Security Operations Lead

Posted 11 Days Ago
Be an Early Applicant
Geneva, Genève, CHE
In-Office
Mid level
Logistics • Transportation • Energy • Financial Services
The Role
Leads a distributed global SOC, overseeing analysts, operating procedures, outsourced SOC performance, detection engineering, threat intelligence, and L2/L3 incident response. Develops playbooks, conducts investigations and post-incident reviews, partners with red and purple teams, improves MITRE ATT&CK coverage, and mentors cybersecurity staff. Coordinates with IT, Legal, Compliance, and business stakeholders while reporting security metrics and risk trends to senior leadership.
Summary Generated by Built In
Company Description

Vitol is an energy and commodities company with revenues of $331 billion in 2024; its primary business is the trading and distribution of energy products globally – it trades over seven million barrels per day of crude oil and products and, at any time, has 250 ships transporting its cargoes.

Vitol’s clients include national oil companies, multinationals, leading industrial companies and utilities. Founded in Rotterdam in 1966, today Vitol serves clients from some 40 offices worldwide and is invested in energy assets globally including 24mM3 of storage, 850kbpd of refining capacity, and 10,000 service stations. To date, we have committed over $2.5 billion of capital to renewable projects and are identifying and developing low-carbon opportunities around the world.

Job Description

We are seeking an experienced Security Operations Lead to build, manage, and continuously improve our internal Security Operations Centre (SOC). Based in Geneva or London, this role combines hands-on cyber defense with team leadership across three global offices (Singapore, London, and Houston). The ideal candidate is a technically proficient cybersecurity professional who can operate as both a senior incident handler (L2/L3) and a people leader shaping our detection and response capabilities.

KEY RESPONSIBILITIES

SOC Leadership & Governance

  • Lead a team of 4 SOC analysts/engineers distributed across Singapore, London, and Houston, ensuring 24/7 coverage alignment and consistent service quality.
  • Define and enforce SOC operating procedures, escalation paths, shift handover protocols, and performance metrics (MTTD, MTTR, false-positive rate).
  • Report on SOC performance, threat landscape trends, and risk posture to the CISO and senior stakeholders.
  • Manage the external SOC relationship — act as the primary interface with the outsourced SOC provider, govern service performance, drive continuous improvement, and ensure alignment with internal security objectives.

Detection Engineering & Threat Management

  • Own the detection engineering lifecycle: develop, tune, and maintain analytics rules, correlation logic, and custom detections in Microsoft Sentinel (KQL) and across the broader security stack.
  • Continuously improve detection coverage mapped to MITRE ATT&CK, reducing blind spots and noise.
  • Evaluate and integrate threat intelligence feeds to enrich alerts and drive proactive hunting.

Incident Response & Hands-on Operations

  • Act as a senior incident responder (L2/L3), leading triage, investigation, containment, eradication, and recovery for complex security incidents.
  • Coordinate cross-functional incident response with IT, Legal, Compliance, and business units.
  • Conduct post-incident reviews and root-cause analysis; translate findings into detection improvements and process updates.

Playbook & Process Development

  • Author, maintain, and test SOC playbooks and runbooks covering the full incident lifecycle (phishing, malware, insider threat, cloud compromise, ransomware, BEC, data exfiltration, etc.).
  • Improve existing playbooks and create new ones based on emerging threats, red team findings, and lessons learned.
  • Drive tabletop exercises and purple-team simulations to validate playbook effectiveness.

Red Team Collaboration & Purple Teaming

  • Partner with the internal Red Team to translate adversary emulation results into actionable detection rules and response procedures.
  • Participate in purple-team exercises, validating detection coverage and tuning alerts based on simulated attack paths.

Training & Capability Development

  • Mentor and develop SOC team members through structured training plans, knowledge-sharing sessions, and hands-on coaching.
  • Foster a culture of continuous improvement and professional growth across the distributed team.

Qualifications

Experience & Education

  • 4+ years of progressive experience in cybersecurity operations, incident response, or security engineering.
  • Demonstrated experience leading or managing a SOC team, including remote/distributed personnel.
  • Strong understanding of SOC operating models (tiered, hybrid, follow-the-sun).
  • Proven track record of building or significantly improving detection and response capabilities.

Technical Expertise

  • SIEM & Analytics: Microsoft Sentinel (KQL), log source onboarding, analytics rule development, workbook/dashboard creation.
  • Endpoint Security: Microsoft Defender for Endpoint (MDE), CrowdStrike Falcon (EDR/XDR).
  • Cloud Security: AWS (GuardDuty, CloudTrail, Security Hub) and Microsoft Azure (Defender for Cloud, Entra ID Protection); Wiz for cloud security posture management (CSPM).
  • Data Security & DLP: Microsoft Purview (DLP, Information Protection, Insider Risk), Varonis (data access governance, threat detection).
  • Network & Web Security: Zscaler (ZIA/ZPA), Palo Alto Networks (NGFW, Panorama, Cortex).
  • Incident Response: Digital forensics fundamentals, malware analysis, memory/disk acquisition, chain-of-custody practices.
  • Frameworks: MITRE ATT&CK, NIST CSF, NIST 800-61 (Incident Handling).

Soft Skills & Leadership

  • Excellent communication and stakeholder management skills; ability to translate technical findings for executive audiences.
  • Strong organisational and project-management abilities to coordinate across time zones.
  • Analytical mindset with attention to detail and a bias for action.
  • Preferred qualifications
  • Industry certifications: CISSP, CISM, GCIH, GCIA, GCED, SC-200, AZ-500, or equivalent.
  • Experience in the commodity trading, energy, or financial services sector.
  • Familiarity with automation and orchestration (SOAR) platforms, scripting (Python, PowerShell, KQL).
  • Experience with threat hunting methodologies and tools.
  • French language skills (advantageous for Geneva-based candidates).

Travel

  • Periodic travel between Geneva and London offices; occasional travel to Singapore and Houston for team engagement and alignment

Skills Required

  • 4+ years of progressive experience in cybersecurity operations, incident response, or security engineering
  • Experience leading or managing a SOC team, including remote or distributed personnel
  • Strong understanding of tiered, hybrid, and follow-the-sun SOC operating models
  • Proven experience building or significantly improving detection and response capabilities
  • Experience with Microsoft Sentinel, KQL, log source onboarding, analytics rules, and workbooks or dashboards
  • Experience with Microsoft Defender for Endpoint and CrowdStrike Falcon
  • Experience with AWS GuardDuty, CloudTrail, Security Hub, Microsoft Azure, Defender for Cloud, and Entra ID Protection
  • Experience with Wiz, Microsoft Purview, Varonis, Zscaler, and Palo Alto Networks security tools
  • Digital forensics fundamentals, malware analysis, memory and disk acquisition, and chain-of-custody practices
  • Knowledge of MITRE ATT&CK, NIST CSF, and NIST 800-61
  • Excellent communication and stakeholder management skills, including explaining technical findings to executives
  • Strong organizational and project-management abilities across time zones
  • CISSP, CISM, GCIH, GCIA, GCED, SC-200, AZ-500, or equivalent certification
  • Experience in commodity trading, energy, or financial services
  • Familiarity with SOAR platforms, Python, PowerShell, KQL, threat hunting methodologies, and tools
  • French language skills
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Geneva
1,800 Employees
Year Founded: 1966

What We Do

Vitol is a global energy and commodities company that trades and distributes energy safely and responsibly, utilizing its logistical expertise and infrastructure network. It operates across the energy spectrum, including oil, gas, power, renewables, and metals.

Similar Jobs

Pfizer Logo Pfizer

Digital Operations Agentic Lead - Senior Manager

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Remote or Hybrid
29 Locations
121990 Employees

Takeda Logo Takeda

Account Manager

Healthtech • Software • Analytics • Biotech • Pharmaceutical • Manufacturing
Remote or Hybrid
CHE
50000 Employees
130K-178K Annually
Hybrid
2 Locations
289097 Employees

Pfizer Logo Pfizer

Senior Manager, HTA, Value and Evidence (HV&E), Genitourinary Cancer

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
In-Office or Remote
30 Locations
121990 Employees
139K-232K Annually

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Ford Energy Thumbnail
Automotive • Software • Energy • Utilities • Manufacturing • Renewable Energy
US
55 Employees
Vega Thumbnail
Artificial Intelligence • Automotive • Insurance • Transportation
US
65 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account