At a Glance
- Tasks: Lead and evolve enterprise cybersecurity operations, managing incident response and security tools.
- Company: Join a leading tech firm focused on innovative cybersecurity solutions.
- Benefits: Enjoy flexible remote work, comprehensive health plans, and generous referral bonuses.
- Why this job: Make a real impact in cybersecurity while developing your leadership skills.
- Qualifications: 6-9 years in security operations with hands-on incident response experience.
- Other info: Dynamic role with global team collaboration and excellent career growth opportunities.
The predicted salary is between 80000 - 100000 ÂŁ per year.
Location: United Kingdom â London (Hybrid or Remote)
Role Overview:
Nasuni is seeking a deeply technical and operationally rigorous Manager, Security Operations to lead and evolve our enterprise cybersecurity operations program. Reporting to the Chief Information Security Officer, this role owns internal security operations across detection, response, identity security, vulnerability management, and operational defense across cloud, endpoint, and hybrid environments. You will lead a global security operations function responsible for incident response, SIEM/SOAR engineering, identity governance, endpoint and email security, and proactive threat detection. This is a handsâon, playerâcoach leadership role, managing a small but growing team across regions, including the US, UK and India. This role requires someone who can personally lead highâseverity incidents endâtoâend, while also building and improving the systems, processes, and team around them. This role includes participation in an onâcall rotation and requires availability during highâseverity incidents, including evenings or weekends as needed. You will act as a key escalation point in partnership with a 24x7 monitoring vendor.
Level & Scope Definition:
This role leads enterpriseâwide security operations and incident response across corporate systems and cloud infrastructure (primarily AWS). The Manager defines operational security standards, drives detection quality improvements, leads automation initiatives, and serves as the primary escalation authority for highâseverity incidents.
This Is a PlayerâCoach Role:
- With direct people leadership (small, distributed team)
- Hands-on technical ownership (incident response, detection, tooling)
- Responsibility for centralizing and improving visibility across multiple security tools and signals
Success In This Role Is Defined By:
- Measurable reduction in risk exposure
- Improved response times (MTTD / MTTR)
- Strong crossâfunctional coordination across regions (US, UK, India)
- Resilient, scalable security operations execution
Key Responsibilities:
Security Operations Leadership:- Lead, mentor, and develop a highâperforming, globally distributed security operations team
- Define operational standards, secure configuration baselines, and detection strategies
- Own the global cybersecurity onâcall model, escalation procedures, and vendor interaction model
- Drive a culture of operational accountability, automation, and detection excellence
- Partner with GRC stakeholders to support audit and compliance requirements (SOC2, ISO, etc.)
- Own enterprise cybersecurity operations across endpoint, identity, email, network, and cloud platforms (AWS primarily)
- Lead EDR operations including threat detection, investigation, containment, and response (e.g., SentinelOne)
- Own and evolve SIEM strategy, detection engineering, and integration roadmap
- Design and maintain SOAR automation and response playbooks
- Define and enforce identity governance, conditional access, and privileged access controls (Entra ID / M365)
- Evaluate and optimize security tooling, integrations, and telemetry quality
- Lead and own incident response from triage through resolution as escalation authority
- Continuously improve incident response plans, playbooks, and runbooks
- Coordinate with MDR partners and internal stakeholders during active incidents
- Conduct postâincident reviews and drive systemic remediation
- Improve detection quality, reduce alert fatigue, and optimize response metrics
- Defend against modern threats including phishing, BEC, malicious attachments, OAuth abuse, and AIâgenerated attack techniques
- Own the endâtoâend vulnerability lifecycle across cloud, endpoint, and infrastructure assets
- Drive visibility and prioritization across multiple tools (e.g., Wiz, Rapid7, endpoint telemetry)
- Lead efforts to centralize vulnerability insights across platforms and improve riskâbased prioritization
- Uphold remediation SLAs and drive crossâfunctional accountability
- Lead patch validation and automation initiatives
- Define and report cybersecurity KPIs and executive dashboards
- Implement automation to improve investigation speed, response consistency, and reporting quality
- Maintain operational documentation, SOPs, and architecture baselines
- Leverage automation and AIâassisted tooling to improve detection quality and operational efficiency
Required Qualifications:
- 6â9+ years of experience in enterprise security operations
- 2â4+ years leading security operations teams or programs
- Proven experience personally leading incident response endâtoâend (not limited to alerting or support roles)
- Handsâon expertise with SIEM engineering, detection tuning, and alert optimization
- SOAR playbook development and automation
