Information Security Operations Manager
Job Description
Information Security Operations Manager - Software Company
Remote-first with occasional travel to London (max once a week)
35-hour working week | 30 days annual leave + bank holidays
Are you an Information Security expert looking to make a real impact in a collaborative and forward-thinking tech environment?
A leading UK-based software company is going through an exciting digital transformation and is looking for an Information Security Operations Manager to lead and evolve their security operations capability. You'll work with a growing, ambitious InfoSec team and be at the heart of protecting systems, services, and data critical to the company's success.
What you'll be doing:
-
Lead the day-to-day security operations function, including vendor oversight and management of the outsourced MDR partner
-
Manage and evolve the Security Operations Centre (SOC), guiding and developing a small in-house team of security professionals
-
Coordinate timely responses to security incidents, ensuring proper documentation and post-incident analysis
-
Collaborate with internal teams to ensure policies, protocols and operations align with business objectives and emerging threats
-
Drive continual improvement in monitoring, incident response, and preventative security measures
Key experience we're looking for:
-
Deep experience working in Security Operations, including working with MDR providers and SOC environments
-
Strong hands-on experience with Microsoft Azure and the Microsoft Defender Suite (including Defender for Endpoint, , Cloud, and Office 365)
-
Proven experience managing and mentoring security teams - this is a core requirement, as all security operations are delivered in-house (no outsourcing)
-
Strong knowledge of relevant frameworks and standards including:
-
PCI-DSS
-
GDPR
-
NIST CSF
-
CIS Critical Security Controls
-
Cyber Essentials Plus
-
-
Hands-on experience across Cloud Security, and Access Management, Zero Trust, Security Service Edge (SSE), and SASE
-
Proven ability to bridge the gap between technical and non-technical stakeholders when communicating security issues
-
A passion for continuous improvement and post-incident analysis to drive security maturity