
Security Operation Center Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United Kingdom.
• Oversee, assess, and investigate security alerts across Google Cloud Platform, Google Workspace, and various other cloud services.
• Create, develop, and optimize detection rules, dashboards, and alerting mechanisms for real-time visibility of security posture.
• Establish and perform daily, monthly, and quarterly security audits, including log inspections, access recertification, vulnerability assessments, configuration drift analysis, and segmentation testing.
• Generate audit-ready documentation for the PCI compliance program, encompassing DSS, P2PE, PIN, and PTS.
• Assist in compliance evaluations.
• Lead initial responses to security incidents, mitigate threats, preserve evidence, and drive remediation efforts to completion.
• Coordinate penetration testing and red team activities, utilizing findings to enhance detection capabilities.
• Collaborate with DevOps and Corporate IT Services to ensure that security controls are effectively implemented and not circumvented.
• Influence SOC tools, runbooks, automation, and KPIs as the function evolves.
• Participate in an on-call rotation outside of regular hours.
• Work embedded within the DevOps team while reporting to a different team.
• Practical experience in a SOC, security engineering, or incident response position.
• In-depth knowledge of Google Cloud Platform security features (IAM, audit logging, Security Command Center, VPC).
• Experience with Google Workspace administration and security.
• Familiarity with SIEM platforms, preferably Google SecOps, including crafting and refining detection queries.
• Sound understanding of PCI DSS and experience providing audit documentation in a regulated setting.
• Background in PCI P2PE, PIN, or PTS, payment HSMs, or key management is highly advantageous.
• Comprehension of cloud architecture, networking, Linux, and containerization.
• Proficiency in scripting languages such as Python, Go, or Bash is beneficial.
• Experience with Infrastructure as Code (Terraform) is an asset.
• Interest or experience in threat hunting, penetration testing, and red team or purple team activities.
• Organized, analytical thinker with outstanding communication skills.
• Ability to constructively challenge engineers and clearly articulate risks to both technical and non-technical team members.
• Willingness to participate in an on-call rotation outside of regular hours.
• Job posting is in English; no specific language requirement mentioned.
• Competitive salary.
• Discretionary bonuses based on company performance.
• 25 days of annual leave plus UK bank holidays.
• Dedicated monthly “well-being days” to promote mental health and work-life balance.
• Attractive company pension scheme.
• Fully remote working environment with an emphasis on flexibility.
• Opportunities for significant growth within a rapidly expanding international company in the payments sector.
Integrity360
Rackspace Technology
Efficient Computer
Presidio
Get handpicked remote jobs straight to your inbox weekly.