Whitehall Resources
Security Operations Lead - SC Cleared

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Security Operations Lead - SC Cleared
Whitehall Resources are currently looking for a Security Operations Lead - SC Cleared based in Lancashire for an initial 6 month contract.
*** MUST HOLD ACTIVE SC CLEARANCE ***
*** INSIDE IR35 ***
Job Spec:
The Security Operations Lead operates within the Operational Integrator (OI) function and provides governance, leadership, assurance, and strategic oversight of security incident management across a complex multi-supplier environment.
The role is responsible for ensuring suppliers manage security incidents consistently, effectively, and in accordance with client policy, regulatory obligations, and operational risk requirements. Acting as the primary OI lead for incident governance, the consultant provides a consolidated view of incident risk, drives supplier accountability, and supports continual improvement across the incident management lifecycle.
This is a governance, assurance, and supplier management role and does not perform SOC monitoring, incident investigation, forensic analysis, or operational response activities.
Key Responsibilities:
Security Incident Governance:
- Own and govern the security incident management framework across suppliers
- Define and maintain:
- Incident classification criteria
- Escalation models
- Reporting standards
- Major incident governance processes
- Ensure alignment to client policies, regulatory obligations, and security controls
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Supplier Governance & Performance Management:
- Act as the primary OI lead for security incident governance
- Challenge, validate, and assure supplier incident management processes
- Drive consistency in reporting, escalation, communications, and evidence standards
- Manage escalations relating to significant or recurring incidents
Incident Risk & Executive Oversight:
- Maintain visibility of security incident exposure across all suppliers
- Ensure major incidents receive appropriate governance attention
- Support risk-based decision making through accurate incident reporting
- Provide oversight of supplier corrective and preventative actions
Reporting & Executive Visibility:
- Produce consolidated security incident reporting across suppliers
- Provide insight into:
- Incident trends
- Response performance
- SLA adherence
- Recurring root causes
- Risk exposure
- Support governance boards, service review meetings, and client security leadership
Assurance & Evidence Management:
- Define incident management evidence requirements
- Ensure traceability across:
- Detection
- Escalation
- Investigation outcomes
- Recovery activities
- Closure decisions
- Support audits, assurance reviews, and regulatory inspections


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Post-Incident Review & Continuous Improvement:
- Coordinate governance of Post Incident Reviews (PIRs)
- Ensure suppliers provide:
- Root cause analysis
- Corrective actions
- Improvement activities
- Identify opportunities to improve incident governance, reporting, and operational effectiveness
Key Skills:
- Significant experience in Security Incident Management, Cyber Governance, Service Management, or GRC roles
- Security incident lifecycles
- Major incident management
- Security reporting and governance
- Experience working within complex multi-supplier environments
- Strong stakeholder engagement and supplier management skills
- Experience presenting incident risk information to senior stakeholders
Desirable Skills:
- NIST Cyber Security Framework (CSF)
- NCSC guidance
- ITIL Major Incident Management
- ISO 27001
- Experience supporting security assurance and audit activities
- Experience in Defence, Government, or highly regulated sectors
Key Deliverables:
- Security Incident Management Framework
- Consolidated supplier incident reporting
- Executive incident dashboards
- Governance and assurance reporting packs
- Post Incident Review governance outputs
- Continuous improvement roadmap
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills