Security Platform Engineering Manager

Security Platform Engineering Manager

Full-Time No working from home possible
ISS

At a Glance

  • Tasks: Lead the security platform engineering team and manage cutting-edge security tools.
  • Company: Join a FTSE 100 company focused on cyber security innovation.
  • Benefits: Enjoy a competitive salary, car allowance, health benefits, and pension contributions.
  • Other info: Dynamic work environment with opportunities for growth and transformation.
  • Why this job: Make a real impact in cyber security while working with top-tier technology.
  • Qualifications: 8+ years in cyber security with hands-on experience in security platforms.

Title: Security Platform Engineering Manager

Reference No: 2159

Company: FTSE 100

Reports to Deputy Group CISO

Location: London

Working Pattern 37.5 hours per week, Monday - Friday. Location: London/Peterborough, with potential travel to divisional sites as required by advisory engagements (hybrid working arrangements in place).

Salary: £84,000 - £100,000

Benefits Car allowance, Bupa, Matched pension contributions.

The Role

The Group Cyber Security (GCS) team is responsible for managing cyber risk appropriately across the Group and has recently refreshed its cyber strategy, with a renewed focus on embedding cyber security as part of the culture and DNA. The Group operates a highly federated business model spanning 11 divisions and over 50 countries, and the cyber strategy has been designed to build materially improved security capabilities whilst working with a divisional focus.

It is an exciting time to join GCS. We are in a period of significant investment, with a multi-year transformation programme under way to build new security capabilities at pace. GCS is responsible for setting the Group cyber standard, measuring compliance against it across all the businesses, and delivering a portfolio of centrally managed security services that divisions can rely on.

A central challenge in a federated Group is translation: the work of turning Group-level standards, strategy, and expertise into something that actually lands and works inside each division’s unique context. That is precisely the purpose of the Cyber Advisory Services function. It bridges Group Cyber Security and the divisions – providing the technical advice, subject-matter expertise, specialist project support, and flexible consulting resource that enables divisions to understand, adopt, implement, leverage and operationalise the Group cyber standard.

Role Summary

Reporting to the Deputy Group CISO, the Security Platform Engineering Manager is the technical owner and custodian of the Group’s security tooling portfolio. Where the Cyber Architecture function sets the direction and standards for how security should be built, this role is responsible for what happens next: ensuring that the security platforms we operate are configured correctly, exploited fully, evolving continuously, and delivering genuine security outcomes and return on investment. The role demands a particular mindset: a genuine passion for the tools under its care. The ideal person does not treat security products as black boxes to be deployed and forgotten – they are curious, hands-on, and proactive. They understand the full capability of each platform, stay ahead of vendor roadmaps, identify where a product’s untapped potential can solve a real problem, and build the relationships with vendors needed to get the most from every licence. The platforms in scope include Microsoft Defender (across the M365 Defender suite), Zscaler, Qualys, Abnormal Security, and Axonius, alongside other centrally managed security technologies as the portfolio evolves. The Security Platform Engineering Manager works in close partnership with the Security Operations Centre and operations teams – ensuring platforms are tuned to support effective detection and response – with the Cyber Architecture Manager to align platform development to the architectural roadmap, and with the Group CTO function to ensure that security platform plans are integrated into the broader technology strategy. The role leads a small, focused team of permanent engineers and flexible resources, deploying expertise precisely where it is needed.

Role Responsibilities / Accountabilities

Security Platform Ownership & Technical Stewardship

  • Act as the technical product owner for each platform in the GCS security tooling portfolio – including Microsoft Defender (M365 Defender suite), Zscaler, Qualys, Abnormal Security, and Axonius – taking personal accountability for their health, configuration, and ongoing development.
  • Maintain deep, current, and expert-level technical knowledge of each platform under management: understand not just what each product does today, but what it is capable of, what is coming in the vendor roadmap, and what problems it could solve, that it is not yet being used to address.
  • Ensure that each platform is configured to its optimal state for our environment: policies are correctly defined and enforced, licensable features that deliver security value are enabled and exploited, and no significant capability is left unused without a deliberate and documented reason.
  • Proactively identify opportunities where a platform’s existing or emerging capability can be matched to a specific business or security problem – thinking creatively about novel applications of the tools already in the estate before new expenditure is considered.
  • Technical Configuration, Policy & Security Standards Alignment
  • Own and maintain the technical configuration baselines for all platforms in scope, ensuring configurations are documented, version-controlled, change-managed, and auditable; define platform-level policy configurations that translate Group cyber technical standards into enforceable product settings.
  • Work closely with the Cyber Architecture Manager to ensure that platform configurations are consistent with the Group’s cyber enterprise architecture, reference patterns, and technical standards; flag and resolve any divergence between as-built and as-designed states.
  • Provide expert technical advice to divisional IT and security teams on the configuration and deployment of centrally managed security platforms within their environments, ensuring local implementations meet Group standards while accommodating legitimate divisional requirements.

