Senior SecOps Specialist

Teya Solutions

Greater London

Hybrid

GBP 63,000 - 103,000

Full time

11 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Health insurance
25 days annual leave
Friday lunch in the office
High-end work equipment
Mental health support

Job summary

Teya is hiring for a full-time Security Engineering role based in London or Porto with a hybrid work mode. You will lead end-to-end investigations of complex security incidents, act as the L3 escalation point, and coordinate with Security, Engineering, IT, Cloud, Legal and Compliance during incidents.

You will maintain playbooks, drive post-incident reviews, and improve detection and automation across SIEM, EDR, and vulnerability tooling.

Qualifications

  • 7+ years in SOC, incident response, detection engineering, or security engineering.
  • Experience leading complex security incidents end-to-end.
  • Strong hands-on experience with SIEM, EDR, and security tooling.
  • Experience building and tuning detections and queries.
  • Experience with log onboarding, telemetry pipelines, and data quality issues.
  • Strong vulnerability management and remediation experience.
  • Solid understanding of attack techniques, cloud, endpoint, identity, and network security.
  • Hands-on scripting and automation experience with Python, PowerShell, Bash, or similar.
  • Experience with APIs, integrations, and automation workflows.
  • Familiarity with Git and engineering practices including testing, review, and deployment.
  • Experience using Jira or similar tools for operational delivery.
  • Strong communication and documentation skills.
  • Ability to work independently and make decisions under pressure.
  • Fintech or regulated industry experience is a nice-to-have.
  • AWS or cloud-native security experience is a nice-to-have.
  • Experience with tools like Exabeam, Splunk, CrowdStrike, or Okta is a nice-to-have.
  • SOAR or security automation experience is a nice-to-have.
  • Threat hunting, purple teaming, or detection-as-code experience is a nice-to-have.
  • CI/CD, IaC, or DevSecOps exposure is a nice-to-have.
  • REST APIs, OAuth, or secrets management experience is a nice-to-have.
  • Security certifications such as GCIA, GCIH, or CISSP are a nice-to-have.

Responsibilities

  • Lead end-to-end investigation and response of complex security incidents.
  • Act as the L3 escalation point for SOC analysts and our MSSP.
  • Coordinate across Security, Engineering, IT, Cloud, Legal, and Compliance during incidents.
  • Make clear, risk-based decisions under pressure with strong documentation.
  • Maintain playbooks, runbooks, and incident workflows.
  • Drive post-incident reviews and ensure improvements and follow-ups are completed.
  • Support incident metrics such as MTTD, MTTR, and recurrence.
  • Operate and improve SIEM, EDR, email security, case management, and vulnerability tools.
  • Monitor health, coverage, data quality, and integrations.
  • Troubleshoot ingestion, parsing, API, and configuration issues.
  • Build and maintain integrations between security tools and internal systems.
  • Manage upgrades, changes, access reviews, and documentation.
  • Apply engineering practices such as version control, testing, peer review, and rollback.
  • Reduce operational toil through automation and simplification.
  • Analyse and prioritise vulnerabilities based on risk and exploitability.
  • Work with Engineering and IT to drive remediation.
  • Track fixes, validate resolution, and escalation high-risk issues.
  • Improve vulnerability workflows and automation.
  • Identify recurring issues and recommend preventative controls.
  • Build, test, and maintain detection rules, queries, and correlation logic.
  • Manage the full detection lifecycle from build to retire.
  • Use version control and detection-as-code where possible.
  • Reduce false positives and improve detection quality and coverage.
  • Map detections to threat behaviours such as MITRE ATT&CK.
  • Validate detections through testing, incidents, and simulations.
  • Onboard and maintain log sources across cloud, identity, endpoint, network, and SaaS.
  • Ensure logs are complete, reliable, and usable for detection and investigation.
  • Troubleshoot ingestion, parsing, schema, and data quality issues.
  • Build validation and monitoring for telemetry pipelines.
  • Offboard unused sources safely with documented impact.
  • Improve telemetry coverage by working with engineering teams.
  • Monitor threats, vulnerabilities, and attacker techniques.
  • Translate intelligence into detections, investigations, and remediation actions.
  • Assess relevance to our environment and risk profile.
  • Share actionable insights with relevant teams.
  • Improve security posture using trends and intelligence.
  • Gather and utilise intelligence for Shadow AI use cases.
  • Partner with Engineering and Platform teams on security requirements.
  • Manage security work in Jira with clear scope and ownership.
  • Support security projects involving tooling, integrations, telemetry, and controls.
  • Contribute to technical design discussions.
  • Produce clear technical documentation and workflows.
  • Communicate effectively with technical and non-technical stakeholders.
  • Automate SOC and security operations workflows.
  • Build scripts, integrations, and event-driven automations using APIs and cloud services.
  • Apply secure engineering practices including testing, logging, secrets management, and error handling.
  • Use version control and peer review for automation and detection content.
  • Monitor and improve automation reliability.
  • Explore AI and automation opportunities to reduce manual effort.
  • Define and track operational and security metrics.

