Security Operations Lead – Incident Response & Detection
La Fosse
Greater London
Hybrid
GBP 110,000 - 140,000
Full time
29 hours ago
Be an early applicant
Application generator
An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Get past ATS filters
Job summary
La Fosse in London is seeking a Security Operations Manager to lead our end-to-end security operations, overseeing the SOC, incident response, detection engineering and threat intelligence. This role combines hands-on technical work with leadership across a global function, operating in a hybrid model with onsite and remote elements. The ideal candidate has led major cyber incident responses and built a SOC or rebuilt one, with strong cloud security expertise across AWS, GCP and Azure.
Qualifications
Led response to serious cyber incidents.
Built or rebuilt a SOC: operating model, hiring, tooling, and metrics.
Technical with strong cloud grounding across AWS, GCP and Azure.
Built or led detection programmes with rule development, coverage mapping, tuning and automation.
Experience with threat hunting and purple teaming.
Responsibilities
Lead end-to-end security operations including SOC and incident response.
Own detection engineering and threat intelligence programs.
Lead incident bridges and manage cross-functional response.
Build and optimise operating model, tooling, and metrics.
Oversee cloud security across AWS, GCP, and Azure.
Skills
Incident response
SOC leadership
Cloud security
Detection engineering
Threat intelligence
Threat hunting
Purple teaming
Incident bridge
People management
Operational metrics
Job description
La Fosse in London is seeking a Security Operations Manager to lead our end-to-end security operations, overseeing the SOC, incident response, detection engineering and threat intelligence. This role combines hands-on technical work with leadership across a global function, operating in a hybrid model with onsite and remote elements. The ideal candidate has led major cyber incident responses and built a SOC or rebuilt one, with strong cloud security expertise across AWS, GCP and Azure.