Leads day-to-day security operations across retail, ecommerce, distribution, and corporate environments. Oversees monitoring, detection, incident response, vulnerability management, tooling, and remediation. Manages the outsourced SOC, including SLAs, detection coverage, reporting, governance, and performance assurance. Maintains operational security controls, incident runbooks, audit evidence, and compliance with PCI DSS, UK GDPR, ISO 27001, and NIST CSF. Partners with technology, ecommerce, infrastructure, legal, risk, and privacy teams.
River Island is a UK high-street and omnichannel apparel retailer trading across 1800+ stores, a major distribution centre, head offices, and a growing ecommerce platform. As the business modernises its digital footprint, it is strengthening in-house security operations capability to complement its existing outsourced Security Operations Centre (SOC).
The Security Operations Lead owns day-to-day security operations delivery and acts as the primary internal control point across both first-line (operational security execution and tooling) and second-line (oversight, assurance, and governance of the security control environment) accountabilities. This is a hybrid, hands-on role suited to someone who can both operate security tooling directly and hold a third-party SOC provider to account against contracted service levels and outcomes.
The role sits within a lean Information Security function and is central to River Island's ability to detect, triage, and respond to threats across stores, ecommerce (including Storefront API/headless platforms), distribution, and corporate estate — while managing the operational relationship with the outsourced SOC.
Key Accountabilities
Key Accountabilities
1. Security Operations Delivery
- Own the operational delivery of security monitoring, detection, and response capability across corporate, retail, distribution, and ecommerce environments.
- Act as the internal escalation and coordination point for security alerts, incidents, and investigations raised by the outsourced SOC, ensuring timely triage and remediation.
- Operate and tune in-house security tooling (e.g. vulnerability scanning, endpoint detection, exposure management, identity/access monitoring) to complement SOC-delivered detection.
- Lead incident response execution: contain, investigate, and coordinate recovery for security incidents, following documented playbooks, and drive post-incident lessons-learned activity.
- Coordinate vulnerability management end-to-end — from detection and prioritisation through to remediation tracking with Technology, Ecommerce, and Infrastructure teams.
- Support patching, hardening, and configuration management activities across store systems, cloud platforms, and the ecommerce stack.
- Maintain and test incident response runbooks, tabletop exercises, and escalation paths, including out-of-hours coverage arrangements with the SOC.
2. Outsourced SOC Management and Oversight
- Act as the primary relationship and performance owner for the outsourced SOC provider, holding them accountable to SLAs, use-case coverage, detection efficacy, and reporting quality.
- Chair or contribute to regular SOC service reviews, tracking key metrics such as mean time to detect (MTTD), mean time to respond (MTTR), false-positive rates, alert volumes, and coverage gaps.
- Define and continuously refine detection use cases and log source onboarding with the SOC to ensure coverage keeps pace with the retail estate, ecommerce releases, and cloud changes.
- Provide independent assurance that SOC-reported findings, incident closures, and control effectiveness claims are accurate and evidenced — challenging and validating rather than simply accepting vendor reporting.
- Own the governance of the SOC contract from a security-operations lens: reviewing scope, escalation matrices, data handling, and change requests as the business or threat landscape evolves.
- Ensure clear ownership of assets, logs, and detection logic remains with River Island, avoiding vendor lock-in or loss of institutional knowledge.
- Feed SOC performance, risk exposure, and control gaps into the Information Security Risk Register and executive/committee reporting.
3. Governance, Risk, and Reporting
- Define and report security operations KPIs/KRIs (detection coverage, incident volumes and trends, remediation SLAs, SOC performance) to the Head of Information Security and relevant governance forums (e.g. GDPR Steering Committee, security committees).
- Support compliance activities across PCI DSS, UK GDPR, and ISO 27001/NIST CSF-aligned control requirements as they relate to operational security and monitoring.
- Maintain evidence and documentation to support internal and external audits, penetration tests, and regulatory reviews.
- Partner with Legal, DPO, and Risk teams on incident notification obligations and data breach response.
4. Cross-Functional Partnership
- Work closely with Ecommerce/Storefront API, Infrastructure, Retail Technology, and Distribution Centre teams to ensure monitoring coverage extends across all channels — stores, web, app, and warehouse systems.
- Partner with the security and tech Engineers on penetration testing, red-teaming, and remediation coordination.
- Support BYOD/MDM security monitoring and access governance activities (RBAC, joiner/mover/leaver, MFA, privileged access, Identity posture) from an operational assurance standpoint.
- Represent security operations in change advisory and project forums to ensure new initiatives are onboarded into monitoring scope pre-go-live.
Essential Experience and Skills
- Proven experience in a security operations, SOC management, or similar hands-on operational security role, ideally within retail, ecommerce, or another complex multi-channel environment.
- Demonstrable experience managing or governing an outsourced/managed SOC or MSSP relationship, including SLA management and detection use-case development.
- Strong working knowledge of SIEM, EDR, vulnerability management, and exposure management tooling.
- Practical incident response experience, including leading or coordinating live incident investigations.
- Familiarity with the three lines of defence model and ability to operate credibly across both first-line delivery and second-line oversight.
- Understanding of PCI DSS, UK GDPR, and NIST CSF control frameworks as applied to operational security.
- Comfortable working in a lean team, prioritising pragmatically, and balancing protection with business/customer experience.
- Strong stakeholder management skills, able to challenge a third-party provider constructively while maintaining an effective working relationship.
Desirable
- Experience securing ecommerce/headless commerce platforms (e.g. Shopify, Storefront APIs) or retail store estates.
