Enable job alerts via email!

Security Operations Lead

Trust In SODA

Carlisle

Remote

GBP 70,000 - 90,000

Full time

Today
Be an early applicant

Job summary

A financial services security firm in the UK is looking for a Security Operations Lead to enhance their security monitoring. This remote-first role involves leadership in incident response, SIEM setup improvement, and collaboration with various teams. Ideal candidates will have experience with Microsoft Defender and large-scale security tools. The position starts as a fixed-term contract but has potential for permanence.

Qualifications

  • Proven experience leading and improving cyber incident response.
  • Expertise with enterprise-level security tools.
  • SIEM tuning and threat detection experience in larger environments.

Responsibilities

  • Improve the SIEM setup and extend signal coverage.
  • Collaborate with teams to enhance security controls.
  • Shape a modern security roadmap for cloud environments.

Skills

Cyber incident response
Microsoft Defender
Intune
SIEM tuning
Threat detection

Education

AZ500, CISSP or CISM certification

Tools

Splunk
Rapid7
Job description

Security Operations Lead

We're launching an urgent role with one of our long‑term clients in the financial services sector. This hands‑on SecOps lead will shape how a fast‑moving organization detects, responds to, and recovers from security incidents. You’ll sit at the heart of the security monitoring and response function, supporting a digital transformation that touches thousands of users across the UK.

What you’ll be doing
  • Owning and improving the SIEM setup, tuning signals, and extending coverage.
  • Working with Microsoft Defender, Intune, 365 and cloud‑based tooling.
  • Collaborating with security, risk and engineering teams to improve controls.
  • Helping shape a modern security roadmap fit for a cloud‑first future.
What you’ll bring
  • Solid experience leading and improving cyber incident response.
  • Expertise in Microsoft Defender, Intune, and enterprise‑level security tools.
  • Experience with SIEM tuning and threat detection in environments with 500+ users.
Nice to have
  • AZ500, CISSP or CISM certification.
  • Experience with Splunk, Rapid7, or similar tools.
  • Exposure to regulated environments.
  • Familiarity with endpoint compliance and cloud security (Azure or AWS).

This is a remote first role with monthly trips to the office. It will start out as a fixed‑term contract but has a good chance of becoming permanent upon completion.

If you’re the kind of person who doesn’t just spot security risks – you fix them, explain them clearly, and help others get smarter in the process – then this is the role for you.

Send across your CV or contact Adam Whitehurst at Trust in Soda for more info.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.