Youll be helping us defend our most critical asset our customers. We are maturing our Security Operations activities and need your expertise to build and scale these efforts from first principles. You will play a key role in establishing a robust SOC improving Incident Response processes leveraging Threat Modelling and Intelligence enabling and improving Proactive Threat Detection and ensuring an effective and automated response to security incidents.
This role requires partnering with various teams across Mews to elevate and automate security handling focusing on building a resilient SOC function that integrates seamlessly into our cloud platform and product ecosystem.
Your mission should you choose to accept it:
- Building and maturing an automated modular SOC integrated with our cloud platform and products leveraging modern practices and tooling.
- Designing and implementing effective threat intelligence capabilities to detect and remediate security issues proactively.
- Ensuring that all aspects of our operating products and the supply chain delivering them have effective security observability striving for early detection and resolution of security incidents.
- Bringing a strong technical security skill set to the overall strategy and direction of our security operations and our Platform & Security teams to enable Mews to operate with a best possible security posture in the cloud.
- Leading post-mortems for security incidents fostering a culture of continuous improvement and awareness of security practices across the organization.
- Developing and automating disaster response plans resilient systems engineering practices and security automation workflows.
- Developing detections and playbooks within Azure Sentinel to automate response actions for high-fidelity alerts.
- Collaborating with teams to improve the integration of security tooling into Azure environments ensuring comprehensive logging and monitoring.
Youll be a great fit if you bring a few of the below with you
- Genuinely cares and enjoys helping your users whilst balancing their needs with the business and security needs.
- Pursues tangible outcomes but has an incredible eye for detail.
- has excellent interpersonal skills/EQ you are a low ego learner and sharer.
- Is a proven expert in technical delivery architecting developing and maintaining security capabilities that enable builder teams to do their best work.
- Has a strong bias towards action
- Has excellent communication skills including communication with less-technical staff
- Has experience working in and contributing to an environment that supports a diverse team
- A desire to mentor junior teammates
You will probably have experience with some of these:
- Hands-on experience with security operations implementation and utilization security automating and threat intelligence.
- Incident response drill exercises
- Supply Chain elements including all elements around the delivery of software
- Development and scripting
- Alerting and monitoring tooling and building a sustainable SIEM process
- Running post-mortems and teaching the culture of security to non-ops engineers
- Disaster response resilient systems engineering and security automation
- Cloud security and systems hardening
- Comfortable both with pair working and with independent work managing their own projects; but is also confident with sense-checks and check-ins to avoid chasing too many issues down rabbit holes.
Required Experience:
Senior IC