Head of Security Operations

Analyst

Head of Security Operations

Apply Now

- $0.00

  • Date posted
    October 5, 2026
  • Expiration date
    January 5, 2027
  • Application ends
    January 5, 2027

Our client is seeking a Head of Security Operations

Responsibilities

What you’ll do

Detection strategy & engineering

  • Define and maintain the detection strategy, mapped to MITRE ATT&CK and iterated against real incidents and threat intel, not left as a static framework exercise
  • Set the standards and review bar for Microsoft Sentinel content (detection rules, analytics, workbooks, Logic Apps playbooks) whether authored by the MSSP or in-house, and own detection-as-code practices – version control, peer review, testing – for that content
  • Own the detections the MSSP can’t reasonably build: bespoke, payments/fraud-specific, or identity-driven logic
  • Onboard new log sources and systems into the detection pipeline as the platform evolves, and integrate Defender XDR , Wiz, Cloudflare, Zscaler , and other tooling as it’s added, including email/data security telemetry (Defender for O365, DLP) once in scope
  • Consume threat intelligence (feeds, ISACs, sector-specific sources) and translate it into detection and hunting priorities rather than treating it as a subscription nobody reads
  • Build and maintain SOAR automation for alert enrichment, triage, and response actions, so the function scales with the estate rather than with headcount

MSSP & outsourced SOC

  • Own the MSSP/outsourced SOC relationship end to end: SLAs, triage quality, playbook tuning, and contract renewal or rescoping as the function’s needs change
  • Actively shape the boundary between MSSP and in-house scope as the team and platform mature, rather than treating today’s split as permanent

Incident response & management

  • Lead incident response: own L3 investigation and forensic analysis across cloud and endpoint, working from MSSP escalations and your own detections
  • Own incident management end to end alongside the CISO – major incident declaration, exec/board notification, and coordination with legal/comms on regulatory notification clocks (GDPR 72-hour, DORA incident classification and reporting) – not just the technical investigation
  • Develop and maintain incident response playbooks and runbooks, and test them regularly through tabletop exercises rather than leaving them filed and unverified
  • Drive post-incident reviews and RCAs, and feed lessons back into detection and playbook updates

Vulnerability management & identity governance

  • Own vulnerability management as a program: scanning coverage across cloud, endpoint, and applications, risk-based prioritization, remediation SLAs, and exception handling with named owners
  • Own identity governance within security operations: privileged access monitoring, access anomaly detection, joiner/mover/leaver assurance from a security lens, and identity-related detection coverage across Entra ID/Okta and cloud IAM

Metrics, team, and reporting

  • Own MTTD, MTTR, and other operational metrics: baseline them, track them, and drive them down
  • Manage the security operations team, including direct line management of the Security Analyst, and build the hiring/leveling plan as team and MSSP scope evolve
  • Manage SOC systems, tooling, and processes end to end, including budget and licensing conversations with the CISO
  • Support the CISO on incident communication, board/customer reporting, and post-incident reviews

What we’re looking for

Essential:

  • Deep Microsoft Sentinel experience: KQL proficient, able to author and critically review detection rules, workbooks, and playbooks, even where day-to-day content maintenance sits with a third party
  • Experience onboarding new data sources into a SIEM and scaling detection coverage as an environment grows
  • Hands-on incident response and digital forensics experience across cloud and endpoint, including running an incident through containment, eradication, and RCA, not just triage
  • Experience sharing ownership of the incident management process: major incident declaration, exec communication, and regulatory notification timelines (GDPR, DORA, or equivalent), typically alongside a CISO or equivalent
  • Applied MITRE ATT&CK knowledge used in detection engineering, not just framework familiarity
  • Experience running or managing vulnerability management as a program: tooling, prioritization, remediation tracking, and reporting
  • Working knowledge of identity governance and access risk (privileged access, JML, IAM/entitlement review) as it applies to security operations
  • Experience managing an MSSP/outsourced SOC relationship, including SLAs, contract or scope negotiation, and holding a third party accountable for quality
  • Experience running tabletop exercises or equivalent IR plan testing
  • Cloud security telemetry: AWS CloudTrail, Azure Monitor, GCP audit logs
  • Strong written communication for incident reports and RCAs aimed at non-technical readers

Nice to have:

  • Prior people management or mentoring experience in a SOC or detection engineering team
  • Experience with Defender XDR (Defender for Endpoint, Identity, Cloud Apps)
  • Wiz or equivalent CSPM integration into detection pipelines
  • Fintech, payments, or regulated environment background
  • Formal threat intelligence platform experience (beyond consuming feeds)
  • Python or PowerShell for automation
  • Certifications (valued, not required): SC-200, AZ-500, GCIA, GCIH, GCFE, GCFA, or equivalent applied experience

Are you interested in this position?

Apply by clicking on the “Apply Now” button below!

#AlbionarcJobs#FintechJobs

#AsiaJobs#MiddleEastCareers

#TechTalent#FintechRecruitment

#FinanceOpportunities#

Apply Now

- $0.00

Select your currency