SecOps Engineering Lead

RM Education Limited•Abingdon, IL
•Hybrid

About The Position

RM is a pioneer in education technology, providing technology and resources to the education sector and supporting over 20 million students globally. The company operates through three divisions: Assessment, Technology, and TTS. This role is for a hands-on Security Engineering & SOC Lead responsible for building and running the controls designed by the Cyber Security Architect and leading security operations for RM's Azure-hosted, multi-tenant SaaS platform. The role involves SOC engineering, detection and monitoring, incident response, and managing a team of three analysts. Approximately 60% of the role is dedicated to engineering, implementing Azure guardrails, SOC tooling, pipeline security tooling, and platform hardening. The remaining 40% focuses on running the SOC, maintaining security observability controls, improving detections, leading response efforts, and developing the analyst team. The position requires a senior hands-on practitioner who will also serve as the escalation point for the analysts, expected to troubleshoot and resolve issues directly.

Requirements

  • Solid experience in security engineering or security operations.
  • Proven experience of leading a SOC function or detection engineering.
  • Experience supervising or mentoring analysts.
  • Hands-on Microsoft Sentinel administration, including workspace design, data connectors and ingestion cost control, retention, workbooks, automation rules, and Logic Apps playbooks.
  • Strong KQL and detection engineering skills: ability to write, tune, and defend an analytics rule mapped to MITRE ATT&CK, and explain its firing logic.
  • Incident response experience on a cloud platform, including triage, containment, evidence collection in Azure, coordination with engineering, and post-incident review.
  • Experience implementing Azure security controls: Entra ID (Conditional Access, PIM, managed identities), Azure Policy, Defender for Cloud, Key Vault, and networking with NSGs, Private Link, Azure Firewall, and WAF.
  • Experience with DevSecOps tooling in GitHub Actions or Azure Pipelines, integrating and tuning SAST, SCA, secrets, container, and IaC scanners, and building reusable pipeline templates.
  • Proficiency in Infrastructure as Code with Terraform or Bicep, and PowerShell or Python for automating controls and response.
  • Working knowledge of AKS and container security.
  • Understanding of the OWASP Top 10.
  • Clear written communication skills for creating runbooks, incident reports, and remediation plans.
  • BPSS (Baseline Personnel Security Standard) clearance is applicable.

Nice To Haves

  • Experience monitoring a multi-tenant SaaS platform, including tenant-aware alerting, isolation testing, and producing evidence for customer security audits.
  • Experience with the wider Microsoft security stack: Defender XDR, Defender for Endpoint and Identity, Entra ID Protection, and UEBA in Sentinel.
  • Experience standing up a SOC or bringing one back in-house from an MDR provider, and defining the coverage model with a small team.
  • Experience with detection validation using purple teaming or Atomic Red Team, and hunting programs that have produced new detections.
  • In-depth knowledge of supply chain security, including SBOM (CycloneDX or SPDX), Sigstore or cosign, and SLSA provenance.
  • Experience with Policy as Code using OPA or Kyverno.
  • A background as a software or platform engineer prior to moving into security.

Responsibilities

  • Build Azure controls such as Azure Policy initiatives, Defender for Cloud plans, Entra ID Conditional Access and PIM, Key Vault and managed identity patterns, and network segmentation with Private Link, Azure Firewall and WAF rules.
  • Deliver DevSecOps tooling in GitHub Actions or Azure Pipelines, including SAST, SCA, secrets, container, and IaC scanning with tuned rules, reusable pipeline templates, and actionable feedback for developers.
  • Implement supply chain controls such as SBOM generation, artifact signing and verification, dependency and base image policies, and transitioning from long-lived pipeline secrets to OIDC federation.
  • Harden AKS and platform services using admission policies, network policy, image provenance, and workload identity, implemented via Terraform or Bicep with tests.
  • Own the remediation of findings from penetration tests, Defender for Cloud, and scanners in collaboration with engineering teams, tracking them to closure and reporting monthly.
  • Support the Secure Software Development Lifecycle (S-SDLC) by running tooling, assisting teams with threat modeling, participating in design reviews for security-relevant changes, and coaching security champions.
  • Run the Security Operations Center (SOC) day-to-day, managing queue health, shift and on-call coverage, escalations, and the runbooks used by analysts.
  • Administer SOC tooling, including workspace and data connector health, ingestion and cost management, retention, and integration with Defender XDR, Defender for Cloud, and Entra ID Protection.
  • Own detection engineering by writing and tuning KQL analytics rules and hunting queries, mapping coverage to MITRE ATT&CK, tracking false-positive rates, and retiring ineffective rules.
  • Automate response actions using automation rules and Logic Apps playbooks for enrichment, ticketing, and common containment steps.
  • Lead incident response, including triage and containment of incidents on the platform, coordination with engineering and the architect, conducting post-incident reviews, and translating lessons learned into new detections and controls.
  • Run regular threat hunts against the platform's telemetry and integrate threat intelligence into detections.
  • Own the logging and telemetry standard with the architect, defining which sources go to Sentinel, at what level, and the process for onboarding new services before go-live.
  • Build SIEM workbooks and dashboards to monitor coverage, alert quality, and response times, and report SOC metrics (time to detect, triage, and contain) monthly.
  • Provide tenant-aware alerting and reporting for the platform, including evidence for customer security audits.
  • Manage vulnerability management across Azure and the platform using Defender Vulnerability Management, prioritizing by exposure and tracking to closure.
  • Line-manage three SOC analysts, including rota and cover, setting objectives, conducting one-to-ones and development plans, and reviewing the quality of their triage and investigations.
  • Train analysts and develop their skills from triage to detection engineering and hunting.
  • Serve as the technical escalation point and provide tool training for analysts, covering shifts when necessary.
  • Maintain current SOC runbooks, on-call arrangements, and handovers, and participate in hiring for the team as it grows.

Benefits

  • Competitive salary
  • Private medical healthcare
  • Life assurance
  • Group Personal Pension Plan with higher contribution levels available
  • Voluntary benefits including additional annual leave purchase, dental plan, health assessment, and cycle to work scheme.
  • Bonus for successfully recommending a friend or family member for a position within RM.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service