Skip page header and navigation
Posted 7 August 2026
Job ref: 261343

Security Operations Technical Lead- Cyber

  • Location: London, Greater London, England
  • Salary: £800 - 900 per day + None
  • Category
  • Sector: IT and Digital
  • Contract type Contract
  • Consultant: Lucinda Mcfarlane

Security Operations Technical Lead

  • Contract duration: 6 months
  • Location: Central London- Hybrid, once per month office visit
  • Pay range: £800.00- £900.00 per day/ Inside IR35
  • Start date: ASAP

Overview

The organisation is undertaking a major transformation of its Security Operations capability and operating model. While the emphasis of the capability was previously on protective monitoring against commodity threats, reactive incident management, and escalation to third-party IT suppliers for remediation and response, the organisation is significantly expanding and developing its Security Operations capability to create an industry-leading team focused on the external threat landscape and internal business context, with responsibility for end-to-end technical cyber defence. The intended scope of services includes threat intelligence, attack surface management, proactive monitoring and threat hunting, incident management and response, supported by strong Security Engineering and DevSecOps practices.

To support this transition, the organisation requires an experienced and industry-leading Security Operations professional to act as the Technical Lead & Product Owner within the transformation programme, shaping, steering and delivering a range of Security Operations transformation initiatives.

The role forms part of the programme leadership team, working alongside Technical Project Management, the Head of Security Operations and the wider programme governance function.

Role Summary

The Security Operations Technical Lead will provide senior-level Security Operations technical leadership and managerial direction, with a strong focus on shaping and defining project outcomes, quality assurance, coordinating junior colleagues and directly applying hands-on expertise to solve complex security technology, process and people challenges. Alongside programme responsibilities, this role will support BAU teams by sharing knowledge and expertise, increasing capability and preparing operational teams to ultimately take ownership of programme deliverables.

The role will operate across both BAU and project delivery activities and will work closely with:

  • IT and Architecture teams
  • Cyber Security teams, including Security Operations, Assurance, Governance and Risk
  • Third-party operational suppliers
  • Application and workload teams
  • Procurement and transition workstreams

The successful candidate will have extensive hands-on Security Operations expertise, combating sophisticated cyber threats, including Advanced Persistent Threats (APTs) and nation-state actors, with transferable skills across a range of technologies and platforms covering:

  • Detection & Response
  • Threat Operations
  • Security Engineering
  • DevSecOps

Key Responsibilities

Security Operations Subject Matter Expertise

  • Possess and apply direct, hands-on technical cyber defence expertise to enrich programme delivery.
  • Provide technical guidance, advice and industry-leading best practice recommendations across Security Operations disciplines, drawing on extensive practical experience.
  • Directly contribute to Security Operations technology selection, configuration and operating processes.

Security Operations Transformation Project Direction & Management

  • Collaborate with programme management to shape project definition, including outcomes, objectives, plans, milestones and delivery structure.
  • Coordinate the activities of junior programme colleagues to ensure timely and effective delivery.
  • Review programme deliverables, providing feedback, quality assurance and technical oversight.
  • Provide regular and ad hoc progress updates, insights and recommendations to programme leadership.

Technical Leadership & Mentoring

  • Share previous operational and incident response experience to coach and develop BAU team members.
  • Provide technical leadership and guidance to support the ongoing professional development of operational teams.
  • Where required, coordinate and direct junior colleagues alongside the Detection & Response Lead during major security incidents.

Supplier & Stakeholder Engagement

  • Work collaboratively with incumbent and future service providers to ensure effective integration and positioning of the organisation’s Security Operations capability.
  • Participate in technical workshops, knowledge transfer sessions and transition activities.
  • Review supplier deliverables and operational approaches.
  • Provide pragmatic guidance to both technical and non-technical stakeholders.
  • Produce and maintain technical documentation, standards and operational artefacts.

Essential Skills & Experience

  • Extensive experience operating at Principal level within a live cyber defence capability, combating sophisticated cyber threats, including Advanced Persistent Threats (APTs), nation-state actors and other advanced adversaries within large enterprise or highly regulated environments.
  • Strong technical expertise that can be applied across multiple technologies and platforms rather than being limited to a specific toolset.

Strong understanding of Security Operations disciplines, including:

  • Protective monitoring and triage
  • Security analysis
  • Security incident response and management
  • Data Loss Prevention (DLP)
  • Digital forensics and eDiscovery
  • Threat intelligence
  • Threat hunting
  • Vulnerability management
  • Security engineering and design, ideally within cloud and DevSecOps environments
  • Detection engineering and content management
  • Data management
  • Endpoint and network security controls

Desirable Skills & Experience

  • Experience supporting regulated or highly governed enterprise environments.
  • Experience delivering complex Security Operations or cyber transformation programmes.

Experience with technologies such as:

  • Microsoft Defender Suite
  • KQL / SPL
  • ASIM / CIM
  • Splunk Enterprise
  • Cribl
  • Wiz Suite
  • Confluence
  • Jira
  • Akamai WAF
  • Bolster.ai Brand Protection
  • ServiceNow ITSM
  • GitHub Actions
  • Microsoft Azure
  • Amazon Web Services (AWS)

Personal Attributes

  • Goal and delivery-oriented, with high quality standards balanced by realism and pragmatism.
  • Adaptive and intellectually agile, with the ability to operate effectively in evolving and ambiguous environments.
  • Natural problem solver, capable of analysing complex technical and Security Operations challenges and developing practical solutions.
  • Able to balance strategic direction with operational realities.
  • Strong collaborator, able to work effectively across organisational boundaries with stakeholders of varying technical knowledge.
  • Self-motivated and capable of operating independently to a consistently high standard.
  • Excellent communicator, able to influence both technical and non-technical stakeholders using clear, pragmatic communication.
  • Strong technical leader, able to inspire Security Operations teams while remaining hands-on where required.
  • Experienced in people, resource and project leadership, with the ability to steer and deliver complex Security Operations transformation programmes.
  • Strong understanding of the modern cyber threat landscape, industry best practice and emerging technologies.
Apply now

Similar jobs