Security Operations Lead

We've had a new urgent role just go live with one of our long term clients in the financial services sector.

This role is for a hands-on SecOps lead who wants to shape how a fast-moving organisation detects, responds to, and recovers from security incidents. You’ll sit at the heart of the security monitoring and response function, supporting a digital transformation that touches thousands of users across the UK.

What you’ll be doing
  • Owning and improving the SIEM setup, tuning signals and extending coverage
  • Working with Microsoft Defender, Intune, 365 and cloud-based tooling
  • Collaborating with security, risk and engineering teams to improve controls
  • Helping shape a modern security roadmap fit for a cloud-first future
What you’ll bring
  • Solid experience leading and improving cyber incident response
  • Expertise in Microsoft Defender, Intune, and enterprise-level security tools
  • Experience with SIEM tuning and threat detection in environments with 500 users
Nice to have
  • AZ500, CISSP or CISM certification
  • Experience with Splunk, Rapid7, or similar tools
  • Exposure to regulated environments
  • Familiarity with endpoint compliance and cloud security (Azure or AWS)
This is a remote first role with monthly trips to the office. It will start out as a fixed term contract but has a good chance of becoming permanent upon completion.

If you’re the kind of person who doesn’t just spot security risks — you fix them, explain them clearly, and help others get smarter in the process, then this is the role for you.

Send across your CV or contact Adam Whitehurst at Trust in Soda for more info.