All Jobs
>
Sr. Security Operations Engineer
Apply
Sr. Security Operations Engineer
London, GBR •
Cybersecurity
Apply
Description
Job Title: Sr. Security Operations EngineerEmployment Type: Full-timeWork Location: UK / HybridDepartment: CISOAbout CloudBeesCloudBees provides the leading software delivery platform for enterprises, enabling them to continuously innovate, compete, and win in a world powered by the digital experience. Designed for the world's largest organizations with the most complex requirements, CloudBees enables software development organizations to deliver scalable, compliant, governed, and secure software from the code a developer writes to the people who use it. The platform connects with other best-of-breed tools, improves the developer experience, and enables organizations to bring digital innovation to life continuously, adapt quickly, and unlock business outcomes that create market leaders and disruptors.CloudBees was founded in 2010 and is backed by Goldman Sachs, Morgan Stanley, Bridgepoint Credit, HSBC, Golub Capital, Delta-v Capital, Matrix Partners, and Lightspeed Venture Partners. Visit www.cloudbees.com and follow us on Twitter, LinkedIn, and Facebook.About the RoleWe are growing quickly and have a new opening for a Sr. Security Operations Engineer to join our global security team. This is not a traditional SOC role - it sits at the intersection of security operations, detection engineering, and AI-driven automation, with a direct influence on how CloudBees products are secured by design.You will own the engineering of our detection capability end-to-end: building detection logic, authoring and maintaining SOAR playbooks, and leveraging AI/ML to reduce manual workload and improve response fidelity. Critically, you will act as a bridge between the Security team and Product Engineering, embedding security detection requirements early in the product lifecycle and ensuring our platform's telemetry supports world-class threat visibility.If you are a proactive self-starter who thinks in pipelines and playbooks - not just tickets - we would love to hear from you.What You'll Do:Detection EngineeringDesign, build, and continuously tune detection rules across endpoint, cloud (AWS), SaaS, and application layers, aligned to the MITRE ATT&CK frameworkOwn the full detection lifecycle: hypothesis - log analysis - rule authoring - testing - deployment - retrospective tuningDevelop and maintain a detection-as-code library (version-controlled, peer-reviewed, tested in CI/CD)Convert threat intelligence, red team findings, and incident post-mortems into actionable, high-fidelity detectionsMap detection coverage against MITRE ATT&CK and maintain visibility gap analyses, reporting coverage metrics to security leadershipSOAR & Automation EngineeringLead the design, development, and maintenance of SOAR playbooks to automate alert triage, enrichment, containment, and notification workflowsIdentify high-volume, repetitive SOC workflows and engineer automated responses that reduce analyst toil and mean time to respond (MTTR)Build integrations between security tooling (SIEM, EDR, CNAPP, DLP, ticketing, threat intel platforms) using APIs, Python scripts, and SOAR connectorsChampion AI-assisted analysis (e.g., LLM-based alert summarisation, anomaly detection, automated IOC correlation) to improve detection quality and analyst efficiencySecurity Operations & Incident ResponseProvide security monitoring and incident response for cyber security events within a highly available SOC supporting internal and external stakeholdersParticipate in the SOC on-call rotation, only on weekends, to support 24/7 security operationsLead and support incident response activities: triage, containment, eradication, recovery, and post-incident reviewMonitor and analyse SIEM alerts, correlating signals across log sources to identify true positives and reduce false positive...
Want jobs like this matched to you?
SimpleCareer scores fresh postings against your résumé so you only see the matches that matter.