[All remote jobs](https://jobicy.com/jobs.md)Open role[![Pleo logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/b27fbed2-221.jpg)](https://jobicy.com/company/pleo.md)Remote opportunity at[Pleo](https://jobicy.com/company/pleo.md)

# Lead Security Operations Engineer

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

[Apply for this job](#job-application)[View company](https://jobicy.com/company/pleo.md)Share27 Aug 2026Published40Listing views2Application actions26 Sep 2026Apply before  Opportunity details

## About this role.

AI SummaryPleo is hiring a senior hands-on security leader to build and own its Security Operations capability for a growing fintech. The role covers SecOps strategy, SIEM and logging architecture, detection engineering, incident response, digital forensics, DLP, WAF, and authentication monitoring. The successful candidate will establish an on-call model, response SLAs, automation workflows, and executive-facing risk and coverage metrics. This is a high-autonomy position requiring close collaboration with Fraud, DevSecOps, Engineering, and Risk & Compliance while mentoring less experienced security engineers.

## Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

### Job Complexity

5/5EasyHard

### Pace & Pressure

5/5RelaxedFast-paced

### Autonomy Level

5/5GuidedFull ownership

### Communication Load

5/5IndependentCollaborative

AI insightThis is a lead-level build-and-scale role requiring more than 10 years of relevant experience and ownership of a SecOps function end to end. The candidate must combine strategic roadmap leadership with deep technical execution across cloud security, SIEM, incident response, automation, and regulated-fintech risk.

## Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate$180,000US market range$155k–$220k0$242k

AI insightNo salary is disclosed in the posting, so these are estimated US-market annual base-salary figures in USD for a lead-level Security Operations Engineer with 10+ years of experience. Actual compensation can vary materially by country, local employment arrangement, equity, bonus structure, and scope of people leadership.

## Core skills

Skills and capabilities most closely associated with this opportunity.

[Security Operations](https://jobicy.com/jobs?search_keywords=Security%20Operations.md)[Incident Response](https://jobicy.com/jobs?search_keywords=Incident%20Response.md)[Digital Forensics](https://jobicy.com/jobs?search_keywords=Digital%20Forensics.md)[SIEM](https://jobicy.com/jobs?search_keywords=SIEM.md)[Detection Engineering](https://jobicy.com/jobs?search_keywords=Detection%20Engineering.md)[AWS Security](https://jobicy.com/jobs?search_keywords=AWS%20Security.md)[GCP Security](https://jobicy.com/jobs?search_keywords=GCP%20Security.md)[Security Automation](https://jobicy.com/jobs?search_keywords=Security%20Automation.md)[MITRE ATT&CK](https://jobicy.com/jobs?search_keywords=MITRE%20ATTCK.md)[Fintech Security](https://jobicy.com/jobs?search_keywords=Fintech%20Security.md)

Sample interview questionsHow would you create a SecOps roadmap for a growing fintech that does not yet have a mature security operations function?I would begin with a current-state assessment of assets, identity paths, cloud environments, data flows, logging coverage, incident history, and regulatory obligations. I would map priority threats and detection gaps to MITRE ATT&CK, NIST, and CIS controls, then sequence work by business risk, exploitability, and implementation effort. The roadmap would include measurable outcomes such as coverage improvements, mean time to detect, mean time to respond, alert fidelity, and reduction of high-risk compliance gaps.

Describe how you would improve a SIEM and logging pipeline where important security signals are being lost in noise.

I would inventory critical services and define standardized logging requirements for identity, cloud control plane, endpoints, network activity, applications, and sensitive-data access. I would normalize high-value fields, establish retention and integrity requirements, and measure ingestion completeness. I would then tune detections using baselines, enrichment, suppression rules, and severity criteria so analysts receive actionable alerts rather than high-volume low-context events.

What is your approach to incident response for suspicious activity involving a potentially compromised cloud identity?

