Lead Security Operations Engineer

Posted 7 days 17 hours ago by Jobtailor

Permanent
Full Time
Other
London, United Kingdom
Job Description
  • Define and deliver Pleo's SecOps roadmap for detection, response, and investigation capabilities
  • Build a structured roadmap based on MITRE ATT&CK, NIST, and CIS benchmarks
  • Lead security investigations and digital forensics through incident response
  • Design, tune, and scale SIEM and standardized logging pipelines
  • Strengthen perimeter and authentication security through WAF configuration, authorization tuning, and suspicious-traffic monitoring
  • Implement DLP controls aligned with sensitive-data locations
  • Improve the on-call rotation, alerting, escalation paths, and response SLAs
  • Automate detection and response workflows using code and AI
  • Reduce SecOps-attributed compliance risk and collect supporting evidence
  • Build dashboards and reporting for response times, coverage, and risk reduction
  • Translate threat models into shippable engineering changes
  • Partner with Fraud, DevSecOps, Engineering, and Risk & Compliance
  • Mentor less experienced security engineers and help mature the security operations function
  • In the first six months, assess the security landscape, publish and begin delivering the roadmap, establish on-call SLAs, ship detection and automation improvements, and define KPIs
Requirements
  • 10+ years of experience in security operations, incident response, or a closely related discipline
  • Proven materialized risk reduction through monetary impact, incidents contained, or forensics that changed outcomes
  • Strong development and engineering background, including writing automation
  • Hands-on SOC and SIEM management experience
  • Experience in detection engineering and log pipeline design
  • Experience building security capability in scale-up environments
  • Strong understanding of cloud architectures, especially AWS, with exposure to GCP
  • Demonstrated use of AI and/or coding automation to implement and operate security controls
  • Fintech, payments, fraud, or trust and safety experience is advantageous
  • Exposure to highly regulated environments is advantageous
  • Experience in incident response, IR management, SOC engineering, security engineering, DevSecOps, red team, or blue team
  • Willingness to participate in an on-call rotation
  • Must be physically based in the chosen country with valid right to work
  • Visa sponsorship is unavailable for the listed locations
  • Application must be submitted in English
Core Competencies

Demonstrates extensive experience in security operations, incident response, and risk reduction, with a strong focus on automation and cloud security. Capable of leading security investigations, designing detection capabilities, and mentoring security teams in a fast-paced environment.

Highest-signal resume keywords
  • Security Operations Management
  • Incident Response
  • Detection Engineering
  • SIEM Management
  • Cloud Security (AWS, GCP)
ATS Optimization Keywords Hard Skills
  • Automation Development
  • Digital Forensics
  • Risk Reduction
  • Log Pipeline Design
  • DLP Implementation
  • WAF Configuration
  • Incident Response Management
  • Security Capability Building
  • Threat Modeling
  • Compliance Risk Management
Soft Skills
  • Mentoring
  • Collaboration
  • Leadership
Industry Keywords
  • Fintech
  • Payments
  • Fraud
  • Trust & Safety
  • Regulated Environments
Tools & Technologies
  • SIEM
  • MITRE ATT&CK
  • NIST
  • CIS Benchmarks
  • AI Automation