7 open roles
Cyber Operations Lead
Job description
The Role Sys. Group is hiring a Cyber Operations Lead, based in Edinburgh, to head the day-to-day delivery of our cyber security managed services. This is the senior operational leadership role in the Cyber Security team under our 2026 operating model: you own the SOC service, lead the security engineers and analysts, and act as the escalation point for major security incidents across our client base.
This is a leadership and delivery role. You will run the operation, develop the people and own the service - including operational delivery of our Zscaler zero trust estate.
Requirements
Key Responsibilities Leadership
- Lead, coach and develop the cyber operations engineers and analysts - 1:1s, development plans, hiring and succession.
- Own capacity, shift and on-call planning for a 24/7 security service.
- Set and track the team's certification and capability plan against the Sys. Group role framework.
- Own operational reporting: client-facing security reports, KPIs and continual service improvement. Security operations
- Own SOC/SIEM service delivery: detection coverage, use-case tuning, triage quality and shift handovers.
- Act as major incident lead for security events: containment, client communication and post-incident review.
- Own the vulnerability management lifecycle across managed clients: scan, triage, remediate, report.
- Set the standard for EDR and security tooling configuration, health and response playbooks.
- Own operational delivery of the Zscaler zero trust estate (ZIA/ZPA): onboarding, policy lifecycle, tuning and upgrades.
- Support Risk & Compliance engagements (ISO 27001, Cyber Essentials Plus) with operational evidence.
- Embed AI-assisted workflows (triage, enrichment, reporting) into the SOC and measure the gains. Experience
- 5+ years in security operations within an MSP/MSSP or equivalent multi-client environment.
- 3+ years leading engineers or analysts, including performance and development responsibility.
- Track record running major security incidents end-to-end, including executive-level communication.
- Operational experience with Zscaler (or equivalent SSE/zero trust platform) is a strong advantage. Certifications
- Essential (or equivalent experience): Microsoft SC-200, plus an incident response credential such as GIAC GCIH.
- Desirable: Zscaler professional-level certification (ZIA/ZPA), SC-300, AZ-500, ISO 27001 Lead Implementer, CISSP or CISM.
Benefits
Why Join Us? Joining Sysgroup means becoming part of a dynamic and innovative team that is dedicated to excellence. We offer a supportive, and collaborative work environment, where your ideas and contributions are valued. Here are some of the benefits of working with us: Competitive Compensation We offer a competitive salary package, including performance-based incentives, to reward your hard work and achievements.
- Private Healthcare
- Life insurance
- Healthcare cash plan
- Pension Growth Opportunities We believe in investing in our employees' professional development. You will have your own individual development learning paths with access to various training material and ongoing career advancement opportunities.
Description copied from SysGroup's careers page. Read the full posting before you apply.
More jobs at SysGroup
New business development manager
SysGroup· London, United KingdomSenior Cyber Security Engineer (CyberArk & PAM)
SysGroup· Edinburgh, United KingdomSenior Account Manager
SysGroup· London, United KingdomManaging Consultant - Cyber Security
SysGroup· London, United KingdomNetwork Operations Engineer
SysGroup