I would first validate the signal and establish scope by reviewing identity-provider, cloud audit, access, and workload logs. I would contain the risk by revoking or rotating credentials, restricting sessions or permissions where appropriate, and preserving evidence before making disruptive changes. After eradication and recovery, I would document root cause, assess blast radius, notify relevant stakeholders, and convert lessons learned into stronger detections, access controls, and response playbooks.

How have you used code or AI-enabled automation to improve security operations?

I use automation to enrich alerts, correlate evidence, open and update cases, collect forensic artifacts, and execute approved containment actions. For AI-enabled workflows, I apply guardrails such as trusted data sources, human approval for high-impact actions, audit logging, and measured accuracy to avoid amplifying poor signals. The objective is to reduce repetitive analyst work while improving response consistency and time to resolution.

How would you communicate a material security risk to engineering leaders and non-security stakeholders?

I would explain the risk in terms of the affected business process, likely attack path, potential customer or financial impact, and the consequences of inaction. I would provide a prioritized, implementable recommendation with clear ownership, timeline, and trade-offs rather than only presenting a technical finding. I would also define the evidence and metrics that demonstrate whether the mitigation has reduced risk.

### About Pleo

Messy spend management is tricky business. And tedious processes are a lose-lose situation for all involved, not just finance. At Pleo, we’re changing that. We build spend solutions that make managing money seamless, empowering, and surprisingly effective for finance teams and employees alike – with a vision to help all businesses ‘go beyond’.

The word ‘Pleo’ actually means ‘more than you’d expect’, and living by that mantra has been the secret to our success over the last 10 years.

Now, we’re at a pivotal moment in our journey; every move we make has a direct impact on our 40,000+ customers, our business, and our collective success. We need people who take pride in uncovering customer needs, who turn complex problems into simple solutions, challenge the way things are done (respectfully), and always aim high. With great ambitions driving us forward, we can’t say we’ve got this whole thing figured out. And frankly, that’s half the fun! What we can say is that we’re a driven, progressive, and, importantly, a kind bunch of 850+ people from over 100 nationalities, all committed to delivering the future of business spending, together.

### About the role

We’re looking for a Lead Security Operations Engineer to join our Cybersecurity team at Pleo. In this role, you’ll define and deliver the SecOps roadmap, building the detection, response, and investigation capability that protects a fast-growing fintech. If you’re excited about owning a security operations function end to end, from framework-based strategy through to the code that makes it run, then this is the opportunity for you!

### Who you’ll be working with and reporting to

You’ll report to our VP of Fraud & Security and work closely with Fraud, DevSecOps, Engineering, and Risk & Compliance. Our team is highly collaborative and dedicated to protecting Pleo’s customers and their money. You’ll also have the chance to partner with teams across the organisation and to bring less experienced security engineers up with you as the function matures.

### What you’ll be doing

As a Lead Security Operations Engineer, you will:

*

Build and own a structured SecOps roadmap grounded in well-known frameworks such as MITRE ATT&CK, NIST, and CIS benchmarks.

*

Lead security investigations and digital forensics, from suspicious traffic through to full incident response, and bring the findings back into how we detect and prevent.

*

Design, tune, and scale our SIEM and logging pipeline through standardized log ingestion across services so signal isn’t lost in the noise.

*

Strengthen our perimeter and authentication posture, including WAF configuration, authorisation tuning, and monitoring for suspicious traffic.

*

Protect sensitive data through DLP controls, and make sure the coverage matches where the data actually lives.

*

Improve our on-call rotation for the team, defining the alerting, escalation paths, and response SLAs that make it work.

*

Automate detection and response workflows, using code and AI to reduce manual toil and shorten time to resolution.

*

Reduce SecOps-attributed risk identified through compliance gaps, and collect the evidence that demonstrates it.

*

Build dashboards and reporting that give the team and leadership real visibility into response times, coverage, and risk reduction.

*

Work cross-functionally with engineers who don’t have a security background, translating threat models into changes they can actually ship.

### What you bring

You’ll thrive in this role if you have:

*

10+ years of experience in security operations, incident response, or a closely related discipline, with a proven track record of materialised risk reduction through monetary impact, incidents contained, forensics that changed outcomes.

