The Cyber Defence Operations function protects AJ Bell against external adversaries and internal risks through four specialist capabilities: Security Monitoring & Detection Engineering, Cyber Threat Intelligence, Cyber Threat Exposure Management and Insider Risk Management. Together, these capabilities combine detection, intelligence, exposure management and insider risk to safeguard AJ Bell's customers, data, critical services and the trust placed in the firm. Security Monitoring & Detection Engineering provides an integrated monitoring, detection and response capability, combining internal technical expertise with 24x7 support from the Managed Security Service Provider. The Security Monitoring & Detection Engineering Lead is the principal technical authority for Security Monitoring & Detection Engineering capability, accountable for the effectiveness of security monitoring, detection engineering, technical investigation and incident response. This is a hands-on technical role responsible for the architecture, engineering and operational performance of Microsoft Sentinel and the wider security monitoring estate. The role would particularly suit an experienced detection engineering, security operations, red-team, purple-team or offensive-security leader who can translate real-world adversary behaviour into effective monitoring, detection and response. The role leads complex investigations and technical incident response, ensures the internal team and MSSP operate as one capability, and drives measurable improvements that reduce the potential for customer, operational, financial and regulatory harm.,
- Own the technical direction, quality and delivery performance of Security Monitoring & Detection Engineering, translating CDO priorities into a clear roadmap for monitoring, detection, investigation and response.
- Lead the architecture, engineering and continued development of our SIEM solution, ensuring the SIEM remains resilient, scalable, cost-effective and aligned with AJ Bell's technology estate and threat profile.
- Define and govern the onboarding of security telemetry across on-premises, Microsoft Azure, AWS and third‑party services, ensuring log sources address genuine visibility gaps and provide reliable value for detection and investigation.
- Own the detection engineering lifecycle across requirements, design, testing, deployment, tuning, performance assessment and retirement, supported by version control, peer review and controlled release practices.
- Lead the development of analytics rules, hunting queries, workbooks and automated investigation and response workflows.
- Own the operational effectiveness of security solutions managed by CDO ensuring configurations, integrations, detections and workflows deliver measurable security outcomes.
- Drive threat‑informed defence with Cyber Threat Intelligence and Cyber Threat Exposure Management, translating relevant threat actors, campaigns, TTPs, IOCs, critical vulnerabilities and attack paths into detections, targeted threat hunts and automated defensive actions.
- Maintain an evidence‑based view of service performance through agreed KPIs, KRIs and operational MI, identifying material variations, recurring failure points and capacity constraints, and driving corrective actions through to a measurable outcome.
- Act as the senior technical escalation point for complex, ambiguous and high‑severity security events, leading investigations through scoping, attack reconstruction, business‑impact assessment, containment and resolution.
- Experience investigating malicious code, identity compromise, business email compromise, fraud‑related intrusion, data exfiltration, cloud compromise or third‑party intrusion.
- Lead technical response within CIRT during declared cyber incidents, coordinating the internal team, MSSP and relevant technology functions in accordance with the firm's incident‑management processes to contain threats and reduce business impact.
- Build and improve investigation and response playbooks for priority threat scenarios, and lead tabletop, purple‑team and practical exercises that test detection coverage, technical readiness and coordination with relevant business functions.
- Operate the internal team and MSSP as one integrated monitoring and response capability, setting clear expectations for investigation quality, escalation consistency and response effectiveness, and addressing service issues before they affect security outcomes.
- Maintain an evidence‑based view of alert demand, detection quality, MTTA, MTTR, investigation outcomes, service capacity and recurring failure points, using these measures to prioritise and demonstrate improvement.
- Lead service reviews with key security vendors and providers, assessing delivery against expected outcomes and driving actions that maximise the contribution of existing investment to CDO's Detect, Defend and Respond objectives.
- Identify and deliver appropriate uses of automation and AI across detection engineering, enrichment, investigation and response, measuring the resulting improvement in quality, speed, consistency or coverage.
- Develop