In addition to technical leadership, you will help identify and shape new opportunities by engaging with client stakeholders to understand strategic security objectives and deliver value-driven outcomes. You will be a confident communicator, capable of influencing senior stakeholders, facilitating workshops, and building consensus across multidisciplinary teams. Key Responsibilities Design end-to-end security architectures that align with business, technical, regulatory, and security requirements. Develop security strategies and controls for cloud-native, hybrid, and on-premise environments. Conduct security architecture reviews and provide recommendations to mitigate identified risks. Translate business and technical requirements into secure, scalable, and resilient designs. Ensure alignment with enterprise security architecture, governance frameworks, and organisational standards. Support Agile delivery teams by embedding security-by-design principles throughout the software development lifecycle. Define and document security patterns, reference architectures, and reusable security artefacts. Lead threat modelling activities and identify appropriate mitigation strategies. Collaborate with stakeholders across business, product, operations, and engineering teams to drive secure decision-making. Advise on identity and access management approaches, including authentication, authorisation, and privileged access controls. Ensure security, privacy, compliance, and risk management requirements are incorporated into solutions. Support security assurance activities, including risk assessments, security testing, and accreditation processes. Contribute to DevSecOps initiatives, promoting automation and continuous security practices. Produce clear architectural documentation, including security views, high-level designs, and security artefacts. Mentor junior team members and contribute to the development of the wider Security Practice. Key Experience Extensive experience engaging with stakeholders at all levels, including senior leadership and C-suite executives. Proven experience operating within client-facing and/or consultancy environments. Demonstrated experience designing and implementing enterprise security architectures. Strong understanding of security architecture methodologies and frameworks. Experience conducting threat modelling and security risk assessments. Experience supporting security assurance activities within regulated environments. Proven ability to balance security requirements with operational and business objectives. Experience designing secure architectures across cloud and hybrid environments. Strong understanding of security controls for applications, infrastructure, data, and identity. Experience working within Agile delivery environments and integrating security into delivery processes. Familiarity with public sector security requirements and accreditation approaches is highly desirable. Experience supporting compliance initiatives involving standards and regulatory frameworks. Key Skills Advanced knowledge of cloud security across Microsoft Azure, AWS, Google Cloud Platform (GCP), and Microsoft 365. Expertise in Zero Trust security principles and secure-by-design methodologies. Strong understanding of identity and access management technologies, including federation, SSO, MFA, and privileged access management. Experience with threat modelling methodologies such as STRIDE, PASTA, or equivalent. Knowledge of security frameworks and standards including: ISO 27001 NIST Cybersecurity Framework NIST 800-53 CIS Controls SABSA TOGAF Understanding of security operations concepts, incident response, and detection capabilities. Knowledge of application security principles, including secure coding practices and OWASP guidance. Experience with DevSecOps practices and security automation. Familiarity with container and Kubernetes security. Understanding of encryption, key management, and data protection principles. Strong documentation, communication, and stakeholder management skills. Benefits Competitive Salary Bonus Scheme Private Healthcare Insurance 25 Days Annual Leave + Bank Holidays Up to 10 days allocated for development training per year Enhanced Parental Leave Paid Fertility Leave (5 Days) Statutory & Contributory Pension EAP with Gym Membership Benefits Cycle to Work and Electric Vehicle schemes Flexible Working Annual Away Days/Company Socials Diversity and Inclusion As an equal opportunities employer, we are committed to creating a work environment that supports, celebrates, encourages and respects all individuals, where all processes are based on merit, competence and business needs. Encouraging high social mobility is really important to us. We foster an inclusive culture by welcoming different perspectives, enabling equitable opportunities and promoting open dialogue. This commitment is reflected in initiatives such as our gender diversity group and our focus on mental health and wellbeing. Whatever stage you are at, you will find an environment where you can thrive. Should you require further assistance or require any reasonable adjustments to be put in place to better support your application process, please do not hesitate to raise this with us. As a Disability Confident employer, we are committed to ensuring our recruitment process is accessible and inclusive, enabling all candidates to demonstrate their skills, experience and potential.
