Cyber Security Manager

Virgin Atlantic

Crawley

On-site

GBP 90,000 - 140,000

Full time

20 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Virgin Atlantic is seeking an experienced Manager, Cyber Security Operations to lead our Information & Cyber Security team. You will drive rapid response to threats, develop detection capabilities and mentor a skilled team across cloud, endpoints, networks and identity services.

You'll manage complex investigations, enhance detection content and playbooks, and coordinate with senior stakeholders while contributing to cyber resilience and a strong security culture.

Qualifications

  • Significant experience in Cyber Security Operations, Incident Response or Security Engineering.
  • Strong hands-on experience leading security investigations through identification, containment, eradication and recovery.
  • Excellent knowledge of Windows, Linux, networking, cloud platforms and modern authentication technologies.
  • Experience using SIEM, EDR/XDR, cloud security and email security platforms, including Microsoft Sentinel and Defender.
  • Experience investigating identity-related attacks and privileged access threats.
  • Understanding attacker tactics and MITRE ATT&CK framework.
  • Experience developing detection use cases, threat hunting methodologies and incident response playbooks.
  • Scripting or automation skills using PowerShell, Python, KQL, Logic Apps or SOAR.
  • Strong analytical and communication skills; able to explain complex issues to diverse audiences.
  • Experience mentoring or leading cyber security professionals.

Responsibilities

  • Lead the technical response to complex cyber security incidents, coordinating investigations from detection through recovery.
  • Act as Cyber Incident Lead during major incidents, providing technical direction to senior stakeholders.
  • Investigate threats across cloud environments, endpoints, networks, and identity platforms.
  • Develop and enhance detection rules, SIEM content, and incident response playbooks.
  • Improve monitoring across Microsoft Sentinel, Defender and other security technologies.
  • Conduct proactive threat hunting using threat intelligence and behavioural analytics.
  • Identify opportunities to automate investigation and response activities using scripting/automation tools.
  • Coach and mentor Cyber Security Operations Analysts to build team capability.
  • Collaborate with technology teams, managed security partners and external specialists.
  • Translate technical findings into risk-based business recommendations and participate in on-call rotations.

Skills

Cyber Security Operations
Incident Response
Security Engineering
Threat Hunting
MITRE ATT&CK
Automation/Scripting

Tools

SIEM
EDR/XDR
Microsoft Defender
Microsoft Sentinel
Azure
AWS

Job description

We're looking for an experienced Manager, Cyber Security Operations to join our Information & Cyber Security team. This is a senior technical role where you'll lead the response to cyber threats, drive improvements across our security operations capability and play a key part in strengthening our cyber resilience.

You'll be at the centre of our security operations, leading complex investigations, developing advanced detection capabilities and mentoring a team of talented security professionals. Working across cloud platforms, infrastructure, applications, networks and identity services, you'll help ensure we're always one step ahead of an ever‑evolving threat landscape.

If you're passionate about cyber security, thrive under pressure and enjoy solving complex technical challenges, we'd love to hear from you.

Day to day

No two days are ever the same in Cyber Security Operations. You'll combine hands‑on technical expertise with leadership, helping protect one of the UK's most recognised brands.

You’ll:

  • Lead the technical response to complex cyber security incidents, coordinating investigations from detection through to recovery.
  • Act as the Cyber Incident Lead during major incidents, providing technical direction and clear updates to senior stakeholders.
  • Investigate sophisticated threats across cloud environments, endpoints, networks, identity platforms and applications.
  • Develop and enhance detection rules, SIEM content, investigation playbooks and response procedures.
  • Improve monitoring capabilities across Microsoft Sentinel, Microsoft Defender and other security technologies.
  • Conduct proactive threat hunting using threat intelligence, behavioural analytics and attacker techniques.
  • Identify opportunities to automate investigation and response activities using PowerShell, Python, KQL, Logic Apps, SOAR or similar technologies.
  • Coach and mentor Cyber Security Operations Analysts, helping build technical capability across the team.
  • Work closely with technology teams, managed security partners and external specialists to continually improve our cyber resilience.
  • Translate technical findings into clear, risk‑based recommendations that support better business decisions.
  • As part of our operational security function, you'll also participate in an on‑call rota and support out‑of‑hours incident response when required.
You'll bring:
  • Significant experience in Cyber Security Operations, Incident Response or Security Engineering.
  • Strong hands‑on experience leading security investigations through identification, containment, eradication and recovery.
  • Excellent knowledge of Windows, Linux, networking, cloud platforms, identity services and modern authentication technologies.
  • Experience using SIEM, EDR/XDR, cloud security and email security platforms, including technologies such as Microsoft Sentinel, Microsoft Defender, Azure or AWS.
  • Experience investigating identity‑related attacks, including account compromise, MFA abuse, token theft and privileged access threats.
  • Strong understanding of attacker tactics, techniques and procedures, including MITRE ATT&CK.
  • Experience developing detection use cases, threat hunting methodologies and incident response playbooks.
  • Practical scripting or automation skills using PowerShell, Python, KQL, Logic Apps, SOAR or similar technologies.
  • Excellent analytical and communication skills, with the ability to explain complex technical issues to both technical and non‑technical audiences.
  • Experience mentoring or leading other cyber security professionals.
  • Above all, you'll be curious, collaborative and committed to continually improving cyber security operations.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Operations Specialist
Cyber Security Operations Specialist

Tank Recruitment • Bath

On-site
GBP 55,000 - 85,000
Cyber security Operation Manager
Cyber security Operation Manager

Agratas – A Tata Enterprise • Bridgwater

On-site
GBP 55,000 - 75,000
Cyber Security Engineer
Cyber Security Engineer

Marks Sattin • England

On-site
GBP 60,000 - 80,000
Cyber Security Operations Analyst
Cyber Security Operations Analyst

Caraffi • Reading

On-site
GBP 55,000 - 75,000
Cyber Security Manager - Hybrid
Cyber Security Manager - Hybrid

Ashdown Group • Greater London

Hybrid
GBP 70,000 - 92,000
Cyber Security Manager
Cyber Security Manager

Top Recruit • Greater London

On-site
GBP 60,000 - 65,000
Cyber Security Manager
Cyber Security Manager

Harvey Nash Group • Harrow

Hybrid
GBP 90,000 - 120,000
Cyber Security Analyst
Cyber Security Analyst

Novia Financial plc • Bath

On-site
GBP 55,000 - 75,000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

eFinancialCareers • Greater London

On-site
GBP 75,000 - 86,000
Cyber Security Engineer
Cyber Security Engineer

Nigel Wright Recruitment • Newcastle upon Tyne

On-site
GBP 42,000 - 65,000