*

A strong development and engineering background. You are comfortable writing the automation, not just specifying it.

*

Hands-on SOC and SIEM management experience, including detection engineering and log pipeline design.

*

Experience in scale-up environments, where you’ve built capability rather than inherited a mature one.

*

A strong understanding of cloud architectures as we use AWS. With part of our estate on GCP and how infrastructure decisions shape detection and response.

*

Demonstrated experience using AI and/or coding automation to get security controls built, implemented, and operating in practice.

*

Fintech, payments, fraud, or trust & safety experience is a real advantage, as is exposure to highly regulated environments.

*

Backgrounds that tend to do well here: incident response, IR management, SOC engineering, security engineering, DevSecOps, red or blue team.

### Why is this role a good fit for you

This role is a good fit for you if:

*

You want a large blast radius. We have high-impact projects where the outcome shows up in real business metrics, at a pre-IPO company.

*

You’re energised by building a function rather than maintaining one, and you’d rather set the roadmap than be handed it.

*

You enjoy raising the bar around you, growing a team of specialists and lifting the people already here.

*

You’re equally at home in a threat model discussion and in an editor writing the automation that acts on it.

This role is not a good fit for you if:

*

You need a well-groomed backlog and assigned tasks in order to do your best work.

*

You’d rather stay purely strategic than get hands-on with the tooling.

*

You’re not up for participating in an on-call rotation.

### How you’ll develop in this role

In your first 6 months at Pleo, you’ll:

*

Get deep into Pleo’s security landscape and our detection coverage, our logging estate, our cloud footprint to form your own view of where the biggest risks sit.

*

Publish a SecOps roadmap mapped to MITRE, NIST, and CIS, agree with Engineering, Risk & Compliance, and leadership, and start delivering against it.

*

Stand up the on-call rotation and the alert response SLAs that go with it.

*

Ship your first wave of detection and automation improvements, and establish the KPIs that show what changed.

We’re committed to helping you develop your career, whether that means taking on bigger projects, stepping into leadership, or acquiring new skills. There’s genuine room here for the scope of this role to grow, including into people leadership.

### The location

Please note: We can hire on a remote, hybrid or in-person set-up in any of the locations listed on the advert but you will need to be physically based in the country of your choice with a valid right to work. We are unable to offer visa sponsorship for this role in any of the listed locations.

### Show me the benefits!

*

Your own Pleo card (no more out-of-pocket spending!)

*

Lunch is on us for your work days – enjoy catered meals or receive a lunch allowance based on your local office

*

Comprehensive private healthcare – depending on your location, coverage options include Vitality, Alan or Médis

*

We offer 25-28 days of holiday (depending on your location) + public holidays

*

For our Team, we offer both hybrid and fully remote working options

*

Option to purchase 5 additional days of holiday through a salary sacrifice

*

We use MyndUp to give our employees access to free mental health and well-being support with great success so far

*

Paid parental leave – we want to make sure that we’re supportive of families and help you feel that you don’t have to compromise your family due to work

### The interview process

We want to ensure you are set-up for success and understand what will be expected of you. If your application is successful, our interview process is as follows:

*

Intro call: A 30-minute chat with our Talent Partner to discuss the role and your background.

*

Hiring Manager interview: a 60-minute conversation covering your experience, how you approach security operations, and how you communicate.

*

Technical deep dive: a 60-minute session with two of our SecOps engineers, going deep on SIEM, detection engineering, your coding and automation experience.

*

Cross-functional interview: a 45-minute conversation with DevSecOps and Engineering leadership on how you work across team boundaries with other senior engineers.

### About your application

*

English first. Since it’s our company language, please submit your application in English. You’ll be using it a lot if you join us.

*

A fair look for everyone. Our talent team reads every single application to ensure the process is fair. To keep things running smoothly, we only accept applications through our system—our support team can’t pass on calls or emails.

*

Diversity drives us. We can only reach our goals if our team reflects the world around us. That starts with you hitting apply, even if you don’t tick every single box. We encourage people from all backgrounds and experiences to join us.

