As the Security Operations Lead, you will take strategic and operational ownership of Lendable’s internal SecOps capability and serve as the technical relationship owner of our external Managed Security Service Provider (MSSP). You will act as our primary incident responder, with a strategic view on how Lendable’s operational defence should mature as we grow.
This is a high-impact, senior individual contributor role with a path to management. We are looking for a "player-coach" who can execute deep 2nd and 3rd-line technical analysis today, while strategically designing and building out our internal SecOps function and team over the coming year.
What You’ll Be Doing
1. Incident Command & Advanced Analysis
Incident Leadership: Serve as the primary Incident Commander for high-severity security escalations, coordinating cross-functional response efforts. You will have on-call responsibilities, but shared with the wider team.
Advanced Tier 2/3 Analysis: Act as the escalation point for technical investigations triggered by the MSSP first line team.
Crisis & Resilience Simulation: Maintain and evolve Lendable’s Security Crisis Management plan, running regular tabletop exercises to ensure business-wide readiness for systemic and supply-chain risks.
2. Vendor Governance & Operational Architecture
MDR/MSSP Technical Governance: Serve as the ultimate authority over our external MSSP. Define KRIs/KPIs, run rigorous service reviews, and hold the provider to strict detection quality standards.
Detection & Logging Strategy: Own Lendable's detection engineering roadmap. Ensure comprehensive, high-fidelity log ingestion pipelines across all corporate and cloud assets, focusing on minimising false positives and alert fatigue.
Automation-Driven Remediation: Oversee the vulnerability management lifecycle, partnering with IT and Engineering to drive automated remediation workflows rather than relying on manual tracking spreadsheets.
3. Capability Architecture & Strategic Maturity
Threat Intelligence: Develop a Threat Intel capability that translates external threats into actionable, proactive defences.
Core Domain Ownership: Take operational security ownership across our foundational tech stack, continuously optimising our posture across domains such as EDR, Email Security, DLP, and IAM to prevent data exfiltration and identity-based attacks.
Capability Scaling: Drive the technical roadmap for SecOps maturity. Systematically close visibility gaps, optimise operational metrics, and introduce AI-augmented capabilities (e.g., automated response playbooks).
Organic Function Growth: Design the future-state roadmap for the SecOps function. As you scale our technical capabilities, architect the requirement for team expansion, ensuring the team grows in lockstep with operational maturity.
What We’re Looking For
Operational Seniority: Extensive experience in modern Security Operations, specifically acting as an Incident Commander or Lead Responder in high-stakes environments.
Strategic Vision: A clear, modern philosophy on how a SecOps function should run, prioritising automation and vendor optimisation over linear headcount growth.
Cloud-Native Literacy: Familiarity with modern tech stacks (AWS, Kubernetes, CI/CD pipelines) and the ability to leverage automation (Python, scripting, or automation platforms) to optimise analyst workflows.
The "Builder" Mentality: You are highly comfortable executing as a senior IC on day one, with the presence and leadership maturity to transition into a team manager.
Interview Process
TA Screening Call
Hiring Manager Call
Technical Interview
Culture Interview