Staff Security Engineer - Security Operations

Posted One Month Ago
Be an Early Applicant
Hiring Remotely in United Kingdom
Remote
Expert/Leader
Marketing Tech
The Role
Lead Pantheon's security operations strategy and roadmap, including SIEM/SOAR architecture, threat detection, incident response, threat intelligence, automation, vulnerability and abuse management, and operational resilience. Own security operations compliance for GDPR, NIS2, SOC 2, PCI DSS, and NIST CSF. Lead major incident response, executive reporting, cross-functional initiatives, and mentorship while remaining hands-on with cloud-native security, detection engineering, and security automation.
Summary Generated by Built In
About Pantheon

Pantheon is the WebOps platform for websites that deliver extraordinary results. We believe in putting the magic of the internet in everyone's hands. That's why we're so passionate about helping developers, IT, and marketing develop, test, and release website changes faster and more reliably.

Pantheon's core values are Trust, Teamwork, Passion, and Customers First. We value individuality, humour, and balance, and we actively contribute to open-source communities. If you're ready to be the incident authority for a platform that ships critical infrastructure for hundreds of thousands of sites, this is your role.

The Role

As a Staff Security Engineer, SecOps, you are the technical anchor of Pantheon's security operations function — and above all, the person we trust to command our hardest incidents. When something serious happens, you set the tempo: scoping, severity, containment strategy, stakeholder communication, and the post-incident work that makes us stronger every time.

This is a staff-level role, which means your impact extends well beyond your own queue. You define the incident response methodology the whole team runs on, you turn every incident and hunt into better detections in partnership with Security Engineering, and you set the direction for what our automation should do next. We are an AI-forward security team: our SOAR capability already exists inside Google SecOps, and we are building ARES, our AI-assisted incident response platform. We are not hiring you to program SOAR playbooks — our L4–L6 engineers own that. We're hiring you to bring the incident judgment that tells ARES what to automate, and the AI fluency to prototype it yourself with tools like Claude.

The engineers who thrive here come from engineering-shaped backgrounds — people who script, automate, read code, and learn new systems on their feet — and pair that with deep, tested incident response craft.

What You'll Do
  • Command major incidents. Lead response for our most complex and critical incidents end-to-end — data breach scenarios, coordinated attacks, platform-level events. Run the war room, make the severity and containment calls, coordinate Engineering, Legal, and executive stakeholders, and own the blameless post-incident review.
  • Own incident response methodology. Define and continuously improve the IR programme the team operates against: severity frameworks, escalation paths, playbooks and runbooks, on-call standards, SLAs, and the continuous-improvement loop that follows every incident. You are accountable for how Pantheon responds — not just that it responds.
  • Drive the hunting → detection feedback loop. Lead hypothesis-driven threat hunting mapped to MITRE ATT&CK across cloud, endpoint, and identity surfaces, and make sure every hunt and every incident feeds back into higher-fidelity, lower-noise detections in partnership with Security Engineering. Establish the methodology and coverage standards the team measures itself by.
  • Direct AI-assisted automation (ARES). Set the automation roadmap for triage, enrichment, investigation, and response based on what incidents actually demand. Use AI tools (Claude, LLM workflows) daily to prototype, accelerate investigations, and help build ARES — bringing the operator's judgment that turns automation from a demo into a force multiplier.
  • Govern the SIEM platform. Own governance of Pantheon's Google SecOps (Chronicle) platform — detection coverage, log source strategy, data quality, and cost — while the team handles day-to-day ingestion and connector work. Keep the platform aligned to how we actually detect and respond.
  • Level up the team. Mentor analysts and engineers through real incidents and hunts — pairing, review, and tabletop exercises. Set the technical bar for how SecOps investigates, documents, and improves.
  • Communicate up. Translate operational reality into risk narratives and programme-level metrics for senior leadership, and represent SecOps in architectural and product discussions.
  • Support the broader programme. Contribute operator judgment to threat intelligence priorities, vendor and tooling evaluations, resilience testing and red/purple team exercises, and partner with GRC on operational evidence for SOC 2, GDPR/NIS2, and related obligations.
What You Bring to the Table
  • 8+ years in information security with substantial time in security operations, including demonstrated command of major incidents — you can walk us through your methodology (scoping, severity, containment, communication, post-incident review), not just war stories.
  • Deep incident response methodology knowledge (NIST 800-61 / SANS PICERL or equivalent, applied in production, not just certified) and a track record of building or materially improving an IR programme: playbooks, severity frameworks, escalation paths, PIR discipline.
  • Threat hunting and detection craft: expert working knowledge of attacker tradecraft (MITRE ATT&CK) and proven ability to convert hunts and incidents into detection logic and response procedures.
  • AI fluency: you use AI assistants and LLM tooling in your daily workflow today, and you're excited to apply them to investigation and response. If you can use Claude well, you can help us build ARES.
  • An engineering mindset: comfortable with Python/Bash scripting, APIs, and cloud-native environments (GCP and/or AWS) — enough to prototype, automate, and hold your own in engineering design discussions. You learn new systems on your feet.
  • CISSP (or equivalent depth — CISM, GCIH/GCIA/GDAT-class GIAC) demonstrating breadth across the security domains this role touches.
  • Hands-on experience operating an enterprise SIEM (Google SecOps/Chronicle strongly preferred; Splunk, Sentinel, or Elastic acceptable) at governance level — coverage, log strategy, quality — not just query writing.
  • Excellent written and verbal communication: you can brief an executive during an incident and write the PIR the team actually learns from.
Preferred Experience
  • Incident command experience in a cloud-native or hosting/platform environment.
  • Building or scaling a detection engineering programme, including coverage metrics and a continuous-improvement cadence.
  • Threat intelligence operationalisation — turning internal telemetry and external feeds into detection and response priorities.
  • Red team / purple team collaboration to validate detection coverage; tabletop design and facilitation.
  • Operational exposure to EU/UK regulatory environments (GDPR, NIS2, DPC/ENISA guidance) and audit frameworks (SOC 2, PCI DSS, NIST CSF).
  • Experience evaluating security vendors and making build-vs-buy recommendations.
What We Offer