*

Interview at your best. We want you to feel comfortable throughout the process. If you have any accessibility requirements or need a specific format, email belonging@pleo.io. We’ll design a process that works for you.

*

Your data is safe. When you apply, we process your personal data as a data processor. For more information on how Pleo processes personal data, read our Privacy Policy [here](https://www.pleo.io/en/legal).

*

Applying for multiple roles? Nothing is stopping you, and we assess every role independently. However, we do look for alignment, so make sure you can explain why your interest and experience are right for each specific role.

*

Reapplying. If you’re applying for the same role again, please wait six months from your last decision before hitting submit.

Show more

[Apply now >](https://jobicy.com/jobs/151792-lead-security-operations-engineer.md)

>  Annual salary information is not provided for this position. Explore salary ranges for similar roles in our [Salary Directory ›](https://jobicy.com/salaries.md)

*

![Upload CV](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NSIgaGVpZ2h0PSI2NSIgZmlsbD0ibm9uZSIgeG1sbnM6dj0iaHR0cHM6Ly92ZWN0YS5pby9uYW5vIj48ZyBjbGlwLXBhdGg9InVybCgjQSkiPjxwYXRoIGQ9Ik0wIDBINjVWNjVIMFYwWiIgZmlsbD0iIzAyOWFlYiIvPjxnIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIj48cGF0aCBkPSJNMzMuMDQ5IDE1LjQ1NGExLjQzIDEuNDMgMCAwIDAtMi4wOTcgMGwtNy41NzkgOC4xNDdhMS4zOCAxLjM4IDAgMCAwIC4wOSAxLjk3MyAxLjQ0IDEuNDQgMCAwIDAgMi4wMDgtLjA4OGw1LjEwOS01LjQ5MnYyMC42MWExLjQxIDEuNDEgMCAwIDAgMS40MjEgMS4zOTdjLjc4NSAwIDEuNDIxLS42MjUgMS40MjEtMS4zOTd2LTIwLjYxbDUuMTA5IDUuNDkyYTEuNDQgMS40NCAwIDAgMCAyLjAwOC4wODggMS4zOCAxLjM4IDAgMCAwIC4wOS0xLjk3M2wtNy41NzktOC4xNDZ6TTE2Ljc2OSAzOC40YzAtLjc3My0uNjItMS40LTEuMzg1LTEuNFMxNCAzNy42MjcgMTQgMzguNHYuMTAybC4yMTUgNi4yMjljLjIyMyAxLjY4LjcwMSAzLjA5NSAxLjgxMyA0LjIxOHMyLjUxIDEuNjA3IDQuMTcyIDEuODMzYzEuNi4yMTggMy42MzYuMjE4IDYuMTYuMjE4aDExLjI4bDYuMTYtLjIxOGMxLjY2Mi0uMjI2IDMuMDYxLS43MDkgNC4xNzItMS44MzNzMS41ODktMi41MzggMS44MTMtNC4yMThDNTAgNDMuMTEzIDUwIDQxLjA1NSA1MCAzOC41MDNWMzguNGMwLS43NzMtLjYyLTEuNC0xLjM4NS0xLjRzLTEuMzg1LjYyNy0xLjM4NSAxLjRsLS4xOSA1Ljk1OGMtLjE4MiAxLjM3LS41MTUgMi4wOTUtMS4wMjYgMi42MTJzLTEuMjI4Ljg1My0yLjU4MyAxLjAzOGMtMS4zOTUuMTktMy4yNDMuMTkzLTUuODkzLjE5M0gyNi40NjJjLTIuNjUgMC00LjQ5OC0uMDAzLTUuODkzLS4xOTMtMS4zNTUtLjE4NC0yLjA3Mi0uNTIxLTIuNTgzLTEuMDM4cy0uODQ0LTEuMjQyLTEuMDI2LTIuNjEyYy0uMTg3LTEuNDEtLjE5MS0zLjI3OS0uMTkxLTUuOTU4eiIvPjwvZz48L2c+PGRlZnM+PGNsaXBQYXRoIGlkPSJBIj48cGF0aCBmaWxsPSIjZmZmIiBkPSJNMCAwaDY1djY1SDB6Ii8+PC9jbGlwUGF0aD48L2RlZnM+PC9zdmc+)

### Upload your resume now

To unlock remote work opportunities and be discovered by global employers.

