Senior SecOps Engineer
OtherEngineer
1 views0 saves0 applied
Quick Summary
Requirements Summary
5+ years in security operations or security engineering in financial services or another environment with formal incident-reporting obligations (DORA,
Technical Tools
OtherEngineer
We are looking for a Lead SecOps Engineer to design and build security operations for a regulated payments group: the SIEM, the vulnerability management programme, and the security incident process. You will own the technical direction of the detection and response stack, and operate with a high degree of independence.
- Location: Limassol, Cyprus or Remote from Poland or Portugal
- Reporting to: Head of Information Security
- Design, build and operate our SIEM from the ground up — architecture, deployment, tuning and run
- Establish attack-surface monitoring: continuous discovery and review of what the group exposes to the internet
- Build AI-assisted triage and enrichment into the pipeline from the start: agent-based alert handling, correlation summaries, draft incident timelines
- Stand up the vulnerability management programme: deployment, asset coverage, risk-based prioritization, remediation SLAs and reporting
- Implement process and procedures to ensure an effective vulnerability lifecycle.
- Operate and continuously improve the security incident process end to end: detection, classification, response, post-incident review
- Develop and maintain runbooks, playbooks and event handlers — and automate them wherever they repeat
- Harden and monitor our AWS estate: GuardDuty, Security Hub and native findings triaged, deduplicated and driven to remediation
- Drive security hardening across our infrastructure and runtime security
- Automate routine security operations aggressively — scripting, APIs, infrastructure-as-code and AI agents are all fair game
- Run proof-of-concepts, evaluate tooling and shape the technical roadmap of the security stack
- Provide security engineering consultancy to Engineering, IT and DevOps teams
Requirements
~1 min read- 5+ years in security operations or security engineering in financial services or another environment with formal incident-reporting obligations (DORA, PCI DSS)
- Strong hands-on experience with SIEM platforms (Elastic/OpenSearch, Wazuh, Splunk or similar) and log pipeline engineering
- Solid AWS security knowledge: GuardDuty, Security Hub, IAM, VPC-level controls and cloud-native logging, hardening
- Practical experience running vulnerability management: scanners, prioritisation, remediation tracking
- Strong IaaC skills
- Genuine enthusiasm for AI-assisted security operations — using LLMs and agents to triage, enrich, summarise and automate is core to how this role works.
- The independence to own a domain end to end: prioritise, decide, deliver and explain
Nice to Have
~1 min read- Kubernetes security hands-on: admission controllers, runtime detection (Falco or similar), cluster hardening
- Detection-as-code practices (Sigma, version-controlled rules, CI for detections)
- Certifications such as CCSP, CISSP, OSCP or equivalent
- Step 1 – Thinking in Action (40 minutes) Your first conversation will be with our Talent Acquisition team. We'll explore your background, career journey, motivations, and overall fit for the role. As part of this discussion, you'll also complete a short technical screening that will be reviewed by our engineering team. This stage helps us understand both your experience and how you approach technical challenges.
- Step 2 – Hiring Manager interview (60-minutes) you will meet the hiring manager Head of Information Security, to explore your skills, achievements, and alignment with the role.
- Step 3 – Final Interview (45 minutes) The final stage is a group interview with senior members of our Technology squad, which may include the CTO, CPO and Head of Security. Together, we'll discuss team fit, collaboration style, expectations from both sides, and any remaining questions about the role, team, or technology domain. This is also an opportunity for you to learn more about our culture and ways of working.
What We Offer
~2 min read✓Future-Proof Your Finances: Once you’ve passed probation, we’ll kickstart your Provident Fund to secure your future.
✓Grow with Us: Annual Learning Budget for professional development (eligible after probation)—because your growth is our growth.
✓Wolt Your Way Through Lunch: €150 monthly Wolt allowance to keep you fueled and happy.
✓Stay Active Your Way: Enjoy a SportsBenefits membership giving you access to a wide variety of gyms and sports facilities to support your active lifestyle.
✓Drive in Style: After one year with us, you may be eligible for a company car—performance and availability permitting.
✓Park with Ease: Complimentary parking space just steps from the office, so your commute is as smooth as your workday.
✓Max Out Your Downtime: 25 days of vacation + public holidays + 10 days of sick leave.
✓Shop & Save: Exclusive local discount card + tickets for exciting events like Beonix, basketball games, and more.
✓Speak Like a Local: Join free Greek language classes, twice a week, open to all team members.
✓Celebrate Together: We bring colleagues from all offices together for unforgettable company celebrations.
✓Global Collaboration & Events: Opportunities to participate in international company events and initiatives, connecting with colleagues from all regions and contributing to a truly global community
Location & Eligibility
Where is the job
Lisbon, Portugal
On-site at the office
Listing Details
- Posted
- August 14, 2026
- First seen
- September 30, 2026
- Last seen
- September 30, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 22%
- Scored at
- September 30, 2026
Signal breakdown
freshnesssource trustcontent trustemployer trust
External application
Newsletter
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
A
B
C
D
No spam. Unsubscribe at any time.