About the Role
The Information Security Tech Lead is responsible for owning and driving the end-to-end information security programme across Asta & its client base. This role involves technical leadership of a team of engineers and provides authoritative security direction across PAM, EDR, SIEM, DLP, identity governance, vulnerability management, and regulatory compliance. The role requires strengthening Asta’s security posture through hands-on security engineering, continuous monitoring, and effective operational resilience, making informed, risk-based decisions during security incidents.
Responsibilities
- Lead a team of engineers, setting direction, managing workloads, and developing capability.
- Act as the primary security escalation point across the Infrastructure function.
- Own the InfoSec roadmap aligned to Asta’s IT transformation programme.
- Implement and maintain security controls across infrastructure & systems.
- Harden infrastructure by applying best practices for IAM, PIM, PAM encryption, network security.
- Review and implement recommendations of security tooling, including AD hardening tools like Ping Castle and Semperis Lightening as well as vendor solutions & systems.
- Collaborate on implementing & Integrating security controls into pipelines including security scans, policy enforcement, and dependency checking.
- Monitor security alerts and events from SIEM, EDR, firewall, IDS/IPS, & other security tools.
- Triage and prioritise alerts based on severity and impact.
- Investigate security incidents and suspicious activities using log analysis, packet captures, and forensic techniques.
- Lead containment, eradication, and recovery efforts during security incidents.
- Maintain alerting for security events & integrate with SIEM/SOAR platforms.
- Define, own, and drive delivery of Asta’s end-to-end security programme spanning PAM, EDR, NDR, SIEM, penetration testing, DLP, and compliance.
- Translate regulatory obligations (FCA/PRA, Lloyd’s Principle 12, CBEST, ISO 27001, Cyber Essentials) into actionable technical controls and measurable outcomes.
- Provide security advisory and managed security services to 20+ syndicate and MGA clients.
- Conduct client security reviews, Secure Score assessments, Semperis/Entra evaluations, and PAM deployment planning.
- Act as the security escalation point for client-facing security incidents and assurance requests.
- Stay current with emerging threats, vulnerabilities, attack techniques, and security trends.
- Apply threat intelligence to improve detection capabilities and identify indicators of compromise.
- Contribute to threat hunting activities and proactive security monitoring.
- Support compliance and audits for ISO 27001, NIST, SOC2, Lloyd's Principle 12, and other standards.
- Prepare incident reports, timelines, reviews, and maintain event logs.
- Contribute to security documentation, runbooks, and standards.
- Produce metrics and quarterly reports on security posture and incidents for senior management.
- Coordinate Cyber Essentials certification and audits.
- Handle security requests and data sharing from third parties.
- Support operational resilience and business continuity planning activities including scenario testing and disaster recovery exercises.
- Participate in post-incident reviews and implement lessons learned.
- Design, implement & manage simulated phishing campaigns to test and improve staff awareness of social engineering threats.
- Analyse results and identify training needs.
- Track metrics on phishing resilience and user security awareness.
Requirements
- 7 years + of hands-on experience with at least 3/4 years in a lead, management, or principal role in cybersecurity, combining security engineering and SOC operations or incident response with experience in regulated industry.
- Demonstrable experience leading and developing a security team.
- Confident communicator able to translate complex security risk into business language for C-suite and board audiences.
- Strong understanding of cybersecurity principles, attack vectors, defense strategies, OWASP Top 10, and the Mitre Attack framework.
- Experience with cloud security (Azure/AWS), IAM, secrets management, encryption, & certificate management.
- Experience with Microsoft 365 security suite including Microsoft Defender, Azure AD Identity Protection, threat analytics, and security compliance tools.
- Hands-on experience with SIEM platforms (Splunk, Crowdstrike (Falcon), Log Rhtyhm, Sentinel, and Microsoft Defender).
- Experience of working with tools such as Varonis, Tenable, Pentera & external and internal SOC processes.
Skills
- PAM
- EDR
- SIEM
- DLP
- Identity governance
- Vulnerability management
- Regulatory compliance
- Security engineering
- Continuous monitoring
- Operational resilience
- Security incidents
- Infrastructure hardening
- Threat detection
- Microsoft 365 security
- IAM
- PIM
- Encryption
- Network security
- AD hardening
- Ping Castle
- Semperis Lightening
- Security scans
- Policy enforcement
- Dependency checking
- Firewall
- IDS/IPS
- Log analysis
- Packet captures
- Forensic techniques
- SOAR platforms
- NDR
- Penetration testing
- FCA/PRA
- Lloyd’s Principle 12
- CBEST
- ISO 27001
- Cyber Essentials
- Secure Score assessments
- Semperis/Entra evaluations
- Threat intelligence
- Indicators of compromise
- Threat hunting
- NIST
- SOC2
- Business continuity planning
- Disaster recovery
- Social engineering threats
- Cloud security (Azure/AWS)
- Secrets management
- Certificate management
- Microsoft Defender
- Azure AD Identity Protection
- Threat analytics
- Security compliance tools
- Splunk
- Crowdstrike (Falcon)
- Log Rhtyhm
- Sentinel
- Varonis
- Tenable
- Pentera
Location
- London UK
Work Type
- Permanent - Full Time
- Hybrid
- Flexible working
Experience Level
- Lead
- Management
- Principal
Benefits
- Market-leading benefits package
- Wellbeing, career development and financial future focus
- Flexible working
- Strong family-friendly policies
- Exceptional rewards
- Supportive, inclusive and high-performing workplace
- 35-hour working week
- Generous holiday allowance that increases with service
- Private medical insurance with virtual GP access
- Annual health screening
- Dental cover
- Eye care
- Subsidised gym or sports club membership
- Enhanced maternity, paternity, adoption and shared parental pay
- Highly competitive pension with up to 13% employer contribution
- Life assurance
- Income protection
- Discretionary annual bonus scheme
- Interest-free season ticket loan
- Salary sacrifice schemes
About the Company
- Asta & its client base
- Asta’s IT transformation programme
- 20+ syndicate and MGA clients including Carbon Underwriting, Dale Underwriting Partners, and Beat Capital.
