Senior Security Operations Engineer
About us
Risk Ledger is developing a network of connected organisations, all working together to defend against cybersecurity attacks in the supply chain.
Organisations rely on us to establish trust, through sharing their security maturity and visualising the risks posed by their supply chain ecosystem. And we’re already trusted by customers like ASOS, British Airways, BAE Systems and the NHS.
We are putting together an amazing and talented team from a diverse set of backgrounds and skillsets to drive us towards our vision. Risk Ledger is built on the respect we have for one another and our users, united by our shared values and mission.
Every one of us is still learning: it’s how we grow as individuals. We’re curious. We’re ambitious. And we’re humble and honest. At Risk Ledger, we aim high to find the best solutions we can and always put our users first.
The team:
You’ll join the Director of Information Security supporting and collaborating with all parts of the business to deliver a secure environment enabling impactful outcomes for Risk Ledger and our customers.
This role:
As our Senior SecOps Engineer you’ll be playing a critical part in maintaining and evolving the security of our product, business tools, people, and organisation.
This is an opportunity to have a huge long-standing impact through improving our technical security strategy, which will lead to even greater success for our business and our customers.
In the short to medium term, your focus will be on improving operational security capability - enhancing detection and response, incident management, vulnerability management and cloud security operations. As these capabilities mature, you’ll increasingly focus on security engineering and architecture; designing scalable security services, improving our security platform and embedding secure-by-design principles across the organisation.
From day one, you'll shape opportunities to empower our team by maintaining and improving the security of our tools and working practices for peak performance, all while safeguarding the confidentiality of our customers' data. Success hinges on collaboration, as you forge strong, trusted relationships across teams.
In this role you will:
Manage, build and mature our Security Operations capability (short to medium term)
- Own and continuously improve security monitoring, detection and incident response capabilities across our cloud, endpoint and SaaS environment.
- Build, tune, and maintain high-quality detections, reducing alert fatigue while increasing confidence that meaningful threats are identified quickly.
- Continuously improve vulnerability management through effective scanning, risk-based prioritisation, remediation and tracking.
- Improve our cloud security posture across AWS and GCP through strong identity management, telemetry, network security, encryption and continuous posture assessment.
- Develop and automate operational processes, playbooks and workflows that improve consistency and allow the team to scale efficiently.
- Support audit and compliance activities by ensuring operational controls are implemented, measurable and operating effectively.
Evolve our Security Engineering capability (medium to long term)
- Design and engineer scalable security capabilities that improve visibility, detection, resilience and operational efficiency across the organisation.
- Architect and evolve our security telemetry and detection platform, transforming raw data into actionable security intelligence.
- Design security services, standards and reusable capabilities that can be adopted consistently across engineering teams.
- Lead technical security initiatives that improve the maturity of our security architecture and reduce long-term organisational risk.
- Partner closely with engineering teams to embed secure-by-design principles into systems and platforms.
- Evaluate emerging security technologies and identify opportunities to improve our overall security architecture through thoughtful adoption and automation.
- Help shape the long-term technical security roadmap alongside Engineering and Technology leadership.
Across both areas
- Help secure and govern the organisation's use of AI technologies, reviewing new tooling, assessing risk and contributing to practical security guardrails.
- Mentor colleagues, provide technical leadership and act as a trusted escalation point during security incidents.
- Manage a varied portfolio of operational work, strategic improvements and technical projects, balancing immediate priorities with long-term objectives.
- Contribute wherever needed in a growing scale-up environment, helping improve the resilience and security of our products and services.
You’ll have:
- 5+ years' experience in Security Operations, Security Engineering or Incident Response, ideally within a customer-focused SaaS organisation.
- Strong hands-on experience securing cloud environments (AWS and/or GCP).
- Deep experience with security monitoring, SIEM platforms, EDR, detection engineering, alert triage and incident response.
- Experience building or improving operational security capabilities rather than simply operating existing tooling.
- Experience with security tooling including SIEM, EDR, DLP, MDM and cloud security platforms.
- Experience automating security processes using scripting or software engineering skills (Python, Go, TypeScript/JavaScript, Bash or similar).
- Strong understanding of attacker techniques (MITRE ATT&CK) and how to translate them into effective detections.
- Experience with vulnerability management and security telemetry.
- Understanding of modern AI tooling, AI security risks and governance considerations.
- Good understanding of networking, distributed systems and cloud architectures.
- An interest in security architecture and building long-term security capabilities.
You might have:
- Experience designing security architecture for cloud-native platforms.
- Experience building or operating detection engineering programmes.
- Threat hunting or purple team experience.
- Experience with CNAPP, CSPM or exposure management platforms.
- Experience with eBPF or modern observability tooling.
- Experience implementing security automation using SOAR or similar orchestration platforms.
- Knowledge of policy-as-code and security governance.
- Familiarity with supply chain security and software integrity.
- Experience evaluating AI/LLM security, agentic systems or model governance.
You will be:
- An excellent communicator, able to produce clear incident reports, technical documentation and stakeholder updates.
- A pragmatic problem solver who balances operational needs with long-term improvements.
- Comfortable working through ambiguity and making sound technical decisions.
- Curious, with a desire to continually learn and improve both operational and engineering practices.
- Someone who enjoys building systems and capabilities that scale, rather than simply maintaining them.
- Collaborative and approachable, working as part of a team rather than in isolation.
- Able to balance short-term operational priorities with medium and long-term engineering and architectural outcomes.
The perks:
- 💰Competitive base salary
- 📈Generous EMI equity package
- 👌Private pension
- ✈️28 days annual leave + bank holidays
- 🏖Additional 30 days of unpaid leave per year to use as you wish
- 🎆Ad-hoc companywide time off over the festive period
- 🏥Private healthcare with AXA Insurance - including enhanced mental wellbeing coverage
- 🏠Hybrid working policy, typically 2-3 days in the office
- 👶Enhanced family (parental) leave - gender-neutral policy, 12 weeks paid leave
- 👪5 days Caretaker's leave
- 😷Enhanced occupational sick pay
- 💻£500 WFH budget
- 📚All the learning resources and books you want to aid in your personal development
- 🎉 Regular socials to unwind and have some fun
Salary range
£90,000 - £100,000 GBP
Apply for this job
*
indicates a required field
