
Security Operations Lead
- London
- Permanent
- Full-time
- Leading investigation and analysis of security alerts to identify and promptly respond to security events.
- Leading the response to major cyber security incidents, collaborating with key business and technical stakeholders during investigations to gather further information and coordinate response actions.
- Identifying and responding to game related threats like leaks, cheats, piracy, copyright abuse and account compromise.
- Managing our security operations outsourcing partners to maximise the value and quality of their service delivery.
- Maintaining a broad understanding of IT/online environments and key company assets to enhance decision making and response to incidents.
- Maintaining and optimising our Cyber Security tools and platforms to continuously improve our detection and response capability.
- Supporting the management, administration and support of our SIEM platform, including general infrastructure and system administration, troubleshooting and user access management
- Maintaining and tuning security detections and alerts within our SIEM platform.
- Onboarding and managing security log sources for our SIEM platform, including agent and policy deployment, creation and maintenance of ingest pipelines and index template and pattern creation.
- Guiding and mentoring the day to day work of our Security Analysts, providing expertise to support their task and project delivery.
- Collaborating with risk and architecture teams to continuously test and refine our security controls through attack simulation and purple team operations.
- Influencing the strategic direction and priorities of our Cyber Security team by presenting insight into the security events, alerts and incidents we handle.
- Continuously improving our security operations processes, escalation paths and playbooks.
- Leveraging AI capabilities to enhance the effectiveness of our security capabilities and your own productivity in the role.
- Consuming relevant threat intelligence to drive proactive action within the Cyber Security and wider IT environment.
- Mean time for business recovery to C1 (Highest criticality) level security incidents
- Security event triage time
- Game/brand leak detection timeframes
- High availability of security tools
- Security maturity improvements
- Held senior roles within Cyber Security/Information Security/Security Operations functions.
- Background in security, IT, network engineering or administration, or software development.
- Experience responding to or handling major cyber security incidents and following common response frameworks.
- Experience within the gaming industry providing security operations support to game releases, game infrastructure monitoring and live game operations.
- Strong appreciation of the cyber threat landscape and attacker tactics, techniques and procedures.
- Experience developing operational processes and playbooks.
- Ability to remain composed and effective during high-pressure situations.
- Clear focus on coaching, mentoring and development of staff.
- Effective communication skills with non-technical stakeholders and executives.
- Flexibility to work out-of-office hours, when necessary, in response to incidents.
- Ability to manage tasks and priorities effectively, with attention to detail.
- Self-motivated and comfortable taking ownership of decisions, with support from the team.
- SIEM engineering (especially Elastic Security)
- Microsoft Defender E5
- Google Cloud Platform (GCP) or similar cloud infrastructure platforms
- Infrastructure automation (Terraform, Ansible, Chef or Puppet)
- Scripting, log analysis and dashboard creation
- AI literacy and a desire to continuously learn and develop.