Information Security Technical Lead

Asta Capital Limited

Greater London

On-site

GBP 120,000 - 170,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Private medical insurance
Annual health screening
Gym membership
Pension plan (13% employer)

Job summary

Asta Capital Limited is seeking an Information Security Tech Lead to own and drive the end‑to‑end security programme across its IT landscape in London. You will lead a team of engineers, set the security direction, and ensure risk‑based decisions during incidents.

The role requires hands‑on security engineering, continuous monitoring, and operational resilience, with responsibilities spanning PAM, EDR, SIEM, DLP, and compliance initiatives for FCA/PRA, ISO 27001 and other standards.

Qualifications

  • 7+ years of hands‑on information security experience, including leadership roles.
  • Proven ability to translate risk into business language for executive audiences.
  • Strong knowledge of regulatory requirements and security controls across cloud and on‑prem environments.

Responsibilities

  • Lead a team of security engineers and own the information security roadmap.
  • Architect and harden infrastructure security, IAM, PAM, encryption and network security.
  • Monitor security alerts, triage incidents, and drive containment, eradication and recovery.

Skills

Security leadership
Team management
Threat intelligence
Incident response
Cloud security
SIEM tools
Regulatory compliance

Tools

Splunk
CrowdStrike Falcon
LogRhythm
Microsoft Defender
Sentinel

Job description

Description

Information Security Tech Lead is responsible for owning and driving the end‑to‑end information security programme across Asta & its client base. This role leads a team of engineers and provides authoritative security direction across PAM, EDR, SIEM, DLP, identity governance, vulnerability management, and regulatory compliance. The role requires hands‑on security engineering, continuous monitoring, and effective operational resilience. Responsibilities include making risk‑based decisions during incidents, prioritising alerts, coordinating containment actions, recommending remediation strategies, delivering infrastructure hardening, threat detection, vulnerability management and supporting Microsoft 365 security improvements.

Department and Location

Department: IT

Location: London, UK

Key Responsibilities
  • Security Leadership & Team Management: Lead a team of engineers, setting direction, managing workloads, developing capability, acting as primary escalation point across Infrastructure, and owning the InfoSec roadmap aligned to Asta’s IT transformation programme.
  • Infrastructure Security Engineering & Hardening: Implement and maintain security controls across infrastructure & systems, harden infrastructure with IAM, PIM, PAM encryption, network security best practices, review and implement recommendations of tools like Ping Castle, Semperis Lightning, and vendor solutions. Collaborate on implementing & integrating security controls into pipelines including scans, policy enforcement, and dependency checking.
  • Security Monitoring & Incident Response: Monitor alerts from SIEM, EDR, firewall, IDS/IPS, triage and prioritise based on severity, investigate incidents using log analysis, packet captures, forensic techniques, lead containment, eradication, recovery, maintain alerting, and integrate with SIEM/SOAR platforms.
  • Security Strategy & Programme Delivery: Define, own and drive delivery of the end‑to‑end security programme covering PAM, EDR, NDR, SIEM, penetration testing, DLP and compliance. Translate regulatory obligations (FCA/PRA, Lloyd’s Principle 12, CBEST, ISO 27001, Cyber Essentials) into actionable technical controls.
  • Client Security Services: Provide security advisory and managed services to 20+ syndicate and MGA clients, conduct security reviews, Secure Score assessments, Semperis/Entra evaluations, PAM deployment planning, act as escalation point for client‑facing incidents.
  • Threat Intelligence & Detection: Stay current with emerging threats, vulnerabilities, attack techniques, apply threat intelligence to improve detection, contribute to threat hunting and proactive monitoring.
  • Compliance & Documentation: Support compliance and audits for ISO 27001, NIST, SOC2, Lloyd’s Principle 12; prepare incident reports, maintain event logs, produce metrics, coordinate Cyber Essentials certification.
  • Operational Resilience & DR: Support resilience and business continuity planning, scenario testing, disaster recovery, post‑incident reviews and lessons learned.
  • Phishing Campaign Management: Design and manage simulated phishing campaigns, analyze results, identify training needs, track resilience metrics.
Skills, Knowledge & Expertise
  • 7+ years of hands‑on experience, with 3–4 years in a lead/management/principal cybersecurity role, combining security engineering, SOC operations or incident response within regulated industries.
  • Demonstrated experience leading and developing a security team, confident communicator translating risk into business language for C‑suite and board.
  • Strong understanding of cybersecurity principles, attack vectors, defense strategies, OWASP Top 10 and Mitre Attack framework.
  • Experience with cloud security (Azure/AWS), IAM, secrets management, encryption, certificate management, and Microsoft 365 security suite (Microsoft Defender, Azure AD Identity Protection, threat analytics, compliance tools).
  • Hands‑on experience with SIEM platforms (Splunk, CrowdStrike Falcon, LogRhythm, Sentinel, Microsoft Defender).
  • Experience with tools such as Varonis, Tenable, Pentera and establishing external/internal SOC processes.
Job Benefits

