Information Security Technical Lead

Asta Capital Limited
London, UK
25 days ago
Apply on www.collegerecruiter.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Microsoft Windows Amazon Web Services Data Analysis Software System Penetration Testing Microsoft Azure Cloud Computing Security Cyber Security Disaster Recovery Identity and Access Management Intrusion Detection and Prevention Intrusion Detection Systems Key Management
+14 more
Network Security Log Analysis Packet Analyzer Open Web Application Security Azure Active Directory Phishing Security Information and Event Management Software Vulnerability Management SSL Certificate Management Cyber Threat Analysis Firewalls (Computer Science) Performance Monitor Splunk Vulnerability Analysis

Job description

Description

Information Security Tech Lead is responsible for owning and driving the end-to-end information security programme across Asta & its client base. This role leads a team of engineers and provides authoritative security direction across PAM, EDR, SIEM, DLP, identity governance, vulnerability management, and regulatory compliance. The role requires hands-on security engineering, continuous monitoring, and effective operational resilience. Responsibilities include making risk-based decisions during incidents, prioritising alerts, coordinating containment actions, recommending remediation strategies, delivering infrastructure hardening, threat detection, vulnerability management and supporting Microsoft 365 security improvements.

Department and Location

Department: IT

Location: London, UK

Key Responsibilities

  • Security Leadership & Team Management: Lead a team of engineers, setting direction, managing workloads, developing capability, acting as primary escalation point across Infrastructure, and owning the InfoSec roadmap aligned to Asta’s IT transformation programme.
  • Infrastructure Security Engineering & Hardening: Implement and maintain security controls across infrastructure & systems, harden infrastructure with IAM, PIM, PAM encryption, network security best practices, review and implement recommendations of tools like Ping Castle, Semperis Lightning, and vendor solutions. Collaborate on implementing & integrating security controls into pipelines including scans, policy enforcement, and dependency checking.
  • Security Monitoring & Incident Response: Monitor alerts from SIEM, EDR, firewall, IDS/IPS, triage and prioritise based on severity, investigate incidents using log analysis, packet captures, forensic techniques, lead containment, eradication, recovery, maintain alerting, and integrate with SIEM/SOAR platforms.
  • Security Strategy & Programme Delivery: Define, own and drive delivery of the end-to-end security programme covering PAM, EDR, NDR, SIEM, penetration testing, DLP and compliance. Translate regulatory obligations (FCA/PRA, Lloyd’s Principle 12, CBEST, ISO 27001, Cyber Essentials) into actionable technical controls.
  • Client Security Services: Provide security advisory and managed services to 20+ syndicate and MGA clients, conduct security reviews, Secure Score assessments, Semperis/Entra evaluations, PAM deployment planning, act as escalation point for client-facing incidents.
  • Threat Intelligence & Detection: Stay current with emerging threats, vulnerabilities, attack techniques, apply threat intelligence to improve detection, contribute to threat hunting and proactive monitoring.
  • Compliance & Documentation: Support compliance and audits for ISO 27001, NIST, SOC2, Lloyd’s Principle 12; prepare incident reports, maintain event logs, produce metrics, coordinate Cyber Essentials certification.
  • Operational Resilience & DR: Support resilience and business continuity planning, scenario testing, disaster recovery, post-incident reviews and lessons learned.
  • Phishing Campaign Management: Design and manage simulated phishing campaigns, analyze results, identify training needs, track resilience metrics.

Skills, Knowledge & Expertise

  • 7+ years of hands-on experience, with 3-4 years in a lead/management/principal cybersecurity role, combining security engineering, SOC operations or incident response within regulated industries.
  • Demonstrated experience leading and developing a security team, confident communicator translating risk into business language for C-suite and board.
  • Strong understanding of cybersecurity principles, attack vectors, defense strategies, OWASP Top 10 and Mitre Attack framework.
  • Experience with cloud security (Azure/AWS), IAM, secrets management, encryption, certificate management, and Microsoft 365 security suite (Microsoft Defender, Azure AD Identity Protection, threat analytics, compliance tools).
  • Hands-on experience with SIEM platforms (Splunk, CrowdStrike Falcon, LogRhythm, Sentinel, Microsoft Defender).
  • Experience with tools such as Varonis, Tenable, Pentera and establishing external/internal SOC processes.

Job Benefits

Work-life balance:

  • 35-hour working week with hybrid and flexible working.
  • Generous holiday allowance that increases with service.

Your health & wellbeing:

  • Private medical insurance with virtual GP access.
  • Annual health screening, dental cover and eye care.
  • Subsidised gym or sports club membership.

Support for you and your family:

  • Enhanced maternity, paternity, adoption and shared parental pay.

Rewarding your contribution:

  • Highly competitive pension with up to 13 % employer contribution.
  • Life assurance and income protection.
  • Discretionary annual bonus scheme.
  • Interest-free season ticket loan and salary sacrifice schemes.

Requirements

  • 7+ years of hands-on experience, with 3-4 years in a lead/management/principal cybersecurity role, combining security engineering, SOC operations or incident response within regulated industries.
  • Demonstrated experience leading and developing a security team, confident communicator translating risk into business language for C-suite and board.
  • Strong understanding of cybersecurity principles, attack vectors, defense strategies, OWASP Top 10 and Mitre Attack framework.
  • Experience with cloud security (Azure/AWS), IAM, secrets management, encryption, certificate management, and Microsoft 365 security suite (Microsoft Defender, Azure AD Identity Protection, threat analytics, compliance tools).
  • Hands-on experience with SIEM platforms (Splunk, CrowdStrike Falcon, LogRhythm, Sentinel, Microsoft Defender).
  • Experience with tools such as Varonis, Tenable, Pentera and establishing external/internal SOC processes.

Benefits & conditions

Work-life balance:

  • 35-hour working week with hybrid and flexible working.
  • Generous holiday allowance that increases with service.

Your health & wellbeing:

  • Private medical insurance with virtual GP access.
  • Annual health screening, dental cover and eye care.
  • Subsidised gym or sports club membership.

Support for you and your family:

  • Enhanced maternity, paternity, adoption and shared parental pay.

Rewarding your contribution:

  • Highly competitive pension with up to 13 % employer contribution.
  • Life assurance and income protection.
  • Discretionary annual bonus scheme.
  • Interest-free season ticket loan and salary sacrifice schemes.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.collegerecruiter.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

11:18 min

Addressing audience questions on security and microservice architectures

Reinhard Kugler · LIVE

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

3:48 min

Leveraging multi-agent systems for autonomous software testing

Ondřej Gróf Ondřej Gróf · World Congress 2026 Europe

2:39 min

Exposing stored XSS and phishing attacks via markdown

Ramona Schwering Ramona Schwering · World Congress 2026 Europe

Videos

See all

Related articles

See all