About the Role
This is the first dedicated security operations role, responsible for maintaining security day-to-day for a fast-moving AI business. The role involves owning and building an autonomous security operations capability from the ground up, from initial detection and response to ongoing operations and validation against real-world attack scenarios.
Responsibilities
- Own alert triage, investigation, and response end-to-end, acting as the named incident declarer, runner, and closer.
- Operate and tune the autonomous security operations capability, treating agent output as a first line of defense.
- Own detection engineering, including logging standards, alert quality, coverage gaps, and false positive reduction.
- Validate detection coverage against attack paths from the internal red team and close identified gaps.
- Run post-incident reviews and drive actions to genuine closure.
- Manage joiners, movers, leavers, privileged access, single sign-on, and secrets management.
- Perform endpoint fleet hardening, patch compliance, EDR administration, and device lifecycle management.
- Manage network and edge controls, remote access, and segmentation.
- Conduct access reviews that meet auditor standards without prior preparation.
- Own the UK IT service, including end-user support, devices, and the on-premise server estate.
- Manage the SaaS estate, including licensing, access, spend, and rationalization for approximately 85 products.
- Set and report service levels, maintaining a healthy support queue.
- Oversee IT procurement and asset management.
- Own backup security and ransomware recovery, testing recovery processes.
- Manage the business continuity and disaster recovery exercise schedule, keeping evidence current.
- Establish and prove an out-of-hours arrangement that does not rely on a single individual.
- Line manage and develop offshore security resources, building them into first-line detection work.
- Set and maintain security standards, acting as the escalation point when standards are not met.
- Produce operational evidence for ISO 27001 and SOC 2 continuously.
- Respond to the operational aspects of client due diligence.
- Maintain accurate and reliable asset, log, and access inventories.
Requirements
- Five or more years in security operations, with at least two years carrying accountability for incident response in a live environment.
- Hands-on cloud security operations experience in AWS and Azure, including logging, monitoring, and identity.
- Experience with identity and access administration at scale, including SSO, privileged access, and joiner/leaver processes.
- Experience with endpoint and EDR administration across a distributed fleet.
- Experience with vulnerability management at volume, with a track record of closing findings.
- Experience working within an ISO 27001 or SOC 2 control environment and producing auditor-accepted evidence.
- Automation-minded, with scripting, infrastructure as code, or demonstrated ability to direct agentic tooling and verify its work.
- Ability to maintain standards with engineers and commercial colleagues and to decline requests with a valid reason.
- Exposure to operational technology or industrial environments (desirable).
- Practical AI or machine learning security awareness, model access, data handling, and prompt safety knowledge (desirable).
- Relevant certification such as CREST, GIAC, or an equivalent hands-on qualification (desirable).
- Experience in a startup, scale-up, or managed service provider environment (desirable).
- Experience managing or coaching an offshore or distributed team member (desirable).
Skills
- Security Operations
- Incident Response
- Detection Engineering
- Cloud Security (AWS, Azure)
- Identity and Access Management (IAM)
- Endpoint Security / EDR
- Vulnerability Management
- ISO 27001
- SOC 2
- Automation
- Scripting
- Infrastructure as Code
- IT Service Management
- SaaS Management
- Procurement
- Asset Management
- Backup and Recovery
- Business Continuity
- Disaster Recovery
- Team Management
- Coaching
- Auditing
Location
- UK
Work Type
- Full-time
Experience Level
- Senior
About the Company
- Applied Computing was founded in 2024 to build Orbital, a physics-informed foundation model for energy operations.
- The company is live across oil and gas, refineries, and petrochemicals, aiming for sustainable abundance for a growing planet.
- Orbital is an AI foundation model designed for energy operations, enabling companies to use AI at scale, harness operational data, and optimize in real time.
- The company has raised over $32 million, including a significant seed round in the UK.
