At a Glance
- Tasks: Lead IT operations and security, ensuring stability and compliance in a dynamic environment.
- Company: Join a leading financial organisation in the heart of London.
- Benefits: Competitive salary, hybrid work model, and comprehensive benefits package.
- Other info: Opportunity for career growth and to work with cutting-edge technologies.
- Why this job: Make a real impact on IT security and operations in a global insurance setting.
- Qualifications: 10+ years in IT infrastructure and security, ideally in banking or insurance.
The predicted salary is between 85000 - 95000 € per year.
In summary, the Client is looking to recruit an all‑round individual with expert knowledge and hands‑on experience of IT Infrastructure coupled with Security, Compliance & Risk Management. You must have upwards of 10 years hands‑on expertise in IT Infrastructure combined with Security and Risk – ideally from within the banking or insurance sector.
The IT Operational Platform and Security Lead is responsible for overseeing the organisation’s IT operations, ensuring the stability, continuity, security, and efficiency of its technology platforms within a global commercial insurance environment. While Microsoft technologies (Microsoft 365, Azure, Exchange Online) form a core part of the infrastructure, the role also encompasses broader enterprise IT systems, multi‑layered networking, security, data management, and third‑party platforms that support global business operations and the associated applications estate.
The role requires a proactive leader who can drive IT operational excellence, manage security risks, focus on continual service improvement, drive transformational delivery projects, and work effectively with internal stakeholders and third‑party vendors to deliver high‑quality Global IT services. Working in line with the Architecture defined IT principle of a “buy before build” environment, the individual will need to ensure that outsourced and cloud‑based services are robust, cost‑effective, and aligned with business needs and the Strategic IT vision.
They will also play a key role in enhancing cybersecurity, protecting data and systems, driving transformative operational change, enhancing IT processes and ensuring compliance with governance bodies and industry regulations. Due to the nature of the role, complexity of the estate, current transformation activities and team size, the role requires the functional capability and proficiency to technically augment the team capabilities (when required) and have a detailed knowledge of technical IT support roles/services as a requirement, across multiple technical areas.
Security, Compliance & Risk Management- Define and enforce cloud security policies, identity management, and access controls to protect systems, networks, and data.
- Oversee the adoption of zero‑trust security principles to enhance protection across cloud platforms.
- Manage identity and access management (IAM) in a cloud‑first environment, including Azure AD, MFA, Conditional Access, SSO, and Privileged Access Management (PAM).
- Lead threat monitoring, detection, and response using cloud‑native security solutions such as Microsoft Defender, Sentinel, and SIEM platforms.
- Ensure compliance with cloud security frameworks and regulatory requirements (ISO 27001, NIST, GDPR, SOC2, FCA).
- Conduct regular security risk assessments, penetration tests, and vulnerability management across cloud services.
- Oversee endpoint security, cloud network and API security for robust protection across all assets.
- Define, manage and maintain accurate DR and BCP plans for the infrastructure area with biannual tests.
- Microsoft Azure Infrastructure design and administration, including topology, Azure networking, services, and component knowledge.
- Microsoft AD (Entra), Server and SQL experience.
- O365 administration and design.
- Global Software Patching and estate management via Intune.
- Firewall (Azure, CheckPoint and Cloudflare), DNS, VPN, WIFI and Local Area Network design & administration experience.
- Software Defined Networking (Cisco, Meraki, Versa).
- Microsoft 365 & Azure: Strong experience managing Microsoft 365 (Exchange, SharePoint, Teams), Azure cloud infrastructure, and security tools such as Microsoft Defender and Sentinel.
- Security & Compliance: Deep knowledge of security frameworks (ISO 27001, NIST, CIS), compliance requirements (GDPR, SOC2), and risk management best practices.
- Identity & Access Management (IAM): Expertise in Azure AD, MFA, Conditional Access, Single Sign‑On (SSO), and Privileged Access Management (PAM).
- Threat Management & Incident Response: Ability to detect, respond to, and mitigate cyber threats using SIEM, endpoint security, and vulnerability management tools.
- Networking & Infrastructure Security: Understanding of firewalls, VPNs, SD‑WAN, DNS security, endpoint protection, and cloud security controls.
- IT Service Management & Automation: Experience implementing ITIL‑based service management, automating operational tasks, and optimising service delivery.
