{"id":1405285,"url":"https://alion.io/job/kentplc-cyber-security-operations-manager","title":"Cyber Security Operations Manager","company":{"id":1837632,"name":"Kent","domain":"kentplc.com","url":"https://alion.io/company/kentplc","size_band":"201-500","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Oracle","truth_index":{"grade":"B","score":75,"open_postings":8,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":29,"computed_at":"2026-10-06T05:45:30Z"}},"role":"Security","role_family":"Security","seniority":"staff","employment_type":null,"work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["India"],"countries":["IN"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":24000,"max_usd":56000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":478},"experience_years_min":10,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Azure","optional":false},{"name":"Copilot","optional":false},{"name":"Crowdstrike","optional":false},{"name":"ISO 27001","optional":false},{"name":"ITSM","optional":false},{"name":"Microsoft Entra ID","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"NIST CSF","optional":false},{"name":"Red Teaming","optional":false},{"name":"Zero Trust","optional":false},{"name":"DLP","optional":true},{"name":"ITIL","optional":true},{"name":"PowerShell","optional":true},{"name":"Python","optional":true},{"name":"SIEM","optional":true}],"status":"live","first_seen_at":"2026-09-28T10:57:37Z","employer_posted_date":"2026-09-28","last_verified_at":"2026-10-07T01:13:23Z","board_verified":true,"closed_at":null,"days_open":8,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":8},"description":"About the job:\nKent is looking for a Cyber Security Operations Manager to lead the end-to-end operation and continuous improvement of our cyber security capability, and to help embed security across the wider technology estate. The role is accountable for detecting, responding to and reducing cyber risk across Kent's global technology environment through effective security operations, threat detection, incident response and vulnerability management, working alongside colleagues in Infrastructure, Cloud, Service Operations, Enterprise Architecture, Applications and Compliance to deliver measurable risk reduction.\nWorking within a lean global cyber security function, the role combines operational leadership with the development of longer-term capability. The Cyber Security Operations Manager is the technical authority for security operations and a trusted partner to the wider technology teams, setting security requirements, coordinating specialist activity and assuring that controls are operating effectively. Infrastructure, Cloud, Network, Applications and Service Operations teams remain accountable for the day-to-day management of the platforms and services within their remit. Success in this role is measured by improved security outcomes and measurable risk reduction across Kent rather than by direct administration of technology platforms.\nWe are looking for a proactive and collaborative security professional with sufficient technical depth to provide credible direction and challenge across endpoint security, identity security, Microsoft 365, Azure, vulnerability management, threat intelligence and security monitoring. The role will raise the organisation's security maturity by working through the teams that design, own and operate these services.\nSkills and Responsibilities:\n1. Security Operations & Incident Response\nProvide security leadership and oversight for Kent's cybersecurity monitoring and response capabilities, including defining requirements, service expectations, escalation paths and measures of effectiveness.\nLead and coordinate the response to significant or complex security events and incidents, working with the teams responsible for the affected platforms and services.\nLead incident containment, eradication, recovery and post-incident review activities.\nDevelop and maintain incident response procedures, playbooks and escalation processes.\nCoordinate internal and external stakeholders during security incidents.\nConduct root cause analysis and ensure remedial actions are implemented and tracked.\n2. Security Monitoring & Threat Detection\nDefine and oversee improvements to security monitoring and detection capabilities, agreeing technical changes with the teams responsible for administering the relevant platforms.\nDevelop and tune detection rules, alerts and use cases to improve visibility of threats.\nConduct proactive threat hunting using available security telemetry and intelligence sources.\nTrack and assess emerging threats and vulnerabilities relevant to Kent's operating environment.\nBenchmark detection and response capabilities against recognised frameworks including MITRE ATT&CK.\n3. Vulnerability & Exposure Management\n Lead the end-to-end vulnerability management process by setting the framework, risk-based priorities and reporting requirements, while Infrastructure, Cloud, Applications and other service owners remain accountable for assessment support, remediation and operational change within their environments.\nDevelop risk-based prioritisation processes for remediation activities.\nTrack remediation performance and provide reporting to stakeholders.\nCoordinate vulnerability assessments, penetration testing and security reviews.\nVerify remediation activities and security improvements.\n4. Security Technology Management\n Act as the security service owner for key cybersecurity capabilities, including CrowdStrike Falcon, by defining security requirements, control outcomes, roadmap priorities and service performance expectations. Day-to-day platform administration remains with the designated Infrastructure or Platform team.\nReview the configuration and effectiveness of security tooling, identify required improvements and work with the relevant platform owners to plan, implement and validate changes\nProvide technical guidance on security controls relating to endpoint security, identity management, email security, cloud security and data protection.\nAssist in evaluating and implementing new security technologies and capabilities.\n5. Identity, Cloud & Microsoft Security\nProvide security oversight for Microsoft 365, Azure and Entra ID environments by defining control requirements, reviewing risk and working with the responsible Platform and Infrastructure teams to prioritise improvements.\nMonitor identity-related threats and security events.\nDefine Zero Trust security requirements and oversee their implementation by the teams responsible for identity, endpoint, network, cloud and application services.\nReview security configurations and recommend improvements across cloud-based platforms.\n6. Attack Surface & Offensive Security\nManage external attack surface monitoring activities.\nCoordinate third-party penetration testing and red team exercises.\nReview security findings and ensure appropriate remediation is planned and completed.\nIdentify opportunities to reduce external exposure and improve resilience.\n7. Governance, Reporting & Continuous Improvement\nDevelop and report operational security metrics and key performance indicators.