09/07/2026
Full time
About Us Solirius Reply, part of the Reply Group, is a technology consultancy and digital transformation partner that helps organisations solve complex challenges through strategy, design, engineering, and delivery. We work closely with our clients to deliver secure, accessible, user-focused services that evolve with their needs. By combining deep technical expertise with people-centred design, we create solutions that deliver meaningful, lasting impact. Our consultants partner directly with client teams, embedding into organisations to understand their goals, challenges, and users. This collaborative approach enables us to deliver tailored solutions that drive measurable outcomes across public and private sectors. Past and present clients include the Ministry of Justice, Department for Education, Ministry of Housing, Communities and Local Government, UEFA, International Olympic Committee, and Mercedes Benz. Our services span the full digital delivery lifecycle, including architecture, engineering, delivery management, user centred design, business analysis, data, DevOps, and AI. We operate as a collaborative and inclusive organisation that empowers our people to take ownership, innovate, and develop their expertise. As an equal opportunities employer, we are committed to encouraging equality, diversity, and social mobility, while creating opportunities for our teams to work on meaningful projects that deliver lasting impact. About You You are a motivated and adaptable professional with a strong analytical mindset and a passion for using technology to solve real-world problems. You enjoy working in collaborative, agile teams and take pride in delivering high-quality solutions that make a tangible impact. With strong communication skills and a consultative approach, you're comfortable engaging with clients, understanding their needs, and translating them into effective outcomes. The Role We are seeking experienced Security Architects to support our public sector and enterprise clients in delivering secure digital services and technology transformation initiatives. The role involves engaging with multiple stakeholders to understand business objectives, identify security risks, and design security architectures that enable the safe delivery of business outcomes. You will work closely with solution architects, engineering teams, delivery managers, and client leadership to ensure that security is embedded by design and aligned with organisational risk appetites. As a Security Architect, you will operate with a high degree of autonomy, applying your expertise to resolve complex security challenges and providing authoritative guidance across projects and programmes. You will also contribute to the growth of the Security Practice by developing new service offerings, maintaining security standards and artefacts, supporting business development activities, and mentoring junior colleagues. In addition to technical leadership, you will help identify and shape new opportunities by engaging with client stakeholders to understand strategic security objectives and deliver value-driven outcomes. You will be a confident communicator, capable of influencing senior stakeholders, facilitating workshops, and building consensus across multidisciplinary teams. Key Responsibilities Design end-to-end security architectures that align with business, technical, regulatory, and security requirements. Develop security strategies and controls for cloud-native, hybrid, and on-premise environments. Conduct security architecture reviews and provide recommendations to mitigate identified risks. Translate business and technical requirements into secure, scalable, and resilient designs. Ensure alignment with enterprise security architecture, governance frameworks, and organisational standards. Support Agile delivery teams by embedding security-by-design principles throughout the software development lifecycle. Define and document security patterns, reference architectures, and reusable security artefacts. Lead threat modelling activities and identify appropriate mitigation strategies. Collaborate with stakeholders across business, product, operations, and engineering teams to drive secure decision-making. Advise on identity and access management approaches, including authentication, authorisation, and privileged access controls. Ensure security, privacy, compliance, and risk management requirements are incorporated into solutions. Support security assurance activities, including risk assessments, security testing, and accreditation processes. Contribute to DevSecOps initiatives, promoting automation and continuous security practices. Produce clear architectural documentation, including security views, high-level designs, and security artefacts. Mentor junior team members and contribute to the development of the wider Security Practice. Key Experience Extensive experience engaging with stakeholders at all levels, including senior leadership and C-suite executives. Proven experience operating within client-facing and/or consultancy environments. Demonstrated experience designing and implementing enterprise security architectures. Strong understanding of security architecture methodologies and frameworks. Experience conducting threat modelling and security risk assessments. Experience supporting security assurance activities within regulated environments. Proven ability to balance security requirements with operational and business objectives. Experience designing secure architectures across cloud and hybrid environments. Strong understanding of security controls for applications, infrastructure, data, and identity. Experience working within Agile delivery environments and integrating security into delivery processes. Familiarity with public sector security requirements and accreditation approaches is highly desirable. Experience supporting compliance initiatives involving standards and regulatory frameworks. Key Skills Advanced knowledge of cloud security across Microsoft Azure, AWS, Google Cloud Platform (GCP), and Microsoft 365. Expertise in Zero Trust security principles and secure-by-design methodologies. Strong understanding of identity and access management technologies, including federation, SSO, MFA, and privileged access management. Experience with threat modelling methodologies such as STRIDE, PASTA, or equivalent. Knowledge of security frameworks and standards including: ISO 27001 NIST Cybersecurity Framework NIST 800-53 CIS Controls SABSA TOGAF Understanding of security operations concepts, incident response, and detection capabilities. Knowledge of application security principles, including secure coding practices and OWASP guidance. Experience with DevSecOps practices and security automation. Familiarity with container and Kubernetes security. Understanding of encryption, key management, and data protection principles. Strong documentation, communication, and stakeholder management skills. Benefits Competitive Salary Bonus Scheme Private Healthcare Insurance 25 Days Annual Leave + Bank Holidays Up to 10 days allocated for development training per year Enhanced Parental Leave Paid Fertility Leave (5 Days) Statutory & Contributory Pension EAP with Gym Membership Benefits Cycle to Work and Electric Vehicle schemes Flexible Working Annual Away Days/Company Socials Diversity and Inclusion As an equal opportunities employer, we are committed to creating a work environment that supports, celebrates, encourages and respects all individuals, where all processes are based on merit, competence and business needs. Encouraging high social mobility is really important to us. We foster an inclusive culture by welcoming different perspectives, enabling equitable opportunities and promoting open dialogue. This commitment is reflected in initiatives such as our gender diversity group and our focus on mental health and wellbeing. Whatever stage you are at, you will find an environment where you can thrive. Should you require further assistance or require any reasonable adjustments to be put in place to better support your application process, please do not hesitate to raise this with us. As a Disability Confident employer, we are committed to ensuring our recruitment process is accessible and inclusive, enabling all candidates to demonstrate their skills, experience and potential.
