About Pleo Messy spend management is tricky business. And tedious processes are a lose-lose situation for all involved, not just finance. We build spend solutions that make managing money seamless, empowering, and surprisingly effective for finance teams and employees alike - with a vision to help all businesses 'go beyond'.
About Pleo
Messy spend management is tricky business. And tedious processes are a lose-lose situation for all involved, not just finance. We build spend solutions that make managing money seamless, empowering, and surprisingly effective for finance teams and employees alike - with a vision to help all businesses 'go beyond'. With great ambitions driving us forward, we can't say we've got this whole thing figured out.
About The Role Were looking for a Lead Security Operations Engineer to join our Cybersecurity team at Pleo. If youre excited about owning a security operations function end to end, from framework-based strategy through to the code that makes it run, then this is the opportunity for you!
Who Youll Be Working With And
Reporting To Youll report to our VP of Fraud & Security and work closely with Fraud, DevSecOps, Engineering, and Risk & Compliance. Youll also have the chance to partner with teams across the organisation and to bring less experienced security engineers up with you as the function matures. Lead security investigations and digital forensics, from suspicious traffic through to full incident response, and bring the findings back into how we detect and prevent.
Strengthen our perimeter and authentication posture, including WAF configuration, authorisation tuning, and monitoring for suspicious traffic. Protect sensitive data through DLP controls, and make sure the coverage matches where the data actually lives. Improve our on-call rotation for the team, defining the alerting, escalation paths,
and response SLAs that make it work.
Reduce
SecOps-attributed risk identified through compliance gaps, and collect the evidence that demonstrates it. Work cross-functionally with engineers who dont have a security background, translating threat models into changes they can actually ship.
What You
Bring 10+ years of experience in security operations, incident response, or a closely related discipline, with a proven track record of materialised risk reduction through monetary impact, incidents contained, forensics that changed outcomes. A strong development and engineering background. You are comfortable writing the automation, not just specifying it.
Hands-on SOC and SIEM management experience, including detection engineering and log pipeline design. A strong understanding of cloud architectures as we use AWS. Demonstrated experience using AI and/or coding automation to get security controls built, implemented, and operating in practice.
Backgrounds that tend to do well here: incident response, IR management, SOC engineering, security engineering, DevSecOps, red or blue team. We have high-impact projects where the outcome shows up in real business metrics, at a pre-IPO company. Youre energised by building a function rather than maintaining one, and youd rather set the roadmap than be handed it. Youre equally at home in a threat model discussion and in an editor writing the automation that acts on it.
How Youll Develop In This Role
Get deep into Pleos security landscape and our detection coverage, our logging estate, our cloud footprint to form your own view of where the biggest risks sit. Publish a SecOps roadmap mapped to MITRE, NIST, and CIS, agree with Engineering, Risk & Compliance, and leadership, and start delivering against it. Stand up the on-call rotation and the alert response SLAs that go with it.
Ship your first wave of detection and automation improvements, and establish the KPIs that show what changed. Were committed to helping you develop your career, whether that means taking on bigger projects, stepping into leadership, or acquiring new skills. We can hire on a remote, hybrid or in-person set-up in any of the locations listed on the advert but you will need to be physically based in the country of your choice with a valid right to work.
We are unable to offer visa sponsorship for this role in any of the listed locations. Lunch is on us for your work days - enjoy catered meals or receive a lunch allowance based on your local office We offer 25-28 days of holiday (depending on your location) + public holidays For our Team, we offer both hybrid and fully remote working options Option to purchase 5 additional days of holiday through a salary sacrifice A 30-minute chat with our Talent Partner to discuss the role and your background.
Hiring Manager interview: a 60-minute conversation covering your experience, how you approach security operations, and how you communicate.
Technical deep dive: a 60-minute session with two of our SecOps engineers, going deep on SIEM, detection engineering, your coding and automation experience. Cross-functional interview: a 45-minute conversation with DevSecOps and Engineering leadership on how you work across team boundaries with other senior engineers. #
📌 Lead Security Operations Engineer (Madrid)
🏢 Pleo
📍 Madrid