Interim Head of Security Operations (SOC & Incident Response)
New Yesterday
Job Description
HW Interim Solutions are supporting a large, complex organisation with a significant IT/OT estate in the appointment of an Interim Head of Security Operations.
This role will operate as a critical number two to the CISO, providing oversight across security operations, acting as a senior escalation point for risk and incidents and supporting the ongoing maturity of the organisation’s cyber capabilities.
Key Responsibilities
- Act as deputy to the CISO, providing day to day oversight of security operations
- Serve as a senior escalation point for security incidents and risk management
- Support the development and optimisation of the Security Operations Centre (SOC), including involvement in RFP processes for future state capability
- Work closely with the Incident Response Lead to strengthen response frameworks and execution
- Oversee and ensure effective use of key security tooling, including:
- Microsoft Sentinel
- Microsoft Defender suite
- Darktrace
- Contribute to broader security strategy across a complex IT and OT environment
- Provide governance and oversight across penetration testing, threat & vulnerability management, and SOC operations
- Engage with senior stakeholders, translating technical risk into clear business impact
Key Requirements
- Proven experience operating at Head of / Deputy Head of Security Operations level
- Strong background in security operations within complex IT/OT environments
- Hands-on familiarity with SIEM/SOAR tooling (Sentinel), endpoint security (Defender) and threat detection platforms (eg. Darktrace)
- Experience supporting or leading SOC design, optimisation, or vendor selection (RFP processes)
- Solid understanding of:
- Incident response frameworks
- Penetration testing
- Threat & vulnerability management
- Ability to operate as a calm, credible escalation point during incidents
- Strong communication skills with the ability to engage both technical and non-technical stakeholders
Location: North West (3 days onsite initially, reducing post-impact)
Duration: 6–12 months
Rate: Competitive (Outside IR35)
- Location:
- North West
- Job Type:
- FullTime
- Category:
- Real Estate