At a Glance
- Tasks: Manage security operations and liaise with outsourced SOC providers in a dynamic environment.
- Company: Join The Openwork Partnership, a fast-paced and ambitious company committed to inclusivity.
- Benefits: Enjoy a competitive salary, bonus scheme, generous holiday, and flexible benefits.
- Why this job: Make a real impact in cybersecurity while developing your skills in a supportive culture.
- Qualifications: Degree in Cybersecurity or related field, with relevant certifications and experience.
- Other info: Hybrid role based in Swindon, with opportunities for personal and professional growth.
The predicted salary is between 43200 - 64800 £ per year.
As a Security Operations Specialist you will manage the relationship with the organisation’s outsourced SOC provider, ensuring effective monitoring, escalation handling, and incident response. Operating within a Microsoft Azure environment, the Specialist will oversee the integration and assurance of security tooling such as Microsoft Sentinel, Microsoft Defender suite, Abnormal, Recorded Future, and Tenable. This role requires strong technical knowledge of Azure-native security, threat intelligence, and vulnerability management, combined with the ability to challenge providers, validate escalations, and coordinate internal remediation. This is a permanent, hybrid role, based in our Swindon office, with the requirement to be in the office 3 days a week.
The Benefits
- Salary - £54,000
- Bonus scheme - on target bonus 7.5%
- Pension scheme - contribute up to 5% of your salary and Openwork will match you and put in an extra 5%
- Critical illness cover
- Income protection - 1x salary
- Death in service - 4x salary
- 27 days holiday + bank holidays, with the opportunity to buy up to an additional 10 days
- A range of other flexible benefits to include private medical insurance, dental insurance and much more.
Key Accountabilities
- Act as the primary liaison between the business and the outsourced SOC provider, managing the relationship, SLAs, KPIs, and service reviews.
- Validate and triage SOC escalations, ensuring incidents are accurately assessed, contained, and remediated.
- Provide assurance that the SOC is effectively leveraging Microsoft Sentinel, Defender suite, and other integrated tools for monitoring and detection.
- Oversee integration and use of Abnormal (email threat protection), Recorded Future (threat intelligence enrichment), and Tenable (vulnerability management) into security operations workflows.
- Collaborate with IT and engineering teams to ensure log sources, telemetry, and alerting are comprehensive across Azure and on-premise systems.
- Ensure detections are mapped to frameworks such as MITRE ATT&CK, continually tuning use cases to improve coverage and reduce false positives.
- Coordinate vulnerability management processes, ensuring Tenable scans are accurate, issues are prioritized, and patching is validated.
- Track remediation activities from incidents, vulnerabilities, and penetration tests, ensuring accountability and closure.
- Drive threat intelligence integration from Recorded Future into SOC playbooks and response processes.
- Produce reporting and metrics on SOC performance, incidents, vulnerabilities, and operational risk for senior management.
- Partner with GRC teams to provide evidence for audits, certifications, and regulatory obligations.
- Mentor colleagues on incident response and SecOps best practices, acting as escalation point for critical issues.
What will you need to succeed?
- Degree in Cybersecurity, Computer Science, or related field.
- Certifications such as AZ-500, SC-200, GCIA, GCIH, or CISSP.
- Experience in financial services, legal, or other regulated industries.
- Proven experience managing outsourced SOC or MSSP providers.
- Deep technical expertise with Microsoft Azure security stack (Sentinel, Defender for Endpoint, Defender for Identity, Defender for Office 365, Entra ID security, Microsoft Purview).
- Hands-on knowledge of: Abnormal (email/phishing protection), Recorded Future (threat intelligence platform), Tenable (vulnerability scanning and management).
- Ability to validate SOC detections and challenge providers on coverage, accuracy, and effectiveness.
- Experience with vulnerability management and patch assurance in Microsoft-centric environments.
- Familiarity with MITRE ATT&CK and integrating threat intelligence into detection engineering.
- Knowledge of regulatory/compliance frameworks (ISO 27001, NIST CSF, Cyber Essentials, GDPR, FCA/DPA) applied to operational security.
- Strong stakeholder management skills, with the ability to bridge technical security findings to business impact.
- Proactive and confident in holding SOC providers and tooling vendors accountable.
Why us?
We’re a dynamic, fast paced, and growing business with huge ambition. This is all made possible by the brilliant people who are part of The Openwork Partnership family. We’re investing heavily in our colleagues, continuously striving to give them the platform to develop personally and professionally and reach their full potential. We’re also very proud of our culture, as one of the Best 100 Large Companies to work for in 2022. The Openwork Partnership values, and respects individuality and we are committed to building an inclusive culture and environment which truly recognises and celebrates our colleague’s individual differences and identities – just like our financial advice, for us, it’s personal. We believe everyone can make a difference and your race, religion, disability, and gender will never be a barrier. At Openwork, we have a strong ethic of care for each other where you can balance a successful career with your commitments and interests outside of work. We believe that you will bring your best self to work if you are trusted to choose when, where and how you do it.
Security Operations Specialist in Swindon employer: The Openwork Partnership
Contact Detail:
The Openwork Partnership Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Security Operations Specialist in Swindon
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Prepare for interviews by practising common questions and scenarios related to security operations. Think about how you’d handle specific incidents or challenges, especially those involving Microsoft Azure tools. Confidence is key!
✨Tip Number 3
Showcase your skills through real-world examples. When chatting with potential employers, share stories of how you've successfully managed SOC relationships or tackled vulnerabilities. This makes you memorable!
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, we love seeing candidates who are genuinely interested in joining our team at Openwork.
We think you need these skills to ace Security Operations Specialist in Swindon
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Security Operations Specialist role. Highlight your experience with Microsoft Azure security tools and any relevant certifications. We want to see how your skills match what we're looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about cybersecurity and how your background makes you a great fit for our team. Don’t forget to mention your experience with SOC providers and incident response.
Showcase Your Technical Skills: In your application, be sure to showcase your technical expertise, especially with tools like Microsoft Sentinel, Defender, and Tenable. We love seeing candidates who can validate detections and challenge providers effectively!
Apply Through Our Website: We encourage you to apply through our website for the best chance of getting noticed. It’s super easy, and you’ll be able to keep track of your application status. Plus, we love seeing applications come directly from our site!
How to prepare for a job interview at The Openwork Partnership
✨Know Your Tech Inside Out
Make sure you brush up on your knowledge of Microsoft Azure security tools like Sentinel and Defender. Be ready to discuss how you've used these tools in past roles, and think of specific examples where you’ve validated SOC detections or managed vulnerabilities.
✨Understand the SOC Landscape
Familiarise yourself with the role of an outsourced SOC provider. Be prepared to talk about how you would manage relationships, SLAs, and KPIs. Think about how you can challenge providers effectively and ensure they meet your expectations.
✨Showcase Your Incident Response Skills
Prepare to discuss your experience with incident response and vulnerability management. Have examples ready that demonstrate your ability to triage escalations and coordinate remediation efforts, especially in a Microsoft-centric environment.
✨Connect the Dots with Compliance
Be ready to talk about regulatory frameworks like ISO 27001 and GDPR. Show how your understanding of these regulations can help bridge technical findings to business impact, which is crucial for stakeholder management.