Cyber Technical Delivery Manager Location: London (Hybrid - 4 Days per Week Onsite) Contract Length:12 Months Engagement:Inside IR35 Industry:Investment Banking / Financial Services Start Date:ASAP Overview We are supporting a leading investment banking client in London who is seeking an experienced Cyber Technical Delivery Manager to join a large-scale Cyber Security Transformation Programme. This role will be responsible for the successful delivery of complex cyber security initiatives across multiple technology domains, including Identity & Access Management (IAM), Security Operations, Cloud Security, Vulnerability Management, Data Protection, and Regulatory Compliance. The successful candidate will act as the bridge between technical engineering teams, cyber security stakeholders, business leaders, and third-party vendors, ensuring projects are delivered on time, within budget, and in line with regulatory and security requirements. Key Responsibilities Programme & Project Delivery Lead the end-to-end delivery of cyber security projects and workstreams. Develop and maintain project plans, milestones, RAID logs, budgets, and resource plans. Ensure delivery aligns with business objectives, security standards, and regulatory requirements. Manage dependencies across multiple technology and business teams. Drive project governance and reporting activities. Cyber Security Delivery Deliver initiatives across: Identity & Access Management (IAM) Privileged Access Management (PAM) Security Operations (SOC) SIEM Platforms Cloud Security Vulnerability Management Data Protection and DLP Security Monitoring and Threat Detection Secure File Transfer and Encryption Programmes Coordinate technical teams to ensure successful implementation of security controls and technologies. Stakeholder Management Engage with senior stakeholders across Cyber Security, Infrastructure, Cloud, Risk, Compliance, and Business Functions. Provide regular programme updates to senior management and governance forums. Manage relationships with third-party suppliers and technology vendors. Facilitate workshops, steering committees, and technical review sessions. Risk & Governance Identify, manage, and mitigate project risks and issues. Ensure compliance with internal security policies and regulatory frameworks. Support audit, risk, and compliance activities. Track and report programme KPIs and delivery metrics. Requirements Required Skills & Experience Cyber Security Experience Strong understanding of enterprise cyber security principles and controls. Experience delivering projects involving: IAM and Access Governance PAM Solutions SIEM and Security Monitoring Cloud Security Endpoint Security Vulnerability Management Data Protection Security Compliance Programmes Familiarity with security frameworks and standards such as: NIST ISO 27001 CIS Controls Cyber Essentials Regulatory requirements within Financial Services Technical Knowledge Good understanding of: Microsoft Azure AWS Active Directory / Entra ID Security Monitoring Platforms Identity Management Solutions Network and Infrastructure Security Ability to engage effectively with technical architects, engineers, and security specialists. Delivery Management Proven experience delivering complex technology or cyber programmes within large enterprise environments. Strong project and programme management experience. Experience managing multiple workstreams simultaneously. Excellent RAID management and governance skills. Strong budget and financial management experience. Essential Experience Previous experience working within Investment Banking, Banking, or Financial Services. Experience delivering cyber security transformation programmes. Experience operating within regulated environments. Strong stakeholder management skills with the ability to engage at Executive and C-Level. Experience managing third-party suppliers and system integrators. Desirable Skills Experience with: Microsoft Sentinel Splunk SailPoint CyberArk Okta CrowdStrike Microsoft Defender Suite Knowledge of DevSecOps practices. Exposure to cloud migration and security transformation programmes. Experience supporting regulatory remediation initiatives. Qualifications & Certifications One or more of the following would be advantageous: PRINCE2 Practitioner PMP Agile Practitioner / Scrum Certification CISSP CISM CISA CRISC Personal Attributes Strong leadership and organisational skills. Excellent communication and presentation abilities. Ability to influence stakeholders at all levels. Strong analytical and problem-solving mindset. Ability to operate effectively in fast-paced, complex environments. Self motivated with a strong focus on delivery and outcomes. Key Deliverables Successful delivery of cyber security projects and workstreams. Effective management of risks, issues, and dependencies. Timely implementation of security controls and technologies. Improved cyber security posture and compliance alignment. High quality governance reporting and stakeholder engagement.
08/07/2026
Full time
Cyber Technical Delivery Manager Location: London (Hybrid - 4 Days per Week Onsite) Contract Length:12 Months Engagement:Inside IR35 Industry:Investment Banking / Financial Services Start Date:ASAP Overview We are supporting a leading investment banking client in London who is seeking an experienced Cyber Technical Delivery Manager to join a large-scale Cyber Security Transformation Programme. This role will be responsible for the successful delivery of complex cyber security initiatives across multiple technology domains, including Identity & Access Management (IAM), Security Operations, Cloud Security, Vulnerability Management, Data Protection, and Regulatory Compliance. The successful candidate will act as the bridge between technical engineering teams, cyber security stakeholders, business leaders, and third-party vendors, ensuring projects are delivered on time, within budget, and in line with regulatory and security requirements. Key Responsibilities Programme & Project Delivery Lead the end-to-end delivery of cyber security projects and workstreams. Develop and maintain project plans, milestones, RAID logs, budgets, and resource plans. Ensure delivery aligns with business objectives, security standards, and regulatory requirements. Manage dependencies across multiple technology and business teams. Drive project governance and reporting activities. Cyber Security Delivery Deliver initiatives across: Identity & Access Management (IAM) Privileged Access Management (PAM) Security Operations (SOC) SIEM Platforms Cloud Security Vulnerability Management Data Protection and DLP Security Monitoring and Threat Detection Secure File Transfer and Encryption Programmes Coordinate technical teams to ensure successful implementation of security controls and technologies. Stakeholder Management Engage with senior stakeholders across Cyber Security, Infrastructure, Cloud, Risk, Compliance, and Business Functions. Provide regular programme updates to senior management and governance forums. Manage relationships