River Island is a UK high-street and omnichannel apparel retailer trading across 1800+ stores, a major distribution centre, head offices, and a growing ecommerce platform. As the business modernises its digital footprint, it is strengthening in-house security operations capability to complement its existing outsourced Security Operations Centre (SOC).
The Security Operations Lead owns day-to-day security operations delivery and acts as the primary internal control point across both first-line (operational security execution and tooling) and second-line (oversight, assurance, and governance of the security control environment) accountabilities. This is a hybrid, hands-on role suited to someone who can both operate security tooling directly and hold a third-party SOC provider to account against contracted service levels and outcomes.
The role sits within a lean Information Security function and is central to River Island's ability to detect, triage, and respond to threats across stores, ecommerce (including Storefront API/headless platforms), distribution, and corporate estate - while managing the operational relationship with the outsourced SOC.
Key Accountabilities
1. Security Operations Delivery
- Own the operational delivery of security monitoring, detection, and response capability across corporate, retail, distribution, and ecommerce environments.
- Act as the internal escalation and coordination point for security alerts, incidents, and investigations raised by the outsourced SOC, ensuring timely triage and remediation.
- Operate and tune in-house security tooling (e.g. vulnerability scanning, endpoint detection, exposure management, identity/access monitoring) to complement SOC-delivered detection.
- Lead incident response execution: contain, investigate, and coordinate recovery for security incidents, following documented playbooks, and drive post-incident lessons-learned activity.
- Coordinate vulnerability management end-to-end - from detection and prioritisation through to remediation tracking with Technology, Ecommerce, and Infrastructure teams.
- Support patching, hardening, and configuration management activities across store systems, cloud platforms, and the ecommerce stack.
- Maintain and test incident response runbooks, tabletop exercises, and escalation paths, including out-of-hours coverage arrangements with the SOC.
2. Outsourced SOC Management and Oversight
- Act as the primary relationship and performance owner for the outsourced SOC provider, holding them accountable to SLAs, use-case coverage, detection efficacy, and reporting quality.
- Chair or contribute to regular SOC service reviews, tracking key metrics such as mean time to detect (MTTD), mean time to respond (MTTR), false-positive rates, alert volumes, and coverage gaps.
- Define and continuously refine detection use cases and log source onboarding with the SOC to ensure coverage keeps pace with the retail estate, ecommerce releases, and cloud changes.
- Provide independent assurance that SOC-reported findings, incident closures, and control effectiveness claims are accurate and evidenced - challenging and validating rather than simply accepting vendor reporting.
- Own the governance of the SOC contract from a security-operations lens: reviewing scope, escalation matrices, data handling, and change requests as the business or threat landscape evolves.
- Ensure clear ownership of assets, logs, and detection logic remains with River Island, avoiding vendor lock-in or loss of institutional knowledge.
- Feed SOC performance, risk exposure, and control gaps into the Information Security Risk Register and executive/committee reporting.
3. Governance, Risk, and Reporting
- Define and report security operations KPIs/KRIs (detection coverage, incident volumes and trends, remediation SLAs, SOC performance) to the Head of Information Security and relevant governance forums (e.g. GDPR Steering Committee, security committees).
- Support compliance activities across PCI DSS, UK GDPR, and ISO 27001/NIST CSF-aligned control requirements as they relate to operational security and monitoring.
- Maintain evidence and documentation to support internal and external audits, penetration tests, and regulatory reviews.
- Partner with Legal, DPO, and Risk teams on incident notification obligations and data breach response.
4. Cross-Functional Partnership
- Work closely with Ecommerce/Storefront API, Infrastructure, Retail Technology, and Distribution Centre teams to ensure monitoring coverage extends across all channels - stores, web, app, and warehouse systems.
- Partner with the security and tech Engineers on penetration testing, red-teaming, and remediation coordination.
- Support BYOD/MDM security monitoring and access governance activities (RBAC, joiner/mover/leaver, MFA, privileged access, Identity posture) from an operational assurance standpoint.
- Represent security operations in change advisory and project forums to ensure new initiatives are onboarded into monitoring scope pre-go-live.
Essential Experience and Skills
- Proven experience in a security operations, SOC management, or similar hands-on operational security role, ideally within retail, ecommerce, or another complex multi-channel environment.
- Demonstrable experience managing or governing an outsourced/managed SOC or MSSP relationship, including SLA management and detection use-case development.
- Strong working knowledge of SIEM, EDR, vulnerability management, and exposure management tooling.
- Practical incident response experience, including leading or coordinating live incident investigations.
- Familiarity with the three lines of defence model and ability to operate credibly across both first-line delivery and second-line oversight.
- Understanding of PCI DSS, UK GDPR, and NIST CSF control frameworks as applied to operational security.
- Comfortable working in a lean team, prioritising pragmatically, and balancing protection with business/customer experience.
- Strong stakeholder management skills, able to challenge a third-party provider constructively while maintaining an effective working relationship.
Desirable
- Experience securing ecommerce/headless commerce platforms (e.g. Shopify, Storefront APIs) or retail store estates.
- Relevant certifications such as CISSP, CISM, GCIH, or equivalent.
- Experience with retail-specific threats (POS malware, card-skimming, credential stuffing, loyalty/gift card fraud).
- Exposure to cloud-native security monitoring (Azure/AWS/GCP) and CI/CD pipeline security.

