Now hiring

Senior SecOps Specialist @ Teya Solutions

Victoria Embankment 100, LondonOnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

Salary: £63,000 - 103,000 per year

Requirements: 7+ years in SOC, incident response, detection engineering, or security engineering.Experience leading complex security incidents end-to-end.Strong hands-on experience with SIEM, EDR, and security tooling.Experience building and tuning detections and queries.Experience with log onboarding, telemetry pipelines, and data quality issues.Strong vulnerability management and remediation experience.Solid understanding of attack techniques, cloud, endpoint, identity, and network security.Hands-on scripting and automation experience with Python, PowerShell, Bash, or similar.Experience with APIs, integrations, and automation workflows.Familiarity with Git and engineering practices including testing, review, and deployment.Experience using Jira or similar tools for operational delivery.Strong communication and documentation skills.Ability to work independently and make decisions under pressure.Fintech or regulated industry experience is a nice-to-have.AWS or cloud-native security experience is a nice-to-have.Experience with tools like Exabeam, Splunk, CrowdStrike, or Okta is a nice-to-have.SOAR or security automation experience is a nice-to-have.Threat hunting, purple teaming, or detection-as-code experience is a nice-to-have.CI/CD, IaC, or DevSecOps exposure is a nice-to-have.REST APIs, OAuth, or secrets management experience is a nice-to-have.Security certifications such as GCIA, GCIH, or CISSP are a nice-to-have. Responsibilities: Lead end-to-end investigation and response of complex security incidents.Act as the L3 escalation point for SOC analysts and our MSSP.Coordinate across Security, Engineering, IT, Cloud, Legal, and Compliance during incidents.Make clear, risk-based decisions under pressure with strong documentation.Maintain playbooks, runbooks, and incident workflows.Drive post-incident reviews and ensure improvements and follow-ups are completed.Support incident metrics such as MTTD, MTTR, and recurrence.Operate and improve SIEM, EDR, email security, case management, and vulnerability tools.Monitor health, coverage, data quality, and integrations.Troubleshoot ingestion, parsing, API, and configuration issues.Build and maintain integrations between security tools and internal systems.Manage upgrades, changes, access reviews, and documentation.Apply engineering practices such as version control, testing, peer review, and rollback.Reduce operational toil through automation and simplification.Analyse and prioritise vulnerabilities based on risk and exploitability.Work with Engineering and IT to drive remediation.Track fixes, validate resolution, and escalate high-risk issues.Improve vulnerability workflows and automation.Identify recurring issues and recommend preventative controls.Build, test, and maintain detection rules, queries, and correlation logic.Manage the full detection lifecycle from build to retire.Use version control and detection-as-code where possible.Reduce false positives and improve detection quality and coverage.Map detections to threat behaviours such as MITRE ATT&CK.Validate detections through testing, incidents, and simulations.Onboard and maintain log sources across cloud, identity, endpoint, network, and SaaS.Ensure logs are complete, reliable, and usable for detection and investigation.Troubleshoot ingestion, parsing, schema, and data quality issues.Build validation and monitoring for telemetry pipelines.Offboard unused sources safely with documented impact.Improve telemetry coverage by working with engineering teams.Monitor threats, vulnerabilities, and attacker techniques.Translate intelligence into detections, investigations, and remediation actions.Assess relevance to our environment and risk profile.Share actionable insights with relevant teams.Improve security posture using trends and intelligence.Gather and utilise intelligence for Shadow AI use cases.Partner with Engineering and Platform teams on security requirements.Manage security work in Jira with clear scope and ownership.Support security projects involving tooling, integrations, telemetry, and controls.Contribute to technical design discussions.Produce clear technical documentation and workflows.Communicate effectively with technical and non-technical stakeholders.Automate SOC and security operations workflows.Build scripts, integrations, and event-driven automations using APIs and cloud services.Apply secure engineering practices including testing, logging, secrets management, and error handling.Use version control and peer review for automation and detection content.Monitor and improve automation reliability.Explore AI and automation opportunities to reduce manual effort.Define and track operational and security metrics. Technologies: AIAPIAWSBashCI/CDCloudDevSecOpsGitSupportJIRANetworkOAuthPowerShellPythonRESTSecuritySplunkDevOps More:

We are Teya, a financial platform built to help local businesses across Europe run with confidence. We support cafés, restaurants, salons, shops, and entrepreneurs with simple tools, thoughtful design, and real human support. We move fast, care about quality, and stay close to the detail. This is a full-time Engineering role based in London or Porto, with a hybrid work mode policy, flexible working hours, health insurance, physical and mental health support through our partnership with MyFitness, 25 days of annual leave plus bank holidays, Friday lunch in the office, high-end work equipment, and the opportunity to visit other Teya offices when travel is safe and appropriate. We are an equal opportunity employer committed to an inclusive environment where everyone can thrive.

last updated 36 week of 2026

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores