RM Technology
SecOps Engineering Lead

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Overview
Would you like to help enrich the lives of learners around the world?
At RM, we’ve been pioneers of education technology since 1973. We provide technology and resources to the education sector, supporting over 20 million students and improving educational outcomes worldwide.
What we do helps learners at all stages of their lives, from preschool to higher education and professional qualification; we partner with schools, examination boards, governments, and professional organisations globally to make learning more accessible, more engaging, and more impactful.
RM operates through three divisions: Assessment (digital assessment and marking solutions), Technology (managed services, hardware, and software for schools), and TTS (educational resources).
Within the assessment market we are experts in providing solutions for online exam testing and marking and the management and analysis of educational data. We work with government ministries, exam boards and professional awarding bodies for high stakes assessment such as GCSEs, A Levels, and professional qualifications. Each year, our software is used globally to conduct hundreds of thousands of on-screen tests and to mark millions of paper-based scripts. For over a decade we have been partnering with the world’s leading awarding bodies to deliver intuitive, secure, and reliable e-marking solutions.
Visit our website to find out more: www.rm.com/assessment
We are hiring a hands-on Security Engineering & SOC Lead to build and run the controls our Cyber Security Architect designs, and to lead security operations for our Azure-hosted, multi-tenant SaaS platform: SOC engineering, detection and monitoring, incident response, and managing a team of three analysts. 60% of the role is engineering: putting Azure guardrails, SOC tooling, pipeline security tooling and platform hardening into production. The rest is running the SOC: keeping security observability controls healthy, improving detections, leading response, and developing the three analysts. You are expected to be a senior hands-on practitioner in the team and the analysts' escalation point, so you are expected to troubleshoot and fix issues yourself rather than only direct.
A BPSS (Baseline Personnel Security Standard) is applicable to this role, therefore appropriate security checks will be carried out as part of the recruitment process prior to any offer being made.
We encourage early applications as the vacancy may close once the position has been filled or final interviews have been arranged.
Responsibilities
Security engineering: implementing the architecture
- Build the Azure controls the security architecture defines: Azure Policy initiatives and Defender for Cloud plans, Entra ID Conditional Access and PIM, Key Vault and managed identity patterns, and network segmentation with Private Link, Azure Firewall and WAF rules.
- Deliver the DevSecOps tooling in GitHub Actions or Azure Pipelines: SAST, SCA, secrets, container and IaC scanning, with tuned rules, reusable pipeline templates and feedback developers can act on.
- Implement supply chain controls: SBOM generation, artifact signing and verification, dependency and base image policy, and the move from long-lived pipeline secrets to OIDC federation.
- Harden AKS and the platform services: admission policies, network policy, image provenance and workload identity, written as Terraform or Bicep with tests.
- Own remediation of penetration test, Defender for Cloud and scanner findings with engineering teams, tracked to closure and reported monthly.
- Support the S-SDLC day to day: run the tooling, help teams threat model, sit on design reviews for security-relevant changes, and coach the security champions.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
SOC operations and Microsoft Sentinel
- Run the SOC day to day: queue health, shift and on-call cover, escalation, and the runbooks the analysts work from.
- Administer SOC tooling: workspace and data connector health, ingestion and cost management, retention, and integration with Defender XDR, Defender for Cloud and Entra ID Protection.
- Own detection engineering: write and tune KQL analytics rules and hunting queries, map coverage to MITRE ATT&CK, track false-positive rates, and retire rules that no longer earn their place.
- Automate response with automation rules and Logic Apps playbooks so enrichment, ticketing and common containment steps run without an analyst.
- Lead incident response: triage and contain incidents on the platform, coordinate engineering and the architect, run post-incident reviews, and turn lessons into detections and controls.
- Run regular threat hunts against the platform's telemetry and bring threat intelligence into detections.
Analytics and monitoring
- Own the logging and telemetry standard with the architect: which sources go to Sentinel, at what level, and how a new service is onboarded before go-live.
- Build SIEM workbooks and dashboards for coverage, alert quality and response times, and report SOC metrics (time to detect, triage and contain) monthly.
