Head of Security Engineering

Date: 3 Aug 2026

Location: Birmingham, United Kingdom, B37 7ES

Company: LRQA

Job ID:44154
Location:Birmingham : 1 Trinity Park : Bi  
Position Category:Information Technology
Position Type:Employee Regular

Role Purpose 

LRQA is entering a pivotal stage in the evolution of its managed security services. We are investing in the platforms, automation and engineering capability that can operate securely at scale, serve government and commercial customers, and make far greater use of Microsoft, CrowdStrike, orchestration and AI.

As Head of SOC Engineering, you will have the mandate to shape that future. This is not a role focused on maintaining the status quo. You will lead a major technology and service transformation: modernising our core platforms, completing the move away from LogRhythm, building a new SOAR capability, introducing AI-assisted operations responsibly, and enabling the next generation of MDR and XDR services.

You will join at a point where the direction is clear, the opportunity is significant and the engineering decisions made now will influence how the service operates for years to come. You will lead multiple engineering teams and subject-matter experts, working across technology, operations, consultancy and customers to turn ambitious ideas into secure, resilient and repeatable capability. 

 

Key Role Responsibilities 

You will own the platforms, architecture, engineering standards, automation and technical delivery capability that enable LRQA's SOC, Managed Vulnerability and Managed NOC services. You will work as a close partner to the leaders responsible for monitoring, incident response and service management. They retain accountability for their operational outcomes; your role is to give them the secure, reliable, scalable and forward-looking technology needed to succeed. 

 

Key responsibilities for the role include: 

  • Set the engineering and platform vision for the MSSP SOC, translating business ambition into a clear, deliverable and commercially sustainable technology strategy. 
  • Own the architecture, security, resilience, performance and lifecycle of Microsoft Defender XDR, Microsoft Sentinel, CrowdStrike Falcon and the wider technology ecosystem that supports the service. 
  • Lead the strategic migration away from LogRhythm, moving customers, detections, integrations and operational workflows without compromising service continuity or detection coverage. 
  • Design and mature a sovereign, multi-tenant SOC architecture capable of serving government and commercial customers while meeting demanding requirements for segregation, assurance, residency and privileged access. 
  • Create an engineering function built for scale through architecture governance, infrastructure as code, source control, automated testing, release management and repeatable deployment patterns. 
  • Build a modern SOAR capability and reusable orchestration framework that reduces repetitive analyst work, accelerates enrichment and response, and improves consistency across the SOC. 
  • Lead the responsible adoption of AI assisted triage, quality assurance and analyst augmentation, combining innovation with strong controls for customer data, human oversight, model assurance, security and cost. 
  • Transform customer onboarding through standardised, automated and light touch engineering patterns that shorten time-to-service while improving quality and control. 
  • Own the long-term health of the platform estate, including roadmaps, technical debt, capacity, observability, disaster recovery, continuity and end-of-life planning. 
  • Shape a commercially effective engineering model by managing licensing, cloud consumption, ingestion, vendor performance and the overall cost-to-serve. 
  • Build strategic relationships with Microsoft, CrowdStrike and other technology partners, ensuring LRQA gains maximum value from their platforms and future roadmaps. 
  • Build and inspire a high-performing engineering organisation through clear accountability, recruitment, succession planning, capability development and the removal of key-person dependencies. 
  • Represent engineering with strategic customers, helping them understand the roadmap, resolve complex challenges and gain confidence in the capability supporting their security operations. 
  • Provide engineering leadership for the platforms, integrations and automation that underpin the Managed NOC and Managed Vulnerability Services, ensuring they are scalable, resilient and suitable for consistent delivery across multiple customers. 
  • Work closely with the NOC and Managed Vulnerability Service leads to improve onboarding, data quality, workflow automation, reporting and remediation tracking, while ensuring operational ownership remains with the respective service teams. 

