Cyber Operations Manager
Previous Experience Required:
* Led or coordinated cyber security incident response as an Incident Commander or equivalent, working with MDR providers and cross-functional stakeholders (IT, Legal, Compliance).
* A strong, hands-on technical background in operational cyber security spanning endpoint & EDR, identity & Active Directory, Microsoft 365 & Azure, network/ZTNA, and SIEM/log management — able to act as a senior technical authority within the team.
* Demonstrable experience leading cyber security incident response (incident command), from detection through containment and remediation.
* Working knowledge of MITRE ATT&CK and at least one recognised control framework (ISO 27001, CIS or NIST).
* Risk-based prioritisation of remediation using threat intelligence.
* Operated endpoint security and endpoint detection and response (EDR) tooling (e.g. CrowdStrike or equivalent) in a production environment.
* Prioritised and managed a risk-based security backlog, applying frameworks such as MITRE ATT&CK and threat-based prioritisation.
* Assured the delivery of security initiatives across distributed teams or sites, tracking vulnerability remediation and patching through to completion.
* Act as Incident Commander for security incidents during London hours, coordinating first responders, IT, Legal, Compliance, specialist providers and EDF Group as required.
* Serve as the first point of escalation for IT and the business in London on cyber security matters.
* Work with the 24/7 Managed Detection and Response (MDR) provider to triage and escalate detections.
* Coordinate local participation in incident response exercises and maintain readiness.
* Track and chase vulnerability remediation and patching on London-managed systems, escalating blockers.
* Own the global prioritisation of the Endpoint, Platform and Incident Response backlog, ordered against the enterprise cyber risk register and exploitation-based intelligence (e.g. MITRE ATT&CK).
* Curate the backlog from inputs across Houston and London, including the endpoint detection and response (CrowdStrike) execution lead.
* Maintain alignment of this domain to the enterprise risks for endpoint compromise, detection and containment, and cyber resilience.
* Operate within the Global Head’s monthly prioritisation cadence; prioritisation across other domains remains with the Global Head.
* Provide the local stakeholder interface for cyber security in London.
* Planned and delivered complex, cross-functional security or technology initiatives end-to-end, coordinating multiple workstreams, stakeholders and dependencies to time and quality.
This is a hybrid role working 3 days a week in the London office and 2 days remotely