Lead Security Operations Engineer
Job description
About the role
The role of represents a pivotal opportunity to define and deliver the organization's SecOps roadmap from the ground up. You will own the end-to-end strategy, design, and execution of detection, response, and investigation capabilities that safeguard a fast-growing fintech serving over 40,000 customers. This position requires a hands-on leader who thrives on transforming complex security challenges into simple, scalable solutions while challenging existing paradigms respectfully. You will be instrumental in building the signal that protects our customers and our business, ensuring that security is proactive rather than reactive. The position is ideal for someone who takes immense pride in uncovering customer needs and turning them into robust technical controls. You will partner with teams across the organization, elevating the security maturity of engineers who may not have a dedicated security background. Ultimately, this role is for a driven individual who wants to build a security function from scratch and see the direct impact of their work on the company's success.
Key facts
What you'll do
- Build and own a structured SecOps roadmap grounded in well-known frameworks such as MITRE ATT&CK, NIST, and CIS benchmarks, ensuring alignment with business objectives.
- Lead security investigations and digital forensics, from suspicious traffic through to full incident response, and bring the findings back into how we detect and prevent future events.
- Design, tune, and scale our SIEM and logging pipeline through standardized log ingestion across services so signal isn't lost in the noise.
- Strengthen our perimeter and authentication posture, including WAF configuration, authorisation tuning, and monitoring for suspicious traffic.
- Protect sensitive data through DLP controls, and make sure the coverage matches where the data actually lives across our environment.
- Improve our on-call rotation for the team, defining the alerting, escalation paths, and response SLAs that make it work efficiently and effectively.
- Automate detection and response workflows, using code and AI to reduce manual toil and shorten time to resolution for critical alerts.
- Reduce SecOps-attributed risk identified through compliance gaps, and collect the evidence that demonstrates our adherence to regulatory and internal standards.
- Build dashboards and reporting that give the team and leadership real visibility into response times, coverage, and risk reduction trends.
- Work cross-functionally with engineers who don't have a security background, translating threat models into changes they can actually ship without friction.
Requirements
You will thrive in this role if you possess a decade of hands-on experience in security operations, incident response, or a closely related discipline, with a proven track record of materialised risk reduction demonstrated through monetary impact, incidents contained, and forensics that changed outcomes. You bring a strong development and engineering background, meaning you are comfortable writing the automation yourself rather than only specifying requirements to others. Your history includes hands-on SOC and SIEM management, with deep expertise in detection engineering and log pipeline design for complex environments. You have built capability in scale-up settings where security functions matured under your guidance rather than being inherited as a finished product. You possess a strong understanding of cloud architectures, particularly AWS, while also accounting for how our use of GCP influences infrastructure decisions, detection logic, and response playbooks. You have demonstrated experience using AI and coding automation to get security controls built, implemented, and operating reliably in production practice. Your background includes fintech, payments, fraud, or trust & safety experience, which is a real advantage in understanding the specific risks we face. You have worked in highly regulated environments where compliance and evidence collection are non-negotiable parts of the job. Your professional background tends to include incident response, IR management, SOC engineering, security engineering, DevSecOps, red team, or blue team disciplines. You are fluent in the languages and tools that allow you to operationalize security controls efficiently and measure their effectiveness.
Nice to have
The source description does not contain any explicitly stated preferred qualifications, certifications, or technologies beyond the core requirements, so there are no nice to have items to list based solely on the provided source material.
Practical notes
The engagement for this position is full-time, and the location is specified as the United Kingdom, which implies that the successful candidate must be eligible to work in that country. The role involves a significant blast radius with high-impact projects at a pre-IPO company, meaning the work will directly influence business outcomes and metrics. You should expect to engage with cross-functional teams and take ownership of defining the roadmap rather than maintaining an established function. The position is part of a growing cybersecurity team dedicated to protecting Pleo's customers and their money. There is no mention of specific working hours, travel requirements, visa sponsorship details, or application deadlines in the provided source, so these aspects are not defined within the scope of this job page.