Rodeo
Get started

River Island

Security Operations Lead

London
Posted about 22 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Department: Operations

Location: Head Office, Chelsea House

Description

River Island is a UK high-street and omnichannel apparel retailer trading across 1800+ stores, a major distribution centre, head offices, and a growing ecommerce platform. As the business modernises its digital footprint, it is strengthening in-house security operations capability to complement its existing outsourced Security Operations Centre (SOC).

The Security Operations Lead owns day-to-day security operations delivery and acts as the primary internal control point across both first-line (operational security execution and tooling) and second-line (oversight, assurance, and governance of the security control environment) accountabilities. This is a hybrid, hands-on role suited to someone who can both operate security tooling directly and hold a third-party SOC provider to account against contracted service levels and outcomes.

The role sits within a lean Information Security function and is central to River Island's ability to detect, triage, and respond to threats across stores, ecommerce (including Storefront API/headless platforms), distribution, and corporate estate — while managing the operational relationship with the outsourced SOC.

Key Accountabilities

1. Security Operations Delivery

  • Own the operational delivery of security monitoring, detection, and response capability across corporate, retail, distribution, and ecommerce environments.
  • Act as the internal escalation and coordination point for security alerts, incidents, and investigations raised by the outsourced SOC, ensuring timely triage and remediation.
  • Operate and tune in-house security tooling (e.g. vulnerability scanning, endpoint detection, exposure management, identity/access monitoring) to complement SOC-delivered detection.
  • Lead incident response execution: contain, investigate, and coordinate recovery for security incidents, following documented playbooks, and drive post-incident lessons-learned activity.
  • Coordinate vulnerability management end-to-end — from detection and prioritisation through to remediation tracking with Technology, Ecommerce, and Infrastructure teams.
  • Support patching, hardening, and configuration management activities across store systems, cloud platforms, and the ecommerce stack.
  • Maintain and test incident response runbooks, tabletop exercises, and escalation paths, including out-of-hours coverage arrangements with the SOC.

2. Outsourced SOC Management and Oversight

  • Act as the primary relationship and performance owner for the outsourced SOC provider, holding them accountable to SLAs, use-case coverage, detection efficacy, and reporting quality.
  • Chair or contribute to regular SOC service reviews, tracking key metrics such as mean time to detect (MTTD), mean time to respond (MTTR), false-positive rates, alert volumes, and coverage gaps.
  • Define and continuously refine detection use cases and log source onboarding with the SOC to ensure coverage keeps pace with the retail estate, ecommerce releases, and cloud changes.
  • Provide independent assurance that SOC-reported findings, incident closures, and control effectiveness claims are accurate and evidenced — challenging and validating rather than simply accepting vendor reporting.
  • Own the governance of the SOC contract from a security-operations lens: reviewing scope, escalation matrices, data handling, and change requests as the business or threat landscape evolves.
  • Ensure clear ownership of assets, logs, and detection logic remains with River Island, avoiding vendor lock-in or loss of institutional knowledge.
  • Feed SOC performance, risk exposure, and control gaps into the Information Security Risk Register and executive/committee reporting.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

3. Governance, Risk, and Reporting

  • Define and report security operations KPIs/KRIs (detection coverage, incident volumes and trends, remediation SLAs, SOC performance) to the Head of Information Security and relevant governance forums (e.g. GDPR Steering Committee, security committees).
  • Support compliance activities across PCI DSS, UK GDPR, and ISO 27001/NIST CSF-aligned control requirements as they relate to operational security and monitoring.
  • Maintain evidence and documentation to support internal and external audits, penetration tests, and regulatory reviews.
  • Partner with Legal, DPO, and Risk teams on incident notification obligations and data breach response.

4. Cross-Functional Partnership

  • Work closely with Ecommerce/Storefront API, Infrastructure, Retail Technology, and Distribution Centre teams to ensure monitoring coverage extends across all channels — stores, web, app, and warehouse systems.

  • Partner with the security and tech Engineers on penetration testing, red-teaming, and remediation coordination.

  • Support BYOD/MDM security monitoring and access governance activities (RBAC, joiner/mover/leaver, MFA, privileged access, Identity posture) from an operational assurance standpoint.

  • Represent security operations in change advisory and project forums to ensure new initiatives are onboarded into monitoring scope pre-go-live.

Essential Experience and Skills

  • Proven experience in a security operations, SOC management, or similar hands-on operational security role, ideally within retail, ecommerce, or another complex multi-channel environment.
  • Demonstrable experience managing or governing an outsourced/managed SOC or MSSP relationship, including SLA management and detection use-case development.
  • Strong working knowledge of SIEM, EDR, vulnerability management, and exposure management tooling.
  • Practical incident response experience, including leading or coordinating live incident investigations.
  • Familiarity with the three lines of defence model and ability to operate credibly across both first-line delivery and second-line oversight.
  • Understanding of PCI DSS, UK GDPR, and NIST CSF control frameworks as applied to operational security.
  • Comfortable working in a lean team, prioritising pragmatically, and balancing protection with business/customer experience.
  • Strong stakeholder management skills, able to challenge a third-party provider constructively while maintaining an effective working relationship.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Desirable

  • Experience securing ecommerce/headless commerce platforms (e.g. Shopify, Storefront APIs) or retail store estates.
  • Relevant certifications such as CISSP, CISM, GCIH, or equivalent.
  • Experience with retail-specific threats (POS malware, card-skimming, credential stuffing, loyalty/gift card fraud).
  • Exposure to cloud-native security monitoring (Azure/AWS/GCP) and CI/CD pipeline security.

About Us

We’re a much-loved brand with an exciting future. Our Islanders are a diverse bunch of bright, talented people who love working together – and are proud of the work they do. Progression here can take you in all kinds of directions. This is what a career at River Island is like. And this is where yours starts.

This role is based at our Head Office in West London. Check us out here on a map.

What we can offer you:

  • 💰 Generous 50% staff discount so you can treat yourself to the latest products, and a bargain staff shop on site!
  • 🛒 Reducing Islanders everyday expenses through discounts, benefits, financial advice, wellbeing solutions and more through the Retail Trust.
  • 🎉 A free onsite gym, subsidised restaurant & café to fill you needs. Various social events to socialise throughout the year.
  • 🤎 Every family is unique, we support Islanders with all different family setups enhanced maternity, paternity, adoption & fertility treatment. We also work closely with the Retail Trust to create dedicated support for all our Islanders!
  • 💻 Flexible working, on top of payday and summer early finish Fridays.
  • 💕 Give as you earn scheme, a ‘Giver Island’ day each year and receive matched funding.
  • 🎓 Support with upskilling through on the job training and qualifications. A succession plan if you want to progress.
  • 💰 A generous bonus scheme & private pension plan.
  • 🩺 The choice to opt in for healthcare through our provider AXA.
  • ☀️ 25 days paid holiday, exclusive of Bank Holidays. With the added option to purchase additional holiday twice a year for whatever the need!

Keeping You Safe

We are committed to providing a safe and inclusive workplace where everyone is treated with dignity and respect. We expect all employees to uphold our values and contribute to a positive working environment. Our business is made up of a diverse community, where we all belong and feel part of something bigger. We are committed to equality of opportunity and welcome applications from individuals regardless of age, gender, ethnicity, disability, sexual orientation, gender identity, socio-economic background, religion or belief. We will consider flexible working requests for all roles unless operational requirements prevent otherwise.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Location

London, England, United Kingdom

Sign up to applySee more jobs like this