About the Role
As our Senior SecOps Engineer, you will play a critical part in maintaining and evolving the security of our product, business tools, people, and organisation. This role offers the opportunity to have a significant long-standing impact by improving our technical security strategy, leading to greater success for our business and customers. Your focus will evolve from enhancing operational security capabilities to security engineering and architecture, designing scalable security services, improving our security platform, and embedding secure-by-design principles.
Responsibilities
- Manage, build, and mature our Security Operations capability.
- Own and continuously improve security monitoring, detection, and incident response capabilities across cloud, endpoint, and SaaS environments.
- Build, tune, and maintain high-quality detections to reduce alert fatigue and increase confidence in threat identification.
- Continuously improve vulnerability management through effective scanning, risk-based prioritization, remediation, and tracking.
- Improve cloud security posture across AWS and GCP through strong identity management, telemetry, network security, encryption, and continuous posture assessment.
- Develop and automate operational processes, playbooks, and workflows for efficiency and scalability.
- Support audit and compliance activities by ensuring operational controls are implemented, measurable, and effective.
- Design and engineer scalable security capabilities to improve visibility, detection, resilience, and operational efficiency.
- Architect and evolve the security telemetry and detection platform, transforming data into actionable security intelligence.
- Design security services, standards, and reusable capabilities for consistent adoption across engineering teams.
- Lead technical security initiatives to improve security architecture maturity and reduce long-term organizational risk.
- Partner closely with engineering teams to embed secure-by-design principles into systems and platforms.
- Evaluate emerging security technologies and identify opportunities to improve the overall security architecture through adoption and automation.
- Help shape the long-term technical security roadmap alongside Engineering and Technology leadership.
- Secure and govern the organization's use of AI technologies, reviewing new tooling, assessing risk, and contributing to practical security guardrails.
- Mentor colleagues, provide technical leadership, and act as a trusted escalation point during security incidents.
- Manage a varied portfolio of operational work, strategic improvements, and technical projects, balancing priorities.
- Contribute to improving the resilience and security of products and services in a growing scale-up environment.
Requirements
- 5+ years of experience in Security Operations, Security Engineering, or Incident Response, ideally within a customer-focused SaaS organization.
- Strong hands-on experience securing cloud environments (AWS and/or GCP).
- Deep experience with security monitoring, SIEM platforms, EDR, detection engineering, alert triage, and incident response.
- Experience building or improving operational security capabilities rather than simply operating existing tooling.
- Experience with security tooling including SIEM, EDR, DLP, MDM, and cloud security platforms.
- Experience automating security processes using scripting or software engineering skills (Python, Go, TypeScript/JavaScript, Bash, or similar).
- Strong understanding of attacker techniques (MITRE ATT&CK) and how to translate them into effective detections.
- Experience with vulnerability management and security telemetry.
- Understanding of modern AI tooling, AI security risks, and governance considerations.
- Good understanding of networking, distributed systems, and cloud architectures.
- An interest in security architecture and building long-term security capabilities.
- Excellent communication skills, able to produce clear incident reports, technical documentation, and stakeholder updates.
- Pragmatic problem-solving skills, balancing operational needs with long-term improvements.
- Comfortable working through ambiguity and making sound technical decisions.
- Curiosity and a desire to continually learn and improve both operational and engineering practices.
- Enjoyment in building systems and capabilities that scale.
- Collaborative and approachable, working as part of a team.
- Ability to balance short-term operational priorities with medium and long-term engineering and architectural outcomes.
Skills
- Security Operations
- Security Engineering
- Incident Response
- Cloud Security (AWS, GCP)
- Security Monitoring
- SIEM Platforms
- EDR
- Detection Engineering
- Alert Triage
- Vulnerability Management
- Security Telemetry
- AI Security
- Networking
- Distributed Systems
- Cloud Architectures
- Security Architecture
- Python
- Go
- TypeScript
- JavaScript
- Bash
- MITRE ATT&CK
Location
- Hybrid
Work Type
- Hybrid
Experience Level
- 5+ years
Salary/Compensations
- £90,000—£100,000 GBP
Benefits
- Competitive base salary
- Generous EMI equity package
- Private pension
- 28 days annual leave + bank holidays
- Additional 30 days of unpaid leave per year
- Ad-hoc companywide time off over the festive period
- Private healthcare with AXA Insurance (including enhanced mental wellbeing coverage)
- Hybrid working policy (2-3 days in office)
- Enhanced family (parental) leave (12 weeks paid)
- 5 days Caretaker's leave
- Enhanced occupational sick pay
- £500 WFH budget
- Learning resources and books for personal development
- Regular socials
About the Company
- Risk Ledger is developing a network of connected organisations to defend against cybersecurity attacks in the supply chain.
- Organisations rely on Risk Ledger to establish trust by sharing security maturity and visualizing supply chain risks.
- Trusted by customers like ASOS, British Airways, BAE Systems, and the NHS.
- The team is built on respect, shared values, and a mission to empower individuals through continuous learning, curiosity, ambition, humility, and honesty.
- Risk Ledger aims high to find the best solutions and always puts users first.
