Security Operations Manager
Listed on 2026-09-03
-
IT/Tech
Cybersecurity, Security Management & Operations, IT Specialist
Who we are
Were IAG Loyalty - one organisation creating more rewarding ways to travel. Home to Avios the global loyalty currency we help millions of members collect and spend rewards across travel retail and financial services.
Were transforming our technology landscape investing in modern platforms and strengthening our cyber security capability to support our ambitious growth plans. Its an exciting time to join us as we continue to build a resilient secure and customer-focused business.
The opportunity
Were looking for a Security Operations Manager to play a key role in developing and maturing our Security Operations capability.
Working at the heart of our Cyber Security team youll act as the bridge between Security Engineering and Security Operations across IAG Group and our operating companies. Youll combine technical expertise with operational leadership to improve monitoring strengthen threat detection optimise security tooling and lead the response to security incidents.
This is a hands-on role where youll have genuine influence over how Security Operations evolves. Youll shape the roadmap improve operational resilience and ensure our security capabilities continue to develop as our technology landscape grows.
If youre passionate about building better security operations enjoy solving complex technical challenges and want to make a visible impact wed love to hear from you.
What youll be doing
Youll lead the continual improvement of our Security Operations capability working closely with Security Engineering technology teams and third-party partners to strengthen monitoring detection and incident response across the business.
Youll own the end-to-end incident management lifecycle coordinating responses to security incidents driving investigations facilitating lessons learned and ensuring improvement actions are delivered. Alongside this youll configure and optimise SIEM threat protection and case management platforms developing new detection rules alerts and automation to improve our ability to identify and respond to emerging threats.
Youll build and maintain operational playbooks and runbooks helping establish consistent ways of working across internal teams and managed service providers. Youll also produce meaningful KPIs and reporting using operational data to identify trends improve service performance and demonstrate the effectiveness of our security controls.
Working collaboratively across technology engineering and business teams youll support security testing assurance activities and resilience exercises helping ensure our operational security capability continues to evolve in line with business priorities and regulatory expectations.
What we need from you
Strong experience working within Security Operations Cyber Defence or Incident Response in a complex enterprise environment
Proven experience managing the end-to-end security incident management lifecycle
Hands-on experience configuring and administering SIEM threat protection logging and case management platforms
Experience developing threat detection use cases alerts dashboards and operational reporting
Strong understanding of security monitoring investigation triage containment recovery and continuous improvement
Experience developing operational playbooks runbooks and standard operating procedures
Experience working closely with Security Engineering teams to improve operational capabilities
Ability to collaborate with suppliers technology teams and stakeholders across the business
Experience developing KPIs operational reporting and service metrics
Strong analytical and communication skills with the ability to translate technical information for different audiences
Good understanding of security governance operational resilience and regulatory requirements
Desirable
Experience supporting Business Continuity and Disaster Recovery activities
Experience working with outsourced Security Operations Centres or Managed Security Service Providers
Familiarity with Microsoft Sentinel Splunk Microsoft Defender Crowd Strike or similar enterprise security platforms
Experience automating security operations using scripting or SOAR technologies
We might not be…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: