
Senior Security Operations Manager
- London
- Permanent
- Full-time
- Lead SOC transformation: Drive the evolution of our SOC and SIEM, integrating security domains (endpoint security, access control, DLP), ensuring seamless operations and supporting ambitious business growth across new verticals.
- Hands-on expertise: Pragmatic, hands-on optimisation of security alerts, refine logging, monitoring, and alerting strategies, tune throughputs to reduce noise and improve efficiency.
- Drive security across our end user environments: partner with IT teams to ensure the ongoing security and oversight of end user environments (e.g. access management, vulnerability management, data leakage, laptop security etc).
- Incident response: enhance incident detection and response capabilities, ensuring rapid and competent handling of security events, that comply with relevant regulatory requirements, e.g. e.g. ISO27001, PCI DSS, GDPR, DORA.
- Collaboration: work closely with teams across the business and SREs to stabilise security operations triage and build out 24x7 support requirements. Act as a subject matter expert and provide guidance and support across the organisation.
- Technology & innovation: leverage SIEM, EDR, SOAR, and other technologies to automate processes, improve efficiency and mitigate security risks.
- Operational excellence: ensure the smooth operation of security tools and processes, and address immediate capacity gaps while driving longer-term strategic planning.
- Problem solving: tackle current and upcoming security challenges head-on, providing practical solutions and insights to optimise efficiency of a lean, ambitious team.
- Threat intelligence: integrate relevant threat intelligence and drive a threat-led approach to security operations.
- Proven experience in security operations, ideally within the FinTech industry.
- Strong hands-on experience with security technologies, e.g. SIEM, EDR, SOAR, firewalls, security alert optimisation, AWS, GCP, IDS/IPS, EDR, threat intelligence, vulnerability management.
- Good understanding of endpoint security and how to integrate into security operations.
- Practical experience of security frameworks and concepts such as the Cyber Kill Chain, Mitre Att&ck and D3FEND
- Proficiency in scripting and automation (Python, Terraform).
- Demonstrated ability to optimise security alerts, tune systems and reduce noise.
- Experience with incident response and management, with an understanding of regulatory requirements.
- Engineering-led mindset to drive automation, innovation and efficiency.
- Excellent communication and collaboration skills, with the ability to work effectively across teams.
- A proactive, can-do attitude and a willingness to roll up your sleeves and get hands-on.
- Experience setting up a SOC from scratch or significantly improving lean SOC functions.
- Relevant certifications such as CISSP, CISM, CISA, or equivalent are preferred, but not essential.