Lead Security Operations Engineer

Payabl Eu — Cyprus · Posted ~23 hours ago

Lead Full-time Remote Visa History ✓

Skills

SIEM security operations vulnerability management security incident response security monitoring detection engineering log-source onboarding AI-assisted security operations AI agents cloud

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A senior security operations engineering opportunity for someone who wants to build and own modern detection and response capabilities in a regulated environment. You will architect and operate a SIEM, develop vulnerability management and incident processes, onboard logs across cloud and application environments, and use AI-driven automation to reduce repetitive alert triage. The role offers substantial autonomy and a chance to shape the technical direction of the security operations function.

Highlights

High-impact security engineering role with direct access to senior security leadership, strong technical ownership, and substantial independence. The role emphasizes modern AI-assisted security operations, meaningful engineering work, and responsibility for building core detection and response capabilities from the ground up.

Description

The role is about: We are looking for a Lead SecOps Engineer to design and build security operations for a regulated payments group: the SIEM, the vulnerability management programme, and the security incident process. You will report directly to the Head of Information Security, own the technical direction of the detection and response stack, and operate with a high degree of independence. The force multiplier is AI. We are deliberately building a security operations model where AI agents handle alert triage, enrichment, correlation and first-draft incident timelines — so your time goes into engineering, detection logic and real incidents, not alert-console-watching. Location: Limassol, Cyprus or Remote from Poland or PortugalReporting to: Head of Information Security What will you do: Design, build and operate our SIEM from the ground up — architecture, deployment, tuning and runPlan and execute log-source onboarding across cloud and application estatesBuild AI-assisted triage and enrichment into the pipeline from the start: agent-based alert handling, correlation summaries, draft incident timelinesStand up the vulnerability management programme: deployment, asset coverage, risk-based prioritization, remediation SLAs and reportingImplement process and procedures to ensure an effective vulnerability lifecycleOperate and continuously improve the security incident process end to end: detection, classification, response, post-incident reviewDevelop and maintain runbooks, playbooks and event handlers — and automate them wherever they repeatHarden and monitor our AWS estate: GuardDuty, Security Hub and native findings triaged, deduplicated and driven to remediationDrive security hardening across our infrastructure and runtime securityAutomate routine security operations aggressively — scripting, APIs, infrastructure-as-code and AI agents are all fair gameRun proof-of-concepts, evaluate tooling and shape the technical roadmap of the security stackProvide security engineering consultancy to Engineering, IT and DevOps teams What we need: 5+ years in security operations or security engineering in financial services or another environment with formal incident-reporting obligations (DORA, PCI DSS)Strong hands-on experience with SIEM platforms (Elastic/OpenSearch, Wazuh, Splunk or similar) and log pipeline engineeringSolid AWS security knowledge: GuardDuty, Security Hub, IAM, VPC-level controls and cloud-native logging, hardeningPractical experience running vulnerability management: scanners, prioritisation, remediation trackingStrong IaaC skillsGenuine enthusiasm for AI-assisted security operations — using LLMs and agents to triage, enrich, summarise and automate is core to how this role worksThe independence to own a domain end to end: prioritise, decide, deliver and explain Nice to have: Kubernetes security hands-on: admission controllers, runtime detection (Falco or similar), cluster hardeningDetection-as-code practices (Sigma, version-controlled rules, CI for detections)Certifications such as CCSP, CISSP, OSCP or equivalent Hiring Process: Step 1 - Thinking in Action (40 minutes) Your first conversation will be with our Talent Acquisition team. We'll explore your background, career journey, motivations, and overall fit for the role. As part of this discussion, you'll also complete a short technical screening that will be reviewed by our engineering team. This stage helps us understand both your experience and how you approach technical challengesStep 2 - Hiring Manager interview (60-minutes) you will meet the hiring manager Head of Information Security, to explore your skills, achievements, and alignment with the roleStep 3 - Final Interview (45 minutes) The final stage is a group interview with senior members of our Technology squad, which may include the CTO, CPO and Head of Security. Together, we'll discuss team fit, collaboration style, expectations from both sides, and any remaining questions about the role, team, or technology domain. This is also an opportunity for you to learn more about our culture and ways of working The perks of being a payabl.er: Future-Proof Your Finances: Once you've passed probation, we'll kickstart your Provident Fund to secure your future. Grow with Us: Annual Learning Budget for professional development (eligible after probation)—because your growth is our growth. Wolt Your Way Through Lunch: €150 monthly Wolt allowance to keep you fueled and happyStay Active Your Way: Enjoy a SportsBenefits membership giving you access to a wide variety of gyms and sports facilities to support your active lifestyleDrive in Style: After one year with us, you may be eligible for a company car—performance and availability permitting. Park with Ease: Complimentary parking space just steps from the office, so your commute is as smooth as your workdayMax Out Your Downtime: 25 days of vacation + public holidays + 10 days of sick leaveShop & Save: Exclusive local discount card + tickets for exciting events like Beonix, basketball games, and more. Speak Like a Local: Join free Greek language classes, twice a week, open to all team members. Celebrate Together: We bring colleagues from all offices together for unforgettable company celebrationsGlobal Collaboration & Events: Opportunities to participate in international company events and initiatives, connecting with colleagues from all regions and contributing to a truly global community The benefits listed above are for our Cyprus office location only, a list of benefits and contract type will be assessed subject to your location and discussed in the first interview with your Talent Acquisition Partner. Let's embark on a journey to redefine the landscape of payments together. We're not just offering a role; we're inviting you to be a part of something bigger. Join our team, and let's innovate, disrupt, and lead the future of payments. Together, we can make an impact that resonates. Welcome to the team! Please review our Privacy Policy to understand how we process your personal data during the recruitment process: https://payabl.com/privacy-policy