Skills

SOC expertise
Incident response
Detection engineering
Security tooling
Scripting
Python
PowerShell
Bash
Git
Jira
Communication
Independent decisions
Threat hunting

Tools

Splunk
Exabeam
CrowdStrike
Okta
Jira

Job description

Salary: £63,000 - 103,000 per year

Requirements:
  • 7+ years in SOC, incident response, detection engineering, or security engineering.
  • Experience leading complex security incidents end-to-end.
  • Strong hands-on experience with SIEM, EDR, and security tooling.
  • Experience building and tuning detections and queries.
  • Experience with log onboarding, telemetry pipelines, and data quality issues.
  • Strong vulnerability management and remediation experience.
  • Solid understanding of attack techniques, cloud, endpoint, identity, and network security.
  • Hands-on scripting and automation experience with Python, PowerShell, Bash, or similar.
  • Experience with APIs, integrations, and automation workflows.
  • Familiarity with Git and engineering practices including testing, review, and deployment.
  • Experience using Jira or similar tools for operational delivery.
  • Strong communication and documentation skills.
  • Ability to work independently and make decisions under pressure.
  • Fintech or regulated industry experience is a nice-to-have.
  • AWS or cloud-native security experience is a nice-to-have.
  • Experience with tools like Exabeam, Splunk, CrowdStrike, or Okta is a nice-to-have.
  • SOAR or security automation experience is a nice-to-have.
  • Threat hunting, purple teaming, or detection-as-code experience is a nice-to-have.
  • CI/CD, IaC, or DevSecOps exposure is a nice-to-have.
  • REST APIs, OAuth, or secrets management experience is a nice-to-have.
  • Security certifications such as GCIA, GCIH, or CISSP are a nice-to-have.
Responsibilities:
  • Lead end-to-end investigation and response of complex security incidents.
  • Act as the L3 escalation point for SOC analysts and our MSSP.
  • Coordinate across Security, Engineering, IT, Cloud, Legal, and Compliance during incidents.
  • Make clear, risk-based decisions under pressure with strong documentation.
  • Maintain playbooks, runbooks, and incident workflows.
  • Drive post-incident reviews and ensure improvements and follow-ups are completed.
  • Support incident metrics such as MTTD, MTTR, and recurrence.
  • Operate and improve SIEM, EDR, email security, case management, and vulnerability tools.
  • Monitor health, coverage, data quality, and integrations.
  • Troubleshoot ingestion, parsing, API, and configuration issues.
  • Build and maintain integrations between security tools and internal systems.
  • Manage upgrades, changes, access reviews, and documentation.
  • Apply engineering practices such as version control, testing, peer review, and rollback.
  • Reduce operational toil through automation and simplification.
  • Analyse and prioritise vulnerabilities based on risk and exploitability.
  • Work with Engineering and IT to drive remediation.
  • Track fixes, validate resolution, and escalation high-risk issues.
  • Improve vulnerability workflows and automation.
  • Identify recurring issues and recommend preventative controls.
  • Build, test, and maintain detection rules, queries, and correlation logic.
  • Manage the full detection lifecycle from build to retire.
  • Use version control and detection-as-code where possible.
  • Reduce false positives and improve detection quality and coverage.
  • Map detections to threat behaviours such as MITRE ATT&CK.
  • Validate detections through testing, incidents, and simulations.
  • Onboard and maintain log sources across cloud, identity, endpoint, network, and SaaS.
  • Ensure logs are complete, reliable, and usable for detection and investigation.
  • Troubleshoot ingestion, parsing, schema, and data quality issues.
  • Build validation and monitoring for telemetry pipelines.
  • Offboard unused sources safely with documented impact.
  • Improve telemetry coverage by working with engineering teams.
  • Monitor threats, vulnerabilities, and attacker techniques.
  • Translate intelligence into detections, investigations, and remediation actions.
  • Assess relevance to our environment and risk profile.
  • Share actionable insights with relevant teams.
  • Improve security posture using trends and intelligence.
  • Gather and utilise intelligence for Shadow AI use cases.
  • Partner with Engineering and Platform teams on security requirements.
  • Manage security work in Jira with clear scope and ownership.
  • Support security projects involving tooling, integrations, telemetry, and controls.
  • Contribute to technical design discussions.
  • Produce clear technical documentation and workflows.
  • Communicate effectively with technical and non-technical stakeholders.
  • Automate SOC and security operations workflows.
  • Build scripts, integrations, and event-driven automations using APIs and cloud services.
  • Apply secure engineering practices including testing, logging, secrets management, and error handling.
  • Use version control and peer review for automation and detection content.
  • Monitor and improve automation reliability.
  • Explore AI and automation opportunities to reduce manual effort.
  • Define and track operational and security metrics.
Technologies:
  • AI
  • API
  • AWS
  • Bash
  • CI/CD
  • Cloud
  • DevSecOps
  • Git
  • Support
  • JIRA
  • Network
  • OAuth
  • PowerShell
  • Python
  • REST
  • Security
  • Splunk
  • DevOps
More:

