Virgin Atlantic Logo

Virgin Atlantic

Manager, Cyber Security Operations

Posted 10 Days Ago
Be an Early Applicant
In-Office
Crawley, West Sussex, England, GBR
Senior level
In-Office
Crawley, West Sussex, England, GBR
Senior level
Leads cyber security incident response, complex threat investigations, threat hunting, detection engineering, and security automation across cloud, endpoint, network, identity, and application environments. Acts as technical incident lead, improves SIEM and response capabilities, mentors security analysts, coordinates with technology teams and external partners, and provides risk-based recommendations. Participates in an on-call rota and supports out-of-hours incident response.
The summary above was generated by AI

Salary: Competitive  

Hours: 37.5 hours, Mon – Friday    

Location:  Hybrid,  3 days per week at VHQ, Crawley  (with travel as required) 

Contract: Permanent    

Closing Date:  8th September 

In a nutshell

At Virgin Atlantic, we're on a mission to become the most loved travel company, and keeping our customers, colleagues and business safe is fundamental to that ambition.

We're looking for an experienced Manager, Cyber Security Operations to join our Information & Cyber Security team. This is a senior technical role where you'll lead the response to cyber threats, drive improvements across our security operations capability and play a key part in strengthening our cyber resilience.

You'll be at the centre of our security operations, leading complex investigations, developing advanced detection capabilities and mentoring a team of talented security professionals. Working across cloud platforms, infrastructure, applications, networks and identity services, you'll help ensure we're always one step ahead of an ever-evolving threat landscape.

If you're passionate about cyber security, thrive under pressure and enjoy solving complex technical challenges, we'd love to hear from you.


Day to day

No two days are ever the same in Cyber Security Operations. You'll combine hands-on technical expertise with leadership, helping protect one of the UK's most recognised brands.

You'll:

  • Lead the technical response to complex cyber security incidents, coordinating investigations from detection through to recovery.  
  • Act as the Cyber Incident Lead during major incidents, providing technical direction and clear updates to senior stakeholders.  
  • Investigate sophisticated threats across cloud environments, endpoints, networks, identity platforms and applications.  
  • Develop and enhance detection rules, SIEM content, investigation playbooks and response procedures.  
  • Improve monitoring capabilities across Microsoft Sentinel, Microsoft Defender and other security technologies.  
  • Conduct proactive threat hunting using threat intelligence, behavioural analytics and attacker techniques.  
  • Identify opportunities to automate investigation and response activities using PowerShell, Python, KQL, Logic Apps, SOAR or similar technologies.  
  • Coach and mentor Cyber Security Operations Analysts, helping build technical capability across the team.  
  • Work closely with technology teams, managed security partners and external specialists to continually improve our cyber resilience.  
  • Translate technical findings into clear, risk-based recommendations that support better business decisions.  
  • As part of our operational security function, you'll also participate in an on-call rota and support out-of-hours incident response when required.

About you

You're an experienced cyber security professional who enjoys investigating complex problems and leading technical teams through challenging situations.

You'll bring:

  • Significant experience in Cyber Security Operations, Incident Response or Security Engineering.  
  • Strong hands-on experience leading security investigations through identification, containment, eradication and recovery.  
  • Excellent knowledge of Windows, Linux, networking, cloud platforms, identity services and modern authentication technologies.  
  • Experience using SIEM, EDR/XDR, cloud security and email security platforms, including technologies such as Microsoft Sentinel, Microsoft Defender, Azure or AWS.  
  • Experience investigating identity-related attacks, including account compromise, MFA abuse, token theft and privileged access threats.  
  • Strong understanding of attacker tactics, techniques and procedures, including MITRE ATT&CK.  
  • Experience developing detection use cases, threat hunting methodologies and incident response playbooks.  
  • Practical scripting or automation skills using PowerShell, Python, KQL, Logic Apps, SOAR or similar technologies.  
  • Excellent analytical and communication skills, with the ability to explain complex technical issues to both technical and non-technical audiences.  
  • Experience mentoring or leading other cyber security professionals.  
  • Above all, you'll be curious, collaborative and committed to continually improving cyber security operations.

