about the company
A fast-growing technology company with a strong focus on innovation, digital platforms and cloud technologies. The organisation is expanding its cybersecurity capabilities and is looking for a hands-on security professional to strengthen its Security Operations and Offensive Security functions.
...
about the job
We are looking for a Senior Security Operations Engineer / Security Architect to take ownership of security monitoring, threat detection, incident response and offensive security across a multi-cloud environment.
This is a hands-on technical role that goes beyond traditional SOC operations. You will conduct penetration testing, attack simulation and vulnerability exploitation while also strengthening detection capabilities and translating real-world attack techniques into effective defensive controls.
Key responsibilities:
• Conduct penetration testing and proactive offensive security testing across Web, API, mobile, cloud and infrastructure environments
• Identify realistic attack paths and validate vulnerabilities beyond automated scanning
• Perform Red Team / Purple Team / attack simulation exercises
• Develop PoCs, scripts and exploit scenarios to demonstrate security weaknesses
• Monitor and investigate security alerts using SIEM and log analytics platforms
• Develop and tune detection rules to improve threat detection and reduce false positives
• Lead end-to-end Incident Response, including investigation, containment, eradication, recovery and post-mortem
• Translate offensive security findings and attacker techniques into practical detection, prevention and response controls
• Develop SOAR and security automation workflows to automate repetitive response activities
• Integrate and analyse security logs across multiple cloud and security platforms
• Operate and optimise cloud security capabilities including WAF and native cloud security controls
• Work closely with Engineering and Product teams on security reviews, attack vectors and secure-by-design initiatives
• Participate in an on-call rotation for critical security incidents