 

Skills/Qualifications 

  • Significant experience leading SOC engineering, security-platform or adjacent technical teams within an MSSP or managed-services environment. 
  • Architectural and operational knowledge of Microsoft Defender XDR, Microsoft Sentinel and Entra ID, with the ability to guide design, implementation and optimisation at scale. 
  • Knowledge of CrowdStrike Falcon and an understanding of how endpoint capability can be extended into broader MDR and XDR services. 
  • Experience leading significant SIEM migration, consolidation or decommissioning programmes; direct LogRhythm experience would be useful but is not essential. 
  • Experience designing or operating SOAR capability, including integrations, playbook engineering, workflow assurance and measurable automation outcomes. 
  • A practical and balanced understanding of AI in security operations, including where it creates genuine value, where human judgement remains essential and how risk should be controlled. 
  • Experience designing secure multi-tenant or sovereign architectures, ideally supporting regulated, sensitive or government-facing environments. Relevant security clearance, or eligibility to obtain it, may be required. 
  • A grasp of identity security, privileged access, tenant segregation, secrets management, resilience, observability and disaster recovery. 
  • Experience introducing mature engineering practices such as infrastructure as code, CI/CD, automated testing, release management and formal change governance. 
  • A track record of leading multiple teams, senior specialists, contractors or geographically distributed resources through meaningful technical change. 
  • Commercial and organisational judgement, with the ability to balance innovation, operational risk, customer value, technical debt, cost and delivery pace. 
  • Relevant senior security, architecture or management certifications, such as CISSP, CISM or SC100, supported by appropriate platform or cloud credentials. 
  • The credibility and communication skills to influence engineers, operational leaders, customers, vendors and senior stakeholders. 
  • Experience leading an engineering capability supporting the full detection lifecycle, including detection development, testing, deployment, tuning, version control and performance measurement across Microsoft Defender, Sentinel and CrowdStrike. 
  • Knowledge of adversary behaviours, MITRE ATT&CK and threat informed defence to improve detection coverage, identify control gaps and ensure engineering priorities remain aligned with relevant threats and customer environments.  

 

Why This Role 

In this role, you will have the opportunity to: 

  • Create a faster, more consistent onboarding model that allows new customers and capabilities to move into service with far less friction. 
  • Build a resilient and observable platform estate that engineers and analysts can trust during the moments that matter most. 
  • Move automation and AI from isolated ideas into safe, measurable and operationally valuable capability across the SOC. 
  • Help define and launch differentiated MDR and XDR services built on the full potential of Microsoft and CrowdStrike. 
  • Create an engineering function recognised for technical excellence, strong leadership, clear career paths and sustainable depth of capability. 
  • Strengthen customer confidence by giving them a clear technical roadmap and a dependable engineering partner behind their managed security service. 
  • Demonstrate that ambitious security engineering can also be scalable, supportable and commercially successful. 
  • Own, develop and grow both MVS and NOC services, through both Managed and Professional Services engagements.  

 

The Leader We Are Looking For 

  • You are energised by the chance to build, modernise and leave a lasting mark rather than simply inherit a finished environment. 
  • You combine technical credibility with leadership judgement, knowing when to challenge, when to empower and when to step into a critical decision. 
  • You are ambitious but pragmatic, able to move quickly without losing sight of security, quality, resilience or commercial reality. 
  • You work naturally across organisational boundaries and can bring engineers, operators, consultants, customers and vendors behind a shared direction. 
  • Above all, you want to build capability that lasts: strong platforms, strong teams and a SOC that is ready for what comes next. 

 

Pre-Employment Checks 

If you are successful in securing a role with us, we will carry out preemployment checks in accordance with what is permitted under local law. 

These checks may include, where legally allowed: right to work, identification, verification of employment history, education, and criminal record checks. 

We will engage our thirdparty background screening provider, Cfirst to conduct these checks on our behalf. Cfirst performs all processing in full compliance with applicable data protection laws and adheres to strict legal, regulatory, and ethical obligations in handling personal data. 

Any personal information collected for the purpose of these checks will be used solely for evaluating your suitability for employment and will be retained only for as long as necessary to fulfil these purposes and meet legal requirements. 

Your data will be stored securely and managed in accordance with all relevant privacy legislation. 

If you have any questions or concerns about the preemployment checks please contact us at Onboarding@lrqa.com  

If you have any questions or concerns on how your data will be handled, please contact us as dataprotection@lrqa.com 

At LRQA, we belive that as a leading Global Leading Assurance and Risk Management Service provider, our talented people are our risk management advantage.

We belive the best outcomes come from diverse perspectives, shared ambition and working together with integrity. That's how we buid a workplace where everyone can contribute, grow and thrive.

Guided by Vision and powered by Expertise, we're united by a shared purpose. If you're driven to make a difference, you'll belong here. 

All rights reserved. Terms of use.  Privacy Policy.