with third-party suppliers and technology vendors. Facilitate workshops, steering committees, and technical review sessions. Risk & Governance Identify, manage, and mitigate project risks and issues. Ensure compliance with internal security policies and regulatory frameworks. Support audit, risk, and compliance activities. Track and report programme KPIs and delivery metrics. Requirements Required Skills & Experience Cyber Security Experience Strong understanding of enterprise cyber security principles and controls. Experience delivering projects involving: IAM and Access Governance PAM Solutions SIEM and Security Monitoring Cloud Security Endpoint Security Vulnerability Management Data Protection Security Compliance Programmes Familiarity with security frameworks and standards such as: NIST ISO 27001 CIS Controls Cyber Essentials Regulatory requirements within Financial Services Technical Knowledge Good understanding of: Microsoft Azure AWS Active Directory / Entra ID Security Monitoring Platforms Identity Management Solutions Network and Infrastructure Security Ability to engage effectively with technical architects, engineers, and security specialists. Delivery Management Proven experience delivering complex technology or cyber programmes within large enterprise environments. Strong project and programme management experience. Experience managing multiple workstreams simultaneously. Excellent RAID management and governance skills. Strong budget and financial management experience. Essential Experience Previous experience working within Investment Banking, Banking, or Financial Services. Experience delivering cyber security transformation programmes. Experience operating within regulated environments. Strong stakeholder management skills with the ability to engage at Executive and C-Level. Experience managing third-party suppliers and system integrators. Desirable Skills Experience with: Microsoft Sentinel Splunk SailPoint CyberArk Okta CrowdStrike Microsoft Defender Suite Knowledge of DevSecOps practices. Exposure to cloud migration and security transformation programmes. Experience supporting regulatory remediation initiatives. Qualifications & Certifications One or more of the following would be advantageous: PRINCE2 Practitioner PMP Agile Practitioner / Scrum Certification CISSP CISM CISA CRISC Personal Attributes Strong leadership and organisational skills. Excellent communication and presentation abilities. Ability to influence stakeholders at all levels. Strong analytical and problem-solving mindset. Ability to operate effectively in fast-paced, complex environments. Self motivated with a strong focus on delivery and outcomes. Key Deliverables Successful delivery of cyber security projects and workstreams. Effective management of risks, issues, and dependencies. Timely implementation of security controls and technologies. Improved cyber security posture and compliance alignment. High quality governance reporting and stakeholder engagement.
Head of Cyber, Band 8b The closing date is 02 August 2026. The Head of Cyber Security is the expert responsible for protecting the confidentiality, integrity and availability of digital services and patient information across acute, community, mental health and primary care partners within the Gloucestershire Integrated Care System (ICS). Protecting staff, systems and safeguarding patient data from harm by ensuring technology and information that underpins patient care remains safe, available and trustworthy is of utmost importance and enables delivery of safe patient care by our 15,000+ staff with confidence, transparency and compliance. The post holder will provide strategic and operational leadership of the Cyber Security Team and act as the expert adviser to the Chief Delivery & Governance Officer, SIRO, Caldicott Guardian and Audit Committees on all cyber-security matters, working closely with the Information Governance lead and DPO. They will ensure compliance with the Data Security and Protection Toolkit (DSPT) aligned with the Cyber Assessment Framework (CAF) and the delivery of the NHS Cyber Security Strategy to 2030 and full participation in the regional "Defend as One" model. The role combines governance, assurance and hands on leadership of proactive and preventative tactics, threat intelligence, incident response, vulnerability management, strategy and cultural change to build cyber resilience across the Integrated Care System (ICS). Main duties of the job The post holder will be an experienced cyber security leader with a proven track record of managing and improving cyber resilience within large, complex or multi organisation environments. They will possess deep technical and governance expertise across areas such as threat detection, vulnerability management and incident response, with the ability to translate complex technical risk into clear, articulate, actionable information for senior executives and boards with assurance and confidence. They will demonstrate a thorough understanding of national and international cyber standards, including the Cyber Assessment Framework (CAF), Data Security and Protection Toolkit (DSPT), ISO 27001, and the NHS Cyber Security Strategy to 2030. Experience of successfully leading cyber compliance programmes, external audits and penetration testing remediation is essential. The successful candidate will bring experience in leading multidisciplinary cyber teams, developing capability through mentoring and training and fostering an open culture of shared responsibility for cyber security. They will have strong stakeholder management and influencing skills, with the ability to build transparent and trusted relationships across digital, information governance and clinical teams, while working collaboratively with regional and national partners under the Defend as One approach. About us We take pride in placing people at the centre of everything we do, working together as a united team. Driven by a shared ambition to continually grow, develop, and learn, we recognise and value every contribution. By combining our experience and skills, we not only support our vibrant, diverse communities, but also support one another. With a team of over 9,000 employees, we are proud to be the largest employer in Gloucestershire and rank among the top 10 largest Trusts in the South West region. By joining our Trust, you will benefit from an excellent package that includes exclusive benefits, flexible working opportunities and the chance to gain valuable experience in one or both of our innovative hospitals. As well as generous annual leave allowance, you will have access to the excellent NHS pension scheme, competitive bank rates, discounts at local shops and restaurants, access to two on site nurseries, discounted public transport, reward and recognition and a range of health and wellbeing initiatives to support you. Job responsibilities Strategic Leadership Act as the senior specialist for cyber security across the ICS, setting strategic direction and delivering the countywide Cyber Security Strategy and annual workplan. Act as the primary countywide interface with NHS England's CSOC, regional cyber leads, and law enforcement, facilitating threat intelligence sharing and collective defence initiatives across the ICS. Track and report key cyber resilience indicators, including MDE and BitSight scores, vulnerability closure rates, CAF maturity levels, and CareCERT compliance metrics. Use data trends to inform Board level assurance and investment priorities. Provide expert assurance to the Chief Delivery & Governance Officer, SIRO, Caldicott Guardian and Audit Committee on cyber risks, controls and maturity. Lead local adoption of NHS England's Defend as One principles, ensuring collaboration on shared tooling, intelligence and incident coordination. Represent the Trust and ICS on regional and national cyber forums, ensuring alignment with NCSC, NHS England Cyber Operations Centre (CSOC) and DHSC guidance. Operational Management Lead and develop the Cyber Security Team to deliver proactive monitoring, detection, response and continuous improvement. Act as the senior technical authority for cyber incident response, providing Tier 3 escalation and decision making oversight during major incidents and overseeing coordination between local and national CSOC functions, ensuring event data are triaged, correlated and acted upon efficiently. Oversee the countywide security tooling stack ensuring optimal configuration and utilisation. Manage day to day cyber operations, including vulnerability management, penetration testing remediation, phishing simulations and user awareness campaigns. Maintain robust incident response plans compliant with the Data Security Protection Toolkit and NCSC guidance, ensuring all major incidents are logged, triaged and reported within mandated timescales. Coordinate technical response during cyber events, acting as joint Incident Manager and providing senior briefings, root cause analysis and lessons learned reports. Risk and Compliance Own and maintain the Cyber Risk Register, consolidating Trust and ICS level risks and ensuring appropriate mitigations and assurance evidence. Lead the internal cyber assurance programme, mapping findings from penetration tests, CareCERT responses and internal audits to DSPT objectives. Maintain oversight of all open cyber audit actions, ensuring timely closure and evidence of improvement. Deliver the DSPT to Standards Met or higher, embedding continual improvement reviews throughout the year. Monitor CareCERT/NHS Cyber Alerts and ensure all critical vulnerabilities are triaged within 48 hours and resolved within 14 days. Oversee removal or mitigation of End of Life systems to maintain 95 % supported infrastructure. Promote sustainable cyber operations by adopting energy efficient hardware lifecycle management and secure and responsible asset disposal to reduce carbon footprint. Ensure all new digital procurements and cloud deployments include security by design and supplier assurance controls. Policy and Governance Lead the review and implementation of Cyber Security Policies, Standards and SOPs covering access, remote working, cloud, IoT/IoMT and third party assurance. Provide governance reporting to the Digital Board Committee, Audit Committee and ICS Cyber Operations Group. Liaise with Information Governance and Data Protection Officer to ensure alignment between IG and Cyber requirements. Work closely with Information Asset Owners and Administrators to ensure security controls, DPIAs and mitigations are documented and reviewed. Ensure all system changes or procurements undergo proportionate cyber risk assessment and IG consultation. People and Culture Inspire, mentor and develop team members, supporting attainment of professional certifications (CISSP, CISM, NHS Cyber Academy). Promote a culture of cyber awareness and accountability through training, communications and engagement campaigns. Act as Subject Matter Expert to advise managers, IAOs and project teams on secure by design principles. Manage the cyber security budget, ensuring effective investment and demonstrable value for money. Oversee contracts for penetration testing, secure disposal and software licensing within standing financial instructions. Prepare business cases for cyber tooling, ensuring sustainability and cost effectiveness. Professional Development, Education and Training Maintain expert awareness of national policy and technical trends, ensuring skills remain current. Undertake continuing professional development and contribute to the learning of others. Planning and Organisation Develop annual cyber workplans with measurable objectives, milestones and KPIs. Coordinate multi organisation programmes, including CAF reviews, Windows 11 migration and SOC development. Contribute to digital business continuity and disaster recovery planning and exercises. Research and Development Lead continuous improvement initiatives, researching emerging threats, Zero Trust architecture, AI security and IoMT protection. Evaluate new technologies through proof of concept pilots and cost benefit analysis. Benchmark performance against national metrics (e.g. MDE, BitSight, Cyber Maturity Model). Communications and Working Relationships Maintain constructive relationships with internal and external stakeholders including Digital Ops, Clinical Engineering, IG, HR, Estates, suppliers . click apply for full job details
05/07/2026
Full time
Head of Cyber, Band 8b The closing date is 02 August 2026. The Head of Cyber Security is the expert responsible for protecting the confidentiality, integrity and availability of digital services and patient information across acute, community, mental health and primary care partners within the Gloucestershire Integrated Care System (ICS). Protecting staff, systems and safeguarding patient data from harm by ensuring technology and information that underpins patient care remains safe, available and trustworthy is of utmost importance and enables delivery of safe patient care by our 15,000+ staff with confidence, transparency and compliance. The post holder will provide strategic and operational leadership of the Cyber Security Team and act as the expert adviser to the Chief Delivery & Governance Officer, SIRO, Caldicott Guardian and Audit Committees on all cyber-security matters, working closely with the Information Governance lead and DPO. They will ensure compliance with the Data Security and Protection Toolkit (DSPT) aligned with the Cyber Assessment Framework (CAF) and the delivery of the NHS Cyber Security Strategy to 2030 and full participation in the regional "Defend as One" model. The role combines governance, assurance and hands on leadership of proactive and preventative tactics, threat intelligence, incident response, vulnerability management, strategy and cultural change to build cyber resilience across the Integrated Care System (ICS). Main duties of the job The post holder will be an experienced cyber security leader with a proven track record of managing and improving cyber