Security Operations Manager

Sportradar

Greater London

Hybrid

GBP 110,000 - 180,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Global travel where applicable
Career development plan
Diversity & global team

Job summary

Sportradar is seeking a hands-on security operations leader to own end-to-end incident response, build a next-gen SOC, and drive detection engineering and threat intelligence across a global cloud estate.

You will work with engineering, product security and the InfoSec leadership to ensure defensible designs and effective responses, while leading distributed teams and shaping security program maturity.

Qualifications

  • Deep, hands-on incident response experience with leadership.
  • Experience building or rebuilding a SOC with operating model, tooling and metrics.
  • Cloud-focused security with understanding of AWS, GCP and Azure attack/defense.
  • Detection engineering experience: rule development, coverage mapping, tuning & automation.
  • Threat intelligence function built or run and operational across hunts and detections.
  • Leadership of globally distributed technical teams across time zones.
  • Hands-on with SIEM/Data Lakes and DDoS mitigation.

Responsibilities

  • Own incident response end to end, lead major incidents personally and set the standard.
  • Build and evolve a SOC operating model, on-call structure, tooling, and automation.
  • Treat detections as code and drive coverage across cloud estates and apps.
  • Develop an intel capability that informs hunts, detections and leadership briefings.
  • Be the voice of operational reality to engineering, product security and InfoSec leadership.
  • Define and improve measures: detection coverage, investigation quality, time to detect/contain.

Skills

Incident Response
Cloud Security
SOC Development
Leadership
Threat Intelligence
DDoS Mitigation
SIEM / Data Lakes
Purple Teaming
Global Leadership
Security Engineering

Tools

Splunk
AWS/Azure/GCP
ThreatConnect

Job description

We’re the world’s leading sports technology company, at the intersection between sports, media, and betting. More than 1,700 sports federations, media outlets, betting operators, and consumer platforms across 120 countries rely on our know-how and technology to boost their business.

Job Description

This is a hands-on leadership role. You need to be technical, in the detail, and able to lead an incident bridge. You will run a global function and own Security Operations end to end: the SOC, incident response, detection engineering and threat intelligence, along with the people and platforms behind them.

THE CHALLENGE:

  • Own incident response.
    • Preparation, triage, containment, eradication, and the post-incident reviews that make the next incident smaller. You will lead major incidents personally and set the standard for what good looks like.
  • Build the SOC we need next, not the one we have.
    • Evolve the operating model, the on-call structure, the tooling and the automation. You will have built a SOC before, either from scratch or through a major rebuild.
  • Treat detection engineering as an engineering discipline.
    • Detections as code: versioned, tested, tuned, and mapped to the threats that actually target us rather than a vendor's default rule pack. You will drive the coverage roadmap across our cloud estate and applications, and you know the difference between a thousand alerts and one good one.
  • Make threat intelligence earn its keep.
    • Build an intel capability that changes what we hunt for, what we detect, and what we brief to leadership.
  • Be the voice of operational reality.
    • At the leadership table, you are the person who knows what is happening on the ground, and says so. You will work closely with engineering, product security and the wider InfoSec leadership so that what we build is defensible and what we defend is understood.
  • Own operational effectiveness.
    • Define and improve measures that matter: detection coverage, investigation quality, time to detect and contain, escalation effectiveness, and whether lessons from incidents get implemented.

ABOUT YOU:

  • Deep, current incident response experience. You have personally led the response to serious incidents rather than observing them from a governance layer.
  • You have built a SOC: stood one up, or rebuilt one that didn't work. The operating model, the hiring, the tooling, the metrics. You know what the first 90 days look like because you have lived them.
  • Technical, with a solid grounding in cloud. You understand how modern cloud environments (AWS, GCP, Azure) are attacked and defended, including identity, logging, lateral movement and containment, and how incident response works within them.
  • Detection engineering experience. You have built or led detection programmes covering rule development, coverage mapping, tuning and automation, and you can review a detection and tell whether it is good.
  • Threat intelligence experience. You have built or run an intel function and made it operational, feeding hunts, detections and decisions.
  • A track record of leading globally distributed technical teams across time zones.
  • Hands-on experience with SIEM/Data Lakes, implementing and supporting.
  • Experience with DDoS mitigation.
  • Experience with threat hunting and purple teaming.