We are Teya, a financial platform built to help local businesses across Europe run with confidence. We support cafés, restaurants, salons, shops, and entrepreneurs with simple tools, thoughtful design, and real human support. We move fast, care about quality, and stay close to the detail. This is a full-time Engineering role based in London or Porto, with a hybrid work mode policy, flexible working hours, health insurance, physical and mental health support through our partnership with MyFitness, 25 days of annual leave plus bank holidays, Friday lunch in the office, high-end work equipment, and the opportunity to visit other Teya offices when travel is safe and appropriate. We are an equal opportunity employer committed to an inclusive environment where everyone can thrive.

last updated 36 week of 2026

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer
Senior Security Engineer

Teya • London

On-site
GBP 50,000 - 90,000
Flexible working hours
GymPass access to 1,500 gyms
Improved maternity and paternity leave
+6
Security Engineer - Security Operations
Security Engineer - Security Operations

Perk • Greater London

On-site
GBP 72,000 - 85,000
Equity options
Private medical insurance
Life insurance
+2
Senior SecOps Lead: Incident Response & Detection
Senior SecOps Lead: Incident Response & Detection

Teya Solutions • Greater London

Hybrid
GBP 63,000 - 103,000
Health insurance
25 days annual leave
Friday lunch in the office
+2
Lead Security Operations Center Analyst (f/m/d)
Lead Security Operations Center Analyst (f/m/d)

Thinkproject • Reading

Hybrid
GBP 65,000 - 85,000
Lunch & Learn Sessions
Hybrid working
Unlimited learning
Senior Security Engineer - Contract
Senior Security Engineer - Contract

United States Digital Space LLC • Greater London

On-site
GBP 70,000 - 110,000
Senior Cyber Security Engineer
Senior Cyber Security Engineer

The Financial Times • Greater London

Hybrid
GBP 62,000 - 88,000
Hybrid work model
Medical cover
Generous annual leave
Security Engineer II
Security Engineer II

Tesco Technology • Welwyn Garden City

On-site
GBP 50,000 - 70,000
Annual bonus scheme up to 20%
25 days holiday plus personal day
Private medical insurance
+2
Senior Security Engineer
Senior Security Engineer

Spendesk • Greater London

On-site
GBP 90,000 - 120,000
Product Manager - Customer Onboarding
Product Manager - Customer Onboarding

Teya • Greater London

On-site
GBP 75,000 - 110,000
Physical and mental health support
London or Porto offices
Private Health and Life Insurance
+5
Information Security Analyst
Information Security Analyst

Fuse Energy Supply • Greater London

On-site
GBP 63,000 - 103,000
Biannual bonus scheme
Fully expensed tech
Paid annual leave
+2