Security Operations Manager

Sportradar AG

Greater London

Hybrid

GBP 120,000 - 180,000

Full time

8 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Global team collaboration
Career development plan
Office-first hybrid model

Job summary

Sportradar AG is seeking a hands-on Security Operations leader to own end-to-end incident response, build and evolve a global SOC, and drive detection engineering and threat intelligence. The role demands technical depth in cloud security and hands-on experience with SIEM/Data Lakes, DDoS mitigation, and threat hunting, across time zones.

You will be the voice of operational reality at the leadership table, shaping on-call structures, tooling, and metrics to improve time to detect and contain,

Qualifications

  • Deep, current incident response experience; you have led serious incidents.

Responsibilities

  • Own incident response end-to-end and lead major incidents.

Skills

Incident response
SOC development
Detections engineering
Threat intelligence
Cloud security (AWS/GCP/Azure)
SIEM / Data Lakes
DDoS mitigation
Threat hunting
Purple teaming
Global team leadership

Tools

SIEM
Cloud platforms

Job description

We’re the world’s leading sports technology company, at the intersection between sports, media, and betting. More than 1,700 sports federations, media outlets, betting operators, and consumer platforms across 120 countries rely on our know-how and technology to boost their business.

Job Description


This is a hands-on leadership role. You need to be technical, in the detail, and able to lead an incident bridge. You will run a global function and own Security Operations end to end: the SOC, incident response, detection engineering and threat intelligence, along with the people and platforms behind them.

THE CHALLENGE:

  • Own incident response.
    • Preparation, triage, containment, eradication, and the post-incident reviews that make the next incident smaller. You will lead major incidents personally and set the standard for what good looks like.
  • Build the SOC we need next, not the one we have.
    • Evolve the operating model, the on-call structure, the tooling and the automation. You will have built a SOC before, either from scratch or through a major rebuild.
  • Treat detection engineering as an engineering discipline.
    • Detections as code: versioned, tested, tuned, and mapped to the threats that actually target us rather than a vendor's default rule pack. You will drive the coverage roadmap across our cloud estate and applications, and you know the difference between a thousand alerts and one good one.
  • Make threat intelligence earn its keep.
    • Build an intel capability that changes what we hunt for, what we detect, and what we brief to leadership.
  • Be the voice of operational reality.
    • At the leadership table, you are the person who knows what is happening on the ground, and says so. You will work closely with engineering, product security and the wider InfoSec leadership so that what we build is defensible and what we defend is understood.
  • Own operational effectiveness.
    • Define and improve measures that matter: detection coverage, investigation quality, time to detect and contain, escalation effectiveness, and whether lessons from incidents get implemented.

ABOUT YOU:

  • Deep, current incident response experience. You have personally led the response to serious incidents rather than observing them from a governance layer.
  • You have built a SOC: stood one up, or rebuilt one that wasn't working. The operating model, the hiring, the tooling, the metrics. You know what the first 90 days look like because you have lived them.
  • Technical, with a solid grounding in cloud. You understand how modern cloud environments (AWS, GCP, Azure) are attacked and defended, including identity, logging, lateral movement and containment, and how incident response works within them.
  • Detection engineering experience. You have built or led detection programmes covering rule development, coverage mapping, tuning and automation, and you can review a detection and tell whether it is good.
  • Threat intelligence experience. You have built or run an intel function and made it operational, feeding hunts, detections and decisions.
  • A track record of leading globally distributed technical teams across time zones.
  • Hands-on experience with SIEM/Data Lakes, implementing and supporting.
  • Experience with DDoS mitigation.
  • Experience with threat hunting and purple teaming.

OUR OFFER

  • A collaborative environment with colleagues from all over the world (Offices in Europe, Asia, North & South America).
  • Impactful Work: Contribute to the development of groundbreaking products that influence industries globally.
  • Ability to shape your own workday and career via a clearly defined professional and personal development plan.
  • We are a diverse and collaborative global team with a unique spirit, determined to achieve our goals with integrity and focus.
  • Opportunity to work with senior leadership, develop yourself and build your career within an inspiring and fast-growing company and digitalsportsenvironment.

While we appreciate the flexibility and benefits of working from home, we strongly believe that coming together in person fosters stronger connections, encourages collaboration, and drives innovation—both as individuals and as a company. The energy, shared ideas, and team support we experience in the office strengthen the foundation of our success and culture. For this reason, we are generally an office-first business operating on a hybrid model, with team members working in the office four days a week to build relationships, exchange ideas, and grow together.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations Manager
Security Operations Manager

Sportradar • Greater London

On-site
GBP 110,000 - 180,000
Global travel where applicable
Career development plan
Diversity & global team
VP, Security Operations
VP, Security Operations

Sportradar • Greater London

On-site
GBP 150,000 - 210,000
Hybrid work model
Global collaboration
Lead Security Operations Center Analyst (f/m/d)
Lead Security Operations Center Analyst (f/m/d)

Eplass • Reading

Hybrid
GBP 90,000 - 110,000
Hybrid working
Work from abroad
Flexible hours
+7
Director, ProdSecOps
Director, ProdSecOps

Genius Sports • Greater London

Hybrid
GBP 150,000 - 210,000
SOC Lead
SOC Lead

SecurityHQ • Greater London

Hybrid
GBP 70,000 - 110,000
Lead Security Operations Center Analyst (f/m/d)
Lead Security Operations Center Analyst (f/m/d)

Thinkproject • Reading

Hybrid
GBP 65,000 - 85,000
Lunch & Learn Sessions
Hybrid working
Unlimited learning
Senior SOC Analyst
Senior SOC Analyst

GCS Recruitment • England

On-site
GBP 90,000 - 120,000
SecOps Engineer
SecOps Engineer

Manchester Arndale • City Of London

On-site
GBP 55,000 - 85,000
Award-winning employer
Digital learning
Retail perks with Hapi app
+2
Global Head of Security Operations & Incident Response
Global Head of Security Operations & Incident Response

Sportradar • Greater London

Hybrid
GBP 150,000 - 210,000
Hybrid work model
Global collaboration
Head of Security Operations & Incident Response
Head of Security Operations & Incident Response

Sportradar AG • Greater London

Hybrid
GBP 120,000 - 180,000
Global team collaboration
Career development plan
Office-first hybrid model