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

## Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Keep exploring

## Related remote jobs.

Matched by job category10 related opportunities[Cybersecurity](https://jobicy.com/categories/cybersecurity.md) [Browse all jobs](https://jobicy.com/jobs.md)
*
![LastPass logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/13842160-221.png)
LastPass  Aug 27

### [Principal Cloud Security Engineer](https://jobicy.com/jobs/151831-principal-cloud-security-engineer.md)

About LastPassLastPass delivers Secure Access Essentials, helping individuals and organizations manage and protect access to AI, applications, and credentials straight from the browser. Trusted by more than 100,000 businesses and…

*
![Ada logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/666ef11e-221.png)
Ada  Aug 27

### [Compliance and Security Lead](https://jobicy.com/jobs/151791-compliance-and-security-lead.md)

About Us Ada is an AI customer service company whose mission is to make customer service extraordinary for everyone. We’re driven to raise a new standard of quality customer service…

*
![Pleo logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/b27fbed2-221.jpg)
Pleo  Aug 27

### [Senior Application Security Manager](https://jobicy.com/jobs/151788-senior-application-security-manager.md)

About Pleo Messy spend management is tricky business. And tedious processes are a lose-lose situation for all involved, not just finance. At Pleo, we’re changing that. We build spend solutions…

*
![GitLab logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/12/WRILS-201207055737-109952.jpg)
GitLab  Aug 27

### [Senior Security Engineer, Security Incident Response Team (SIRT) – EMEA](https://jobicy.com/jobs/149309-senior-security-engineer-security-incident-response-team-sirt-emea.md)

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50…

*
![Vercel logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/a6aded72-221.png)
Vercel  Aug 27

### [Security Software Engineer, IAM](https://jobicy.com/jobs/147750-security-software-engineer-iam.md)

About Vercel: Vercel is the agentic infrastructure company. We free people and agents to ship what’s next. For more than a decade, Vercel has shaped how the web is built….

*
![Bloomreach logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/08/60790cd5-221.png)
Bloomreach  Aug 26

### [Director, AI Enablement & Security](https://jobicy.com/jobs/151780-director-ai-enablement-security.md)

Bloomreach is building the world’s premier agentic platform for personalization.We’re revolutionizing how businesses connect with their customers, building and deploying AI agents to personalize the entire customer journey. We’re taking…

*
![OpenAI logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2023/03/0523b13262b12c215d8009938f5c14f1.jpeg)
OpenAI  Aug 26

### [Security Engineer, Infrastructure Security](https://jobicy.com/jobs/151778-security-engineer-infrastructure-security.md)

About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products….

*
![OpenAI logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2023/03/0523b13262b12c215d8009938f5c14f1.jpeg)
OpenAI  Aug 26

### [Security Engineer, Agent Security](https://jobicy.com/jobs/151775-security-engineer-agent-security.md)

About the TeamThe team’s mission is to accelerate the secure evolution of agentic AI systems at OpenAI. To achieve this, the team designs, implements, and continuously refines security policies, frameworks,…

*
![OpenAI logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2023/03/0523b13262b12c215d8009938f5c14f1.jpeg)
OpenAI  Aug 26

### [Security Engineer, Detection and Response](https://jobicy.com/jobs/151765-security-engineer-detection-and-response.md)

About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products….

*
![OpenAI logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2023/03/0523b13262b12c215d8009938f5c14f1.jpeg)
OpenAI  Aug 26

### [Technical Threat Investigator, Threat Intel Engineering](https://jobicy.com/jobs/151752-technical-threat-investigator-threat-intel-engineering.md)

About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Threat Intelligence team protects OpenAI’s technology, people, research,…