Overview
In this role you lead and drive Asta’s information security program across the enterprise and client base. You provide authoritative direction on IAM, PAM, EDR, SIEM, DLP, and compliance, while hands-on engineering strengthens the security posture. You will coordinate incident response, threat detection, and resilience, working with cross-functional teams to reduce risk. You shape security strategy within the IT transformation program and partner with risk, compliance, and development teams. This is a hands-on leadership role focused on secure, scalable, and compliant infrastructure.
Pay / Benefits
- 35-hour working week with hybrid and flexible working
- Private medical insurance with virtual GP access
- Annual health screening, dental and eye care
- Highly competitive pension with employer contributions
- Discretionary annual bonus
- Life assurance and income protection
Responsibilities
- Lead and develop a securityEngineering team, setting direction and managing workloads
- Act as primary security escalation point within the Infrastructure function
- Own and deliver the information security roadmap aligned to IT transformation
- Implement and maintain security controls across infrastructure and systems
- Harden infrastructure with IAM, PIM, PAM and encryption; review AD hardening tooling
- Collaborate on integrating security controls into pipelines with scans and policy enforcement
- Monitor security alerts from SIEM, EDR, firewall, IDS/IPS; triage by severity
- Lead containment, eradication, and recovery during incidents
- Maintain alerting and integrate with SIEM/SOAR platforms
- Define and drive end-to-end security programme across PAM, EDR, NDR, SIEM, DLP and compliance
- Translate regulatory obligations into actionable controls and measurable outcomes
- Provide security advisory and managed services to clients; conduct client security reviews
- Lead threat intelligence, detection improvements, and threat hunting initiatives
- Support ISO 27001, NIST, SOC2, Lloyd’s Principle 12 audits and documentation
- Coordinate Cyber Essentials certification and audits
- Support operational resilience, disaster recovery planning and post-incident reviews
- Design and manage simulated phishing campaigns to improve staff awareness
Key requirements
- 7+ years in cybersecurity with 3–4+ years in a lead/principal role
- Experience in security engineering and SOC/IR within a regulated industry
- Proven leadership of a security team
- Ability to communicate security risk to C-suite and board
- Strong knowledge of security principles, OWASP Top 10, MITRE ATT&CK
- Cloud security experience (Azure/AWS), IAM, secrets and encryption management
- Experience with Microsoft 365 security suite and Defender tools
- Hands-on with SIEM platforms (Splunk, CrowdStrike Falcon, LogRhythm, Sentinel, Defender)
- Familiarity with Varonis, Tenable, Pentera and SOC processes
- Strategic leadership
- Clear communication with executive stakeholders
- Collaborative mindset
- IAM, PAM, PIM, encryption, certificate management
- Security monitoring and incident response
- Threat intelligence and threat hunting
…