resilience within large, complex or multi organisation environments. They will possess deep technical and governance expertise across areas such as threat detection, vulnerability management and incident response, with the ability to translate complex technical risk into clear, articulate, actionable information for senior executives and boards with assurance and confidence. They will demonstrate a thorough understanding of national and international cyber standards, including the Cyber Assessment Framework (CAF), Data Security and Protection Toolkit (DSPT), ISO 27001, and the NHS Cyber Security Strategy to 2030. Experience of successfully leading cyber compliance programmes, external audits and penetration testing remediation is essential. The successful candidate will bring experience in leading multidisciplinary cyber teams, developing capability through mentoring and training and fostering an open culture of shared responsibility for cyber security. They will have strong stakeholder management and influencing skills, with the ability to build transparent and trusted relationships across digital, information governance and clinical teams, while working collaboratively with regional and national partners under the Defend as One approach. About us We take pride in placing people at the centre of everything we do, working together as a united team. Driven by a shared ambition to continually grow, develop, and learn, we recognise and value every contribution. By combining our experience and skills, we not only support our vibrant, diverse communities, but also support one another. With a team of over 9,000 employees, we are proud to be the largest employer in Gloucestershire and rank among the top 10 largest Trusts in the South West region. By joining our Trust, you will benefit from an excellent package that includes exclusive benefits, flexible working opportunities and the chance to gain valuable experience in one or both of our innovative hospitals. As well as generous annual leave allowance, you will have access to the excellent NHS pension scheme, competitive bank rates, discounts at local shops and restaurants, access to two on site nurseries, discounted public transport, reward and recognition and a range of health and wellbeing initiatives to support you. Job responsibilities Strategic Leadership Act as the senior specialist for cyber security across the ICS, setting strategic direction and delivering the countywide Cyber Security Strategy and annual workplan. Act as the primary countywide interface with NHS England's CSOC, regional cyber leads, and law enforcement, facilitating threat intelligence sharing and collective defence initiatives across the ICS. Track and report key cyber resilience indicators, including MDE and BitSight scores, vulnerability closure rates, CAF maturity levels, and CareCERT compliance metrics. Use data trends to inform Board level assurance and investment priorities. Provide expert assurance to the Chief Delivery & Governance Officer, SIRO, Caldicott Guardian and Audit Committee on cyber risks, controls and maturity. Lead local adoption of NHS England's Defend as One principles, ensuring collaboration on shared tooling, intelligence and incident coordination. Represent the Trust and ICS on regional and national cyber forums, ensuring alignment with NCSC, NHS England Cyber Operations Centre (CSOC) and DHSC guidance. Operational Management Lead and develop the Cyber Security Team to deliver proactive monitoring, detection, response and continuous improvement. Act as the senior technical authority for cyber incident response, providing Tier 3 escalation and decision making oversight during major incidents and overseeing coordination between local and national CSOC functions, ensuring event data are triaged, correlated and acted upon efficiently. Oversee the countywide security tooling stack ensuring optimal configuration and utilisation. Manage day to day cyber operations, including vulnerability management, penetration testing remediation, phishing simulations and user awareness campaigns. Maintain robust incident response plans compliant with the Data Security Protection Toolkit and NCSC guidance, ensuring all major incidents are logged, triaged and reported within mandated timescales. Coordinate technical response during cyber events, acting as joint Incident Manager and providing senior briefings, root cause analysis and lessons learned reports. Risk and Compliance Own and maintain the Cyber Risk Register, consolidating Trust and ICS level risks and ensuring appropriate mitigations and assurance evidence. Lead the internal cyber assurance programme, mapping findings from penetration tests, CareCERT responses and internal audits to DSPT objectives. Maintain oversight of all open cyber audit actions, ensuring timely closure and evidence of improvement. Deliver the DSPT to Standards Met or higher, embedding continual improvement reviews throughout the year. Monitor CareCERT/NHS Cyber Alerts and ensure all critical vulnerabilities are triaged within 48 hours and resolved within 14 days. Oversee removal or mitigation of End of Life systems to maintain 95 % supported infrastructure. Promote sustainable cyber operations by adopting energy efficient hardware lifecycle management and secure and responsible asset disposal to reduce carbon footprint. Ensure all new digital procurements and cloud deployments include security by design and supplier assurance controls. Policy and Governance Lead the review and implementation of Cyber Security Policies, Standards and SOPs covering access, remote working, cloud, IoT/IoMT and third party assurance. Provide governance reporting to the Digital Board Committee, Audit Committee and ICS Cyber Operations Group. Liaise with Information Governance and Data Protection Officer to ensure alignment between IG and Cyber requirements. Work closely with Information Asset Owners and Administrators to ensure security controls, DPIAs and mitigations are documented and reviewed. Ensure all system changes or procurements undergo proportionate cyber risk assessment and IG consultation. People and Culture Inspire, mentor and develop team members, supporting attainment of professional certifications (CISSP, CISM, NHS Cyber Academy). Promote a culture of cyber awareness and accountability through training, communications and engagement campaigns. Act as Subject Matter Expert to advise managers, IAOs and project teams on secure by design principles. Manage the cyber security budget, ensuring effective investment and demonstrable value for money. Oversee contracts for penetration testing, secure disposal and software licensing within standing financial instructions. Prepare business cases for cyber tooling, ensuring sustainability and cost effectiveness. Professional Development, Education and Training Maintain expert awareness of national policy and technical trends, ensuring skills remain current. Undertake continuing professional development and contribute to the learning of others. Planning and Organisation Develop annual cyber workplans with measurable objectives, milestones and KPIs. Coordinate multi organisation programmes, including CAF reviews, Windows 11 migration and SOC development. Contribute to digital business continuity and disaster recovery planning and exercises. Research and Development Lead continuous improvement initiatives, researching emerging threats, Zero Trust architecture, AI security and IoMT protection. Evaluate new technologies through proof of concept pilots and cost benefit analysis. Benchmark performance against national metrics (e.g. MDE, BitSight, Cyber Maturity Model). Communications and Working Relationships Maintain constructive relationships with internal and external stakeholders including Digital Ops, Clinical Engineering, IG, HR, Estates, suppliers . click apply for full job details
