Head of Security Operations & Delivery (IT)
Summary
Lead a team to modernize VAPT and SOC operations with AI-assisted workflows, ensuring high-quality delivery across client engagements and mentoring junior consultants.
Role Overview
You'll be the technical backbone of our delivery practice — replacing and elevating the senior technical leadership the team is losing, while building a modern, AI-augmented VAPT and SOC operation instead of running the same manual playbook the team has used for years. You'll own delivery quality across every client engagement and mentor a small team of consultants into specialists.
KeyResponsibilities
- Own end-to-end delivery quality for VAPT, SOC/managed detection, and risk assessment engagements — from scoping through final report sign-off.
- Redesign delivery workflows to incorporate AI-assisted reconnaissance, scanning, and alert triage, working closely with the AI Security & Automation Lead — freeing the team to focus on exploitation logic, business-context risk rating, and client communication.
- Launch and run our continuous/subscription-based VAPT offering, distinct from traditional point-in-time engagements.
- Mentor and technically develop 2 junior consultants, giving each a clear specialization track (VAPT/red-team or SOC/GRC).
- Act as the senior technical escalation point for clients and act as a technical sign-off authority on all findings before they leave the building.
- Partner with the Director, BD & Client Success on scoping calls and technical credibility during sales conversations.
- Own technical hiring decisions for future delivery-team growth.
Required Qualifications
- 6–10 years in penetration testing, red teaming, or security operations, with at least 2 years in a technical lead or team-lead capacity.
- Recognized offensive security certification (OSCP, OSCE, or equivalent) or strong demonstrable equivalent experience.
- Hands-on experience across web/network/cloud penetration testing and SOC/SIEM operations.
- Demonstrated (not just theoretical) use of AI/automation tooling in a security engagement — this is a genuine screening bar, not a nice-to-have.
- Strong written and verbal communication — able to translate technical findings into business risk for non-technical stakeholders.
Preferred
- Experience running or scaling a security consulting/delivery team of 3+ people.
- Familiarity with ISO 27001, NIST CSF, or similar frameworks.
- Exposure to continuous/DevSecOps-aligned testing models.