Overview
In this role, you drive advanced technical security analysis and lead complex investigations to strengthen security controls. You will operate at the intersection of hands-on security and governance, coaching peers and translating threat and risk information into board-ready updates. You’ll own key security domains including DLP, MFA, vulnerability management, and security architecture, shaping how the organisation reduces cyber risk. This is a chance to impact security maturity while enabling business through proportionate risk management.
Responsibilities
- Lead complex security investigations across endpoints, networks, identities, email, cloud and data sources; define triage and escalation standards; improve detection logic and playbooks
- Coordinate and drive significant incident response efforts; ensure evidence handling, timelines, lessons learned, and remediation actions are documented and auditable
- Translate findings into risk statements and remediation plans; support risk assessments, audits and assurance with evidence
- Own or lead DLP monitoring and MFA governance, tune rules, manage exceptions and analyse trends for improvement
- Lead vulnerability prioritisation and remediation support; track trends and use threat intelligence to improve detection and risk prioritisation
- Review changes and projects for security risks; advise on secure design across identity, endpoints, networks, cloud and data protection
- Produce management information and KPIs/KRIs for incidents, vulnerabilities, DLP, MFA and control assurance; identify improvement actions
- Coach colleagues and communicate security findings to both technical and non-technical stakeholders; promote a constructive security culture
Key requirements
- Advanced security investigation capabilities using SIEM, EDR, endpoint protection, identity, email, web, network and cloud data
- Strong DLP policy design, tuning and exception management
- Strong MFA implementation, exception governance and conditional access
- Vulnerability management and secure configuration assessment
- Incident command, evidence handling, root cause analysis and post-incident review
- Security architecture assurance for identity, endpoint, network, cloud, data protection
- Detection engineering and automation using scripts or workflows
- Knowledge of CAF, CSF, CIS Controls and ISO/IEC 27001
- Strong written and verbal communication
- Sound judgement and integrity
- Ability to prioritise under pressure
- SIEM
- EDR
- Endpoint protection
…