We have all the usual perks and benefits, but what we can really offer you is a fantastic work environment powered by an amazing team.

  • Industry competitive compensation and equity plan
  • Robust vacation package with 28 days of holiday
  • Private medical and dental coverage
  • Life and critical illness insurance
  • Attractive workplace pension scheme
  • Access to Employee Resource Platform
  • Top-of-line equipment
  • Monthly allowance for wellness, reading, and access to LinkedIn Learning for continued development
  • Events and activities, both team-based and company-wide, that inspire, educate, and cultivate

Pantheon is an equal opportunity employer and we welcome applications from all backgrounds regardless of race, color, religion, sex, national origin, ancestry, age, marital status, sexual orientation, gender identity, veteran status, disability, or any other classification protected by law. Pantheon complies with federal and local disability laws and makes reasonable accommodations for applicants and employees with disabilities. If you need a reasonable accommodation due to a disability for any part of the interview process, please contact [email protected].

To review the Employee and Applicant's Privacy Policy, click here.

Visa Sponsorship is not available at this time.


Skills Required

  • 10+ years of experience in information security
  • 7+ years focused on security operations, including detection engineering, incident response, threat hunting, or SecOps program leadership
  • Expertise architecting and operating enterprise-grade SIEM and SOAR platforms at scale
  • Hands-on cloud-native security experience with GCP and/or AWS, including logging pipelines, cloud security posture management, and IAM monitoring
  • Expert-level knowledge of attack techniques, threat actor tradecraft, MITRE ATT&CK, and MITRE D3FEND
  • Experience leading major incident response, cross-functional war rooms, and post-incident improvement
  • Proficiency in Python, Bash, or equivalent scripting and automation
  • Experience with EU regulatory compliance requirements, including GDPR and NIS2, from an operational security perspective
  • Experience influencing technical direction through design reviews, architecture documents, or cross-functional program leadership
  • Excellent written and verbal communication skills for technical and executive audiences
  • Security certification such as CISSP, CISM, GIAC, OSCP, GCP Professional Cloud Security Engineer, or AWS Security Specialty
  • Experience building or scaling a detection engineering program from the ground up
  • Hands-on experience with threat intelligence platforms such as Recorded Future or Mandiant Advantage
  • Experience with abuse monitoring, phishing detection, and takedown coordination
  • Exposure to bug bounty operations and red team or purple team collaboration
  • Experience managing security vendors, running RFPs, and making build-versus-buy decisions
  • Experience in the Irish or EU regulatory environment, including DPC, NIS2, or ENISA guidance
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
San Francisco, CA
322 Employees
Year Founded: 2010

What We Do

At Pantheon, we're building the world's best WebOps (Website Operations) platform - one that empowers marketing and development teams to take control of their websites, while giving them the agility to win in the dynamic world of digital marketing. Our mission is to make the web a first-class platform that delivers results.

Similar Jobs

UL Solutions Logo UL Solutions

Compliance Analyst

Automotive • Professional Services • Software • Consulting • Energy • Chemical • Renewable Energy
Remote or Hybrid
United Kingdom
15000 Employees

Samsara Logo Samsara

Regional Sales Director, Strategic Enterprise - UK

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
United Kingdom
4000 Employees

Atlassian Logo Atlassian

Senior Solution Engineer, Strategic, UKI

Cloud • Information Technology • Productivity • Security • Software • App development • Automation
Remote
United Kingdom
11000 Employees
Remote
2 Locations
125 Employees
215K-235K Annually

Similar Companies Hiring

MFour Data Research Thumbnail
Marketing Tech • Software
Irvine, CA
98 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account