VP, Security Operations & SIEM
We are looking for a VP Security Operations & SIEM to take ownership of the organisation's security monitoring, SIEM and Managed Detection & Response capabilities.The role focuses on the day-to-day management and maintenance of the security environment, including SIEM administration, log onboarding, detection use cases and platform optimisation. What You'll Do Own the day-to-day management, maintenance and optimisation of the SIEM environment, including log onboarding, ingestion, parsing and troubleshooting. Develop, maintain and tune detection rules, correlation searches and security use cases to improve detection coverage and reduce false positives. Manage and optimise security platforms including SIEM, SOAR, EDR and DLP, ensuring they remain effective and fit for purpose. Work closely with MDR/SOC providers on monitoring, alert triage, escalation and service performance, while acting as a senior technical escalation point. Support incident response, threat hunting and detection engineering, including improving detection coverage and security monitoring across cloud, endpoint, network and identity environments.
What You'll Bring Minimum 10 years of Cyber Security experience with strong hands-on expertise in SIEM and Security Operations, ideally with platforms such as Splunk, Microsoft Sentinel, QRadar or Elastic. Proven experience in SIEM administration, log source onboarding, detection rule development, tuning, troubleshooting and platform maintenance. Strong understanding of MDR/SOC operations, Detection Engineering, Threat Hunting and Incident Response, with experience working across EDR, SOAR and security automation. Experience within a financial services, banking or insurance environment, with good knowledge of security frameworks such as MAS TRM, NIST and MITRE ATT&CK.