Be yourself. Our differences make us stronger.

Virgin Atlantic are committed equal opportunities employers and positively encourage applications from suitably qualified and eligible applicants regardless of sex, race, disability, age, sexual orientation, gender reassignment, religion or belief, marital status, pregnancy and maternity. Diversity brings strength which is why we strive to provide an inclusive environment where individuality is celebrated, and we can ignite the potential of our forward-thinking mix of people.  

Please be aware as part of our recruitment process we may look to use a variety of resourcing tools to help us understand your skills and experience in relation to the role you have applied for. These may include application questions, video interviews or online testing. Please feel free to contact us at [email protected] if there are any reasonable adjustments to our process that you would like us to consider, for example use of hearing loops, sign language interpreter etc. Please don’t hesitate to reach out if there are any issues preventing you from being at your best during your application or assessment process. Any issues raised after your assessment is completed or once a decision has been made will be too late for us to consider within our process.  


HQ

Virgin Atlantic Crawley, England Office

The VHQ, Fleming Way, Crawley, Crawley, United Kingdom, RH10 9DF

Virgin Atlantic Hillingdon, England Office

Hillingdon, United Kingdom

Similar Jobs

27 Minutes Ago
Easy Apply
Hybrid
City of London, City and County of the City of London, England, GBR
Easy Apply
Mid level
Mid level
Cloud • Information Technology • Security • Software • Cybersecurity
Manage a UK commercial sales territory targeting net new logos and upsell opportunities within accounts of 750–5,000 employees. Build customer business cases, generate pipeline through field marketing and channel partners, collaborate with sales engineering and consulting teams, and execute disciplined sales cycles. The role requires quota-carrying sales experience, consistent new-logo overachievement, channel partnership expertise, and the ability to lead cross-functional team sales.
Top Skills: Ai-Powered Sales IntelligenceAi/MlCloud SecurityConversational AiEnterprise SoftwarePredictive Pipeline AnalyticsSaaSSaseZero Trust Exchange
31 Minutes Ago
Hybrid
London, Greater London, England, GBR
Senior level
Senior level
Artificial Intelligence • Productivity • Sales • Software
Own AI transformation engagements for 1–2 strategic customers, partnering with executives and technical teams to architect, build, deploy, and measure production AI solutions. Develop monday AI agents, vibe apps, MCP integrations, workflows, and custom scripts. Define business outcomes, run evaluations, provide product feedback, and turn customer-specific solutions into reusable assets and product requirements while collaborating with Sales, Customer Success, and Product.
Top Skills: Ai/Llm SystemsMcpMonday Ai AgentsNode.jsReactTypescript
34 Minutes Ago
Hybrid
Internship
Internship
Aerospace • Artificial Intelligence • Cloud • Machine Learning • Software • Cybersecurity • Defense
Supports aerospace manufacturing software development through dashboards, IoT/SCADA data integration, analytics, AI-based failure analysis, predictive modeling, and production simulation. The intern collaborates with engineering teams to improve data visibility, identify bottlenecks, optimize production flows, and drive continuous improvement. The role includes mentorship, training, and hands-on experience in industrial systems and automation.
Top Skills: AIC#Data AnalyticsIotPredictive ModelingPythonScadaSimulation ToolsSQL

What you need to know about the London Tech Scene

London isn't just a hub for established businesses; it's also a nursery for innovation. Boasting one of the most recognized fintech ecosystems in Europe, attracting billions in investments each year, London's success has made it a go-to destination for startups looking to make their mark. Top U.K. companies like Hoptin, Moneybox and Marshmallow have already made the city their base — yet fintech is just the beginning. From healthtech to renewable energy to cybersecurity and beyond, the city's startups are breaking new ground across a range of industries.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account