OUR OFFER

  • A collaborative environment with colleagues from all over the world (Offices in Europe, Asia, North & South America).
  • Impactful Work: Contribute to the development of groundbreaking products that influence industries globally.
  • Ability to shape your own workday and career via a clearly defined professional and personal development plan.
  • We are a diverse and collaborative global team with a unique spirit, determined to achieve our goals with integrity and focus.
  • Opportunity to work with senior leadership, develop yourself and build your career within an inspiring and fast-growing company and digitalsportsenvironment.

While we appreciate the flexibility and benefits of working from home, we strongly believe that coming together in person fosters stronger connections, encourages collaboration, and drives innovation—both as individuals and as a company. The energy, shared ideas, and team support we experience in the office strengthen the foundation of our success and culture. For this reason, we are generally an office-first business operating on a hybrid model, with team members working in the office four days a week to build relationships, exchange ideas, and grow together.

OUR RECRUITMENT PROCESS:

  • Initial Screening: A quick chat with our Talent Acquisition Partner to understand your background and expectations.
  • Two Hiring Team Interviews: Meet with the Hiring team and Hiring Manager to dive into your expertise, as also discuss team fit.
  • Final Steps: Receive feedback and, if successful, an offer!
Additional Information

To be selected for a Senior Executive role at Sportradar or a role within the Compliance, Finance, Integrity, or Legal business areas of Sportradar, Candidates must, as permitted by applicable laws, successfully complete a background check or submit proof of successfully passing such a check. Candidates with criminal histories will be considered in a manner consistent with the applicable requirements necessary for the business area and consistent with applicable laws.

At Sportradar, we celebrate our diverse group of hardworking employees. Sportradar is committed to ensuring equal access to its programs, facilities, and employment opportunities. All qualified applicants will receive consideration for employment without regard to age, race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. We encourage you to apply even if you only meet most of the requirements (but not 100% of the listed criteria) – we believe skills evolve over time. If you’re willing to learn and grow with us, we invite you to join our team!

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

VP, Security Operations
VP, Security Operations

Sportradar • Greater London

On-site
GBP 150,000 - 210,000
Hybrid work model
Global collaboration
VP, Security Operations
VP, Security Operations

Sportradar AG • Greater London

Hybrid
GBP 120,000 - 180,000
Intelligence Analyst, Risk & Investigations
Intelligence Analyst, Risk & Investigations

Sportradar • Greater London

On-site
GBP 42,000 - 65,000
Global Employee Assistance Programme
Well-being apps
Office-first on-site model
Senior Director, Revenue Performance & Planning
Senior Director, Revenue Performance & Planning

Sportradar • City Of London

On-site
GBP 90,000 - 130,000
Collaborative work environment
Flexible working hours
Global Employee Assistance Programme
Intelligence Analyst, Blockchain & Crypto
Intelligence Analyst, Blockchain & Crypto

Sportradar • City Of London

On-site
GBP 65,000 - 95,000
Collaborative environment
Autonomy and flexible work style
Structure and autonomy balance
+3
Partnership Protection Specialist, Europe & Asia
Partnership Protection Specialist, Europe & Asia

Sportradar • City Of London

On-site
GBP 65,000 - 90,000
Partnership Protection Specialist, Europe & Asia
Partnership Protection Specialist, Europe & Asia

Sportradar • Greater London

On-site
GBP 70,000 - 95,000
Trading Investigator
Trading Investigator

Sportradar AG • Greater London

Hybrid
GBP 65,000 - 95,000
Global Employee Assistance Programme
Calm and Reulay app
Senior Client Success Partner - Strategic Accounts
Senior Client Success Partner - Strategic Accounts

Sportradar • Greater London

Hybrid
GBP 70,000 - 95,000
Senior Director, Group Reporting and Technical Accounting
Senior Director, Group Reporting and Technical Accounting

Sportradar • Greater London

On-site
GBP 180,000 - 240,000
Competitive compensation