- Company Name
- AJ Bell
- Job Title
- Head of Security Operations
- Job Description
-
**Job Title:** Head of Security Operations
**Role Summary:**
Lead and manage a security operations team to safeguard the organization’s data integrity, confidentiality, and availability. Drive proactive cyber‑defence, incident response, threat intelligence, and vulnerability management. Ensure 24/7 coverage, automate processes, and align security initiatives with business objectives. Report security posture to executive leadership and maintain regulatory compliance.
**Expectations:**
- Provide strategic direction for the Security Operations Centre (SOC).
- Deliver continuous improvement through automation, AI, and metrics.
- Maintain strong vendor relationships and manage service‑level agreements.
- Communicate risk and security posture to senior management and board.
- Foster a “security‑first” culture across all levels of the organization.
**Key Responsibilities:**
- Develop and maintain incident‑response playbooks; conduct tabletop exercises and executive‑level training.
- Own end‑to‑end vulnerability lifecycle: scanning, testing, mitigation, and remediation tracking.
- Maintain threat‑intelligence program; disseminate actionable insights to SOC and stakeholders.
- Ensure effective operations of SIEM, EDR, email/web gateways, DLP, and other security solutions.
- Oversee 24x7 monitoring and response activities in partnership with managed services.
- Manage SOC staff, provide coaching, and act as day‑to‑day escalation point.
- Evaluate and optimize security tools, processes, and automation to increase efficiency.
- Lead vendor performance reviews, negotiate contracts, and manage commercial budgets.
- Align security controls with ISO 27001, NIST, GDPR, FCA, PRA, and other applicable regulations.
- Prepare regular metrics, reporting, and governance presentations for executive and board audiences.
- Plan and execute security awareness initiatives and training for all staff levels.
**Required Skills:**
- Deep knowledge of information‑security risk‑management tools and frameworks (ISO 27001, NIST, CRISC, etc.).
- Proven experience with SOC operations, SIEM, EDR, email/web gateways, DLP, and cloud security solutions.
- Familiarity with Microsoft Purview, cloud‑native services, DevOps pipelines, and related security practices.
- Hands‑on expertise in managing Microsoft Active Directory, Windows, and Linux environments.
- Understanding of threat‑intelligence lifecycle and capability to conduct or oversee penetration testing.
- Strong written and verbal communication skills; ability to produce executive‑level documentation.
- Leadership experience managing a team of security analysts; ability to cultivate continuous improvement.
- Strategic mindset: challenge existing approaches, develop future‑proof security capabilities, and guide cross‑functional alignment.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Cyber‑Security, Information Technology, or related field.
- Professional certifications such as CISSP, CISM, CRISC, or equivalent; ISO 27001 Lead Auditor preferred.
- Additional specialized certifications (e.g., CompTIA Security+, CEH, or cloud‑security certifications) are advantageous.