Lead Security Operations Engineer

Pleo
United Kingdom, Denmark, Portugal, Spain
Workplace: RemoteFull timeFunction: Administration & Executive AssistanceExperience: 10+ yearsSkills: ["Communication","Collaboration","Problem-solving","Stakeholder management"]

Define and deliver the SecOps roadmap for a fast-growing fintech, building detection, response, and investigation capabilities end to end. Lead investigations and forensics, improve SIEM and centralized logging, and strengthen perimeter/authentication posture with WAF, tuning, and monitoring. Protect sensitive data with DLP, automate detection/response workflows with code and AI, improve on-call SLAs, and report on coverage, response times, and risk reduction.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Pleo
Pleo
11 hours ago

Lead Security Operations Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 9 hours agoStatus: Live

Job Summary

Define and deliver the SecOps roadmap for a fast-growing fintech, building detection, response, and investigation capabilities end to end. Lead investigations and forensics, improve SIEM and centralized logging, and strengthen perimeter/authentication posture with WAF, tuning, and monitoring. Protect sensitive data with DLP, automate detection/response workflows with code and AI, improve on-call SLAs, and report on coverage, response times, and risk reduction.
Location: United Kingdom, Denmark, Portugal, Spain
Workplace: Remote
Employment Type: Full time
Job Function: Administration & Executive Assistance
Seniority: Mid level

Key Responsibilities

  • •Build and own a structured SecOps roadmap using frameworks such as MITRE ATT&CK, NIST, and CIS benchmarks.
  • •Lead security investigations and digital forensics through full incident response, feeding findings back into detection and prevention.
  • •Design, tune, and scale SIEM and centralized logging with standardized log ingestion across services.
  • •Strengthen perimeter and authentication posture (including WAF configuration and authorization tuning) and monitor for suspicious traffic.
  • •Automate detection and response workflows, improve on-call rotation with SLAs, and provide dashboards and reporting on response times, coverage, and risk reduction.

Pay and Benefits

Perks:Health InsuranceMeal AllowancePaid ParentalRemote WorkHybrid Work

Key Requirements

  • •10+ years in security operations, incident response, or a closely related discipline with demonstrated risk reduction impact.
  • •Strong development/engineering background with comfort writing automation, not only specifying it.
  • •Hands-on SOC and SIEM management experience, including detection engineering and log pipeline design.
  • •Experience building capability in scale-up environments (not only inheriting mature operations).
  • •Strong understanding of cloud architectures, including AWS and exposure to GCP.
Experience:10+ yearsFintechPaymentsFraudTrust & safety
Skills:CommunicationCollaborationProblem-solvingStakeholder management
Languages:English
Tech Stack:MITRE ATT&CKNISTCIS benchmarksSIEMLogging pipelineAWSGCPWAFDLPAIAutomation

Eligibility

Work Authorization:Authorization required. Sponsorship not provided.

Company Brief

Pleo
Provides spend management software that helps businesses issue company cards, control expenses, automate reimbursements, and track team spending in one platform. Aims to simplify financial workflows for modern companies.
Industry: Fintech Infrastructure
Company Size: Large (251 to 1,000 employees)
Growth: Scaleup
Headquarters: Copenhagen, Denmark
Founded: 2015
WebsiteLinkedIn