Skip to main content
Pleo

Lead Security Operations Engineer

RemoteUnited Kingdom only
Published
Role
Security
Experience
Lead
Employment
Full-time
Company size
Mid-size
Salary not disclosed
Check eligibility

Open to GB only. Set where you work from to check your eligibility.

No BS summary

Lead SecOps engineer with 10+ years in security operations, incident response, or related work. Needs hands-on SOC/SIEM, detection engineering, log pipeline design, cloud security with AWS/GCP, and coding/automation. Must be physically based in the listed hiring country with valid right to work; no visa sponsorship.

Core skills

SIEMDetection EngineeringSecurity Automation

Required skills

MITRE ATT&CKNISTCIS benchmarksAWSGCPAIDLPWAF

Required languages

English

What you'll do

  • Build and own a structured SecOps roadmap grounded in well-known frameworks such as MITRE ATT&CK, NIST, and CIS benchmarks.
  • Lead security investigations and digital forensics, from suspicious traffic through to full incident response, and bring the findings back into how we detect and prevent.
  • Design, tune, and scale our SIEM and logging pipeline through standardized log ingestion across services so signal isn't lost in the noise.
  • Strengthen our perimeter and authentication posture, including WAF configuration, authorisation tuning, and monitoring for suspicious traffic.
  • Protect sensitive data through DLP controls, and make sure the coverage matches where the data actually lives.
  • Improve our on-call rotation for the team, defining the alerting, escalation paths, and response SLAs that make it work.
  • Automate detection and response workflows, using code and AI to reduce manual toil and shorten time to resolution.
  • Reduce SecOps-attributed risk identified through compliance gaps, and collect the evidence that demonstrates it.
  • Build dashboards and reporting that give the team and leadership real visibility into response times, coverage, and risk reduction.
  • Work cross-functionally with engineers who don't have a security background, translating threat models into changes they can actually ship.
  • Get deep into Pleo's security landscape and our detection coverage, our logging estate, our cloud footprint to form your own view of where the biggest risks sit.
  • Publish a SecOps roadmap mapped to MITRE, NIST, and CIS, agree with Engineering, Risk & Compliance, and leadership, and start delivering against it.
  • Stand up the on-call rotation and the alert response SLAs that go with it.
  • Ship your first wave of detection and automation improvements, and establish the KPIs that show what changed.

What they require

  • 10+ years of experience in security operations, incident response, or a closely related discipline, with a proven track record of materialised risk reduction through monetary impact, incidents contained, forensics that changed outcomes.
  • A strong development and engineering background. You are comfortable writing the automation, not just specifying it.
  • Hands-on SOC and SIEM management experience, including detection engineering and log pipeline design.
  • Experience in scale-up environments, where you've built capability rather than inherited a mature one.
  • A strong understanding of cloud architectures as we use AWS. With part of our estate on GCP and how infrastructure decisions shape detection and response.
  • Demonstrated experience using AI and/or coding automation to get security controls built, implemented, and operating in practice.
  • Fintech, payments, fraud, or trust & safety experience is a real advantage, as is exposure to highly regulated environments.
  • Backgrounds that tend to do well here: incident response, IR management, SOC engineering, security engineering, DevSecOps, red or blue team.
  • You want a large blast radius. We have high-impact projects where the outcome shows up in real business metrics, at a pre-IPO company.
  • You're energised by building a function rather than maintaining one, and you'd rather set the roadmap than be handed it.
  • You enjoy raising the bar around you, growing a team of specialists and lifting the people already here.
  • You're equally at home in a threat model discussion and in an editor writing the automation that acts on it.
  • You need a well-groomed backlog and assigned tasks in order to do your best work.
  • You'd rather stay purely strategic than get hands-on with the tooling.
  • You're not up for participating in an on-call rotation.
  • You will need to be physically based in the country of your choice with a valid right to work.
  • We are unable to offer visa sponsorship for this role in any of the listed locations.
  • Since it's our company language, please submit your application in English.

Benefits

  • Your own Pleo card (no more out-of-pocket spending!)
  • Lunch is on us for your work days - enjoy catered meals or receive a lunch allowance based on your local office
  • Comprehensive private healthcare - depending on your location, coverage options include Vitality, Alan or Médis
  • We offer 25-28 days of holiday (depending on your location) + public holidays
  • For our Team, we offer both hybrid and fully remote working options
  • Option to purchase 5 additional days of holiday through a salary sacrifice
  • We use MyndUp to give our employees access to free mental health and well-being support with great success so far
  • Paid parental leave - we want to make sure that we're supportive of families and help you feel that you don't have to compromise your family due to work
  • We're committed to helping you develop your career, whether that means taking on bigger projects, stepping into leadership, or acquiring new skills.
  • There's genuine room here for the scope of this role to grow, including into people leadership.

Pleo builds spend solutions that make managing money seamless for finance teams and employees.

🇬🇧 United KingdomFintechMid-size

Details

Visa sponsorshipNo
Salary not disclosed