- Provide tenant-aware alerting and reporting where the platform needs it, including evidence for customer security audits.
- Run vulnerability management across Azure and the platform with Defender Vulnerability Management, prioritised by exposure and tracked to closure.
Leading the team
- Line-manage three SOC analysts: rota and cover, objectives, one-to-ones and development plans, and quality review of their triage and investigations.
- Train the analysts and grow them from triage into detection engineering and hunting.
- Be the technical escalation point and the person they learn the tools from; cover shifts when needed.
- Keep the SOC's runbooks, on-call arrangements and handovers current, and take part in hiring when the team grows.
Experience
Essential:
- Solid experience in security engineering or security operations, including proven experience of leading a SOC function or detection engineering, and experience supervising or mentoring analysts.
- Hands-on Microsoft Sentinel administration: workspace design, data connectors and ingestion cost control, retention, workbooks, automation rules and Logic Apps playbooks.
- Strong KQL and detection engineering: you can write, tune and defend an analytics rule mapped to MITRE ATT&CK, and explain why it fires and why it does not.
- Incident response on a cloud platform: triage, containment, evidence collection in Azure, coordination with engineering, and post-incident review.
- Implementing Azure security controls: Entra ID (Conditional Access, PIM, managed identities), Azure Policy, Defender for Cloud, Key Vault, and networking with NSGs, Private Link, Azure Firewall and WAF.
- DevSecOps tooling in GitHub Actions or Azure Pipelines: integrating and tuning SAST, SCA, secrets, container and IaC scanners, and building reusable pipeline templates.
- Infrastructure as code with Terraform or Bicep, and PowerShell or Python to automate controls and response.
- Working knowledge of AKS and container security, and of the OWASP Top 10.
- Clear written communication: runbooks, incident reports and remediation plans that engineers and managers can act on.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Desirable
- Monitoring a multi-tenant SaaS platform: tenant-aware alerting, isolation testing, and producing evidence for customer security audits.
- The wider Microsoft stack: Defender XDR, Defender for Endpoint and Identity, Entra ID Protection and UEBA in Sentinel.
- Standing up a SOC, or taking one back in-house from an MDR provider, and defining the coverage model with a small team.
- Detection validation with purple teaming or Atomic Red Team, and hunting programmes that produced new detections.
- Supply chain security in depth: SBOM (CycloneDX or SPDX), Sigstore or cosign, and SLSA provenance.
- Policy as code with OPA or Kyverno.
- A background as a software or platform engineer before moving into security.
Qualifications And Certifications
Certifications are not a requirement: what you have run and built counts. These are the ones we recognise for this role.
- Security operations and Sentinel Microsoft SC-200 (Security Operations Analyst), GIAC GCDA or GCIA, CompTIA CySA+
- Incident response GIAC GCIH or GCFA
- Azure security and identity Microsoft AZ-500, SC-300
- Engineering and platform HashiCorp Terraform Associate, CKA or CKS
What’s in it for you?
At RM we have My Work Blend @RM which provides office-based colleagues with multi location and hybrid working options. As well as your office base, you can spend a proportion of your time working at other locations that suit your role and your life, including home, other offices, customer sites, distribution centres or on the move. We encourage you to discuss arrangements for this role with your potential line manager during the recruitment process.
As well as a competitive salary and our core benefits package which includes private medical healthcare, life assurance and a Group Personal Pension Plan with higher contribution levels available. There are lots of voluntary benefits too. You could buy additional annual leave, join our dental plan, sign up for a health assessment, or take part in our cycle to work scheme. You could even earn yourself an extra bonus for successfully recommending a friend or family member for a position within RM.
To better reflect the society that we serve, we’re committed to building a diverse workforce and creating an inclusive and welcoming environment for all. To achieve this, we create teams of talented people from different backgrounds and experiences and strive to be a business where our people can bring their whole selves to work, we also want to make the recruitment process as inclusive as possible for everyone. Should you require additional support with your application or through the interview process, please contact us at recruitment@rm.com.
Unfortunately, we are unable to offer visa sponsorship for this role.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London