Remote job
Security Operation Center Engineer
Job details
About this role
Role overview Two SOC Engineer openings are available to help build a brand-new Security Operations Centre inside a fast-scaling, regulated payments environment. The role sits embedded with the DevOps team for day-to-day collaboration yet reports outside that team, giving the holder independent oversight of cloud and corporate IT security controls. It suits someone who wants to shape detection, monitoring and incident response practices from the ground up rather than inheriting an existing function.
Responsibilities - Monitor, triage and investigate security alerts spanning Google Cloud Platform, Google Workspace and other cloud services in use across the business. - Design, build and tune detection rules, dashboards and alerting that give stakeholders clear, real-time visibility of the security posture. - Run daily, monthly and quarterly security checks, including log reviews, access recertifications, vulnerability scans, configuration drift analysis and segmentation testing. - Produce audit-ready evidence for PCI-related compliance programmes and support external assessments and audits. - Lead first response when a security incident occurs, containing threats, preserving evidence and driving closure of remediation actions. - Coordinate penetration tests and red team exercises, then translate findings into stronger detection coverage. - Partner with platform and corporate IT teams to confirm controls remain in place, effective and not bypassed. - Contribute to SOC tooling choices, runbooks, automation and KPIs as the function matures, and take part in an out-of-hours on-call rota.
Requirements - Hands-on experience in a SOC, security engineering or incident response role. - Strong knowledge of Google Cloud Platform security, including IAM, audit logging, Security Command Center and VPC, alongside Google Workspace administration and security. - Practical experience with SIEM platforms, ideally Google SecOps, including writing and tuning detection queries. - Working knowledge of PCI DSS and a track record of producing audit evidence in a regulated environment. - Understanding of cloud architecture, networking, Linux and containerisation concepts. - Organised, analytical problem-solving mindset with the communication skills to challenge engineers constructively and explain risk to non-technical colleagues.
Nice to have - Familiarity with PCI P2PE, PIN or PTS, payment HSMs or key management. - Scripting ability in Python, Go or Bash and Infrastructure as Code with Terraform. - Experience with, or strong interest in, threat hunting, penetration testing and red or purple team exercises.
Benefits and work setup - Competitive base salary plus a discretionary bonus tied to company performance. - 25 days of annual leave plus UK bank holidays. - Dedicated monthly well-being days to support mental health and work-life balance. - Company pension plan. - Fully remote working with a focus on flexibility. - Scope for high-impact growth within an international scale-up operating in the payments sector.