Detego Global is on the lookout for a SOC Subject Matter Expert to join our Product Management team. We are looking for a mid to senior SOC analyst with extensive operational experience who is ready to transition into a product-focused role. You will be the voice of the SOC development team, translating deep operational security experience into product requirements and strategic direction for advanced SOC command and control tools. You will work closely with product managers, engineers, UX designers, and customers to ensure our products solve real analyst challenges and improve SOC efficiency and effectiveness. This role will provide the right candidate with the opportunity to work on some extremely rewarding projects supporting the development of impactful security operations software while working with a friendly and supportive team. The role has a strong opportunity for growth and will play an integral role in helping shape the future of SOC products and security operations tools. Reports to: Senior Product Manager Place of Work: Hybrid Remote/Office in Horsham Responsibilities and Duties The SOC Subject Matter Expert role requires a professional who combines extensive SOC operational experience with strategic product thinking to bridge the gap between security operations needs and product development. They will be responsible for providing expert SOC operational guidance throughout the product development lifecycle, defining system-level requirements, and ensuring our products genuinely address the challenges faced by SOC analysts in real-world environments. Their primary responsibility lies in translating SOC analyst pain points, workflows, and use cases into actionable product features, with particular focus on alert/incident prioritisation and intelligent playbook execution that helps analysts make critical security decisions. Their responsibilities will include: Providing expert SOC operational guidance to product management and engineering teams throughout the product development lifecycle. Defining and documenting detailed system-level requirements for SOC analyst tools, ensuring alignment with real-world operational needs. Translating SOC analyst pain points, workflows, and use cases into actionable product features and user stories. Designing and validating alert prioritisation algorithms, incident triage workflows, and automated playbook logic based on operational experience. Collaborating with product managers to shape product strategy, roadmap priorities, and feature definitions. Conducting customer discovery sessions, interviews, and workshops with SOC teams to gather requirements and validate concepts. Creating realistic user personas, journey maps, and workflow diagrams that represent authentic SOC analyst experiences. Evaluating competitive SOC tools and industry trends to inform product differentiation and innovation opportunities. Participating in proof-of-concept development to validate new features addressing critical analyst decision-making challenges. Working with UX designers to ensure intuitive interfaces that match SOC analyst mental models and workflow patterns. Providing technical consultation on threat detection logic, MITRE ATT&CK mapping, and security operations best practices. Supporting go-to-market activities by creating technical content, conducting product demonstrations, and engaging with prospective customers. Mentoring and educating internal teams on SOC operations, threat landscapes, and analyst workflows. Ensuring product features align with industry frameworks (MITRE ATT&CK, NIST, ISO 27001) and SOC maturity models. Act as a trusted SOC and cyber defence expert in customer meetings, workshops, and solution design sessions. Support pre-sales engagements by articulating operational value, use cases, and real-world applicability. Deliver product demonstrations and technical briefings tailored to SOC practitioners, security leaders, and decision-makers. Translate complex SOC workflows and technical concepts into clear, compelling narratives for customers and stakeholders. Support go-to-market activities through technical content creation, presentations, and customer engagement. Skills and Experience Minimum 6 years of hands on experience as a SOC Analyst, Senior SOC Analyst, or SOC Team Lead Deep understanding of end to end SOC operations including alert triage, incident response, threat hunting, and case management Extensive experience with SIEM platforms, security orchestration tools, and the broader SOC technology stack Strong knowledge of threat detection methodologies, alert correlation, and incident prioritisation frameworks Expert level understanding of MITRE ATT&CK framework and its practical application in SOC operations Proven ability to identify operational inefficiencies and translate them into product improvement opportunities Experience developing or optimising SOC playbooks, runbooks, and standard operating procedures Excellent communication skills with ability to articulate complex security concepts to both technical and business audiences Strong analytical and strategic thinking capabilities Understanding of common attack patterns, threat actor TTPs, and the evolving threat landscape Ability to balance ideal security outcomes with practical operational constraints and business realities Strong problem solving skills and willingness to roll up one's sleeves to get the job done Skilled at working effectively with cross functional teams in a matrix organisation 8+ years of progressive SOC experience including team leadership or senior analyst responsibilities. Experience in Tier 2 or Tier 3 SOC roles with incident response and threat hunting responsibilities. Previous involvement in SOC tool evaluation, selection, or implementation projects. Experience with security automation, SOAR platforms, or playbook development. Experience working with or partnering with SOC/SIEM/EDR vendors and MSSP (Managed Security Service Provider) vendors. Familiarity with product management principles, agile methodologies, or requirements gathering processes. Experience presenting to executive leadership or external stakeholders. Knowledge of multiple SIEM platforms (Splunk, QRadar, Sentinel, Chronicle, etc.) and their operational strengths/weaknesses. Understanding of SOC metrics, KPIs, and performance measurement frameworks. Security certifications (e.g., GCIH, GCIA, GCFA, CISSP, GMON) demonstrating advanced security operations expertise. Experience working in regulated industries or with compliance driven security operations. Bachelor's degree in cybersecurity, information technology, or related field. "
