Security Operations – Technical Lead
Version
LondonOn-siteEst. £60k - £80k (similar roles)full timeServices Reliability GroupPosted 1mo agoEarly applicant likely
This role is aggregated from the employer's public careers feed - the button opens their application page.
A hands-on technical leader who owns the security operations function - threat detection, incident response, phishing response, vulnerability management, and identity and access management and the day-to-day defense of the organisation's systems and data.
Acts as the internal owner of security operations while coordinating with an outsourced/managed SOC provider and manages reporting on risk posture to leadership.
Responsibilities:
- Lead and coordinate security operations strategy; act as primary internal liaison with the managed SOC provider (escalations, tuning requests, SLA management)
- Own incident response end-to-end: detection, triage, containment, post-incident review whether initiated internally or escalated by the SOC provider
- Lead phishing detection and response: triage reported emails, coordinate takedowns, run awareness/simulation programs, and refine email security controls
- Build and tune detection rules and hunting queries in Microsoft Sentinel and Defender XDR using KQL
- Administer and optimize Microsoft Defender suite (Endpoint, Cloud, Identity, Office 365)
- Run vulnerability management lifecycle using Tenable for scanning and ServiceNow Vulnerability Response for remediation tracking and SLAs
- Manage Palo Alto firewall policies, rule hygiene, and log integration
- Oversee EDR/NDR coverage and correlate alerts across endpoint and network telemetry
- Write and maintain PowerShell scripts/automation for response actions and operational efficiency
- Coordinate with IT, engineering, and compliance on audits, controls, and architecture reviews
- Report metrics, incident summaries, and risk posture to leadership
Required Skills
- Strong grounding in security operations - SIEM platforms (Sentinel), EDR/XDR (Defender), and SOAR tooling
- KQL skills for Sentinel analytics, hunting, and workbooks
- Microsoft Defender suite (XDR, endpoint, identity, cloud) administration
- Phishing analysis and response (headers, URLs, attachments) and email security tooling
- Identity and access management - Entra ID (Azure AD), conditional access, MFA, PIM, identity governance
- Vulnerability management tools (Tenable, Defender)
- ServiceNow Vulnerability Response for workflow
- PowerShell scripting for automation and incident response actions
- NDR concepts and cross-telemetry correlation
- Experience managing/coordinating a third-party or outsourced SOC
- Incident response methodology ( NIST 800-61)
- People management + executive communication
- Calm, decisive under incident pressure
- Familiarity with frameworks like MITRE ATT&CK, NIST CSF, and ISO 27001
- Palo Alto Networks firewall policy administration desirable
Certifications:
- Microsoft SC-100, SC-200, SC-300, SC-100, SC-500/AZ-500
- CISSP, GCIH
Experience:
5-8+ years in SecOps/IR with hands-on Microsoft security stack experience, demonstrated experience managing or working alongside a managed SOC/MSSP, 1-3+ years in a lead role preferred
About Version
Based on these excerpts, Version delivers technical project management and quality assurance services, primarily for public sector clients. The company hires delivery managers to oversee Agile projects, test engineers to design and execute testing frameworks, and QA specialists to support software development and integration testing.
All Version jobsStop searching - get matched.
Upload your CV and our AI will surface roles like this one, with the reasons they fit you.
Upload CV - it's free