Interim Head of Security Operations (SOC & Incident Response)

New Yesterday

Job Description

HW Interim Solutions are supporting a large, complex organisation with a significant IT/OT estate in the appointment of an Interim Head of Security Operations.


This role will operate as a critical number two to the CISO, providing oversight across security operations, acting as a senior escalation point for risk and incidents and supporting the ongoing maturity of the organisation’s cyber capabilities.


Key Responsibilities

  • Act as deputy to the CISO, providing day to day oversight of security operations
  • Serve as a senior escalation point for security incidents and risk management
  • Support the development and optimisation of the Security Operations Centre (SOC), including involvement in RFP processes for future state capability
  • Work closely with the Incident Response Lead to strengthen response frameworks and execution
  • Oversee and ensure effective use of key security tooling, including:
  • Microsoft Sentinel
  • Microsoft Defender suite
  • Darktrace
  • Contribute to broader security strategy across a complex IT and OT environment
  • Provide governance and oversight across penetration testing, threat & vulnerability management, and SOC operations
  • Engage with senior stakeholders, translating technical risk into clear business impact


Key Requirements

  • Proven experience operating at Head of / Deputy Head of Security Operations level
  • Strong background in security operations within complex IT/OT environments
  • Hands-on familiarity with SIEM/SOAR tooling (Sentinel), endpoint security (Defender) and threat detection platforms (eg. Darktrace)
  • Experience supporting or leading SOC design, optimisation, or vendor selection (RFP processes)
  • Solid understanding of:
  • Incident response frameworks
  • Penetration testing
  • Threat & vulnerability management
  • Ability to operate as a calm, credible escalation point during incidents
  • Strong communication skills with the ability to engage both technical and non-technical stakeholders


Location: North West (3 days onsite initially, reducing post-impact)

Duration: 6–12 months

Rate: Competitive (Outside IR35)

Location:
North West
Job Type:
FullTime
Category:
Real Estate