\nContribute to monthly security reporting and governance forums.\nSupport security audits, risk assessments and compliance activities.\nMaintain operational security standards, procedures and documentation.\nDrive continuous improvement initiatives to enhance the maturity of Kent's cybersecurity capability.\n8. Cross-Functional Collaboration & Security by Design\nWork as a trusted partner to Infrastructure, Cloud, Network and Application teams to embed security-by-design principles into solutions from the outset.\nPartner with Service Operations to ensure security incidents, vulnerabilities and remediation activities are properly operationalised through ITSM processes, clear ownership models and escalation paths.\nSupport Enterprise Architecture and project teams to identify and address security risks early in the solution lifecycle rather than after implementation.\nImprove visibility of technology assets by aligning asset management, endpoint management and security monitoring.\nChampion the use of automation to reduce manual security effort and improve response times.\nProvide oversight and guidance on AI, Copilot and emerging technology risks as adoption grows across the business.\nWork with Compliance, Internal Audit and business stakeholders to translate security activity into measurable risk reduction.\nIn addition to the responsibilities listed herein, the employee may be required to perform other ad-hoc tasks as needed or directed by the supervisor or management. These tasks will be within the reasonable scope of the employee's skills, capabilities, and role within the organization. The intent of this provision is to allow for flexibility and adaptability in meeting the dynamic needs of the organization, ensuring that operational requirements can be met efficiently. All such tasks will be assigned considering the employee's current workload and with respect to their professional development.\nYour knowledge/skills, education, and experience:\nKnowledge/ Qualification/ Training/ Certification:\nEssential\nBachelor's degree in Cybersecurity, Information Technology, Computer Science or a related discipline.\n Minimum 7-10 years of cybersecurity experience with at least 5 years focused on security operations, incident response and vulnerability management.\nDemonstrable experience providing technical leadership, assurance or service ownership for CrowdStrike Falcon or a comparable enterprise endpoint security platform.\nExperience in incident response, threat hunting and security investigations.\nStrong understanding of Microsoft 365, Azure and Entra ID security capabilities.\nExperience managing vulnerability management and penetration testing programmes.\nKnowledge of security frameworks including NIST CSF, ISO27001, CIS Controls and MITRE ATT&CK.\nDesirable\nExperience with SIEM, SOAR, CASB, DLP, Email Security and Cloud Security platforms.\nKnowledge of OT and industrial environments within the energy sector.\nScripting and automation experience using PowerShell, Python or similar technologies.\nExperience creating operational dashboards and security reporting.\nExperience working through ITSM/ITIL processes and partnering with service operations, infrastructure and architecture teams.\nCertifications\nOne or more of the following certifications would be advantageous:\nCISSP\nGIAC GCIH\nCompTIA Security+\nMicrosoft Security Certifications (SC-200, SC-300, SC-100)\nCrowdStrike CCFA or CCFR\nOSCP or equivalent offensive security certification\nCommunication\nExcellent command of the English language in both oral and written communication and skills.\nAbility to communicate technical findings and incident summaries clearly to both technical and non-technical stakeholders.\nBehavior/ Core Competencies:\nStrong technical troubleshooting and investigative skills.\nAbility to assess cyber risk and make pragmatic risk-based decisions.\nExcellent stakeholder management and communication skills.\nAbility to explain technical risks to non-technical audiences.\nSelf-motivated and able to operate independently while working collaboratively across teams.\nStrong analytical and problem-solving capability.\nMaintains composure and effectiveness during security incidents and high-pressure situations.\nDemonstrates ownership, accountability and continuous improvement mindset.\nCollaborative by nature, building trusted relationships across technology and business teams.\nFocused on outcomes and measurable risk reduction rather than tooling alone.\nHSSEQ:\nThe Employee shall observe the Health, Safety, Sustainability, Environment and Quality rules of the Company; it’s clients and the governing authorities of the host country.\nDetails about the role:\nLocation: Mumbai (Hybrid, 2-3 Days a week in the Office)\nRelocation required: No\nTravel required: Sometimes\nContract type: Regular \nExperience level: 10-15 Years\nFoster a culture of equity, diversity and inclusion - a safe and respectful workplace. In addition to the responsibilities listed herein, the employee may be required to perform other ad-hoc tasks as needed or directed by the supervisor or management. These tasks will be within the reasonable scope of the employee's skills, capabilities, and role within the organization. The intent of this provision is to allow for flexibility and adaptability in meeting the dynamic needs of the organization, ensuring that operational requirements can be met efficiently. All such tasks will be assigned considering the employee's current workload and with respect to their professional development.\nKent | The Energy Within","description_format":"text","description_chars":11095,"description_truncated":false,"requirements":{"experience_years_min":10,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[{"language":"English","level":"All levels","optional":true}]},"benefits":["Equity","Professional development"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":true,"industries":["Cybersecurity","Professional Services","Science & Engineering","Information Security"],"lifecycle":[{"event":"open","at":"2026-09-28T17:26:13Z"}],"visa":[],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":7,"expected_fill_days":29,"reasons":["conf:0","velocity","win:early","comp:brand"],"computed_at":"2026-10-06T05:45:30Z"},"pay":null,"html_url":"https://alion.io/job/kentplc-cyber-security-operations-manager","json_url":"https://alion.io/job/kentplc-cyber-security-operations-manager.json","meta":{"generated_at":"2026-10-07T01:48:49Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":2950,"day_limit":5000,"remaining_today":2050,"minute_limit":60,"resets_at":"2026-10-08T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":1837632},"rest":"https://alion.io/mcp/rest/get_company?id=1837632"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fkentplc-cyber-security-operations-manager"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fkentplc-cyber-security-operations-manager"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fkentplc-cyber-security-operations-manager"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/kentplc-cyber-security-operations-manager\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fkentplc-cyber-security-operations-manager"}]}