Security Operations – Technical Lead at Version 1 | London, England, United Kingdom | Rezi

Security Operations – Technical Lead at Version 1

Security Operations – Technical Lead

Version 1 · London, England, United Kingdom

1 weeks ago

Security Operations – Technical Lead

Version 1 · London, England, United Kingdom

12 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

A hands-on technical leader responsible for the security operations function, including threat detection, incident response, phishing response, vulnerability management, and identity and access management, ensuring the day-to-day defense of the organization's systems and data. This role acts as the internal owner of security operations, coordinating with an outsourced/managed SOC provider and reporting on risk posture to leadership.

Responsibilities

  • Lead and coordinate security operations strategy, acting as the primary internal liaison with the managed SOC provider for escalations, tuning requests, and SLA management.
  • Own incident response end-to-end, including detection, triage, containment, and post-incident review, whether initiated internally or escalated by the SOC provider.
  • Lead phishing detection and response, including triaging reported emails, coordinating takedowns, running awareness/simulation programs, and refining email security controls.
  • Build and tune detection rules and hunting queries in Microsoft Sentinel and Defender XDR using KQL.
  • Administer and optimize the Microsoft Defender suite (Endpoint, Cloud, Identity, Office 365).
  • Run the vulnerability management lifecycle using Tenable for scanning and ServiceNow Vulnerability Response for remediation tracking and SLAs.
  • Manage Palo Alto firewall policies, rule hygiene, and log integration.
  • Oversee EDR/NDR coverage and correlate alerts across endpoint and network telemetry.
  • Write and maintain PowerShell scripts/automation for response actions and operational efficiency.
  • Coordinate with IT, engineering, and compliance on audits, controls, and architecture reviews.
  • Report metrics, incident summaries, and risk posture to leadership.

Requirements

  • Strong grounding in security operations including SIEM platforms (Sentinel), EDR/XDR (Defender), and SOAR tooling.
  • KQL skills for Sentinel analytics, hunting, and workbooks.
  • Microsoft Defender suite (XDR, endpoint, identity, cloud) administration.
  • Phishing analysis and response (headers, URLs, attachments) and email security tooling.
  • Identity and access management including Entra ID (Azure AD), conditional access, MFA, PIM, and identity governance.
  • Vulnerability management tools (Tenable, Defender).
  • ServiceNow Vulnerability Response for workflow.
  • PowerShell scripting for automation and incident response actions.
  • NDR concepts and cross-telemetry correlation.
  • Experience managing/coordinating a third-party or outsourced SOC.
  • Incident response methodology (NIST 800-61).
  • People management and executive communication skills.
  • Ability to remain calm and decisive under incident pressure.
  • Familiarity with frameworks like MITRE ATT&CK, NIST CSF, and ISO 27001.
  • Palo Alto Networks firewall policy administration is desirable.
  • Microsoft SC-100, SC-200, SC-300, SC-100, SC-500/AZ-500 certifications.
  • CISSP, GCIH certifications.
  • 5-8+ years in SecOps/IR with hands-on Microsoft security stack experience.
  • Demonstrated experience managing or working alongside a managed SOC/MSSP.
  • 1-3+ years in a lead role preferred.

Skills

  • Security Operations
  • Threat Detection
  • Incident Response
  • Phishing Response
  • Vulnerability Management
  • Identity and Access Management
  • SIEM platforms (Sentinel)
  • EDR/XDR (Defender)
  • SOAR tooling
  • KQL
  • Microsoft Defender suite
  • Email security tooling
  • Entra ID (Azure AD)
  • Conditional Access
  • MFA
  • PIM
  • Identity Governance
  • Tenable
  • ServiceNow Vulnerability Response
  • PowerShell scripting
  • NDR concepts
  • Cross-telemetry correlation
  • NIST 800-61
  • MITRE ATT&CK
  • NIST CSF
  • ISO 27001
  • Palo Alto Networks firewall policy administration

Location

  • Remote

Work Type

  • Full-time
  • Remote

Experience Level

  • Lead
  • Senior

Education Level

  • Microsoft SC-100, SC-200, SC-300, SC-100, SC-500/AZ-500
  • CISSP
  • GCIH

Benefits

  • Quarterly Performance-Related Profit Share Scheme
  • Strong Career Progression & mentorship coaching
  • Strength in Balance & Leadership schemes
  • Dedicated quarterly Pathways Career Development programme
  • Flexible/remote working
  • Pension
  • Private Healthcare Cover
  • Life Assurance
  • Financial advice
  • Employee Discount scheme
  • Gym Discounts
  • Bike to Work
  • Fitness classes
  • Mindfulness Workshops
  • Employee Assistance Programme
  • Generous holiday allowance
  • Enhanced maternity/paternity leave
  • Marriage/civil partnership leave
  • Special leave policies
  • Educational assistance
  • Incentivised certifications and accreditations (AWS, Microsoft, Oracle, Red Hat)
  • Version 1’s Annual Excellence Awards
  • ‘Call-Out’ platform
  • Environment, Social and Community First initiatives
  • Involvement in local fundraising and development opportunities

About the Company

  • Version 1 has celebrated 30 years in business and continues to be trusted by global brands to deliver technology and transformation solutions that drive customer success.
  • Deep expertise enables customers to navigate the rapidly evolving technology landscape.
  • Strong partnerships with global technology leaders including Microsoft, AWS, Oracle, Red Hat, OutSystems, Snowflake.
  • Award-winning employer.
  • UK & Ireland's premier AWS, Microsoft & Oracle partner.
  • 3300+ strong, €350/£300m revenue business.
  • 10+ years as a Great Place to Work in Ireland & UK.
  • Best Workplace for Women in the UK & Ireland by GPTW.
  • Best Workplace for Wellbeing in the UK by GPTW.
  • Core values driven company that hires and rewards people who share its values.
  • Invest in employees and expect investment in return.

Equal Opportunity

  • Version 1 is an equal opportunities employer.
  • Committed to building a diverse, inclusive and respectful workplace where everyone feels valued and able to thrive.
  • Welcome applications from people of all backgrounds, identities and lived experiences.
  • Value the different perspectives people bring, including those shaped by disability and neurodiversity.
  • Want every candidate to have a positive and accessible recruitment experience.
  • If reasonable adjustments are needed at any stage of the process, candidates should contact their recruiter at Version 1.
  • All requests for adjustments will be considered carefully, respectfully and confidentially.