OSB Group
Head of Security Operations

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
About the team:
Group Information Security (GIS) at OSB supports the business by protecting the bank, its customers, and its critical assets while enabling the organisation to operate safely and effectively. We identify, assess, and manage security risks across people, processes, technology, data, and third-party suppliers, ensuring risks remain within the bank's risk appetite. The function establishes security policies, standards, and governance frameworks, oversees compliance with regulatory and industry requirements, and works closely with business and technology teams to embed security into new products, services, and change initiatives. It also monitors and responds to security incidents, promotes operational resilience, manages third-party security risks, and drives security awareness across the organisation. Through these activities, the security function helps maintain customer trust, supports regulatory compliance, and enables the bank to achieve its strategic objectives while effectively managing risk.
What you will be doing:
As the Head of Security Operations you will be accountable for the effective operation, continuous improvement and resilience of the Bank's security operations capability, covering Security Operations Centre monitoring and response, Identity and Access Management services, security analysis, operational security controls and supplier-delivered security services. The Head of Security Operations is a senior leadership role within the Group Information Security (GIS) function, reporting directly to the Information Security Director. The role leads a team of approximately 15-20 security professionals located in the UK and India offices, supported where appropriate by third-party managed security service providers. The team provides 24x7 or extended-hours security monitoring and response, identity and access management operations, vulnerability and threat analysis, security tooling administration, control assurance support, reporting, and operational support.
Your responsibilities will include…
Security Operations Leadership & Strategy
- Leading and developing the Security Operations function, setting clear direction, priorities, and performance expectations for a team of 15-20 professionals
- Build a high-performing, collaborative and service-focused culture, supported by workforce planning and recruitment, performance management and professional development whilst ensuring the function has the appropriate capability, capacity, tooling, and governance to meet current and future business needs
Cyber Security Operations (SOC & Incident Response)
- Owning the end-to-end security monitoring and cyber incident response, including internal SOC and third-party services
- Overseeing detection, triage, investigation and response to threats using security tooling (e.g. SIEM, SOAR, EDR/XDR) and acting as the senior escalation point and cyber incident commander where required
- Ensuring incident response plans, playbooks, testing, and post-incident reviews are effective and continuously improved
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Identity & Access Management (IAM)
- Leading IAM operations, ensuring secure, compliant access to systems, data and platforms whilst driving improvements in IAM automation, governance, and control effectiveness, ensuring risks are identified, reported and remediated in line with policy
Security Analysis, Assurance & Risk Management
- Leading security analyst services including threat analysis, vulnerability management, investigations, reporting and control assurance
- Ensuring security risks, vulnerabilities and control weaknesses are identified, prioritised, and remediated in partnership with technology teams
- Support risk assessments, change initiatives, and assurance activities while maintaining alignment with risk frameworks, policies, and regulatory requirements
Service Delivery, Performance & Continuous Improvement
- Defining and tracking KPIs, KRIs and SLAs to measure performance, risk reduction and control effectiveness
- Delivering clear, insightful reporting for operational teams, senior stakeholders, audit and regulators
- Driving continuous improvement through automation, tooling optimisation, and process enhancements
Third-Party & Service Management
- Managing relationships and performance of security vendors and managed service providers to ensure third-party services meet contractual, regulatory and security requirements
Operational Resilience & Business Continuity
- Ensuring Security Operations services are resilient and recoverable, supporting the Bank through incidents and disruptions whilst maintaining continuity and disaster recovery plans for critical security services
Stakeholder Management & Governance
- Building effective relationships with the wider Group to successfully and effectively achieve the above outlined responsibilities
- Providing appropriate challenge on risk and control issues and represent Security Operations at IT Security governance forums
What's in it for you?
We offer a competitive base salary depending on experience from £120,000 - £135,000 and a competitive benefits package including:
- Annual discretionary bonus opportunity
- 30 days annual leave
- Choose to contribute 3% or 5% pension, with employer contributions of 6% or 8% respectively
- Enhanced family-focused benefits
- Hybrid-working - 3 days a week in the office
- Access to Private Medical Insurance and Medical Cash Plan
Please use this link to see the fantastic benefits available at OSB: [OSB Careers](OSB Careers)
About us:
At OSB Group, we understand how much our people bring to our organisation, which is why we try our best to give back too! Our Purpose is to help our customers, colleagues and communities prosper and we are on a transformation journey to become 'the bank of the future'. Our commitment to professional development, flexible working, and employee well-being fosters a dynamic and supportive workplace.
Do you have the skills?
We are looking for talented individuals who have the experience and knowledge set out below:


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Essential experience:
- Leading a Security Operations function within a complex, regulated or financial services environment managing medium-sized, multi-disciplinary security teams (c.15-25), including analysts, engineers, IAM specialists and team leads
- Strong operational experience across SOC monitoring, cyber incident response, escalation management and Identity & Access Management
- Experience delivering security analysis and operational services, including threat and vulnerability management, control monitoring and reporting
- Strong understanding of risk, audit, compliance and governance requirements within a regulated environment
- Experience managing third-party security providers, including MSP's and outsourced services
- Proven ability to develop and use operational metrics and produce effective management reporting
- Experience in incident management, root cause analysis and continuous improvement, alongside exposure to operational resilience, business continuity and disaster recovery
- Strong stakeholder management skills, with the ability to influence and clearly communicate complex security issues
Next steps:
Interested? Apply now! Still considering? Hear from our team or learn more about our recruitment process: [OSB Careers](OSB Careers) We believe in a personalised and inclusive approach, ensuring the process is relevant and conversational. If you need any adjustments or support, we're here to make sure you can show your best self. We are proud to be a Disability Confident employer and are committed to creating an inclusive and accessible workplace where everyone can thrive. We welcome applications from people of all backgrounds and encourage candidates with disabilities and long-term health conditions to apply. If you meet the minimum criteria for the role and would like to be considered under our Disability Confident Scheme, please indicate this on your application. Diversity, Equity & Inclusion Our team value spending time together in the office, typically 3 days a week to support collaboration and connection with colleagues, but we're happy to have a conversation about what flexibility might look like for you. Not sure if you meet all the criteria? Let us decide. Studies show that candidates from underrepresented backgrounds often feel they need to meet 100% of the criteria before applying. At OSB, we value the unique perspectives and experiences that diversity brings. We're committed to creating an inclusive space where everyone feels empowered to apply - even if you don't check every box. We actively promote diversity at all levels, with Board-level Diversity Champions monitoring our progress. We're proud to be signatories of the Women in Finance Charter, supporting the growth of senior women in our sector. Our commitment extends to treating all employees and applicants equitably, ensuring fairness and respect for all.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills