The posting
Purpose of the Role Responsible for the operational delivery, continuous improvement, and performance oversight of client’s Managed Security Services capability under the Cyber Fusion Centre. The role supports the implementation, operation, monitoring, and optimisation of security controls across enterprise platforms, infrastructure, cloud services, applications, and emerging technology environments. The incumbent is expected to provide hands-on engineering support, maintain effective security operations processes, strengthen preventive and detective controls, and contribute to the organisation’s cyber resilience, regulatory readiness, and threat response capabilities.
Role Attributes Operational ownership and engineering support for client Managed Security Services across the client Group, with focus on reliable service delivery, effective control operations, timely issue resolution, measurable security outcomes, and alignment with Enterprise Information Security priorities.
Key Responsibilities § Managed Security Services Operations
o Operate, maintain, and continuously improve managed security services across the enterprise security technology stack.
o Oversee service delivery, incident handling support, operational health, capacity, availability, and performance of assigned security platforms.
o Maintain service documentation, runbooks, escalation paths, standard operating procedures, and operational metrics.
§ Security Engineering and Control Implementation
o Implement, configure, tune, troubleshoot, and maintain security controls across infrastructure, endpoint, network, cloud, application, and identity environments.
o Support design and deployment of preventive, detective, and responsive security controls aligned to enterprise risk and regulatory expectations.
o Validate control effectiveness through monitoring, testing, reporting, and continuous improvement activities.
§ Security Tools and Technology Management
o Provide hands-on support for security solutions including email security, intrusion detection and prevention, attack surface monitoring, anti-malware, web application firewall, certificate management, vulnerability monitoring, and related managed services.
o Maintain platform configuration baselines, access controls, integration points, and operational readiness for assigned tools.
o Work with vendors and managed service providers to resolve issues, track service improvements, and ensure agreed service levels are met.
§ System Security Requirements and Documentation
o Identify, document, and maintain system security requirements, operational procedures, configuration standards, and technical artefacts.
o Support evidence collection, audit responses, control attestation, and compliance reporting where required.
o Ensure operational documentation remains accurate, current, and usable by internal teams and service providers.
§ AI Security Operations Support
o Assist in implementing security controls for AI and machine learning environments, including data protection, model deployment, inference endpoints, logging, access control, and secure configuration.
o Support identification and mitigation of AI-related risks such as data leakage, prompt injection, adversarial attacks, model abuse, and data poisoning.
o Contribute to operational readiness for AI security monitoring and incident response.
§ Post-Quantum Cryptography and Crypto-Agility Support
o Support post-quantum cryptography readiness activities, including cryptographic inventory, certificate visibility, dependency tracking, and migration planning.
o Track developments in quantum-resistant cryptographic standards and assess potential impacts on TLS, digital signatures, encryption services, and certificate management.
o Contribute to hybrid cryptographic migration planning and crypto-agility improvements.
§ Project Delivery, Risk Reduction, and Continuous Improvement
o Support security projects, remediation initiatives, service improvements, and operational uplift activities from planning through delivery.
o Track assigned actions, risks, dependencies, and milestones to ensure timely completion and transparent reporting.
o Recommend practical improvements to strengthen resilience, reduce operational risk, and improve security outcomes.
Key Decisions within the Role § Prioritisation of day-to-day operational activities, service requests, alert tuning, troubleshooting, and remediation support within agreed scope.
§ Recommendation of security configuration improvements, control enhancements, process changes, and service optimisation opportunities.
§ Development and maintenance of standard operating procedures, runbooks, operational workflows, and BAU process documentation.
§ Escalation of material risks, control gaps, recurring incidents, vendor performance concerns, and unresolved operational issues to the Managed Security Services Lead.
§ Individual contributor within the Cyber Fusion Centre, with direct operational accountability for assigned Managed Security Services activities and indirect coordination responsibilities across internal technology teams, vendors, and managed service providers.
Requirements Experience
§ Minimum 3years of relevant experience in cybersecurity operations, security engineering, managed security services, infrastructure security, or related technology risk functions.
§ Practical experience supporting security technologies such as email security, IDPS, WAF, anti-malware, attack surface monitoring, certificate management, vulnerability management, SIEM/SOAR, endpoint security, or cloud security controls.
§ Strong understanding of cybersecurity principles, secure configuration practices, incident response support, threat detection, vulnerability management, access control, logging, and security monitoring.
§ Ability to analyse complex security issues, identify root causes, assess risk, propose practical remediation options, and communicate findings clearly.
§ Working knowledge of scripting or automation using languages such as Python, PowerShell, Bash, or equivalent is preferred.
§ Strong stakeholder management, documentation, problem-solving, and collaboration skills, with the ability to operate effectively in a regulated financial services environment.
Education
§ Academic: Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related discipline is preferred.
§ Professional Certification(s): CISSP, CISM, CCSP, Security+, GIAC, cloud security, network security, or relevant vendor certifications are preferred.



