Cyber Security Lead β (Entra ID, Defender, Purview, SIEM, SOC, Cyber Essentials Plus, ISO 27001, NIST, CISSP, Hands-On, 3rd Party Management) β Permanent β Home Based
Please make sure you read the following details carefully before making any applications.
Position: Technical Cyber Security Lead
Location: Home Based (UK) with occasional travel
Salary: Β£55,000 to Β£65,000 + strong benefits
The short version:
A fast-growing UK business wants a hands-on security lead to own cyber security across the organisation. The official title is Manager, but this isn't a people management role. You'll manage suppliers and make the big calls, and you'll still spend a good chunk of your week in Defender, Entra ID and Purview yourself.
If you're tired of roles where security means chasing tickets for someone else's roadmap, this is worth a look. You'll be writing the roadmap.
Why this one is different:
Three things stand out to me about this role.
You pick the tools. The business has no fixed security stack. If you've spent years working around tools someone else chose, this is your chance to choose them. You'll assess what's in place, decide what stays, what goes and what comes in, and make the case for it.
You decide the SOC and SIEM model. Both are outsourced right now. Part of your brief is to work out whether that's the right setup long term or whether it should come in house. That means a proper look at cost, coverage, headcount and risk, followed by a recommendation the business will act on. Very few roles at this level give you that kind of decision.
You take the business through certification. Cyber Essentials Plus and ISO 27001 are both on the plan, and you'll lead them. If you've done it before, you'll know how much difference it makes when the person running it is also the person fixing the controls.
The setup:
Microsoft-centric estate: M365, Entra ID, Active Directory, Defender, Purview, Azure, Windows endpoints and servers
Outsourced SOC, MDR and SIEM providers already in place
You'll work alongside the internal IT team and external security partners
The business has sites across the UK. You'll visit a couple of times a year to run security awareness sessions with staff in person. Otherwise you're fully remote.
What you'll actually be doing:
Hands-on security
Configuring, hardening and fixing things yourself across Entra ID, Purview and Defender
Finding and remediating weaknesses across identity, endpoints, email, network, servers, apps and cloud
Owning vulnerability management from discovery through to resolution
Threat hunting and security analysis using the telemetry and threat intel available
Writing practical hardening standards that people will follow
Spotting where monitoring, investigation and reporting can be automated or scripted
Incidents and suppliers
Leading the technical response to incidents: investigation, evidence, containment, recovery and root cause
Managing the outsourced SOC, MDR and SIEM providers and reviewing alerts, incidents and trends
Challenging providers when the quality isn't there. This role needs someone who won't just accept the monthly report.
Coordinating pen tests and independent security assessments
Direction and governance
Building and running the security improvement roadmap
Leading Cyber Essentials Plus and ISO 27001 certification
Putting together the insource vs outsource business case for SOC and SIEM, costs included
Choosing the security technologies the business uses going forward
Writing and maintaining security policies and procedures
Building security into IT projects, new technology and supplier onboarding
Assessing third-party and technology risk
Reporting on risk, incidents and progress in plain English to people who aren't technical
What they're looking for:
Strong hands-on security experience in a Microsoft environment. You'll be expected to work in Defender, Entra ID and Purview yourself, not just oversee them.
Experience managing outsourced SOC, MDR or SIEM services, and the confidence to challenge them
You've taken a business through Cyber Essentials Plus and/or ISO 27001
Incident response experience, leading or supporting investigations
Good grounding in infrastructure and networking: AD, DNS, virtualisation, cloud, firewalls
Working knowledge of frameworks such as NIST CSF or CIS Controls
You can explain risk to a board member or a frontline team without losing either of them
Pragmatic. xohmjla You know the difference between perfect security and proportionate security.
The package:
Β£55,000 to Β£65,000 depending on experience
Fully remote, with occasional travel to sites (expenses covered)
5% matched pension
Private medical insurance and a Bupa health cash plan
Life assurance at 4x salary
25 days' holiday plus bank holidays, with the option to buy an extra week
Electric car scheme
Ongoing learning and development, including certification support
Cyber Security Manager in Manchester employer: Charles Simon Associates Ltd
At Charles Simon Associates, we pride ourselves on being an exceptional employer, offering a dynamic remote work environment that fosters collaboration and innovation. Our commitment to employee growth is evident through continuous learning opportunities and the chance to work on cutting-edge infrastructure projects, ensuring that our team members are always at the forefront of technology. Join us for a rewarding experience where your expertise will be valued and your contributions will make a significant impact.
Contact Details:
Charles Simon Associates Ltd Recruitment Team