At a Glance
- Tasks: Lead IT operations and security, ensuring stability and compliance in a global insurance environment.
- Company: Dynamic financial organisation based in the heart of London.
- Benefits: Competitive salary, hybrid work model, and comprehensive benefits package.
- Other info: Opportunity for career growth and to work with cutting-edge technologies.
- Why this job: Drive transformative change and enhance cybersecurity in a fast-paced tech landscape.
- Qualifications: 10+ years in IT infrastructure and security, ideally in banking or insurance.
The predicted salary is between 85000 - 95000 £ per year.
In summary, the Client is looking to recruit an all‑round individual with expert knowledge and hands‑on experience of IT Infrastructure coupled with Security, Compliance & Risk Management. You must have upwards of 10 years hands‑on expertise in IT Infrastructure combined with Security and Risk – ideally from within the banking or insurance sector.
The IT Operational Platform and Security Lead is responsible for overseeing the organisation’s IT operations, ensuring the stability, continuity, security, and efficiency of its technology platforms within a global commercial insurance environment. While Microsoft technologies (Microsoft 365, Azure, Exchange Online) form a core part of the infrastructure, the role also encompasses broader enterprise IT systems, multi‑layered networking, security, data management, and third‑party platforms that support global business operations and the associated applications estate.
The role requires a proactive leader who can drive IT operational excellence, manage security risks, focus on continual service improvement, drive transformational delivery projects, and work effectively with internal stakeholders and third‑party vendors to deliver high‑quality Global IT services. Working in line with the Architecture defined IT principle of a “buy before build” environment, the individual will need to ensure that outsourced and cloud‑based services are robust, cost‑effective, and aligned with business needs and the Strategic IT vision.
They will also play a key role in enhancing cybersecurity, protecting data and systems, driving transformative operational change, enhancing IT processes and ensuring compliance with governance bodies and industry regulations. Due to the nature of the role, complexity of the estate, current transformation activities and team size, the role requires the functional capability and proficiency to technically augment the team capabilities (when required) and have a detailed knowledge of technical IT support roles/services as a requirement, across multiple technical areas.
Security, Compliance & Risk Management- Define and enforce cloud security policies, identity management, and access controls to protect systems, networks, and data.
- Oversee the adoption of zero‑trust security principles to enhance protection across cloud platforms.
- Manage identity and access management (IAM) in a cloud‑first environment, including Azure AD, MFA, Conditional Access, SSO, and Privileged Access Management (PAM).
- Lead threat monitoring, detection, and response using cloud‑native security solutions such as Microsoft Defender, Sentinel, and SIEM platforms.
- Ensure compliance with cloud security frameworks and regulatory requirements (ISO 27001, NIST, GDPR, SOC2, FCA).
- Conduct regular security risk assessments, penetration tests, and vulnerability management across cloud services.
- Oversee endpoint security, cloud network and API security for robust protection across all assets.
- Define, manage and maintain accurate DR and BCP plans for the infrastructure area with biannual tests.
- Microsoft Azure Infrastructure design and administration, including topology, Azure networking, services, and component knowledge.
- Microsoft AD (Entra), Server and SQL experience.
- O365 administration and design.
- Global Software Patching and estate management via Intune.
- Firewall (Azure, CheckPoint and Cloudflare), DNS, VPN, WIFI and Local Area Network design & administration experience.
- Software Defined Networking (Cisco, Meraki, Versa).
- Microsoft 365 & Azure: Strong experience managing Microsoft 365 (Exchange, SharePoint, Teams), Azure cloud infrastructure, and security tools such as Microsoft Defender and Sentinel.
- Security & Compliance: Deep knowledge of security frameworks (ISO 27001, NIST, CIS), compliance requirements (GDPR, SOC2), and risk management best practices.
- Identity & Access Management (IAM): Expertise in Azure AD, MFA, Conditional Access, Single Sign‑On (SSO), and Privileged Access Management (PAM).
- Threat Management & Incident Response: Ability to detect, respond to, and mitigate cyber threats using SIEM, endpoint security, and vulnerability management tools.
- Networking & Infrastructure Security: Understanding of firewalls, VPNs, SD‑WAN, DNS security, endpoint protection, and cloud security controls.
- IT Service Management & Automation: Experience implementing ITIL‑based service management, automating operational tasks, and optimising service delivery.
