Enter a job title or keyword

Lead Security Operations Engineer

Pleo


Job Location:

London - UK

Monthly Salary: Not provided by the employer
Posted: 21 August 2026 (13 hours ago)
Application Deadline: 18 November 2026
Vacancies: 1 Vacancy

Department:

Engineering

Job Summary

About Pleo

Messy spend management is tricky business. And tedious processes are a lose-lose situation for all involved not just finance. At Pleo were changing that. We build spend solutions that make managing money seamless empowering and surprisingly effective for finance teams and employees alike - with a vision to help all businesses go beyond.

The word Pleo actually means more than youd expect and living by that mantra has been the secret to our success over the last 10 years.

Now were at a pivotal moment in our journey; every move we make has a direct impact on our 40000 customers our business and our collective success. We need people who take pride in uncovering customer needs who turn complex problems into simple solutions challenge the way things are done (respectfully) and always aim high. With great ambitions driving us forward we cant say weve got this whole thing figured out. And frankly thats half the fun! What we can say is that were a driven progressive and importantly a kind bunch of 850 people from over 100 nationalities all committed to delivering the future of business spending together.

About the role

Were looking for a Lead Security Operations Engineer to join our Cybersecurity this role youll define and deliver the SecOps roadmap building the detection response and investigation capability that protects a fast-growing fintech. If youre excited about owning a security operations function end to end from framework-based strategy through to the code that makes it run then this is the opportunity for you!

Who youll be working with and reporting to

Youll report to our VP of Fraud & Security and work closely with Fraud DevSecOps Engineering and Risk & Compliance. Our team is highly collaborative and dedicated to protecting Pleos customers and their money. Youll also have the chance to partner with teams across the organisation and to bring less experienced security engineers up with you as the function matures.

What youll be doing

As a Lead Security Operations Engineer you will:

  • Build and own a structured SecOps roadmap grounded in well-known frameworks such as MITRE ATT&CK NIST and CIS benchmarks.

  • Lead security investigations and digital forensics from suspicious traffic through to full incident response and bring the findings back into how we detect and prevent.

  • Design tune and scale our SIEM and logging pipeline through standardized log ingestion across services so signal isnt lost in the noise.

  • Strengthen our perimeter and authentication posture including WAF configuration authorisation tuning and monitoring for suspicious traffic.

  • Protect sensitive data through DLP controls and make sure the coverage matches where the data actually lives.

  • Improve our on-call rotation for the team defining the alerting escalation paths and response SLAs that make it work.

  • Automate detection and response workflows using code and AI to reduce manual toil and shorten time to resolution.

  • Reduce SecOps-attributed risk identified through compliance gaps and collect the evidence that demonstrates it.

  • Build dashboards and reporting that give the team and leadership real visibility into response times coverage and risk reduction.

  • Work cross-functionally with engineers who dont have a security background translating threat models into changes they can actually ship.

What you bring

Youll thrive in this role if you have:

  • 10 years of experience in security operations incident response or a closely related discipline with a proven track record of materialised risk reduction through monetary impact incidents contained forensics that changed outcomes.

  • A strong development and engineering background. You are comfortable writing the automation not just specifying it.

  • Hands-on SOC and SIEM management experience including detection engineering and log pipeline design.

  • Experience in scale-up environments where youve built capability rather than inherited a mature one.

  • A strong understanding of cloud architectures as we use AWS. With part of our estate on GCP and how infrastructure decisions shape detection and response.

  • Demonstrated experience using AI and/or coding automation to get security controls built implemented and operating in practice.

  • Fintech payments fraud or trust & safety experience is a real advantage as is exposure to highly regulated environments.

  • Backgrounds that tend to do well here: incident response IR management SOC engineering security engineering DevSecOps red or blue team.

Why is this role a good fit for you

This role is a good fit for you if:

  • You want a large blast radius. We have high-impact projects where the outcome shows up in real business metrics at a pre-IPO company.

  • Youre energised by building a function rather than maintaining one and youd rather set the roadmap than be handed it.

  • You enjoy raising the bar around you growing a team of specialists and lifting the people already here.

  • Youre equally at home in a threat model discussion and in an editor writing the automation that acts on it.

This role is not a good fit for you if:

  • You need a well-groomed backlog and assigned tasks in order to do your best work.

  • Youd rather stay purely strategic than get hands-on with the tooling.

  • Youre not up for participating in an on-call rotation.

How youll develop in this role

In your first 6 months at Pleo youll:

  • Get deep into Pleos security landscape and our detection coverage our logging estate our cloud footprint to form your own view of where the biggest risks sit.

  • Publish a SecOps roadmap mapped to MITRE NIST and CIS agree with Engineering Risk & Compliance and leadership and start delivering against it.

  • Stand up the on-call rotation and the alert response SLAs that go with it.

  • Ship your first wave of detection and automation improvements and establish the KPIs that show what changed.

Were committed to helping you develop your career whether that means taking on bigger projects stepping into leadership or acquiring new skills. Theres genuine room here for the scope of this role to grow including into people leadership.

The location

Please note: We can hire on a remote hybrid or in-person set-up in any of the locations listed on the advert but you will need to be physically based in the country of your choice with a valid right to work. We are unable to offer visa sponsorship for this role in any of the listed locations.

Show me the benefits!
  • Your own Pleo card (no more out-of-pocket spending!)

  • Lunch is on us for your work days - enjoy catered meals or receive a lunch allowance based on your local office

  • Comprehensive private healthcare - depending on your location coverage options include Vitality Alan or Médis

  • We offer 25-28 days of holiday (depending on your location) public holidays

  • For our Team we offer both hybrid and fully remote working options

  • Option to purchase 5 additional days of holiday through a salary sacrifice

  • We use MyndUp to give our employees access to free mental health and well-being support with great success so far

  • Paid parental leave - we want to make sure that were supportive of families and help you feel that you dont have to compromise your family due to work

The interview process

We want to ensure you are set-up for success and understand what will be expected of you. If your application is successful our interview process is as follows:

  1. Intro call: A 30-minute chat with our Talent Partner to discuss the role and your background.

  2. Hiring Manager interview: a 60-minute conversation covering your experience how you approach security operations and how you communicate.

  3. Technical deep dive: a 60-minute session with two of our SecOps engineers going deep on SIEM detection engineering your coding and automation experience.

  4. Cross-functional interview: a 45-minute conversation with DevSecOps and Engineering leadership on how you work across team boundaries with other senior engineers.

About your application
  • English first. Since its our company language please submit your application in English. Youll be using it a lot if you join us.

  • A fair look for everyone. Our talent team reads every single application to ensure the process is fair. To keep things running smoothly we only accept applications through our systemour support team cant pass on calls or emails.

  • Diversity drives us. We can only reach our goals if our team reflects the world around us. That starts with you hitting apply even if you dont tick every single box. We encourage people from all backgrounds and experiences to join us.

  • Interview at your best. We want you to feel comfortable throughout the process. If you have any accessibility requirements or need a specific format email Well design a process that works for you.

  • Your data is safe. When you apply we process your personal data as a data processor. For more information on how Pleo processes personal data read our Privacy Policy here.

  • Applying for multiple roles Nothing is stopping you and we assess every role independently. However we do look for alignment so make sure you can explain why your interest and experience are right for each specific role.

  • Reapplying. If youre applying for the same role again please wait six months from your last decision before hitting submit.


Required Experience:

IC