- Relevant certifications such as CISSP, CISM, GCIH, or equivalent.
- Experience with retail-specific threats (POS malware, card-skimming, credential stuffing, loyalty/gift card fraud).
- Exposure to cloud-native security monitoring (Azure/AWS/GCP) and CI/CD pipeline security.
About Us
We’re a much-loved brand with an exciting future. Our Islanders are a diverse bunch of bright, talented people who love working together – and are proud of the work they do. Progression here can take you in all kinds of directions. This is what a career at River Island is like. And this is where yours starts.
This role is based at our Head Office in West London. Check us out here on a map.
What we can offer you:
💰 Generous 50% staff discount so you can treat yourself to the latest products, and a bargain staff shop on site!
🛒 Reducing Islanders everyday expenses through discounts, benefits, financial advice, wellbeing solutions and more through the Retail Trust.
🎉 A free onsite gym, subsidised restaurant & café to fill you needs. Various social events to socialise throughout the year.
🤎 Every family is unique, we support Islanders with all different family setups enhanced maternity, paternity, adoption & fertility treatment. We also work closely with the Retail Trust to create dedicated support for all our Islanders!
💻 Flexible working, on top of payday and summer early finish Fridays.
💕 Give as you earn scheme, a ‘Giver Island’ day each year and receive matched funding.
🎓 Support with upskilling through on the job training and qualifications. A succession plan if you want to progress.
💰 A generous bonus scheme & private pension plan.
🩺 The choice to opt in for healthcare through our provider AXA.
☀️ 25 days paid holiday, exclusive of Bank Holidays. With the added option to purchase additional holiday twice a year for whatever the need!
This role is based at our Head Office in West London. Check us out here on a map.
What we can offer you:
💰 Generous 50% staff discount so you can treat yourself to the latest products, and a bargain staff shop on site!
🛒 Reducing Islanders everyday expenses through discounts, benefits, financial advice, wellbeing solutions and more through the Retail Trust.
🎉 A free onsite gym, subsidised restaurant & café to fill you needs. Various social events to socialise throughout the year.
🤎 Every family is unique, we support Islanders with all different family setups enhanced maternity, paternity, adoption & fertility treatment. We also work closely with the Retail Trust to create dedicated support for all our Islanders!
💻 Flexible working, on top of payday and summer early finish Fridays.
💕 Give as you earn scheme, a ‘Giver Island’ day each year and receive matched funding.
🎓 Support with upskilling through on the job training and qualifications. A succession plan if you want to progress.
💰 A generous bonus scheme & private pension plan.
🩺 The choice to opt in for healthcare through our provider AXA.
☀️ 25 days paid holiday, exclusive of Bank Holidays. With the added option to purchase additional holiday twice a year for whatever the need!
Keeping You Safe
We are committed to providing a safe and inclusive workplace where everyone is treated with dignity and respect. We expect all employees to uphold our values and contribute to a positive working environment.
Our business is made up of a diverse community, where we all belong and feel part of something bigger. We are committed to equality of opportunity and welcome applications from individuals regardless of age, gender, ethnicity, disability, sexual orientation, gender identity, socio-economic background, religion or belief. We will consider flexible working requests for all roles unless operational requirements prevent otherwise.
Our business is made up of a diverse community, where we all belong and feel part of something bigger. We are committed to equality of opportunity and welcome applications from individuals regardless of age, gender, ethnicity, disability, sexual orientation, gender identity, socio-economic background, religion or belief. We will consider flexible working requests for all roles unless operational requirements prevent otherwise.
Similar Jobs
Artificial Intelligence • Big Data • Healthtech • Machine Learning • Software • Database • Analytics
Leads InterSystems’ Australia and New Zealand business, owning regional sales strategy, revenue growth, customer relationships, partnerships, and P&L accountability. Manages sales and sales engineering teams, develops business plans and KPIs, engages senior executives, coordinates cross-functional resources, expands the customer base, and ensures customer success. The role requires extensive regional travel, enterprise software expertise, strong technical selling skills, and the ability to lead through influence across a multinational organization.
Cloud • Information Technology • Productivity • Security • Software • App development • Automation
Build and refine core AI and machine learning infrastructure supporting model development, training, evaluation, deployment, and monitoring. Design scalable distributed ML systems, collaborate with product and engineering teams, lead projects from technical design through launch, review code, document solutions, resolve infrastructure challenges, and mentor junior engineers.
Top Skills:
AWSAzureCi/CdDaskGCPGoGpusJavaJaxLarge Language Models (Llms)MlopsPythonPyTorchRayRetrieval-Augmented Generation (Rag)ScalaSparkTensorFlow
Cloud • Information Technology • Productivity • Security • Software • App development • Automation
Lead regional security incident response for high-severity enterprise incidents, directing investigations, communications, coordination, and remediation. Build incident response tools, systems, playbooks, and programs; conduct exercises and post-incident reviews; mentor team members; collaborate across security teams; engage law enforcement and industry bodies; and produce threat intelligence. The role requires expertise across multiple security domains, cloud and network technologies, scripting, and incident response leadership.
Top Skills:
FirewallsGCPGoIntrusion Detection Systems (Ids)Network ProtocolsPython
What you need to know about the Sydney Tech Scene
From opera to comedy shows, the Sydney Opera House hosts more than 1,600 performances a year, yet its entertainment sector isn't the only one taking center stage. The city's tech sector has earned a reputation as one of the fastest-growing in the region. More specifically, its IT sector stands out as the country's third-largest, growing at twice the rate of overall employment in the past decade as businesses continue to digitize their operations to stay competitive.


