Security Operations – Technical Lead in London

Security Operations – Technical Lead in London

London Full-Time 60000 - 80000 £ / year (est.) Home office (partial)
Version 1

At a Glance

  • Tasks: Lead security operations, manage incident response, and optimise threat detection.
  • Company: Join Version 1, a trusted tech partner with 30 years of success.
  • Benefits: Enjoy flexible working, competitive pay, and a focus on wellbeing.
  • Other info: Be part of a diverse team that values inclusion and personal growth.
  • Why this job: Make a real impact in cybersecurity while growing your career.
  • Qualifications: 5-8 years in security operations with hands-on Microsoft experience.

The predicted salary is between 60000 - 80000 £ per year.

Version 1 has celebrated 30 years in business and continues to be trusted by global brands to deliver technology and transformation solutions that drive customer success. Our deep expertise enables our customers to navigate the rapidly evolving technology landscape. We foster strong partnerships with global technology leaders including Microsoft, AWS, Oracle, Red Hat, OutSystems, Snowflake, ensuring that our customers are provided with the highest quality solutions and services.

We’re an award-winning employer reflecting how our employees are at the very heart of what we do:

  • UK & Ireland's premier AWS, Microsoft & Oracle partner
  • 3300+ strong, €350/£300m revenue business
  • 10+ years as a Great Place to Work in Ireland & UK
  • Best Workplace for Women in the UK & Ireland by GPTW
  • Best Workplace for Wellbeing in the UK by GPTW

We’re a core values driven company, we hire people who share our values, and we reward those who display and foster them, it’s deeply embedded within our DNA. Invest in us and we’ll invest in you!

A hands-on technical leader who owns the security operations function - threat detection, incident response, phishing response, vulnerability management, and identity and access management and the day-to-day defense of the organisation's systems and data. Acts as the internal owner of security operations while coordinating with an outsourced/managed SOC provider and manages reporting on risk posture to leadership.

Responsibilities:

  • Lead and coordinate security operations strategy; act as primary internal liaison with the managed SOC provider (escalations, tuning requests, SLA management)
  • Own incident response end-to-end: detection, triage, containment, post-incident review whether initiated internally or escalated by the SOC provider
  • Lead phishing detection and response: triage reported emails, coordinate takedowns, run awareness/simulation programs, and refine email security controls
  • Build and tune detection rules and hunting queries in Microsoft Sentinel and Defender XDR using KQL
  • Administer and optimize Microsoft Defender suite (Endpoint, Cloud, Identity, Office 365)
  • Run vulnerability management lifecycle using Tenable for scanning and ServiceNow Vulnerability Response for remediation tracking and SLAs
  • Manage Palo Alto firewall policies, rule hygiene, and log integration
  • Oversee EDR/NDR coverage and correlate alerts across endpoint and network telemetry
  • Write and maintain PowerShell scripts/automation for response actions and operational efficiency
  • Coordinate with IT, engineering, and compliance on audits, controls, and architecture reviews
  • Report metrics, incident summaries, and risk posture to leadership

Qualifications:

  • Strong grounding in security operations - SIEM platforms (Sentinel), EDR/XDR (Defender), and SOAR tooling
  • KQL skills for Sentinel analytics, hunting, and workbooks
  • Microsoft Defender suite (XDR, endpoint, identity, cloud) administration
  • Phishing analysis and response (headers, URLs, attachments) and email security tooling
  • Identity and access management - Entra ID (Azure AD), conditional access, MFA, PIM, identity governance
  • Vulnerability management tools (Tenable, Defender)
  • ServiceNow Vulnerability Response for workflow
  • PowerShell scripting for automation and incident response actions
  • NDR concepts and cross-telemetry correlation
  • Experience managing/coordinating a third-party or outsourced SOC
  • Incident response methodology (NIST 800-61)
  • People management + executive communication
  • Calm, decisive under incident pressure
  • Familiarity with frameworks like MITRE ATT&CK, NIST CSF, and ISO 27001
  • Palo Alto Networks firewall policy administration desirable

Certifications:

  • Microsoft SC-100, SC-200, SC-300, SC-500/AZ-500
  • CISSP, GCIH

Experience:

  • 5-8+ years in SecOps/IR with hands-on Microsoft security stack experience, demonstrated experience managing or working alongside a managed SOC/MSSP, 1-3+ years in a lead role preferred

Additional Information:

At Version 1, we believe in providing our employees with a comprehensive benefits package that prioritises their wellbeing, professional growth, and financial stability. Share in our success with our Quarterly Performance-Related Profit Share Scheme, where employees collectively benefit from a share of our company's profits.

  • Strong Career Progression & mentorship coaching through our Strength in Balance & Leadership schemes with a dedicated quarterly Pathways Career Development programme
  • Flexible/remote working, Version 1 is tremendously understanding of life events and people’s individual circumstances and offer flexibility to help achieve a healthy work-life balance
  • Financial Wellbeing initiatives including; Pension, Private Healthcare Cover, Life Assurance, Financial advice and an Employee Discount scheme
  • Employee Wellbeing schemes including Gym Discounts, Bike to Work, Fitness classes, Mindfulness Workshops, Employee Assistance Programme and much more.
  • Generous holiday allowance, enhanced maternity/paternity leave, marriage/civil partnership leave and special leave policies
  • Educational assistance, incentivised certifications, and accreditations, including AWS, Microsoft, Oracle, and Red Hat
  • Reward schemes including Version 1’s Annual Excellence Awards & ‘Call-Out’ platform.
  • Environment, Social and Community First initiatives allow you to get involved in local fundraising and development opportunities as part of fostering our diversity, inclusion and belonging schemes.

Version 1 is an equal opportunities employer. We are committed to building a diverse, inclusive and respectful workplace where everyone feels valued and able to thrive. We welcome applications from people of all backgrounds, identities and lived experiences, and we value the different perspectives people bring including those shaped by disability and neurodiversity. We want every candidate to have a positive and accessible recruitment experience. If you need reasonable adjustments at any stage of the process, please contact your recruiter at Version 1. We will consider all requests carefully, respectfully and confidentially.

Security Operations – Technical Lead in London employer: Version 1

Version 1 is an exceptional employer that prioritises the well-being and professional growth of its employees. With a strong focus on fostering a collaborative work culture, this role offers unique opportunities to engage with leading Private Sector organisations in the UK & Ireland, driving meaningful impact while enjoying competitive salaries, bonuses, and comprehensive benefits. Join us to be part of a dynamic team that values innovation and personal development.

Version 1

Contact Details:

Version 1 Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Security Operations – Technical Lead in London

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Version 1, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Version 1

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Version 1. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Security Operations – Technical Lead in London

Security Operations
Threat Detection
Incident Response
Phishing Response
Vulnerability Management
Identity and Access Management
Microsoft Sentinel

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Version 1 insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Version 1 that you’re committed to staying ahead in the game.

How to prepare for a job interview at Version 1

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Version 1 to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Version 1.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.