Haystack
← Back to Jobs
Temporary/Casual
Operations & Project Management

Security Operations Lead - MUST HAVE SC CLEARANCE - Inverness or Preston - 6 months+

Octopus Computer AssociatesPreston, Lancashire🇬🇧United KingdomPosted 13 Aug 2026

Quick Overview

Work Type
On Site
Schedule
Temporary/Casual
Level
Mid Senior

Job Description

Security Operations Lead - MUST HAVE SC CLEARANCE - Inverness or Preston - 6 months+

One of our Blue Chip Clients is urgently looking for a Security Operations Lead.

Please note this role is to start end of September/early October.

Please find some details below:

The candidate hasn't been outside the UK for more than 28 consecutive days during the last 5 years

Location: Inverness or Preston | 5 days onsite

MUST BE PAYE THROUGH UMBRELLA

Role Description:

The Senior Security Incident Management Consultant operates within the Operational Integrator (OI) function and provides governance, leadership, assurance, and strategic oversight of security incident management across a complex multi-supplier environment.

The role is responsible for ensuring suppliers manage security incidents consistently, effectively, and in accordance with client policy, regulatory obligations, and operational risk requirements. Acting as the primary OI lead for incident governance, the consultant provides a consolidated view of incident risk, drives supplier accountability, and supports continual improvement across the incident management life cycle.

This is a governance, assurance, and supplier management role and does not perform SOC monitoring, incident investigation, forensic analysis, or operational response activities.

Key Responsibilities:

Security Incident Governance

  • Own and govern the security incident management framework across suppliers
  • Define and maintain:
    • Incident classification criteria
    • Escalation models
    • Reporting standards
    • Major incident governance processes
  • Ensure alignment to client policies, regulatory obligations, and security controls

Supplier Governance & Performance Management

  • Act as the primary OI lead for security incident governance
  • Challenge, validate, and assure supplier incident management processes
  • Drive consistency in reporting, escalation, communications, and evidence standards
  • Manage escalations relating to significant or recurring incidents

Incident Risk & Executive Oversight

  • Maintain visibility of security incident exposure across all suppliers
  • Ensure major incidents receive appropriate governance attention
  • Support risk-based decision making through accurate incident reporting
  • Provide oversight of supplier corrective and preventative actions

Reporting & Executive Visibility

  • Produce consolidated security incident reporting across suppliers
  • Provide insight into:
    • Incident trends
    • Response performance
    • SLA adherence
    • Recurring root causes
    • Risk exposure
  • Support governance boards, service review meetings, and client security leadership

Assurance & Evidence Management

  • Define incident management evidence requirements
  • Ensure traceability across:
    • Detection
    • Escalation
    • Investigation outcomes
    • Recovery activities
    • Closure decisions
  • Support audits, assurance reviews, and regulatory inspections

Post-Incident Review & Continuous Improvement

  • Coordinate governance of Post Incident Reviews (PIRs)
  • Ensure suppliers provide:
    • Root cause analysis
    • Corrective actions
    • Improvement activities
  • Identify opportunities to improve incident governance, reporting, and operational effectiveness

Your skills and experience

Essential

  • Significant experience in Security Incident Management, Cyber Governance, Service Management, or GRC roles
  • Strong understanding of:
    • Security incident life cycles
    • Major incident management
    • Security reporting and governance
  • Experience working within complex multi-supplier environments
  • Strong stakeholder engagement and supplier management skills
  • Experience presenting incident risk information to senior stakeholders

Desirable

  • Knowledge of:
    • NIST Cyber Security Framework (CSF)
    • NCSC guidance
    • ITIL Major Incident Management
    • ISO 27001
  • Experience supporting security assurance and audit activities
  • Experience in Defence, Government, or highly regulated sectors

Key Deliverables

  • Security Incident Management Framework
  • Consolidated supplier incident reporting
  • Executive incident dashboards
  • Governance and assurance reporting packs
  • Post Incident Review governance outputs
  • Continuous improvement roadmap

Role Definition

The role governs and assures security incident management across suppliers, ensuring incidents are consistently escalated, evidenced, reviewed, and reported to the client through a controlled and audit-ready process, without performing operational security response activities.

What This Role Does/Does Not Do

Does

  • Govern, assure, challenge and coordinate
  • Provide enterprise-wide incident visibility
  • Drive supplier accountability
  • Support risk-informed operational decision making
  • Lead incident governance and reporting

Does Not

  • Operate SOC tooling
  • Perform forensic investigations
  • Respond to incidents directly
  • Own technical remediation activities
  • Conduct security monitoring or threat hunting

Please send CV for full details and immediate interviews. We are a preferred supplier to the client.

Skills

Continuous Improvement
Root Cause Analysis

Similar jobs