Lead Security Operations Engineer
Key details
- Compensation
- $70,000 - $105,000
Job Description
Salary: £70,000 - 105,000 per year
Requirements
- 10+ years of experience in security operations, incident response, or a closely related discipline.
- Proven track record of materialised risk reduction through monetary impact, incidents contained, and forensics that changed outcomes.
- Strong development and engineering background, with comfort writing automation rather than only specifying it.
- Hands-on SOC and SIEM management experience, including detection engineering and log pipeline design.
- Experience in scale-up environments, where capability was built rather than inherited.
- Strong understanding of cloud architectures, including AWS and part of the estate on GCP, and how infrastructure decisions shape detection and response.
- Demonstrated experience using AI and/or coding automation to get security controls built, implemented, and operating in practice.
- Fintech, payments, fraud, or trust & safety experience is an advantage, as is exposure to highly regulated environments.
- Backgrounds that tend to do well here include incident response, IR management, SOC engineering, security engineering, DevSecOps, red team, or blue team.
- Must be physically based in the country of choice with a valid right to work.
- Must be available to participate in an on-call rotation.
Responsibilities
- Build and own a structured SecOps roadmap grounded in frameworks such as MITRE ATT&CK, NIST, and CIS benchmarks.
- Lead security investigations and digital forensics, from suspicious traffic through to full incident response, and feed findings back into detection and prevention.
- Design, tune, and scale the SIEM and logging pipeline through standardized log ingestion across services.
- Strengthen perimeter and authentication posture, including WAF configuration, authorisation tuning, and monitoring for suspicious traffic.
- Protect sensitive data through DLP controls and ensure coverage matches where the data actually lives.
- Improve the on-call rotation, including alerting, escalation paths, and response SLAs.
- Automate detection and response workflows using code and AI to reduce manual toil and shorten time to resolution.
- Reduce SecOps-attributed risk identified through compliance gaps and collect evidence that demonstrates it.
- Build dashboards and reporting that give the team and leadership visibility into response times, coverage, and risk reduction.
- Work cross-functionally with engineers who do not have a security background, translating threat models into changes they can actually ship.
- Get deep into Pleos security landscape, detection coverage, logging estate, and cloud footprint to assess the biggest risks.
- Publish a SecOps roadmap, align it with Engineering, Risk & Compliance, and leadership, and start delivering against it.
- Stand up the on-call rotation and the associated alert response SLAs.
- Ship the first wave of detection and automation improvements and establish KPIs to show what changed.
Technologies
- AI
- AWS
- Cloud
- DevSecOps
- GCP
- Support
- Security
- WAF
- LESS
More
We at Pleo are changing spend management by building solutions that make managing money seamless, empowering, and effective for finance teams and employees. We are a driven, progressive, and kind team of 850+ people from over 100 nationalities, supporting 40,000+ customers. This Lead Security Operations Engineer role sits within our Cybersecurity team and reports to our VP of Fraud & Security, working closely with Fraud, DevSecOps, Engineering, and Risk & Compliance. We offer remote, hybrid, or in-person working in London, Copenhagen, Lisbon, or Madrid, provided you are physically based in the country of choice with a valid right to work, and we cannot offer visa sponsorship. Benefits include your own Pleo card, lunch on work days, comprehensive private healthcare depending on location, 25-28 days of holiday plus public holidays, hybrid and fully remote options, the option to buy 5 extra days of holiday, free mental health and well-being support through MyndUp, and paid parental leave. The role offers a large blast radius at a pre-IPO company, the chance to build a function rather than just maintain one, and room for growth into people leadership.
last updated 34 week of 2026
Company & context
Evidence is labeled so you can tell internal community data from public sources.
Range from 7 indexed roles at this employer: $70,000 - $105,000(mid ~87500)
Context reflects data collected at crawl time.
Trust-check this listing
Verify scam risk and ghost-job signals before you apply.
Related roles
Browse more remote Security Engineer jobs, or every remote job category.
Senior Application Security Manager
Analytics Engineer
Analytics Engineer
Source: DevITJobs • Last updated 1w ago