About this Team Manager - Security Operations role at Baillie Gifford
Job Title
Team Manager - Security OperationsDepartment
TSD Information Security-BG-UKOverview of Department
Purpose of Role
As our Team Manager - Security Operations, you will lead Baillie Gifford’s Security Operations team and ensure we maintain effective detection and response to cybersecurity threats. You will act as one of the firm’s incident response leads, develop our threat-informed defence capability and help shape the Security Operations roadmap in line with the wider Information Security strategy.You will combine people leadership, technical judgement and operational oversight, supporting the team to respond effectively to incidents while continuing to strengthen our detection and response capabilities. You will also help the team adapt its monitoring and response as the firm increases its use of AI.
Responsibilities
- Lead, coach and develop a team of permanent colleagues and contractors, setting priorities and managing operational capacity.
- Ensure effective security monitoring, alert investigation, detection tuning and threat hunting, continually improving our ability to identify and respond to relevant threats.
- Act as an incident response lead, coordinating assessment, containment, escalation and recovery.
- Provide a technical escalation point for teams dealing with cyber incident-related issues.
- Own the operational use of threat intelligence and drive the threat-informed defence programme.
- Set the Security Operations roadmap, balancing capability development, operational priorities, capacity and costs.
- Oversee the operational use of SIEM, EDR, and SOAR, working with Security Engineering on platform development and integrations.
- Develop the team’s ability to monitor and respond to AI-enabled activity.
- Provide security expertise to projects and technology teams, working with Security Governance and Information Risk on controls and material risks.
- Represent Security Operations at relevant forums and report to senior leaders on threats, incidents, performance and capability gaps.
- Use incident reviews and operational evidence to improve detections, response procedures and ways of working.
What success looks like
- The team has clear priorities, effective operational coverage and opportunities to develop its capability.
- Significant incidents are led decisively, with timely escalation, clear communication and lessons put into practice.
- Detection and response capabilities continue to improve against threats relevant to the firm.
- The Security Operations roadmap is deliverable within the agreed capacity and costs.
- Senior stakeholders have a clear understanding of operational threats, incidents and capability gaps.
Your Knowledge and Experience
- Experience leading a security operations, detection and response, or incident response team.
- Experience leading significant security incidents and coordinating technical and business stakeholders.
- Experience setting operational priorities and delivering improvements to security capabilities.
- Strong practical knowledge of security investigations, incident management, containment and recovery.
- Knowledge of common attack techniques, threat intelligence, threat hunting and prevention methods.
- Experience using security telemetry and SIEM, EDR or XDR tools to investigate threats and improve detection.
- An understanding of identity, endpoint, network and cloud security.
- Experience managing operational costs or supplier services. (Preferred).
- Experience in a large or regulated organisation. (Preferred).
- An awareness of and interest in how AI may change security monitoring and incident response. (Preferred).
- Relevant security or incident response certification. (Preferred).
The type of candidate that we're looking for
You are a supportive and decisive manager who develops people while maintaining a strong operational service. You have the technical credibility to guide investigations and advise other teams, alongside the judgement to set direction and make sensible choices about priorities and resources.
During an incident, you bring structure to incomplete information, involve the right people and communicate clearly. You work well across engineering, governance, risk and technology teams, and are curious about emerging threats and technologies, including AI.
Critical skills
- Digital effectiveness (incl. AI)
- Enabling others
- Improvement mindset
- Openness & discernment
- Systems thinking
Note - There is no formal out-of-hours requirement for this role, but due to the nature of the role, flexibility may be required to help lead the response to significant security incidents. The position is hybrid.
Closing Date
October 21, 2026Should you choose to use AI tools to support your application, we ask that you do this thoughtfully. We encourage you to ensure your application reflects your own voice, experience, and motivations. We value authenticity and want to understand your individual strengths and perspectives.
At Baillie Gifford, we are committed to fostering an inclusive and respectful culture in which each of our colleagues can thrive and develop. We believe that our clients are best served by a diverse workforce with the experiences, ideas and perspectives that this brings.
If you are currently working at Baillie Gifford as an employee or contractor please apply to this job from the firm's Workday internal career site.