Platform Roadmap Development & Lifecycle Management

  • Develop and own a rolling platform development roadmap for each product in the portfolio; plan the evolution of each platform in line with the Group’s cyber strategy, the vendor’s product roadmap, and emerging operational requirements from the SOC and business.
  • Lead platform replacement or consolidation assessments when a product is approaching end of life, failing to meet evolving requirements, or where a better-fit alternative exists; work with the Cyber Architecture Manager to develop the business case and transition plan.
  • Ensure that platform roadmaps are aligned and integrated with the Group CTO technology strategy and the GCS architecture roadmap; surface dependencies, conflicts, and opportunities early through structured engagement with both functions.
  • Maintain a clear view of licence entitlements across all platforms; ensure the Group are consuming the features it is paying for, identify capability gaps and overlaps, and provide well-evidenced recommendations on licence optimisation and renewal decisions.

Vendor Engagement, Partnership & Return on Investment

  • Build and maintain strong, productive working relationships with the technical and commercial teams at each strategic vendor; position the Group as an engaged, informed customer that vendors want to invest in – gaining early access to roadmap briefings, beta features, escalation paths, and best-practice guidance.
  • Ensure the organisation extracts maximum value from every security platform investment; track and evidence return on investment, measuring security outcomes – not just uptime or feature counts – and presenting findings clearly to the Deputy CISO and senior stakeholders.
  • Work with vendors to address product gaps and deficiencies; elevate issues effectively, influence vendor product direction through formal feedback channels where appropriate, and ensure support and professional services engagements deliver value.
  • Provide commercially aware input to contract renewals, procurement decisions, and licence negotiations, drawing on operational evidence and an objective assessment of each platform’s value.

SOC, Operations & Stakeholder Alignment

  • Work hand-in-glove with the SOC and security operations teams, ensuring that platforms are tuned and configured to support effective detection, investigation, and response; act as the primary technical escalation point for platform-related operational issues that affect SOC effectiveness.
  • Participate actively in the platform and tooling prioritisation process alongside the SOC, operations, architecture, and GCS leadership teams; ensure that engineering effort is directed at the changes that will most improve the security posture and operational effectiveness.
  • Maintain a structured engagement with the Group CTO function to ensure that security platform development plans are visible, understood, and integrated into the broader IT technology strategy and infrastructure roadmap; proactively surface platform interdependencies that span security and non-security technology.
  • Collaborate with the Cyber Architecture Manager to ensure that platform engineering activity is grounded in and consistent with the Group’s cyber enterprise architecture; participate in design authority processes and provide engineering-level input to architectural decisions.

Team Leadership & Resourcing

  • Lead, develop, and motivate a small, focused team of permanent security platform engineers and flexible resources drawn from the GCS resourcing desk; set clear expectations, foster a culture of technical excellence, and ensure each team member is growing their skills alongside the platforms they support.
  • Manage the deployment of engineering resource across the platform portfolio and project demand pipeline; prioritise workload intelligently, balance BAU platform health against transformation delivery, and deploy flexible resource where it adds most value.
  • Ensure that platform knowledge is not siloed in individuals; promote documentation, runbooks, and knowledge-sharing practices that make the team’s expertise resilient and accessible, and reduce dependency on key persons.
  • Transformation, Continuous Improvement & Innovation
  • Lead the engineering delivery component of the GCS transformation programme for platforms in scope; plan and execute platform deployments, upgrades, and capability enhancements with minimal disruption to the business and to SOC operations.
  • Champion a continuous improvement ethos within the team: regularly review platform configurations and performance against security outcomes, identify what is not working, and drive incremental improvement as a matter of routine rather than exception.
  • Stay current with developments in the security platform and product engineering landscape; bring relevant innovation and new thinking to the Deputy CISO and wider GCS leadership team in a structured, evidence-based way.

