Key Responsibilities
- Own and run the SIEM, EDR and vulnerability management estate, driving detection, triage and remediation against agreed SLAs
- Manage identity, DLP and cloud security controls across Microsoft Entra ID, Purview, AWS and Azure, keeping the estate compliant and hardened
- Lead technical response, containment and recovery for security incidents, escalating material incidents to the Head of Technology and the Information Security Officer
- Investigate and resolve insider security events, escalating outcomes to the Information Security Officer for risk assessment and governance
- Manage the MSSP and MSP relationships on day-to-day technical security matters, escalating where needed
- Coordinate execution of the penetration testing programme, manage suppliers and drive remediation to closure
- Drive threat hunting and detection engineering to improve the bank's proactive security posture beyond reactive alert response
- Own the Information Security roadmap and delivery of security improvements, partnering with the Information Security Officer on review, challenge and governance of the Information Security strategy and risk appetite prior to committee and Board submission
- Produce technical security metrics and reporting that support board, committee and regulatory requirements, partnering with the Information Security Officer to evidence audit and risk assurance
Corporate Responsibilities
-
Read and follow all relevant company policies and procedures
-
Adhere to all risk-related responsibilities applicable to your role, as set out in the Risk Management Policy
-
Abide by all compliance and financial crime related policies, procedures and reporting obligations applicable to your role
- A Material Risk Taker for the bank you will need to act in accordance with regulatory expectations of a Certified individual
Required Skills & Experience
- Relevant industry certification (e.g. CompTIA Security+, Microsoft SC-200) or equivalent demonstrable hands-on experience
- Proven hands-on experience in a SOC analyst, security engineer or technical security role, in either a senior or lead position and within financial services or another regulated sector; experience running vulnerability management programmes and handling technical incident response end to end
- Strong working knowledge of a SIEM platform; practical EDR/XDR experience; Microsoft 365 and Entra ID security controls (Conditional Access, PIM, Defender suite); scripting or automation (PowerShell or Python); network security fundamentals; cloud security in AWS and Azure
- CISSP, CISM, GIAC (GCIH, GCIA or GSEC), CREST, Tenable / Sentinel One / Google SecOps vendor accreditations
- Experience in a regulated UK financial services environment; MSSP / supplier management experience
- Google SecOps (Chronicle), Microsoft Defender suite depth, beyond the baseline EntraID knowledge, AWS security tooling such as Guard Duty, Cloud Security etc
Information Security Manager in Milton Keynes employer: Recognise Bank
Recognise Bank is an exceptional employer that prioritises employee well-being and professional growth, offering a competitive salary package alongside flexible hybrid working arrangements. Our collaborative work culture fosters innovation and encourages continuous learning, making it an ideal environment for those looking to excel in IT service delivery while maintaining a healthy work-life balance.