Cyber Security Manager
Applied Computing was founded in 2024 to build Orbital, a physics-informed foundation model for energy operations. We’re live across oil and gas, refineries, and petrochemicals, working towards our mission: sustainable abundance for a growing planet.
The hydrocarbon industry keeps the world running. But its complexity has left operators tied to legacy systems, making critical decisions on less than 10% of available data.
We built Orbital to change that. It’s a foundation model built specifically for energy that lets companies use AI at scale, harnessing all of their operational data and optimising in real time for any metric. Decisions get faster, operations get safer, and carbon intensity falls.
We’ve raised over $32 million, including one of the largest seed rounds for an AI company in the UK. We’re just getting started.
The role
This is the first role in the company whose whole job is to keep us secure day to day. Right now detection, identity, endpoints, IT service and the UK estate are spread across four people and a Director, and nobody owns the operational half of it end to end. You would.
You will run security operations for a fast-moving AI business supporting three lines: our core business, our commercial client work, and Metis Red, our agentic security testing platform. You own identity and access, endpoints, network controls, vulnerability remediation, resilience testing, and the UK IT service and facilities that sit underneath all of it.
The part that makes this role unusual: we are not building a twenty-person SOC, we are building an autonomous one and we have not built it yet. The first job is to take the estate as it is, establish honestly where the monitoring gaps are, and close them.
From there you work with the team to design and build the agentic detection and response capability, validated against attacks from our own internal red team. You will run operations by hand while that is being built, and you will run what you helped build afterwards. If you want to shape a capability from the ground up and own the outcome, this is the right role. If you want a mature toolchain and a large team to inherit, it is not.
Key Responsibilities
Detection and incident response
•Own alert triage, investigation and response end to end, be the named person who declares an incident, runs it, and closes it out.
•Operate and tune the autonomous security operations capability. Treat agent output as a first line, never as a verdict.
•Own detection engineering: logging standards, alert quality, coverage gaps and false positive reduction.
•Validate detection coverage against attack paths from our internal red team, and close what it finds.
•Run post-incident reviews and drive the actions to genuine closure, not to a spreadsheet.
Identity, endpoints and network
•Joiners, movers and leavers; privileged access; single sign-on; secrets management.
•Endpoint fleet hardening, patch compliance, EDR administration and device lifecycle.
•Network and edge controls, remote access and segmentation.
•Run access reviews that stand up to an auditor without a fire drill beforehand.
IT operations and service
•Own the UK IT service: end user support, devices, and the on-premise server estate.
•Own the SaaS estate, roughly 85 products, including licensing, access, spend and rationalisation.
•Set and report service levels and keep the queue healthy rather than merely open.
•Own IT procurement and asset management.
Resilience and continuity
•Own backup security and ransomware recovery, and test recovery rather than document it.
•Run the business continuity and disaster recovery exercise schedule and keep the evidence current.
•Establish and prove an out-of-hours arrangement that does not depend on one person's phone.
People and coaching
•Line manage and develop our offshore security resource, building them into first-line detection work.
•Set the standard, hold it, and be the escalation point when it is not met.
Assurance and evidence
•Produce operational evidence for ISO 27001 and SOC 2 continuously, as a by-product of the work, not in an audit sprint.
•Answer the operational half of client due diligence so commercial is never waiting on us.
•Keep asset, log and access inventories accurate enough to be relied on.
Essential Experience
•Five or more years in security operations, with at least two carrying real accountability for incident response in a live environment.
•Hands-on cloud security operations, AWS and Azure, including logging, monitoring and identity.
•Identity and access administration at scale: SSO, privileged access, joiner and leaver process.
•Endpoint and EDR administration across a distributed fleet.
•Vulnerability management at volume, with a track record of closing findings rather than counting them.
•Has worked inside an ISO 27001 or SOC 2 control environment and produced evidence an auditor accepted.
•Automation-minded: scripting, infrastructure as code, or a demonstrated ability to direct agentic tooling and check its work.
•Able to hold a standard with engineers and commercial colleagues, and to say no with a reason rather than a policy reference.
Desirable
•Exposure to operational technology or industrial environments.
•Practical AI or machine learning security awareness, model access, data handling, prompt safety.
•Relevant certification such as CREST, GIAC, or an equivalent hands-on qualification.
•Experience in a startup, scale-up or managed service provider, where scope changes faster than process.
•Experience managing or coaching an offshore or distributed team member.
What Success Looks Like
In the first 90 days
•You are the named owner of security operations, and the VP is out of the alert queue and the service desk.
•Every alert path has a documented triage route, an owner and an escalation point.
•The incident response plan has been tested at least once with the leadership team in the room.
•The asset and SaaS inventories are accurate and owned, and you can say what we run and who has access to it.
By six months
•Autonomous security operations is running with your validation layer on top, and time to triage is measured and improving.
•The remediation programme is burning down against agreed SLAs, with engineering bought in rather than chased.
•Operational evidence for certification is produced as a by-product of the work.
•The offshore resource is handling first-line triage independently, with you as escalation.
By twelve months
•An out-of-hours cover arrangement is in place and has been proven by a real event or a serious exercise.
•Detection coverage has been validated against internal red team attack paths, and the gaps are closed.
•IT service is measured, predictable, and no longer the reason security work slips.
•No operational process depends on a single person, including you.
•The operational load has come off the VP permanently, freeing security leadership to sit inside the customer signing process rather than behind it.
- Department
- Finance
- Role
- Cyber Security & Compliance
- Locations
- London Office, Remote UK
- Remote status
- Fully Remote
About Applied Computing
Applied computing is one of its kind revolution with a mission to deliver sustainable abundance for a growing planet,
through AI that works for the Energy Industry