We are looking for a VP Security Operations & SIEM to take ownership of the organisation's security monitoring, SIEM and Managed Detection & Response capabilities.The role focuses on the day-to-day management and maintenance of the security environment, including SIEM administration, log onboarding, detection use cases and platform optimisation.
What You'll Do
- Own the day-to-day management, maintenance and optimisation of the SIEM environment, including log onboarding, ingestion, parsing and troubleshooting.
- Develop, maintain and tune detection rules, correlation searches and security use cases to improve detection coverage and reduce false positives.
- Manage and optimise security platforms including SIEM, SOAR, EDR and DLP, ensuring they remain effective and fit for purpose.
- Work closely with MDR/SOC providers on monitoring, alert triage, escalation and service performance, while acting as a senior technical escalation point.
- Support incident response, threat hunting and detection engineering, including improving detection coverage and security monitoring across cloud, endpoint, network and identity environments.
What You'll Bring
- Minimum 10 years of Cyber Security experience with strong hands-on expertise in SIEM and Security Operations, ideally with platforms such as Splunk, Microsoft Sentinel, QRadar or Elastic.
- Proven experience in SIEM administration, log source onboarding, detection rule development, tuning, troubleshooting and platform maintenance.
- Strong understanding of MDR/SOC operations, Detection Engineering, Threat Hunting and Incident Response, with experience working across EDR, SOAR and security automation.
- Experience within a financial services, banking or insurance environment, with good knowledge of security frameworks such as MAS TRM, NIST and MITRE ATT&CK.