- IT Operations & Service Continuity: Ability to ensure IT systems are highly available, resilient, and fit for purpose, with a strong focus on business continuity and disaster recovery.
- Supplier & Vendor Management: Experience managing third‑party IT vendors, MSPs, and SaaS providers, ensuring service levels, performance, and cost‑effectiveness.
- Project Leadership & Change Management: Ability to lead technology projects, system upgrades, and platform migrations, ensuring smooth execution and minimal business disruption.
- Process Improvement & Automation: Strong analytical mindset to identify inefficiencies, automate workflows, and enhance security controls.
- Problem‑Solving & Decision‑Making: Capable of making informed decisions and resolving complex IT issues in a fast‑paced environment.
- Stakeholder Engagement: Ability to communicate effectively with technical and non‑technical stakeholders, including senior leadership and business users.
- Resilience & Adaptability: Comfortable working in an evolving technology landscape, with a proactive and security‑first approach.
The Client is a financial organisation based in the City of London. This is a hybrid position with 3 days in the office. Must have a Bachelor’s degree in IT or similar. The salary for this role will be in the range £85K - £95K plus Benefits.
IT Operations and Security Lead employer: Onyx-Conseil
As a leading financial organisation located in the heart of the City of London, we pride ourselves on fostering a dynamic and inclusive work culture that prioritises employee growth and development. Our commitment to innovation and excellence is reflected in our comprehensive benefits package, which includes competitive salaries, flexible working arrangements, and opportunities for professional advancement within a collaborative environment. Join us to be part of a transformative journey in IT operations and security, where your expertise will directly contribute to enhancing our global business operations.
StudySmarter Expert Advice🤫
We think this is how you could land IT Operations and Security Lead
✨Tip Number 1
Network like a pro! Attend industry events, webinars, or local meetups related to IT operations and security. Connecting with professionals in the banking or insurance sector can open doors and give you insider info on job opportunities.
✨Tip Number 2
Show off your skills! Create a personal website or LinkedIn profile that highlights your expertise in Microsoft Azure, security frameworks, and risk management. This is your chance to showcase projects you've led or challenges you've overcome.
✨Tip Number 3
Prepare for interviews by brushing up on common questions related to IT operations and security. Be ready to discuss your hands-on experience with cloud security policies and incident response strategies. Practice makes perfect!
✨Tip Number 4
Don’t forget to apply through our website! We’re always on the lookout for talented individuals like you. Plus, it’s a great way to ensure your application gets the attention it deserves.
We think you need these skills to ace IT Operations and Security Lead
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the role of IT Operations and Security Lead. Highlight your experience with Microsoft technologies, security frameworks, and risk management, as these are key for us.
Showcase Your Leadership Skills:We’re looking for a proactive leader! In your application, emphasise your experience in managing teams, driving operational excellence, and leading transformational projects. This will help us see your fit for the role.
Be Specific About Your Experience:When detailing your past roles, be specific about your hands-on experience with IT infrastructure and security. Mention any relevant certifications or frameworks you’ve worked with, like ISO 27001 or NIST, to catch our eye.
Apply Through Our Website:Don’t forget to apply through our website! It’s the best way for us to receive your application and ensures you’re considered for this exciting opportunity. We can’t wait to hear from you!
How to prepare for a job interview at Onyx-Conseil
✨Know Your Tech Inside Out
Make sure you brush up on your knowledge of Microsoft Azure, Microsoft 365, and security frameworks like ISO 27001 and NIST. Be ready to discuss your hands-on experience with these technologies and how you've applied them in real-world scenarios, especially in the banking or insurance sectors.
✨Showcase Your Leadership Skills
As an IT Operations and Security Lead, you'll need to demonstrate your ability to lead teams and manage projects. Prepare examples of how you've successfully led technology projects or improved processes in previous roles. Highlight your experience in vendor management and stakeholder engagement.
✨Prepare for Scenario-Based Questions
Expect questions that assess your problem-solving skills and decision-making abilities. Think of specific situations where you've had to manage security risks or respond to incidents. Use the STAR method (Situation, Task, Action, Result) to structure your answers effectively.
✨Understand the Company’s Vision
Research the company’s strategic IT vision and how they approach cloud services and security. Be prepared to discuss how your experience aligns with their goals, particularly around operational excellence and compliance with industry regulations. This shows you're not just a fit for the role, but also for the company's culture.