664,807open jobs
38,858companies
99,669added this week
Browse all
Location
Remote/Hybrid
Seniority
Staff
Employment
Full-Time
Overview
Company
Impact
Profile match
Find the latest clothing trends at River Island as well as the latest girls and boys clothes collection. Shop online at your favourite high street store.

River Island is a UK high-street and omnichannel apparel retailer trading across 1800+ stores, a major distribution centre, head offices, and a growing ecommerce platform. As the business modernises its digital footprint, it is strengthening in-house security operations capability to complement its existing outsourced Security Operations Centre (SOC).

The Security Operations Lead owns day-to-day security operations delivery and acts as the primary internal control point across both first-line (operational security execution and tooling) and second-line (oversight, assurance, and governance of the security control environment) accountabilities. This is a hybrid, hands-on role suited to someone who can both operate security tooling directly and hold a third-party SOC provider to account against contracted service levels and outcomes.

The role sits within a lean Information Security function and is central to River Island's ability to detect, triage, and respond to threats across stores, ecommerce (including Storefront API/headless platforms), distribution, and corporate estate - while managing the operational relationship with the outsourced SOC.

Key Accountabilities

1. Security Operations Delivery

  • Own the operational delivery of security monitoring, detection, and response capability across corporate, retail, distribution, and ecommerce environments.
  • Act as the internal escalation and coordination point for security alerts, incidents, and investigations raised by the outsourced SOC, ensuring timely triage and remediation.
  • Operate and tune in-house security tooling (e.g. vulnerability scanning, endpoint detection, exposure management, identity/access monitoring) to complement SOC-delivered detection.
  • Lead incident response execution: contain, investigate, and coordinate recovery for security incidents, following documented playbooks, and drive post-incident lessons-learned activity.
  • Coordinate vulnerability management end-to-end - from detection and prioritisation through to remediation tracking with Technology, Ecommerce, and Infrastructure teams.
  • Support patching, hardening, and configuration management activities across store systems, cloud platforms, and the ecommerce stack.
  • Maintain and test incident response runbooks, tabletop exercises, and escalation paths, including out-of-hours coverage arrangements with the SOC.

2. Outsourced SOC Management and Oversight

  • Act as the primary relationship and performance owner for the outsourced SOC provider, holding them accountable to SLAs, use-case coverage, detection efficacy, and reporting quality.
  • Chair or contribute to regular SOC service reviews, tracking key metrics such as mean time to detect (MTTD), mean time to respond (MTTR), false-positive rates, alert volumes, and coverage gaps.
  • Define and continuously refine detection use cases and log source onboarding with the SOC to ensure coverage keeps pace with the retail estate, ecommerce releases, and cloud changes.
  • Provide independent assurance that SOC-reported findings, incident closures, and control effectiveness claims are accurate and evidenced - challenging and validating rather than simply accepting vendor reporting.
  • Own the governance of the SOC contract from a security-operations lens: reviewing scope, escalation matrices, data handling, and change requests as the business or threat landscape evolves.
  • Ensure clear ownership of assets, logs, and detection logic remains with River Island, avoiding vendor lock-in or loss of institutional knowledge.
  • Feed SOC performance, risk exposure, and control gaps into the Information Security Risk Register and executive/committee reporting.

3. Governance, Risk, and Reporting

  • Define and report security operations KPIs/KRIs (detection coverage, incident volumes and trends, remediation SLAs, SOC performance) to the Head of Information Security and relevant governance forums (e.g. GDPR Steering Committee, security committees).
  • Support compliance activities across PCI DSS, UK GDPR, and ISO 27001/NIST CSF-aligned control requirements as they relate to operational security and monitoring.
  • Maintain evidence and documentation to support internal and external audits, penetration tests, and regulatory reviews.
  • Partner with Legal, DPO, and Risk teams on incident notification obligations and data breach response.

4. Cross-Functional Partnership

  • Work closely with Ecommerce/Storefront API, Infrastructure, Retail Technology, and Distribution Centre teams to ensure monitoring coverage extends across all channels - stores, web, app, and warehouse systems.
  • Partner with the security and tech Engineers on penetration testing, red-teaming, and remediation coordination.
  • Support BYOD/MDM security monitoring and access governance activities (RBAC, joiner/mover/leaver, MFA, privileged access, Identity posture) from an operational assurance standpoint.
  • Represent security operations in change advisory and project forums to ensure new initiatives are onboarded into monitoring scope pre-go-live.

Essential Experience and Skills

  • Proven experience in a security operations, SOC management, or similar hands-on operational security role, ideally within retail, ecommerce, or another complex multi-channel environment.
  • Demonstrable experience managing or governing an outsourced/managed SOC or MSSP relationship, including SLA management and detection use-case development.
  • Strong working knowledge of SIEM, EDR, vulnerability management, and exposure management tooling.
  • Practical incident response experience, including leading or coordinating live incident investigations.
  • Familiarity with the three lines of defence model and ability to operate credibly across both first-line delivery and second-line oversight.
  • Understanding of PCI DSS, UK GDPR, and NIST CSF control frameworks as applied to operational security.
  • Comfortable working in a lean team, prioritising pragmatically, and balancing protection with business/customer experience.
  • Strong stakeholder management skills, able to challenge a third-party provider constructively while maintaining an effective working relationship.

Desirable

  • Experience securing ecommerce/headless commerce platforms (e.g. Shopify, Storefront APIs) or retail store estates.
  • Relevant certifications such as CISSP, CISM, GCIH, or equivalent.
  • Experience with retail-specific threats (POS malware, card-skimming, credential stuffing, loyalty/gift card fraud).
  • Exposure to cloud-native security monitoring (Azure/AWS/GCP) and CI/CD pipeline security.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
664,807 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
In office • Full-Time • Bachelor's Degree • Gurgaon
Databases
Oracle
AI/ML
AI Agents
Edge AI
DevOps
SLI/SLO/SLA
Apply
Remote • Full-Time • Bachelor's Degree • Noida
Databases
Oracle
AI/ML
AI Agents
Edge AI
DevOps
SLI/SLO/SLA
Apply
$111k – $150k per year • Remote • Full-Time • 10+ years exp • Bachelor's Degree
AI/ML
Multimodal AI
DevOps
SLI/SLO/SLA
Apply
$146k – $234k per year • Remote/Hybrid • Full-Time • 7+ years exp • Bachelor's Degree
Python
PowerShell
Bash
DevOps
VMWare
Azure
Windows Server
AWS
Hyper-V
Cybersecurity
PCI DSS
NIST 800-53
Management
Google Workspace
Agile
Apply
Lead Account Manager 8 hours ago
$29k – $69k per year (Estimated) • Remote/Hybrid • Full-Time • Beijing
AI/ML
AI Agents
Cybersecurity
GDPR
Apply
Product Manager 1 day ago
$77k – $167k per year (Estimated) • In office • Full-Time • Glasgow
Apply
Product Manager 1 day ago
$79k – $172k per year (Estimated) • In office • Full-Time • Edinburgh
Apply
In office • Full-Time
Apply
Product Manager 1 day ago
$79k – $180k per year (Estimated) • In office • Full-Time • Waterford
Apply
In office • Full-Time
Apply
See all jobs
This is one of many
664,807 more open roles from verified company boards, updated every day.