Lead Security Operations Engineer
RemoteLondon, England, United Kingdom
Job Summary
Build and own a structured SecOps roadmap grounded in MITRE ATT&CK, NIST, and CIS benchmarks to define detection, response, and investigation capabilities. Lead security investigations and digital forensics from suspicious traffic through full incident response, while designing, tuning, and scaling SIEM and logging pipelines to ensure signal integrity. Strengthen perimeter and authentication postures via WAF configuration and authorization tuning, then protect sensitive data through DLP controls aligned with actual data locations. Automate detection and response workflows using code and AI to reduce manual toil, and improve on-call rotations by defining alerting, escalation paths, and response SLAs. Reduce SecOps-attributed risk through compliance gap analysis and build dashboards providing leadership visibility into response times and coverage. Partner cross-functionally to translate threat models into actionable changes for engineers without security backgrounds, establishing the function end-to-end from strategy through code.
Required Qualifications
- 10+ years of experience in security operations, incident response, or a closely related discipline
- A strong development and engineering background
- Hands-on SOC and SIEM management experience
- Experience in scale-up environments
- A strong understanding of cloud architectures as we use AWS
- Demonstrated experience using AI and/or coding automation to get security controls built, implemented, and operating in practice
Desired Qualifications
- Fintech, payments, fraud, or trust & safety experience
- Exposure to highly regulated environments
- Backgrounds that tend to do well here: incident response, IR management, SOC engineering, security engineering, DevSecOps, red or blue team
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.