Skip to main content
AfterDuty

IT Operations Director

Bain & Company · London, Greater London

Type
Full-time
Posted
12 days ago

Overview

WHAT MAKES US A GREAT PLACE TO WORK We are proud to be consistently recognized as one of the world’s best places to work. We are currently the top ranked consulting firm on Glassdoor’s Best Places to Work list and have earned the #1 overall spot a record seven times.

About this role

WHAT MAKES US A GREAT PLACE TO WORK

We are proud to be consistently recognized as one of the world’s best places to work. We are currently the top ranked consulting firm on Glassdoor’s Best Places to Work list and have earned the #1 overall spot a record seven times. Extraordinary teams are at the heart of our business strategy, but these don’t happen by chance. They require intentional focus on bringing together a broad set of backgrounds, cultures, experiences, perspectives, and skills in a supportive and inclusive work environment. We hire people with exceptional talent and create an environment in which every individual can thrive professionally and personally.

WHO YOU’LL WORK WITH

You’ll join Bain’s Technology Solutions Group (TSG) and work closely with teams across Global Technology Operations, Product Engineering, Service Management, Security Operations, and other technology functions around the world.

You’ll lead a globally distributed Tier 2 Operations capability spanning infrastructure, digital workplace, and cloud operations. You’ll also lead our Vulnerability and Patch Management Centre of Excellence, partnering across technology and security teams to strengthen service reliability, operational consistency, vulnerability remediation, and readiness across our global technology environment.

WHERE YOU’LL FIT WITHIN THE TEAM

As IT Operations Director, you’ll lead the day-to-day operations of our consolidated Tier 2 support function, serving as a key point of escalation and coordination between Tier 1 support teams and Tier 3 Product Engineering teams.

You’ll turn our Tier 2 operating model into consistent, scalable ways of working across infrastructure, cloud, and digital workplace support. This includes establishing shared support practices, playbooks, escalation frameworks, operating rhythms, and performance standards.

You’ll also own and lead our Vulnerability and Patch Management Centre of Excellence across global technology operations. You’ll be accountable for the end-to-end patching lifecycle, vulnerability remediation standards, compliance reporting, and automated remediation workflows, working closely with Security Operations to ensure vulnerabilities and zero-day exposures are consistently triaged, remediated, and evidenced.

A key part of your role will be advancing the maturity of our technology operations through observability, automation, disciplined incident response, and continuous improvement. You’ll identify opportunities for automation and AI-enabled agent workflows to reduce routine operational effort and embed these capabilities into everyday Tier 2 and Centre of Excellence delivery.

WHAT YOU’LL DO

Lead global Tier 2 operations and teams

  • Lead the day-to-day coordination and delivery of our consolidated Tier 2 Operations function across infrastructure, digital workplace, and cloud operations.
  • Own and run the Vulnerability and Patch Management Centre of Excellence, leading its practitioners and establishing consistent operating standards, cadence, and ways of working.
  • Establish an effective operational rhythm across teams, including daily stand-ups, triage rotations, escalation protocols, and follow-the-sun handovers.
  • Lead and develop a geographically distributed operations team, fostering accountability, customer focus, and continuous learning.
  • Partner with Talent Acquisition and managed service providers to build and scale operational support capabilities.
  • Manage the onboarding and operational alignment of additional support teams into the Tier 2 function.

Drive operational and service excellence

  • Help define and own key Tier 2 performance measures, including mean time to resolution, uptime, automated incident resolution rate, and unplanned work ratio.
  • Own vulnerability and patch management measures, including patch compliance, adherence to remediation targets, mean time to remediate, and automated remediation coverage.
  • Provide regular performance reporting to the VP of Global Tech Operations, creating visibility into operational trends, vulnerability posture, risks, and capacity considerations.
  • Lead operational improvement initiatives that reduce unplanned work and strengthen service reliability.
  • Operationalize event-management integrations across platforms such as Datadog, Wiz, CrowdStrike, and ServiceNow.
  • Advance the adoption of observability and operational monitoring practices within day-to-day support activities.
  • Help mature our 24/7 operating model by improving operational readiness and incident response while identifying opportunities for automation and self-healing.

Strengthen cross-team partnership and transformation

  • Oversee escalation processes across Tier 1, Tier 2, and Tier 3 support teams.
  • Partner with Service Hub leadership to strengthen escalation service levels, handoff protocols, and shared reporting.
  • Collaborate with Service Management on continuous improvement, knowledge management, and root cause analysis.
  • Act as operational owner of the patching lifecycle and automated remediation workflows, partnering with Security Operations on zero-day mitigation and vulnerability governance.
  • Participate in change coordination and operational reviews to ensure technology changes are visible, coordinated, and tracked.
  • Help embed more proactive, intelligence-led support practices across global technology operations.

ABOUT YOU

  • You bring strong knowledge of ITIL service management frameworks, with practical experience supporting incident, event, and problem management processes. ITIL v3 or v4 certification is preferred.
  • You have experience in technology operations spanning infrastructure operations, platform or cloud operations, or IT service management at a senior management or associate director level.
  • You have managed or consolidated multi-domain operational support functions across geographies and time zones.
  • You have experience establishing or managing on-call rotations, major incident management, and cross-team escalation frameworks in a global environment.
  • You have practical experience with observability and monitoring tools such as Datadog, Dynatrace, Splunk, or equivalent platforms.
  • You understand vulnerability management and patching tools such as Wiz, Qualys, Tenable, CrowdStrike, Intune/SCCM, or equivalent solutions, as well as vulnerability scoring, prioritization, and remediation service levels.
  • You have familiarity with AWS, Azure, and/or GCP and understand the operational challenges associated with hybrid infrastructure environments.
  • You have experience with IT service management platforms, ideally ServiceNow, across incident, change, and problem management workflows.
  • You have hands-on experience operationalizing automated remediation workflows, self-healing infrastructure patterns, or event-driven operational automation.
  • You have led or owned vulnerability management and patching capabilities at enterprise scale, including compliance reporting and remediation governance.
  • You are an experienced people leader who can build and develop operationally focused, geographically distributed teams.
  • You are comfortable partnering with engineering, service management, security operations, and senior business leaders.
  • You bring an operationally rigorous, data-driven approach, a bias toward action, and a continuous improvement mindset.
  • Experience in professional services, financial services, or a similarly complex global enterprise is relevant to this role.
  • ITIL v4 Managing Professional or relevant cloud operations certifications, such as AWS Solutions Architect or Azure Administrator, are advantageous. Security certifications such as CompTIA Security+ or CISSP are also advantageous.

This role follows a hybrid model, requiring in-office presence at least 1 day per week.

*U.S.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in London

Why this fits a police background — match score 90/100

  • Intelligence & OSINT
  • Incident command & response
  • Working to legislation & regulation
  • Security operations

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Full-time

    Your experience managing operational risk and leading incident reviews translates directly into shaping security culture and resilience.

    Posted 3 days ago

  • Information Security Analyst

    Europa Worldwide Group · London

    Full-time

    £40,000 – £45,000Estimated

    Your experience managing evidence, compliance, and risk under ISO standards translates directly into this security assurance role.

    Posted 4 days ago

  • Cyber Security & Compliance Analyst

    Shivom Consultancy Ltd · London

    Full-time

    Your incident management, evidence handling, and risk assessment from policing transfer directly to this role.

    Posted 4 days ago

  • £570 a dayEstimated

    Your experience managing security incidents and coordinating multi-agency responses transfers directly to this governance role.

    Posted 4 days ago