Security Operations – Technical Lead

Security Operations – Technical Lead

Full-Time 60000 - 80000 £ / year (est.) No working from home possible
Version 1 Group

At a Glance

  • Tasks: Lead security operations, manage incident response, and optimise threat detection.
  • Company: Join Version 1, a forward-thinking tech company prioritising employee wellbeing.
  • Benefits: Enjoy flexible working, competitive pay, and comprehensive health benefits.
  • Other info: Diverse and inclusive workplace with strong career progression opportunities.
  • Why this job: Make a real impact in cybersecurity while growing your skills in a supportive environment.
  • Qualifications: 5-8 years in security operations with hands-on Microsoft security stack experience.

The predicted salary is between 60000 - 80000 £ per year.

A hands-on technical leader who owns the security operations function – threat detection, incident response, phishing response, vulnerability management, and identity and access management and the day-to-day defense of the organisation's systems and data. Acts as the internal owner of security operations while coordinating with an outsourced/managed SOC provider and manages reporting on risk posture to leadership.

Responsibilities:

  • Lead and coordinate security operations strategy; act as primary internal liaison with the managed SOC provider (escalations, tuning requests, SLA management)
  • Own incident response end-to-end: detection, triage, containment, post-incident review whether initiated internally or escalated by the SOC provider
  • Lead phishing detection and response: triage reported emails, coordinate takedowns, run awareness/simulation programs, and refine email security controls
  • Build and tune detection rules and hunting queries in Microsoft Sentinel and Defender XDR using KQL
  • Administer and optimise Microsoft Defender suite (Endpoint, Cloud, Identity, Office 365)
  • Run vulnerability management lifecycle using Tenable for scanning and ServiceNow Vulnerability Response for remediation tracking and SLAs
  • Manage Palo Alto firewall policies, rule hygiene, and log integration
  • Oversee EDR/NDR coverage and correlate alerts across endpoint and network telemetry
  • Write and maintain PowerShell scripts/automation for response actions and operational efficiency
  • Coordinate with IT, engineering, and compliance on audits, controls, and architecture reviews
  • Report metrics, incident summaries, and risk posture to leadership

Qualifications Required Skills:

  • Strong grounding in security operations – SIEM platforms (Sentinel), EDR/XDR (Defender), and SOAR tooling
  • KQL skills for Sentinel analytics, hunting, and workbooks
  • Microsoft Defender suite (XDR, endpoint, identity, cloud) administration
  • Phishing analysis and response (headers, URLs, attachments) and email security tooling
  • Identity and access management – Entra ID (Azure AD), conditional access, MFA, PIM, identity governance
  • Vulnerability management tools (Tenable, Defender)
  • ServiceNow Vulnerability Response for workflow
  • PowerShell scripting for automation and incident response actions
  • NDR concepts and cross-telemetry correlation
  • Experience managing/coordinating a third-party or outsourced SOC
  • Incident response methodology (NIST 800-61)
  • Calm, decisive under incident pressure
  • Familiarity with frameworks like MITRE ATT&CK, NIST CSF, and ISO 27001
  • Palo Alto Networks firewall policy administration desirable

Certifications:

  • Microsoft SC-100, SC-200, SC-300, SC-500/AZ-500
  • CISSP, GCIH

Experience:

  • 5-8+ years in SecOps/IR with hands-on Microsoft security stack experience, demonstrated experience managing or working alongside a managed SOC/MSSP, 1-3+ years in a lead role preferred

Additional Information:

At Version 1, we believe in providing our employees with a comprehensive benefits package that prioritises their wellbeing, professional growth, and financial stability. Share in our success with our Quarterly Performance-Related Profit Share Scheme, where employees collectively benefit from a share of our company's profits. Strong Career Progression & mentorship coaching through our Strength in Balance & Leadership schemes with a dedicated quarterly Pathways Career Development programme. Flexible / remote working, Version 1 is tremendously understanding of life events and people’s individual circumstances and offer flexibility to help achieve a healthy work-life balance. Financial Well-being initiatives including Pension, Private Healthcare Cover, Life Assurance, Financial advice and an Employee Discount scheme. Employee Well-being schemes including Gym Discounts, Bike to Work, Fitness classes, Mindfulness Workshops, Employee Assistance Programme and much more. Generous holiday allowance, enhanced maternity/paternity leave, marriage/civil partnership leave and special leave policies. Educational assistance, incentivised certifications, and accreditations, including AWS, Microsoft, Oracle, and Red Hat. Reward schemes including Version 1’s Annual Excellence Awards & ‘Call-Out’ platform. Environment, Social and Community First initiatives allow you to get involved in local fundraising and development opportunities as part of fostering our diversity, inclusion and belonging schemes.

Version 1 is an equal opportunities employer. We are committed to building a diverse, inclusive and respectful workplace where everyone feels valued and able to thrive. We welcome applications from people of all backgrounds, identities and lived experiences, and we value the different perspectives people bring including those shaped by disability and neurodiversity. We want every candidate to have a positive and accessible recruitment experience. If you need reasonable adjustments at any stage of the process, please contact your recruiter at Version 1. We will consider all requests carefully, respectfully and confidentially.

Security Operations – Technical Lead employer: Version 1 Group

Version 1 Group is an excellent employer for those seeking meaningful and rewarding employment in the public sector. With a strong focus on collaboration and user-centric design, employees benefit from a flexible work environment, performance-related profit sharing, and ample opportunities for professional growth, making it an ideal place to advance your career while contributing to impactful projects.

Version 1 Group

Contact Details:

Version 1 Group Recruitment Team

We think you need these skills to ace Security Operations – Technical Lead

Security Operations
Threat Detection
Incident Response
Phishing Response
Vulnerability Management
Identity and Access Management
Microsoft Sentinel