03/07/2026
Full time
Detego Global is on the lookout for a SOC Subject Matter Expert to join our Product Management team. We are looking for a mid to senior SOC analyst with extensive operational experience who is ready to transition into a product-focused role. You will be the voice of the SOC development team, translating deep operational security experience into product requirements and strategic direction for advanced SOC command and control tools. You will work closely with product managers, engineers, UX designers, and customers to ensure our products solve real analyst challenges and improve SOC efficiency and effectiveness. This role will provide the right candidate with the opportunity to work on some extremely rewarding projects supporting the development of impactful security operations software while working with a friendly and supportive team. The role has a strong opportunity for growth and will play an integral role in helping shape the future of SOC products and security operations tools. Reports to: Senior Product Manager Place of Work: Hybrid Remote/Office in Horsham Responsibilities and Duties The SOC Subject Matter Expert role requires a professional who combines extensive SOC operational experience with strategic product thinking to bridge the gap between security operations needs and product development. They will be responsible for providing expert SOC operational guidance throughout the product development lifecycle, defining system-level requirements, and ensuring our products genuinely address the challenges faced by SOC analysts in real-world environments. Their primary responsibility lies in translating SOC analyst pain points, workflows, and use cases into actionable product features, with particular focus on alert/incident prioritisation and intelligent playbook execution that helps analysts make critical security decisions. Their responsibilities will include: Providing expert SOC operational guidance to product management and engineering teams throughout the product development lifecycle. Defining and documenting detailed system-level requirements for SOC analyst tools, ensuring alignment with real-world operational needs. Translating SOC analyst pain points, workflows, and use cases into actionable product features and user stories. Designing and validating alert prioritisation algorithms, incident triage workflows, and automated playbook logic based on operational experience. Collaborating with product managers to shape product strategy, roadmap priorities, and feature definitions. Conducting customer discovery sessions, interviews, and workshops with SOC teams to gather requirements and validate concepts. Creating realistic user personas, journey maps, and workflow diagrams that represent authentic SOC analyst experiences. Evaluating competitive SOC tools and industry trends to inform product differentiation and innovation opportunities. Participating in proof-of-concept development to validate new features addressing critical analyst decision-making challenges. Working with UX designers to ensure intuitive interfaces that match SOC analyst mental models and workflow patterns. Providing technical consultation on threat detection logic, MITRE ATT&CK mapping, and security operations best practices. Supporting go-to-market activities by creating technical content, conducting product demonstrations, and engaging with prospective customers. Mentoring and educating internal teams on SOC operations, threat landscapes, and analyst workflows. Ensuring product features align with industry frameworks (MITRE ATT&CK, NIST, ISO 27001) and SOC maturity models. Act as a trusted SOC and cyber defence expert in customer meetings, workshops, and solution design sessions. Support pre-sales engagements by articulating operational value, use cases, and real-world applicability. Deliver product demonstrations and technical briefings tailored to SOC practitioners, security leaders, and decision-makers. Translate complex SOC workflows and technical concepts into clear, compelling narratives for customers and stakeholders. Support go-to-market activities through technical content creation, presentations, and customer engagement. Skills and Experience Minimum 6 years of hands on experience as a SOC Analyst, Senior SOC Analyst, or SOC Team Lead Deep understanding of end to end SOC operations including alert triage, incident response, threat hunting, and case management Extensive experience with SIEM platforms, security orchestration tools, and the broader SOC technology stack Strong knowledge of threat detection methodologies, alert correlation, and incident prioritisation frameworks Expert level understanding of MITRE ATT&CK framework and its practical application in SOC operations Proven ability to identify operational inefficiencies and translate them into product improvement opportunities Experience developing or optimising SOC playbooks, runbooks, and standard operating procedures Excellent communication skills with ability to articulate complex security concepts to both technical and business audiences Strong analytical and strategic thinking capabilities Understanding of common attack patterns, threat actor TTPs, and the evolving threat landscape Ability to balance ideal security outcomes with practical operational constraints and business realities Strong problem solving skills and willingness to roll up one's sleeves to get the job done Skilled at working effectively with cross functional teams in a matrix organisation 8+ years of progressive SOC experience including team leadership or senior analyst responsibilities. Experience in Tier 2 or Tier 3 SOC roles with incident response and threat hunting responsibilities. Previous involvement in SOC tool evaluation, selection, or implementation projects. Experience with security automation, SOAR platforms, or playbook development. Experience working with or partnering with SOC/SIEM/EDR vendors and MSSP (Managed Security Service Provider) vendors. Familiarity with product management principles, agile methodologies, or requirements gathering processes. Experience presenting to executive leadership or external stakeholders. Knowledge of multiple SIEM platforms (Splunk, QRadar, Sentinel, Chronicle, etc.) and their operational strengths/weaknesses. Understanding of SOC metrics, KPIs, and performance measurement frameworks. Security certifications (e.g., GCIH, GCIA, GCFA, CISSP, GMON) demonstrating advanced security operations expertise. Experience working in regulated industries or with compliance driven security operations. Bachelor's degree in cybersecurity, information technology, or related field. "