Security Operations – Technical Lead
Version1Job Description
📋 Description Lead security operations strategy; liaison with the managed SOC Own end-to-end incident response: detection, triage, containment, review Lead phishing detection and response: triage emails, takedowns, awareness Build/tune detection rules and hunting queries in Sentinel/Defender XDR (KQL) Administer and optimize Defender suite (Endpoint, Cloud, Identity, O365) Oversee audits, controls and architecture reviews with IT/compliance 🎯 Requirements Security ops with SIEM (Sentinel), EDR/XDR (Defender), and SOAR KQL for Sentinel analytics, hunting, and workbooks Microsoft Defender suite administration (XDR, endpoint, identity, cloud) Phishing analysis/response and email security tooling IAM management – Entra ID/Azure AD, conditional access, MFA, PIM Vulnerability tools (Tenable, Defender) and SOC coordination; NIST/MITRE familiarity 🎁 Benefits Quarterly profit share based on company performance Career progression and mentorship programs Flexible/remote working options Pension, private healthcare, life assurance Wellbeing: gym discounts, Mindfulness, EAP Educational assistance and certs (AWS, Microsoft, Oracle, Red Hat)