14 hours ago
Bucharest, RomaniaSenior
Responsibilities
- Plan and deliver detection and response initiatives from detection rules through automated response.
- Build, tune, and maintain Elastic SIEM detections across AWS environments.
- Triage, investigate, escalate, and resolve security incidents while documenting findings.
- Build runbooks and Python or no-code automations using tools such as Zapier and Tines.
- Make and document risk decisions and escalate issues when appropriate.
- Maintain audit-ready security controls and contribute evidence for SOC 2 and PCI DSS audits.
- Use Terraform and Python to maintain detection and security tooling infrastructure.
- Participate in an on-call rotation for incident response and monitoring.
Requirements
- Hands-on experience building and tuning SIEM detections, preferably with Elastic; Splunk, Sentinel, or similar experience is also accepted.
- Experience with AWS and cloud-native detection and response.
- Comfort using Python for scripting and automation.
- Experience with Terraform or other infrastructure-as-code tools.
- Working knowledge of MITRE ATT&CK.
- Practical experience triaging, investigating, and resolving security incidents.
- Clear and structured written communication.
- Experience with no-code security automation or SOAR-style tooling is preferred.
- Exposure to PCI DSS, SOC 2, or ISO 27001 is preferred.
- Background in fintech, payments, or another regulated industry is preferred.
Benefits
- Fully remote and globally distributed work arrangement.
- Competitive share options.
- Uncapped holiday with a minimum of 25 days to be taken.
- Co-working space access across major cities.
- Workations and an annual company retreat.
- Best equipment for the role.
- £500 toward a home office setup.
- Generous learning budget.
- Private Medical Insurance.
- Additional location-dependent perks and benefits.