Security Operations – Technical Lead

Version 1

London, UKonsitePosted Jul 22, 2026
Posting intelligenceActively listedReposted 4×, possible evergreen/ghost posting

Skills

snowflakeoracleazureaws

About the role

Company Description

Version 1 has celebrated 30 years in business and continues to be trusted by global brands to deliver technology and transformation solutions that drive customer success. Our deep expertise enables our customers to navigate the rapidly evolving technology landscape. We foster strong partnerships with global technology leaders including Microsoft, AWS, Oracle, Red Hat, OutSystems, Snowflake, ensuring that our customers are provided with the highest quality solutions and services.

We’re an award-winning employer reflecting how our employees are at the very heart of what we do:

UK & Ireland's premier AWS, Microsoft & Oracle partner

3300+ strong, €350/£300m revenue business

10+ years as a Great Place to Work in Ireland & UK

Best Workplace for Women in the UK & Ireland by GPTW

Best Workplace for Wellbeing in the UK by GPTW

We’re a core values driven company, we hire people who share our values, and we reward those who display and foster them, it’s deeply embedded within our DNA. Invest in us and we’ll invest in you!.

Job Description

A hands-on technical leader who owns the security operations function - threat detection, incident response, phishing response, vulnerability management, and identity and access management and the day-to-day defense of the organisation's systems and data.

Acts as the internal owner of security operations while coordinating with an outsourced/managed SOC provider and manages reporting on risk posture to leadership.

Responsibilities:

Lead and coordinate security operations strategy; act as primary internal liaison with the managed SOC provider (escalations, tuning requests, SLA management)

Own incident response end-to-end: detection, triage, containment, post-incident review whether initiated internally or escalated by the SOC provider

Lead phishing detection and response: triage reported emails, coordinate takedowns, run awareness/simulation programs, and refine email security controls

Build and tune detection rules and hunting queries in Microsoft Sentinel and Defender XDR using KQL

Administer and optimize Microsoft Defender suite (Endpoint, Cloud, Identity, Office 365)

Run vulnerability management lifecycle using Tenable for scanning and ServiceNow Vulnerability Response for remediation tracking and SLAs

Manage Palo Alto firewall policies, rule hygiene, and log integration

Oversee EDR/NDR coverage and correlate alerts across endpoint and network telemetry

Write and maintain PowerShell scripts/automation for response actions and operational efficiency

Coordinate with IT, engineering, and compliance on audits, controls, and architecture reviews

Report metrics, incident summaries, and risk posture to leadership

Qualifications

Required Skills

Strong grounding in security operations - SIEM platforms (Sentinel), EDR/XDR (Defender), and SOAR tooling

KQL skills for Sentinel analytics, hunting, and workbooks

Microsoft Defender suite (XDR, endpoint, identity, cloud) administration

Phishing analysis and response (headers, URLs, attachments) and email security tooling

Identity and access management - Entra ID (Azure AD), conditional access, MFA, PIM, identity governance

Vulnerability management tools (Tenable, Defender)

ServiceNow Vulnerability Response for workflow

PowerShell scripting for automation and incident response actions

NDR concepts and cross-telemetry correlation

Experience managing/coordinating a third-party or outsourced SOC

Incident response methodology ( NIST 800-61)

People management + executive communication

Calm, decisive under incident pressure

Familiarity with frameworks like MITRE ATT&CK, NIST CSF, and ISO 27001

Palo Alto Networks firewall policy administration desirable

Certifications:

Microsoft SC-100, SC-200, SC-300, SC-100, SC-500/AZ-500

CISSP, GCIH

Experience:

5-8+ years in SecOps/IR with hands-on Microsoft security stack experience, demonstrated experience managing or working alongside a managed SOC/MSSP, 1-3+ years in a lead role preferred

Additional Information

Why Version 1?

At Version 1, we believe in providing our employees with a comprehensive benefits package that prioritises their wellbeing, professional growth, and financial stability.

Share in our success with our Quarterly Performance-Related Profit Share Scheme, where employees collectively benefit from a share of our company's profits

Strong Career Progression & mentorship coaching through our Strength in Balance & Leadership schemes with a dedicated quarterly Pathways Career Development programme

Flexible/remote working, Version 1 is tremendously understanding of life events and people’s individual circumstances and offer flexibility to help achieve a healthy work life balance

Financial Wellbeing initiatives including; Pension, Private Healthcare Cover, Life Assurance, Financial advice and an Employee Discount scheme

Employee Wellbeing schemes including Gym Discounts, Bike to Work, Fitness classes, Mindfulness Workshops, Employee Assistance Programme and much more. Generous holiday allowance, enhanced maternity/paternity leave, marriage/civil partnership leave and special leave policies

Educational assistance, incentivised certifications, and accreditations, including AWS, Microsoft, Oracle, and Red Hat

Reward schemes including Version 1’s Annual Excellence Awards & ‘Call-Out’ platform.

Environment, Social and Community First initiatives allow you to get involved in local fundraising and development opportunities as part of fostering our diversity, inclusion and belonging schemes.

And many more exciting benefits… drop us a note to find out more.

Version 1 is an equal opportunities employer.

We are committed to building a diverse, inclusive and respectful workplace where everyone feels valued and able to thrive. We welcome applications from people of all backgrounds, identities and lived experiences, and we value the different perspectives people bring including those shaped by disability and neurodiversity.

We want every candidate to have a positive and accessible recruitment experience. If you need reasonable adjustments at any stage of the process, please contact your recruiter at Version 1. We will consider all requests carefully, respectfully and confidentially.

Video links: https://www.youtube.com/watch?v=F_d3ELTH5zo

Questions about this role

Click "Apply with AI Applyd" above. We auto-fill the application from your resume and answer screening questions in seconds. No copy and paste, no juggling tabs.

Compensation for Security Engineer roles in United Kingdom varies widely by seniority, employer size, and remote vs onsite arrangement. Check the salary range on this listing when published, or browse our Security Engineer hub for United Kingdom medians across recent openings.

Most applications complete in under 90 seconds. You can track the status in your dashboard and watch the screenshot proof land the moment the application submits.

AI Applyd supports Greenhouse, Lever, Ashby, Workday, iCIMS, SmartRecruiters, Personio, Teamtailor and other major ATS platforms. If we can submit through the platform, we do.

Want AI Applyd to auto-apply to roles like this?

We tailor your resume per posting, fill the forms, and track replies for you.