Back to Jobs
Pleo
Development 1d ago

Lead Security Operations Engineer

Pleo
United KingdomUnited Kingdom
DenmarkDenmark
PortugalPortugal
SpainSpain
Full-time
Not Disclosed
Lead/Manager

Job Description

Key Skills Required

Master these to land this role

AWSSIEMDevSecOpsCybersecurityIncident Response

Want to know if you're a match for this job?

Calculate My Match Score

About the role

We're looking for a Lead Security Operations Engineer to join our Cybersecurity team at Pleo. In this role, you'll define and deliver the SecOps roadmap, building the detection, response, and investigation capability that protects a fast-growing fintech. If you're excited about owning a security operations function end to end, from framework-based strategy through to the code that makes it run, then this is the opportunity for you!

Who you'll be working with and reporting to

You'll report to our VP of Fraud & Security and work closely with Fraud, DevSecOps, Engineering, and Risk & Compliance. Our team is highly collaborative and dedicated to protecting Pleo's customers and their money. You'll also have the chance to partner with teams across the organisation and to bring less experienced security engineers up with you as the function matures.

What you'll be doing

As a Lead Security Operations Engineer, you will:

  • Build and own a structured SecOps roadmap grounded in well-known frameworks such as MITRE ATT&CK, NIST, and CIS benchmarks.
  • Lead security investigations and digital forensics, from suspicious traffic through to full incident response, and bring the findings back into how we detect and prevent.
  • Design, tune, and scale our SIEM and logging pipeline through standardized log ingestion across services so signal isn't lost in the noise.
  • Strengthen our perimeter and authentication posture, including WAF configuration, authorisation tuning, and monitoring for suspicious traffic.
  • Protect sensitive data through DLP controls, and make sure the coverage matches where the data actually lives.
  • Improve our on-call rotation for the team, defining the alerting, escalation paths, and response SLAs that make it work.
  • Automate detection and response workflows, using code and AI to reduce manual toil and shorten time to resolution.
  • Reduce SecOps-attributed risk identified through compliance gaps, and collect the evidence that demonstrates it.
  • Build dashboards and reporting that give the team and leadership real visibility into response times, coverage, and risk reduction.
  • Work cross-functionally with engineers who don't have a security background, translating threat models into changes they can actually ship.

What you bring

You'll thrive in this role if you have:

  • 10+ years of experience in security operations, incident response, or a closely related discipline, with a proven track record of materialised risk reduction through monetary impact, incidents contained, forensics that changed outcomes.
  • A strong development and engineering background. You are comfortable writing the automation, not just specifying it.
  • Hands-on SOC and SIEM management experience, including detection engineering and log pipeline design.
  • Experience in scale-up environments, where you've built capability rather than inherited a mature one.
  • A strong understanding of cloud architectures as we use AWS. With part of our estate on GCP and how infrastructure decisions shape detection and response.
  • Demonstrated experience using AI and/or coding automation to get security controls built, implemented, and operating in practice.
  • Fintech, payments, fraud, or trust & safety experience is a real advantage, as is exposure to highly regulated environments.
  • Backgrounds that tend to do well here: incident response, IR management, SOC engineering, security engineering, DevSecOps, red or blue team.

Why is this role a good fit for you

This role is a good fit for you if:

  • You want a large blast radius. We have high-impact projects where the outcome shows up in real business metrics, at a pre-IPO company.
  • You're energised by building a function rather than maintaining one, and you'd rather set the roadmap than be handed it.
  • You enjoy raising the bar around you, growing a team of specialists and lifting the people already here.
  • You're equally at home in a threat model discussion and in an editor writing the automation that acts on it.

This role is not a good fit for you if:

  • You need a well-groomed backlog and assigned tasks in order to do your best work.
  • You'd rather stay purely strategic than get hands-on with the tooling.
  • You're not up for participating in an on-call rotation.

How you'll develop in this role

In your first 6 months at Pleo, you'll:

  • Get deep into Pleo's security landscape and our detection coverage, our logging estate, our cloud footprint to form your own view of where the biggest risks sit.
  • Publish a SecOps roadmap mapped to MITRE, NIST, and CIS, agree with Engineering, Risk & Compliance, and leadership, and start delivering against it.
  • Stand up the on-call rotation and the alert response SLAs that go with it.
  • Ship your first wave of detection and automation improvements, and establish the KPIs that show what changed.

We're committed to helping you develop your career, whether that means taking on bigger projects, stepping into leadership, or acquiring new skills. There's genuine room here for the scope of this role to grow, including into people leadership.

How would you rate this job post?

See what other professionals think about this role.

banner

Pleo is a financial technology company that offers a range of payment and expense management solutions for businesses. The company's platform provides a seamless and integrated way for employees to make purchases, track expenses, and manage company spending. With a focus on innovation and user experience, Pleo aims to simplify financial management for businesses of all sizes. By leveraging cutting-edge technology and machine learning algorithms, Pleo provides real-time insights and analytics, enabling companies to make data-driven decisions and optimize their financial operations. The company's solutions are designed to be scalable, secure, and compliant with regulatory requirements, making it an attractive option for businesses looking to streamline their financial processes. With a strong commitment to customer satisfaction and a growing presence in the market, Pleo is poised to become a leading player in the financial technology industry.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More
Lead Security Operations Engineer at Pleo