Information Security Technical Lead
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+14 more
Job description
Description
Information Security Tech Lead is responsible for owning and driving the end-to-end information security programme across Asta & its client base. This role leads a team of engineers and provides authoritative security direction across PAM, EDR, SIEM, DLP, identity governance, vulnerability management, and regulatory compliance. The role requires hands-on security engineering, continuous monitoring, and effective operational resilience. Responsibilities include making risk-based decisions during incidents, prioritising alerts, coordinating containment actions, recommending remediation strategies, delivering infrastructure hardening, threat detection, vulnerability management and supporting Microsoft 365 security improvements.
Department and Location
Department: IT
Location: London, UK
Key Responsibilities
- Security Leadership & Team Management: Lead a team of engineers, setting direction, managing workloads, developing capability, acting as primary escalation point across Infrastructure, and owning the InfoSec roadmap aligned to Asta’s IT transformation programme.
- Infrastructure Security Engineering & Hardening: Implement and maintain security controls across infrastructure & systems, harden infrastructure with IAM, PIM, PAM encryption, network security best practices, review and implement recommendations of tools like Ping Castle, Semperis Lightning, and vendor solutions. Collaborate on implementing & integrating security controls into pipelines including scans, policy enforcement, and dependency checking.
- Security Monitoring & Incident Response: Monitor alerts from SIEM, EDR, firewall, IDS/IPS, triage and prioritise based on severity, investigate incidents using log analysis, packet captures, forensic techniques, lead containment, eradication, recovery, maintain alerting, and integrate with SIEM/SOAR platforms.
- Security Strategy & Programme Delivery: Define, own and drive delivery of the end-to-end security programme covering PAM, EDR, NDR, SIEM, penetration testing, DLP and compliance. Translate regulatory obligations (FCA/PRA, Lloyd’s Principle 12, CBEST, ISO 27001, Cyber Essentials) into actionable technical controls.
- Client Security Services: Provide security advisory and managed services to 20+ syndicate and MGA clients, conduct security reviews, Secure Score assessments, Semperis/Entra evaluations, PAM deployment planning, act as escalation point for client-facing incidents.
- Threat Intelligence & Detection: Stay current with emerging threats, vulnerabilities, attack techniques, apply threat intelligence to improve detection, contribute to threat hunting and proactive monitoring.
- Compliance & Documentation: Support compliance and audits for ISO 27001, NIST, SOC2, Lloyd’s Principle 12; prepare incident reports, maintain event logs, produce metrics, coordinate Cyber Essentials certification.
- Operational Resilience & DR: Support resilience and business continuity planning, scenario testing, disaster recovery, post-incident reviews and lessons learned.
- Phishing Campaign Management: Design and manage simulated phishing campaigns, analyze results, identify training needs, track resilience metrics.
Skills, Knowledge & Expertise
- 7+ years of hands-on experience, with 3-4 years in a lead/management/principal cybersecurity role, combining security engineering, SOC operations or incident response within regulated industries.
- Demonstrated experience leading and developing a security team, confident communicator translating risk into business language for C-suite and board.
- Strong understanding of cybersecurity principles, attack vectors, defense strategies, OWASP Top 10 and Mitre Attack framework.
- Experience with cloud security (Azure/AWS), IAM, secrets management, encryption, certificate management, and Microsoft 365 security suite (Microsoft Defender, Azure AD Identity Protection, threat analytics, compliance tools).
- Hands-on experience with SIEM platforms (Splunk, CrowdStrike Falcon, LogRhythm, Sentinel, Microsoft Defender).
- Experience with tools such as Varonis, Tenable, Pentera and establishing external/internal SOC processes.
Job Benefits
Work-life balance:
- 35-hour working week with hybrid and flexible working.
- Generous holiday allowance that increases with service.
Your health & wellbeing:
- Private medical insurance with virtual GP access.
- Annual health screening, dental cover and eye care.
- Subsidised gym or sports club membership.
Support for you and your family:
- Enhanced maternity, paternity, adoption and shared parental pay.
Rewarding your contribution:
- Highly competitive pension with up to 13 % employer contribution.
- Life assurance and income protection.
- Discretionary annual bonus scheme.
- Interest-free season ticket loan and salary sacrifice schemes.
Requirements
- 7+ years of hands-on experience, with 3-4 years in a lead/management/principal cybersecurity role, combining security engineering, SOC operations or incident response within regulated industries.
- Demonstrated experience leading and developing a security team, confident communicator translating risk into business language for C-suite and board.
- Strong understanding of cybersecurity principles, attack vectors, defense strategies, OWASP Top 10 and Mitre Attack framework.
- Experience with cloud security (Azure/AWS), IAM, secrets management, encryption, certificate management, and Microsoft 365 security suite (Microsoft Defender, Azure AD Identity Protection, threat analytics, compliance tools).
- Hands-on experience with SIEM platforms (Splunk, CrowdStrike Falcon, LogRhythm, Sentinel, Microsoft Defender).
- Experience with tools such as Varonis, Tenable, Pentera and establishing external/internal SOC processes.
Benefits & conditions
Work-life balance:
- 35-hour working week with hybrid and flexible working.
- Generous holiday allowance that increases with service.
Your health & wellbeing:
- Private medical insurance with virtual GP access.
- Annual health screening, dental cover and eye care.
- Subsidised gym or sports club membership.
Support for you and your family:
- Enhanced maternity, paternity, adoption and shared parental pay.
Rewarding your contribution:
- Highly competitive pension with up to 13 % employer contribution.
- Life assurance and income protection.
- Discretionary annual bonus scheme.
- Interest-free season ticket loan and salary sacrifice schemes.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
What Are The Top Skills Required For Azure Developers?
9 Ways to Make Money Hacking
Walking Into The Era of Supply Chain Risks
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.