Experience

Experience, Knowledge, Skills & Attributes - Essential

  • 8+ years in cyber security, with significant hands-on experience in security platform engineering, security operations technology, or a comparable technical security role.
  • Demonstrable, deep technical expertise in at least two of the platform portfolio – Microsoft Defender / M365 Defender suite, Zscaler, Qualys, Abnormal Security, or Axonius – including practical configuration, policy management, and operational tuning experience.
  • Experience as a platform or product owner for a security technology at enterprise scale, including managing configuration baselines, licence entitlements, vendor relationships, and a forward-looking development roadmap.
  • Experience working in close operational partnership with a SOC or security operations function, with a clear understanding of how platform configuration directly affects detection quality, alert fidelity, and analyst effectiveness.
  • Experience managing or leading a small technical team, including line management of permanent staff and direction of contractor or flexible resources.
  • Experience managing vendor relationships for strategic security products, including participation in technical account reviews, escalation of product issues, and commercial input to renewal decisions.

Knowledge & Skills

  • Genuine technical curiosity and product passion: the ability and instinct to go beyond surface-level familiarity with a platform, understand its full capability depth, and think creatively about how its features can be applied to novel business or security problems.
  • Strong working knowledge of the Microsoft security stack, including Defender for Endpoint, Defender for Identity, Defender for Cloud Apps, Defender for Office 365, Sentinel integration patterns, and M365 security policy configuration.
  • Understanding of security platform integration patterns – including API connectivity, SIEM/SOAR data feeds, and automation workflows – and the ability to design and implement integrations that improve operational efficiency and detection capability.
  • Ability to communicate technical platform status, recommendations, and roadmap plans clearly to both technical peers and non-technical senior stakeholders; able to make the case for investment or change with evidence rather than opinion.
  • Commercially aware; understands the relationship between licence terms, feature availability, and security outcomes, and can engage constructively and knowledgeably in commercial conversations with vendors and procurement teams.

Qualifications

  • Degree-level education in computer science, information security, or a related technical discipline; or equivalent professional experience.
  • Relevant professional certification: CISSP, CISM, CompTIA Security+, or a vendor-specific advanced certification in one or more of the platforms in scope (e.g. Microsoft SC-200, SC-300, Zscaler ZCCA-IA/ZCCA-PA, or equivalent).

Experience

Experience, Knowledge, Skills & Attributes - Desirable

  • Experience in a large FMCG, food and beverage, retail, or FTSE-listed manufacturing organisation, with an appreciation of the breadth and complexity of securing a highly federated, multi-divisional estate.
  • Experience managing the full platform lifecycle from procurement through deployment, steady-state operation, and planned replacement or consolidation for an enterprise security product.
  • Prior experience as a technical lead or engineering manager within a managed SOC or MSSP environment, giving strong insight into how platform configuration decisions affect managed detection and response quality.
  • Experience participating in formal M365 E5 or enterprise security platform deployment programmes, including migration from legacy tooling and consolidation of overlapping capability.
  • Hands-on experience with security automation and orchestration: scripting (PowerShell, Python), API integrations between security platforms, or SOAR playbook development.

Knowledge & Skills

  • Familiarity with OT/ICS security monitoring tooling (e.g. Claroty) and an understanding of the particular challenges of extending enterprise security platform coverage into operational technology environments.
  • Understanding of CAASM (Cyber Asset Attack Surface Management) platforms such as Axonius and how they can be used to drive continuous controls visibility and improve the accuracy of the asset inventory underpinning security operations.
  • Understanding of identity security concepts – including Entra ID, conditional access policy design, privileged identity management, and their interaction with Defender and Zscaler configurations.
  • Awareness of the broader security technology estate – including DMARC Advisor and Fortinet – and the ability to consider platform engineering decisions in the context of the wider tool ecosystem rather than in isolation.

Qualifications

  • Advanced vendor certifications across multiple platforms in the portfolio (e.g. Microsoft SC-100, Zscaler ZCCP, Qualys certifications, or equivalent).
  • Membership of a recognised professional body (CIISec, BCS, ISACA, (ISC)²) is welcome.
#J-18808-Ljbffr

Security Platform Engineering Manager employer: ISS

At ISS, we pride ourselves on being a world-leading workplace and facility management company that values people at its core. Our commitment to employee growth is evident through our diverse and inclusive work culture, where every team member has the opportunity to develop their skills and make a meaningful impact. With a focus on service excellence and a strong safety culture, we offer a rewarding environment for Key Account Managers to thrive in, all while contributing to the success of our clients across various sectors.

ISS

Contact Details:

ISS Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Security Platform Engineering Manager

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including ISS, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through ISS

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at ISS. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Security Platform Engineering Manager

Technical Product Ownership
Security Platform Engineering
Microsoft Defender (M365 Defender suite)
Zscaler
Qualys
Abnormal Security
Axonius

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at ISS insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to ISS that you’re committed to staying ahead in the game.

How to prepare for a job interview at ISS

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at ISS to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at ISS.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.