- IT Operations & Service Continuity: Ability to ensure IT systems are highly available, resilient, and fit for purpose, with a strong focus on business continuity and disaster recovery.
- Supplier & Vendor Management: Experience managing third‑party IT vendors, MSPs, and SaaS providers, ensuring service levels, performance, and cost‑effectiveness.
- Project Leadership & Change Management: Ability to lead technology projects, system upgrades, and platform migrations, ensuring smooth execution and minimal business disruption.
- Process Improvement & Automation: Strong analytical mindset to identify inefficiencies, automate workflows, and enhance security controls.
- Problem‑Solving & Decision‑Making: Capable of making informed decisions and resolving complex IT issues in a fast‑paced environment.
- Stakeholder Engagement: Ability to communicate effectively with technical and non‑technical stakeholders, including senior leadership and business users.
- Resilience & Adaptability: Comfortable working in an evolving technology landscape, with a proactive and security‑first approach.
The Client is a financial organisation based in the City of London. This is a hybrid position with 3 days in the office. Must have a Bachelor’s degree in IT or similar. The salary for this role will be in the range £85K - £95K plus Benefits.
IT Operations and Security Lead in London employer: Onyx-Conseil
As a leading financial organisation located in the heart of the City of London, we pride ourselves on fostering a dynamic and inclusive work culture that prioritises employee growth and development. Our commitment to innovation and excellence in IT operations and security is matched by our competitive benefits package, which includes flexible working arrangements and opportunities for professional advancement, making us an exceptional employer for those seeking a meaningful career in a global commercial insurance environment.
StudySmarter Expert Advice🤫
We think this is how you could land IT Operations and Security Lead in London
✨Tip Number 1
Network like a pro! Get out there and connect with folks in the industry, especially those in banking or insurance. Attend meetups, webinars, or even just grab a coffee with someone who’s already in the role you want.
✨Tip Number 2
Show off your skills! When you get the chance to chat with potential employers, be ready to discuss specific projects you've led or challenges you've overcome in IT operations and security. Real-life examples can make you stand out.
✨Tip Number 3
Don’t forget to follow up! After interviews or networking events, shoot a quick thank-you email. It shows your enthusiasm and keeps you on their radar. Plus, it’s a great way to reiterate your interest in the role.
✨Tip Number 4
Apply through our website! We’ve got loads of opportunities that might be perfect for you. Plus, applying directly can sometimes give you an edge over other candidates. So, don’t hesitate!
We think you need these skills to ace IT Operations and Security Lead in London
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the role of IT Operations and Security Lead. Highlight your experience with Microsoft technologies, security frameworks, and risk management. We want to see how your skills align with what we're looking for!
Showcase Your Leadership Skills:Since this role requires a proactive leader, don’t forget to showcase your leadership experience. Share examples of how you've driven IT operational excellence or managed teams in previous roles. We love seeing candidates who can lead and inspire!
Be Clear and Concise:When writing your application, keep it clear and concise. Use bullet points where possible to make it easy for us to read. We appreciate straightforward communication that gets to the point without fluff!
Apply Through Our Website:We encourage you to apply through our website for the best chance of getting noticed. Make sure to include your CV in Word format along with your salary expectations and notice period. We can't wait to hear from you!
How to prepare for a job interview at Onyx-Conseil
✨Know Your Tech Inside Out
Make sure you brush up on your knowledge of Microsoft Azure, Microsoft 365, and security frameworks like ISO 27001 and NIST. Be ready to discuss your hands-on experience with these technologies, as well as any specific projects you've led that demonstrate your expertise.
✨Showcase Your Leadership Skills
As an IT Operations and Security Lead, you'll need to demonstrate your ability to lead teams and manage projects. Prepare examples of how you've successfully driven transformational change or improved IT processes in previous roles, especially in a banking or insurance context.
✨Understand Compliance and Risk Management
Familiarise yourself with compliance requirements such as GDPR and SOC2, and be prepared to discuss how you've managed security risks in past positions. Highlight any experience you have with conducting security assessments or implementing zero-trust security principles.
✨Engage with Stakeholders
Communication is key! Be ready to explain complex technical concepts to non-technical stakeholders. Think of examples where you've effectively engaged with senior leadership or business users to ensure alignment on IT strategies and initiatives.