Назад
Company hidden
11 часов назад

Head of Security Operations (Fintech)

Формат работы
hybrid
Тип работы
fulltime
Грейд
head
Английский
b2
Страна
UK/UAE
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Head of Security Operations (Fintech): Building and scaling security operations for a global payments platform with an accent on detection strategy, incident response, vulnerability management, and identity governance. Focus on leading L3 investigations and forensics, engineering Microsoft Sentinel and SOAR capabilities, managing MSSP quality, and coordinating regulatory incident reporting.

Location: Hybrid in London or Dubai. Candidates must have the right to work in the jurisdiction where they work. The role may require occasional work outside normal hours.

Company

hirify.global provides B2B financial services for global payments, foreign exchange, treasury management, and finance reconciliations.

What you will do

  • Define and maintain the security detection strategy using MITRE ATT&CK, threat intelligence, and real incident learnings.
  • Set quality standards for Microsoft Sentinel content, including detection rules, analytics, workbooks, Logic Apps playbooks, and detection-as-code practices.
  • Lead L3 incident investigations and digital forensics across cloud and endpoint environments, including containment, eradication, and root-cause analysis.
  • Own incident management with the CISO, including major incident declarations, executive and board notifications, and regulatory reporting coordination.
  • Run vulnerability management and identity governance programs covering risk prioritization, remediation, privileged access, and joiner/mover/leaver assurance.
  • Manage the MSSP relationship, security operations metrics, SOC tooling, budget discussions, and the security operations team.

Requirements

  • Deep Microsoft Sentinel experience with strong KQL skills and the ability to author and review detection rules, workbooks, and playbooks.
  • Hands-on incident response and digital forensics experience across cloud and endpoint environments.
  • Experience with major incident management, executive communication, and GDPR, DORA, or equivalent regulatory timelines.
  • Applied MITRE ATT&CK knowledge, SIEM data-source onboarding, vulnerability management, and identity governance.
  • Experience managing an MSSP or outsourced SOC, including SLAs, scope negotiations, and quality assurance.
  • Experience with AWS CloudTrail, Azure Monitor, GCP audit logs, tabletop exercises, and clear incident reporting for non-technical audiences.

Nice to have

  • People management or mentoring experience in a SOC or detection engineering team.
  • Experience with Defender XDR, Wiz or equivalent CSPM integrations, and formal threat intelligence platforms.
  • Fintech, payments, or regulated-environment experience.
  • Python or PowerShell automation skills.
  • SC-200, AZ-500, GCIA, GCIH, GCFE, GCFA, or equivalent applied experience.

Culture & Benefits

  • Direct access to the CISO and ownership of the security operations function from day one.
  • Authority to shape the operating model between the outsourced SOC and in-house engineering.
  • Opportunity to build detection strategy, incident response, vulnerability management, and identity governance as one function.
  • Work in a rapidly expanding global payments environment serving clients across multiple industries.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →