обновлено 10 дней назад
Staff Security Engineer (Security Operations)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Staff Security Engineer (Security Operations) (Google SecOps/Chronicle, AI): Commanding major security incidents and defining the incident response methodology for a WebOps platform with an accent on threat hunting, detection engineering, and AI-assisted automation. Focus on governing SIEM coverage, guiding ARES development, improving incident response programmes, and mentoring security engineers through complex investigations.
Location: United Kingdom
Company
provides a WebOps platform that helps developers, IT, and marketing teams develop, test, and release website changes faster and more reliably.
What you will do
- Command complex security incidents, including data breach scenarios, coordinated attacks, and platform-level events.
- Define and improve incident response methodology, including severity frameworks, escalation paths, playbooks, runbooks, on-call standards, and SLAs.
- Lead MITRE ATT&CK-aligned threat hunting across cloud, endpoint, and identity environments, converting findings into higher-fidelity detections.
- Set the automation direction for triage, enrichment, investigation, and response while contributing operator judgment to the AI-assisted ARES platform.
- Govern Google SecOps (Chronicle), including detection coverage, log source strategy, data quality, and cost.
- Mentor analysts and engineers, communicate operational risk to senior leadership, and support threat intelligence, resilience testing, audits, and red/purple team exercises.
Requirements
- 8+ years of information security experience, including substantial security operations experience and demonstrated command of major incidents.
- Deep knowledge of incident response methodology such as NIST 800-61 or SANS PICERL, with experience building or materially improving an incident response programme.
- Expertise in threat hunting, attacker tradecraft, MITRE ATT&CK, detection logic, and response procedures.
- Daily experience with AI assistants and LLM tooling, plus an engineering mindset with Python, Bash, APIs, and cloud-native environments.
- Experience operating an enterprise SIEM at governance level; Google SecOps/Chronicle is preferred, with Splunk, Sentinel, or Elastic also accepted.
- CISSP or equivalent security certification depth and excellent written and verbal communication skills.
Culture & Benefits
- Work environment built around trust, teamwork, passion, customers first, individuality, humour, and balance.
- Industry-competitive compensation and equity plan.
- 28 days of holiday, private medical and dental coverage, life and critical illness insurance, and a workplace pension scheme.
- Top-of-line equipment, wellness and reading allowance, and access to LinkedIn Learning.
- Team and company-wide events, activities, and an employee resource platform.
- Visa sponsorship is not available.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
7 дней назад
Senior Security Engineer, Security Incident Response Team (SIRT) - EMEA (Cybersecurity)
WRITER
5 дней назад
Security Engineer Detection and Response UK (AI Security)
5 часов назад
Security Analyst (AI/Cybersecurity)
5 дней назад
Security Analyst III - SOC
5 дней назад
Senior Security Engineer - SecOps
66 000 - 87 000GBP
3 дня назад