Lead Security Operations Engineer

Jobtailor

Greater London

On-site

GBP 120,000 - 170,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor in the United Kingdom seeks a senior Security Operations lead to shape and execute the SecOps roadmap, covering detection, response, and investigations. You will build structured plans aligned with MITRE ATT&CK, NIST, and CIS benchmarks, while guiding forensics and incident response activities.

The role requires hands-on SOC/SIEM management, cloud security expertise (AWS/GCP), and a background in automation and threat modeling.

Qualifications

  • 10+ years of experience in security operations, incident response, or a closely related discipline.
  • Hands-on SOC and SIEM management experience.
  • Strong development and engineering background, including writing automation.
  • Experience in detection engineering and log pipeline design.
  • Willingness to participate in an on-call rotation.
  • Must be based in the United Kingdom with valid right to work.

Responsibilities

  • Define and deliver SecOps roadmap for detection, response, and investigation capabilities.
  • Build a structured roadmap based on MITRE ATT&CK, NIST, and CIS benchmarks.
  • Lead security investigations and digital forensics through incident response.
  • Design, tune, and scale SIEM and standardized logging pipelines.
  • Strengthen perimeter and authentication security through WAF config, auth tuning, and monitoring.
  • Automate detection and response workflows using code and AI.

Skills

Security Operations Management
Incident Response
Detection Engineering
SIEM Management
Cloud Security
Automation Development
Digital Forensics
Risk Reduction
Threat Modeling
Compliance Risk Management
Leadership
Mentoring

Education

Tools

SIEM
MITRE ATT&CK
NIST
CIS Benchmarks
AI Automation
AWS
GCP
WAF
DLP

Job description

  • Define and deliver Pleo's SecOps roadmap for detection, response, and investigation capabilities
  • Build a structured roadmap based on MITRE ATT&CK, NIST, and CIS benchmarks
  • Lead security investigations and digital forensics through incident response
  • Design, tune, and scale SIEM and standardized logging pipelines
  • Strengthen perimeter and authentication security through WAF configuration, authorization tuning, and suspicious-traffic monitoring
  • Implement DLP controls aligned with sensitive-data locations
  • Improve the on-call rotation, alerting, escalation paths, and response SLAs
  • Automate detection and response workflows using code and AI
  • Reduce SecOps-attributed compliance risk and collect supporting evidence
  • Build dashboards and reporting for response times, coverage, and risk reduction
  • Translate threat models into shippable engineering changes
  • Partner with Fraud, DevSecOps, Engineering, and Risk & Compliance
  • Mentor less experienced security engineers and help mature the security operations function
  • In the first six months, assess the security landscape, publish and begin delivering the roadmap, establish on-call SLAs, ship detection and automation improvements, and define KPIs
Requirements
  • 10+ years of experience in security operations, incident response, or a closely related discipline
  • Proven materialized risk reduction through monetary impact, incidents contained, or forensics that changed outcomes
  • Strong development and engineering background, including writing automation
  • Hands-on SOC and SIEM management experience
  • Experience in detection engineering and log pipeline design
  • Experience building security capability in scale-up environments
  • Strong understanding of cloud architectures, especially AWS, with exposure to GCP
  • Demonstrated use of AI and/or coding automation to implement and operate security controls
  • Fintech, payments, fraud, or trust and safety experience is advantageous
  • Exposure to highly regulated environments is advantageous
  • Experience in incident response, IR management, SOC engineering, security engineering, DevSecOps, red team, or blue team
  • Willingness to participate in an on-call rotation
  • Must be physically based in the chosen country with valid right to work
  • Visa sponsorship is unavailable for the listed locations
  • Application must be submitted in English
Core Competencies

Demonstrates extensive experience in security operations, incident response, and risk reduction, with a strong focus on automation and cloud security. Capable of leading security investigations, designing detection capabilities, and mentoring security teams in a fast-paced environment.

Highest-signal resume keywords
  • Security Operations Management
  • Incident Response
  • Detection Engineering
  • SIEM Management
  • Cloud Security (AWS, GCP)
ATS Optimization Keywords
Hard Skills
  • Automation Development
  • Digital Forensics
  • Risk Reduction
  • Log Pipeline Design
  • DLP Implementation
  • WAF Configuration
  • Incident Response Management
  • Security Capability Building
  • Threat Modeling
  • Compliance Risk Management
Soft Skills
  • Mentoring
  • Collaboration
  • Leadership
Industry Keywords
  • Fintech
  • Payments
  • Fraud
  • Trust & Safety
  • Regulated Environments
Tools & Technologies
  • SIEM
  • MITRE ATT&CK
  • NIST
  • CIS Benchmarks
  • AI Automation
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Detection and Response Engineer
Senior Detection and Response Engineer

Jobtailor • Cambridge

On-site
GBP 65,000 - 95,000
Head of Security Operations
Head of Security Operations

Jobtailor • Greater London

On-site
GBP 70,000 - 110,000
Senior Operational Security Engineer
Senior Operational Security Engineer

Crown Agents Bank Ltd. • Greater London

On-site
GBP 70,000 - 90,000
Head of Security Operations Technology · London, Dubai · Hybrid
Head of Security Operations Technology · London, Dubai · Hybrid

Sokin • Greater London

Hybrid
GBP 120,000 - 180,000
L3 SOC Analyst
L3 SOC Analyst

Saviynt • United Kingdom

On-site
GBP 60,000 - 80,000
Head of Security Operations
Head of Security Operations

Sokin • Harrow

On-site
GBP 120,000 - 170,000
Data Security Engineer
Data Security Engineer

Jobtailor • Greater London

On-site
GBP 70,000 - 110,000
Senior Security Engineer
Senior Security Engineer

United States Digital Space LLC • Greater London

Hybrid
GBP 100,000 - 150,000
AWS Security & Cloud Platform Consultant
AWS Security & Cloud Platform Consultant

Kryptos Technologies limited • Greater London

On-site
GBP 111,000 - 221,000
Security Design Consultant
Security Design Consultant

Jobtailor • Leeds

On-site
GBP 75,000 - 110,000