- EDR platforms (e.g., SentinelOne) and endpoint detection/response
- Enterprise email security controls and phishing defence
- Identity security (Entra ID / Microsoft 365)
- Strong experience securing cloud environments (AWS required; Azure/GCP exposure a plus)
- Experience operating within an onâcall rotation and escalation model
- Experience working with MDR or managed security partners
- Strong communication and decisionâmaking skills during highâseverity incidents
- Experience using scripting, automation, or query languages (e.g., Python, KQL) to improve workflows
Preferred Qualifications:
- Experience centralizing or integrating multiple security tools into a unified operational view
- Experience with vulnerability management platforms (e.g., Wiz, Rapid7)
- Familiarity with GRC programs (SOC 2, ISO 27001) and audit support
- Experience operating across globally distributed teams and time zones
- CISSP or equivalent practical experience
Ideal Qualifications:
- Experience building or maturing a security operations function in a cloudâfirst environment
- Demonstrated success improving detection quality, reducing alert fatigue, and improving MTTR
- Experience supporting M&A integration or scaling security programs
- Strong ability to balance handsâon technical depth with team leadership in a playerâcoach model
AI Competency Expectations:
- Experience defending against AIâenabled phishing and social engineering attacks
- Experience leveraging automation or AIâassisted tooling to improve detection and response workflows
- Ability to assess emerging risks in identity, email, and OAuth ecosystems driven by AIâenabled threats
Ideal Candidate Profile:
- Remain technically handsâon while leading a team
- Be comfortable owning and leading highâseverity incidents
- Value automation, detection precision, and measurable security outcomes
- Prefer operational ownership over complianceâonly roles
- Can operate effectively across global teams and time zones
Benefits:
- Best in class employee onboarding and training
- Comprehensive health, dental and vision plans
- Life and disability insurance
- Retirement plan
- Generous employee referral bonuses
- Flexible remote work policy
- Collaborative workspaces
Manager, Security Operations in London employer: Nasuni
Contact Detail:
Nasuni Recruiting Team
StudySmarter Expert Advice đ¤Ť
We think this is how you could land Manager, Security Operations in London
â¨Tip Number 1
Network like a pro! Reach out to your connections in the cybersecurity field, especially those who work at companies you're interested in. A friendly chat can lead to insider info about job openings or even a referral.
â¨Tip Number 2
Prepare for interviews by brushing up on your technical skills and incident response strategies. Be ready to discuss real-life scenarios where youâve led high-severity incidents. Show them youâre not just a manager but also a hands-on leader!
â¨Tip Number 3
Donât underestimate the power of follow-ups! After an interview, send a quick thank-you note to express your appreciation. It keeps you fresh in their minds and shows your enthusiasm for the role.
â¨Tip Number 4
Check out our website for the latest job openings! Weâre always looking for talented individuals to join our team. Applying directly through our site gives you a better chance to stand out!
We think you need these skills to ace Manager, Security Operations in London
Some tips for your application đŤĄ
Tailor Your CV: Make sure your CV is tailored to the role of Manager, Security Operations. Highlight your experience in cybersecurity operations, incident response, and team leadership. We want to see how your skills align with what we're looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about security operations and how your background makes you the perfect fit for our team. Keep it engaging and relevant to the job description.
Showcase Your Technical Skills: Donât forget to highlight your hands-on technical expertise, especially with SIEM, SOAR, and EDR platforms. We love seeing specific examples of how you've tackled high-severity incidents or improved detection quality in your previous roles.
Apply Through Our Website: We encourage you to apply directly through our website. Itâs the best way for us to receive your application and ensures youâre considered for the role. Plus, it shows youâre keen on joining our team at StudySmarter!
How to prepare for a job interview at Nasuni
â¨Know Your Stuff
Make sure you brush up on your technical knowledge, especially around SIEM engineering, EDR platforms, and incident response. Be ready to discuss specific tools and strategies you've used in the past, as this role demands hands-on expertise.
â¨Show Your Leadership Skills
Prepare examples of how you've led teams or projects in the past. This role is a player-coach position, so highlight your ability to mentor others while also being involved in the technical side of things.
â¨Be Ready for Scenario Questions
Expect to be asked about high-severity incidents you've managed. Think through your approach to triage, resolution, and post-incident reviews. Theyâll want to see how you handle pressure and make decisions in critical situations.
â¨Understand the Companyâs Security Landscape
Research Nasuni's security operations and their cloud infrastructure, particularly AWS. Familiarise yourself with their current challenges and think about how you can contribute to improving their security posture.