Information Security Manager
HybridLondon, England, United Kingdom or Milton Keynes, England, United Kingdom
Job Summary
Own and run the SIEM, EDR, and vulnerability management estate, driving detection, triage, and remediation against agreed SLAs. Manage identity, DLP, and cloud security controls across Microsoft Entra ID, Purview, AWS, and Azure while leading technical response, containment, and recovery for security incidents. Investigate insider security events, coordinate penetration testing programmes, and drive threat hunting to improve the bank's proactive security posture. Own the Information Security roadmap, partnering with the Information Security Officer on governance and strategy prior to Board submission. Produce technical security metrics supporting board, committee, and regulatory requirements.
Required Qualifications
- Relevant industry certification (e.g. CompTIA Security+, Microsoft SC-200) or equivalent demonstrable hands-on experience
- Proven hands-on experience in a SOC analyst, security engineer or technical security role, in either a senior or lead position and within financial services or another regulated sector
- experience running vulnerability management programmes and handling technical incident response end to end
- Strong working knowledge of a SIEM platform
- practical EDR/XDR experience
- Microsoft 365 and Entra ID security controls (Conditional Access, PIM, Defender suite)
- scripting or automation (PowerShell or Python)
- network security fundamentals
- cloud security in AWS and Azure
Desired Qualifications
- CISSP, CISM, GIAC (GCIH, GCIA or GSEC), CREST, Tenable / Sentinel One / Google SecOps vendor accreditations
- Experience in a regulated UK financial services environment
- MSSP / supplier management experience
- Google SecOps (Chronicle)
- Microsoft Defender suite depth, beyond the baseline EntraID knowledge
- AWS security tooling such as Guard Duty, Cloud Security etc
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.