Security Operations Engineer

Mesh · EU (Remote) · Engineering

Posted 2026-08-19

Apply for this role →

Overview

As a Security Ops Engineer, you will be a hands-on technical builder and responder responsible for designing, implementing, and operating security controls across our infrastructure, systems, and operational workflows. This role spans building robust security architecture, conducting threat modeling, analyzing attack vectors from an analyst's perspective, and driving active incident response. While you should understand code and participate in security reviews, your primary focus is implementing security systems, detecting threats, and leading response efforts. You will work autonomously across engineering, infrastructure, and product teams to strengthen our defensive posture and ensure rapid, effective response when security events occur.

What You'll Do

Implement Security Controls and Architecture by designing, deploying, and maintaining core defensive systems, security integrations, and infrastructure guardrails.

Perform Threat Analysis and Modeling by evaluating system architectures from an attacker's perspective, identifying key attack surfaces, and building practical defensive mitigations.

Conduct Practical Code and System Reviews by evaluating new features and integration architectures for security risks, leveraging code comprehension to improve overall security posture.

Manage Vulnerability Remediation by tracking findings from scans, pentests, and bug reports, prioritizing by risk, and driving fixes to closure with engineering owners.

Own Security Operations Platform Management by administering, configuring, and maintaining SIEM/SOAR platforms for threat detection and incident response.

Engineer Detection Rules and Alerts by writing, tuning, and optimizing detection queries to identify real threats while minimizing false positives.

Conduct Security Investigations and Incident Response by analyzing alerts, performing forensic analysis, and managing escalation and communication during active incidents.

Document Findings by producing clear reports for security reviews, threat models, and incident investigations that support institutional knowledge and audits.

Support Compliance and Evidence Collection by ensuring security events, review findings, and remediation work are properly logged and available for audit and regulatory requirements.

Maintain Operational Readiness by staying current on emerging threats, attack techniques, and security engineering practices relevant to our infrastructure and threat model.

Who You Are

Bachelor's degree in Computer Science, Cybersecurity, or a related field.

5–7+ years of hands-on experience building defensive security systems, implementing security controls, or operating in security response environments.

Strong technical background in understanding attack techniques, performing threat analysis, and leading incident response efforts.

Experience managing vulnerability findings from identification through remediation.

Working knowledge of SIEM/SOAR platforms and writing detection rules (e.g. SPL, KQL, or similar).

Deep understanding of network, host, application, and cloud security concepts.

Strong written and verbal communication skills, with the ability to clearly document findings and escalate issues.

Ability to work independently with minimal supervision in a fast-paced environment.

Experience collaborating with small, international teams across multiple time zones.

Willingness to work outside normal business hours when needed for incident response.

Nice to have

Familiarity with threat modeling frameworks (e.g. STRIDE, MITRE ATT&CK).

Experience implementing automated security controls and infrastructure security tooling.

Hands-on experience with SIEM platforms at scale (Sumo Logic, Splunk, Azure Sentinel, Datadog, or similar).

Experience with cloud security monitoring (AWS, Azure, GCP) and native security services.

Exposure to containerized environments (Docker, Kubernetes) and securing cloud-native workloads.

Familiarity with security and compliance frameworks (ISO 27001/2, NIST, SOC2, GDPR, DORA).

Experience with at least one object-oriented programming language; Python preferred.

Experience with at least one query language such as KQL or similar.

Apply for this role →

← Back to all jobs