At a Glance
- Tasks: Lead UCL's Detection and Response function, shaping security monitoring and incident response.
- Company: Join a prestigious university with a commitment to security and innovation.
- Benefits: 41 days holiday, pension scheme, on-site gym, and enhanced family leave.
- Other info: Dynamic role with opportunities for professional growth and collaboration.
- Why this job: Make a real impact on UCL's security posture while developing your leadership skills.
- Qualifications: Significant experience in security operations and strong stakeholder management skills.
The predicted salary is between 58500 - 71500 £ per year.
Overview
In this role, you will head UCL’s Detection and Response function within Security Operations, shaping how we monitor, triage alerts, investigate incidents and coordinate responses.
You’ll drive capability development, establish robust processes and playbooks, and oversee exercises to test readiness.
The role requires strong stakeholder engagement and translating complex security issues into clear risk-based guidance.
You will partner across units and with external bodies to strengthen UCL’s security posture and resilience.
- Pay / Benefits
- 41 days holiday (27 days annual leave, 8 bank holiday, 6 closure days)
- CARE pension scheme
- Cycle to work scheme
- On-site nursery and gym
- Enhanced maternity/paternity/adoption pay
- Employee assistance programme: Staff Support Service
Responsibilities
- Lead the Detection and Response function and drive security monitoring, alert triage, investigations and incident response
- Provide calm, decisive leadership during security incidents and steer post-incident improvements
- Develop team capabilities, processes, tooling, metrics, and escalation arrangements
- Identify and close gaps in detection and response capabilities; update incident response plans and runbooks
- Coordinate exercises to test readiness and maturity of security operations
- Build trusted relationships with senior stakeholders, service providers, government bodies and law enforcement
- Translate complex technical issues into clear operational and risk-based advice for diverse audiences
- Key requirements
- Significant experience leading or managing security operations, SOC, detection and response, or incident response services in a complex organisation
- Strong knowledge of security monitoring, alert triage, investigation workflows, incident declaration and post-incident improvement
- Experience with security tooling and platforms (SIEM, SOAR, EDR, NDR, identity protection, CSPM, CTEM) and specialist incident response tools
- Experience developing incident response plans, playbooks, runbooks, exercises and operational process documentation
- Ability to provide calm, decisive, evidence-based leadership during security incidents
- Experience leading multidisciplinary technical teams and fostering continuous improvement
- Strong stakeholder management and communication skills to explain security issues to technical and non-technical audiences
- Experience using metrics and operational data to improve services and report outcomes to senior stakeholders
- Ability to collaborate across internal teams, external suppliers and partners to resolve gaps
- Calm under pressure
- Clear communication
- Stakeholder management
- SIEM
- SOAR
- EDR
Detection and Response Lead in London employer: UNIVERSITY COLLEGE LONDON
UCL's Information Services Division (ISD) is an exceptional employer, offering a dynamic work environment that fosters innovation and collaboration among over 50,000 staff and students. With a commitment to employee growth, ISD provides extensive benefits including 41 days of holiday, a defined benefit pension scheme, and opportunities for professional development in cutting-edge technology areas. Located in the heart of London, UCL promotes a diverse and inclusive culture, making it an ideal place for those looking to make a meaningful impact in higher education.