- Company Name
- Compass Group UK & Ireland
- Job Title
- Group Deputy CISO - Operations
- Job Description
-
**Job Title:**
Group Deputy CISO – Operations
**Role Summary:**
Lead global cyber security operations, overseeing the Security Operations Centre (SOC), threat detection, incident response, and vulnerability management. Direct automation initiatives, drive metrics reporting, shape security policy frameworks, and mentor a high‑performance security team to protect the enterprise’s IT infrastructure, cloud environments, and data assets.
**Expactations:**
- Demonstrate senior‑level expertise in cyber security operations and incident response.
- Own cross‑functional collaboration with IT, business units and external partners.
- Provide executive‑level reporting and insights on security posture and vendor performance.
- Maintain alignment with global security frameworks (NIST, ISO 27001, ISF, etc.).
- Foster continuous improvement and professional development within the security team.
**Key Responsibilities:**
- Lead and optimize SOC and Managed Detection & Response (MDR) services.
- Design and implement incident response strategy, including detection, triage, containment and recovery processes.
- Own enterprise vulnerability management, threat exposure program, scanning, patching, and penetration testing.
- Champion automation and orchestration (SOAR, SIEM, EDR) to reduce response times and increase scalability.
- Define, track, and report key security metrics to senior leadership.
- Contribute to development and continual improvement of security policies, standards and controls.
- Manage vendor relationships, ensuring value delivery and operational efficiency.
- Mentor and develop the cyber security workforce, driving a culture of innovation.
- Act as a cyber security advisor to senior management, providing guidance on risk, compliance and technology initiatives.
**Required Skills:**
- Proven leadership in SOC management and incident response.
- Deep knowledge of SIEM, SOAR, EDR, vulnerability scanners, and automated threat detection.
- Strong analytical, problem‑solving and decision‑making abilities.
- Excellent communication skills for technical and non‑technical audiences.
- Understanding of regulatory requirements and compliance related to cyber security.
- Ability to manage contractor and service‑provider resources.
- Proficiency in English.
**Required Education & Certifications:**
- Bachelor’s or Master’s degree in Information Security, Computer Science or a related discipline.
- Professional certification such as CISSP, CISM or equivalent preferred.