About this role
Salary: £63,000 - 103,000 per year
Requirements: Background in IT, SOC operations, or other hands-on technical workSolid grasp of cloud infrastructure, ideally AWSStrong networking knowledge: can read a PCAP, spot beaconing in flow logs, and reason about lateral movement across VLANs and firewallsKnowledge of attacker tradecraft, including initial access, persistence, privilege escalation, and exfiltration, and the ability to map an investigation to itComfortable scripting in Python or similar to automate enrichment, triage, and responseStrong ownership mindset: sees things through end-to-end with little guidanceDeep familiarity with an EDR platform such as CrowdStrike, SentinelOne, or Defender as an investigation toolDetection-as-code experience, including Sigma, detection rules in Git, and CI-tested detectionsSOAR or custom automation experience for response workflowsExperience defending data centre or colocation environments, including OOB networks, BMC/IPMI, and physical access telemetryExperience handling security audits such as ISO27001 or SOC2Familiarity with FortiGate logging and NetFlow/sFlow analysisDFIR certifications such as GCIH, GCFA, or GCIA are useful but not requiredExperience in energy, fintech, trading, or another high-value-target environment Responsibilities: Act as an escalation point for IT in areas such as IAM, security, and automationAct as our security AI champion, building tools to make everyones jobs easierOwn security monitoring end to end: build and tune log pipelines from AWS, endpoints, identity providers, SaaS audit logs, and network infrastructure into a coherent detection stackWrite, test, and maintain detection rules that reduce noise and measure coverage against real attacker behaviourLead incident response from detection through containment, eradication, and post-mortem; own the IR runbooks and keep them tested through tabletop exercisesPerform forensic analysis on compromised endpoints, cloud workloads, and accounts, preserving evidence properly when it mattersWork with IT to develop and improve security and IT policies and documentationAct as the point of contact for the business on external audits and assessmentsTrack threat intelligence relevant to energy, trading, and GPU infrastructure and turn it into detections and huntsRun vulnerability management from a threat-led angle: prioritise by exploitability and exposure, and drive remediation through the IT and engineering teams who own the fixesMonitor the security of our data centre environments and flag anything that breaks the segmentation modelFeed findings back into prevention by working with IT and engineering to close root causes Technologies: AIAWSCloudFortiGateFlowGitIAMNetworkPythonSecurityFirewall More:
We are Fuse Energy, a forward-thinking renewable energy startup on a mission to deliver a terawatt of renewable energy fast. We are building a fully integrated energy company, from developing energy generation projects to real-time power trading and distributed energy installations, and by selling directly to consumers we aim to cut out the middleman, lower costs, and pass on savings to customers. We raised $170M from top-tier investors including Multicoin, Balderton, Lakestar, Accel, Creandum, Lowercarbon, Ribbit, Box Group, and strategic angels. This is a full-time role based within the team that owns security across our IT and cloud environment, spanning AWS infrastructure, identity providers, endpoints, SaaS applications, and our data centre environments. Benefits include a biannual bonus scheme, fully expensed tech to match our needs, paid annual leave, and breakfast and dinner allowance for office-based employees.
last updated 36 week of 2026