About the Role
A hands-on technical leader responsible for the security operations function, including threat detection, incident response, phishing response, vulnerability management, and identity and access management, ensuring the day-to-day defense of the organization's systems and data. This role acts as the internal owner of security operations, coordinating with an outsourced/managed SOC provider and reporting on risk posture to leadership.
Responsibilities
- Lead and coordinate security operations strategy, acting as the primary internal liaison with the managed SOC provider for escalations, tuning requests, and SLA management.
- Own incident response end-to-end, including detection, triage, containment, and post-incident review, whether initiated internally or escalated by the SOC provider.
- Lead phishing detection and response, including triaging reported emails, coordinating takedowns, running awareness/simulation programs, and refining email security controls.
- Build and tune detection rules and hunting queries in Microsoft Sentinel and Defender XDR using KQL.
- Administer and optimize the Microsoft Defender suite (Endpoint, Cloud, Identity, Office 365).
- Run the vulnerability management lifecycle using Tenable for scanning and ServiceNow Vulnerability Response for remediation tracking and SLAs.
- Manage Palo Alto firewall policies, rule hygiene, and log integration.
- Oversee EDR/NDR coverage and correlate alerts across endpoint and network telemetry.
- Write and maintain PowerShell scripts/automation for response actions and operational efficiency.
- Coordinate with IT, engineering, and compliance on audits, controls, and architecture reviews.
- Report metrics, incident summaries, and risk posture to leadership.
Requirements
- Strong grounding in security operations including SIEM platforms (Sentinel), EDR/XDR (Defender), and SOAR tooling.
- KQL skills for Sentinel analytics, hunting, and workbooks.
- Microsoft Defender suite (XDR, endpoint, identity, cloud) administration.
- Phishing analysis and response (headers, URLs, attachments) and email security tooling.
- Identity and access management including Entra ID (Azure AD), conditional access, MFA, PIM, and identity governance.
- Vulnerability management tools (Tenable, Defender).
- ServiceNow Vulnerability Response for workflow.
- PowerShell scripting for automation and incident response actions.
- NDR concepts and cross-telemetry correlation.
- Experience managing/coordinating a third-party or outsourced SOC.
- Incident response methodology (NIST 800-61).
- People management and executive communication skills.
- Ability to remain calm and decisive under incident pressure.
- Familiarity with frameworks like MITRE ATT&CK, NIST CSF, and ISO 27001.
- Palo Alto Networks firewall policy administration is desirable.
- Microsoft SC-100, SC-200, SC-300, SC-100, SC-500/AZ-500 certifications.
- CISSP, GCIH certifications.
- 5-8+ years in SecOps/IR with hands-on Microsoft security stack experience.
- Demonstrated experience managing or working alongside a managed SOC/MSSP.
- 1-3+ years in a lead role preferred.
Skills
- Security Operations
- Threat Detection
- Incident Response
- Phishing Response
- Vulnerability Management
- Identity and Access Management
- SIEM platforms (Sentinel)
- EDR/XDR (Defender)
- SOAR tooling
- KQL
- Microsoft Defender suite
- Email security tooling
- Entra ID (Azure AD)
- Conditional Access
- MFA
- PIM
- Identity Governance
- Tenable
- ServiceNow Vulnerability Response
- PowerShell scripting
- NDR concepts
- Cross-telemetry correlation
- NIST 800-61
- MITRE ATT&CK
- NIST CSF
- ISO 27001
- Palo Alto Networks firewall policy administration
Location
- Remote
Work Type
- Full-time
- Remote
Experience Level
- Lead
- Senior
Education Level
- Microsoft SC-100, SC-200, SC-300, SC-100, SC-500/AZ-500
- CISSP
- GCIH
Benefits
- Quarterly Performance-Related Profit Share Scheme
- Strong Career Progression & mentorship coaching
- Strength in Balance & Leadership schemes
- Dedicated quarterly Pathways Career Development programme
- Flexible/remote working
- Pension
- Private Healthcare Cover
- Life Assurance
- Financial advice
- Employee Discount scheme
- Gym Discounts
- Bike to Work
- Fitness classes
- Mindfulness Workshops
- Employee Assistance Programme
- Generous holiday allowance
- Enhanced maternity/paternity leave
- Marriage/civil partnership leave
- Special leave policies
- Educational assistance
- Incentivised certifications and accreditations (AWS, Microsoft, Oracle, Red Hat)
- Version 1’s Annual Excellence Awards
- ‘Call-Out’ platform
- Environment, Social and Community First initiatives
- Involvement in local fundraising and development opportunities
About the Company
- Version 1 has celebrated 30 years in business and continues to be trusted by global brands to deliver technology and transformation solutions that drive customer success.
- Deep expertise enables customers to navigate the rapidly evolving technology landscape.
- Strong partnerships with global technology leaders including Microsoft, AWS, Oracle, Red Hat, OutSystems, Snowflake.
- Award-winning employer.
- UK & Ireland's premier AWS, Microsoft & Oracle partner.
- 3300+ strong, €350/£300m revenue business.
- 10+ years as a Great Place to Work in Ireland & UK.
- Best Workplace for Women in the UK & Ireland by GPTW.
- Best Workplace for Wellbeing in the UK by GPTW.
- Core values driven company that hires and rewards people who share its values.
- Invest in employees and expect investment in return.
Equal Opportunity
- Version 1 is an equal opportunities employer.
- Committed to building a diverse, inclusive and respectful workplace where everyone feels valued and able to thrive.
- Welcome applications from people of all backgrounds, identities and lived experiences.
- Value the different perspectives people bring, including those shaped by disability and neurodiversity.
- Want every candidate to have a positive and accessible recruitment experience.
- If reasonable adjustments are needed at any stage of the process, candidates should contact their recruiter at Version 1.
- All requests for adjustments will be considered carefully, respectfully and confidentially.