Work‑life balance:

  • 35‑hour working week with hybrid and flexible working.
  • Generous holiday allowance that increases with service.

Your health & wellbeing:

  • Private medical insurance with virtual GP access.
  • Annual health screening, dental cover and eye care.
  • Subsidised gym or sports club membership.

Support for you and your family:

  • Enhanced maternity, paternity, adoption and shared parental pay.

Rewarding your contribution:

  • Highly competitive pension with up to 13 % employer contribution.
  • Life assurance and income protection.
  • Discretionary annual bonus scheme.
  • Interest‑free season ticket loan and salary sacrifice schemes.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Technical Lead
Information Security Technical Lead

Davies Group • Greater London

Hybrid
GBP 80,000 - 110,000
Private medical insurance
Generous holiday allowance
Highly competitive pension
Senior Security Operations Engineer New London
Senior Security Operations Engineer New London

Risk Ledger • Greater London

Hybrid
GBP 90,000 - 135,000
EMI equity
Healthcare AXA
Hybrid working policy
+3
Engineering Manager, Security
Engineering Manager, Security

Insignis • Greater London

Hybrid
GBP 120,000 - 180,000
25 days holiday
Pension 5%
Private medical insurance
+4
Engineering Manager, Security
Engineering Manager, Security

Insignis Cash • Greater London

Hybrid
GBP 120,000 - 180,000
25 days holiday
5% Pension contributions
Private medical insurance with Vitaliy
+5
Information Security Architecture & Engineering Lead (UK-based)
Information Security Architecture & Engineering Lead (UK-based)

PCI Pal • Greater London

On-site
GBP 120,000 - 160,000
25 days holiday
Medical, dental and optical insurance
Work from anywhere policy
+3
Head of Cyber Security and Productivity Solutions
Head of Cyber Security and Productivity Solutions

M+C Saatchi UK • Greater London

On-site
GBP 120,000 - 180,000
Cultural stimulation allowance – £250 per person per year
Half days off before bank holidays
Emergency care days for dependants
+5
Principal Security Architect
Principal Security Architect

Artificial Labs Ltd • Greater London

Hybrid
GBP 110,000 - 160,000
Private medical insurance
Income protection insurance
Life insurance
+11
Senior Security Operations Engineer
Senior Security Operations Engineer

Risk Ledger • Greater London

On-site
GBP 90,000 - 100,000
Competitive salary
Equity package
Private pension
+5
Security Assurance Specialist
Security Assurance Specialist

G-Research • Greater London

On-site
GBP 90,000 - 130,000
Competitive compensation
Annual discretionary bonus
Lunch via Just Eat for Business
+6
Information Security Manager
Information Security Manager

Recognise Bank • Greater London

Hybrid
GBP 90,000 - 100,000
Competitive Time Off
Work From Anywhere
Hybrid Working
+4