Senior Information Security Engineer
Job Summary
Purpose
The Senior Information Security Engineer is a senior technical and leadership role within IFSs global Security Operations Center (SOC) responsible for driving advanced threat detection deep-dive investigation and major cyber incident response across a fast-growing global SaaS business. This role combines hands-on operational excellence with a mandate to mature the SOC itself leading capability-building and transformation initiatives that scale detection engineering automation and analyst tooling in step with IFSs growth. The Senior Information Security Engineer acts as the senior escalation point for high-priority incidents mentors and uplifts Tier 1/2 analysts and brings a genuinely curious investigative mindset to uncovering and closing gaps in the organizations defensive posture.
Summary
IFS is seeking an experienced and highly curious Senior Information Security Engineer to strengthen its global Security Operations Center. Reporting to the SOC Manager this role is central to detecting investigating and responding to advanced threats across a fast-scaling global SaaS estate while also leading the ongoing transformation and maturity uplift of the SOC function itself.
We are looking for someone who has thrived in a fast-growth organization and is comfortable building process and capability from a lower level of maturity and confident designing the detection engineering automation and reporting foundations that a scaling security function needs. You will be very familiar with responding to cyber incidents and will experience leading major cyber incident responses bringing the calm structured leadership that high-pressure investigations demand.
This position suits a technically strong and curious security professional who enjoys digging beneath the alert to understand root cause who takes ownership of SOC transformation initiatives and who can mentor and elevate the analysts around them.
Key Responsibilities:
- Major Incident Response & Leadership: Lead and coordinate the end-to-end response to high-priority and major cyber incidents acting as senior technical authority and calm decision-maker under pressure from triage through containment eradication and post-incident review.
- Deep-Dive Investigation & Threat Validation: Perform advanced forensic analysis malware and log investigation and root-cause assessment applying a naturally curious hypothesis-driven approach to uncover threats others might miss.
- SOC Capability Development & Transformation: Design lead and deliver SOC maturity and transformation initiatives from detection engineering and use-case development to workflow automation tooling consolidation and process redesign drawing on proven experience building SOC capability within a fast-growth organization.
- Threat Detection Engineering: Build tune and continuously improve SIEM detection logic alerting and correlation rules (preferably Microsoft Sentinel) to reduce false positives and improve signal quality.
- Proactive Threat Hunting: Conduct intelligence-led threat hunts using MITRE ATT&CK and emerging TTPs identifying gaps in detection coverage before they can be exploited.
- Automation & AI Enablement: Champion the use of automation SOAR playbooks and AI-assisted tooling to increase SOC efficiency and free analysts for higher-value investigative work.
- Vulnerability & Risk Management: Support vulnerability scanning risk-based prioritization and remediation tracking across the environment.
- Runbooks Documentation & Quality: Own the creation and continuous improvement of incident and detection runbooks ensuring documentation quality and consistency across the SOC.
- Team Development & Mentorship: Act as an escalation point and mentor for Tier 1/2 analysts coaching investigative technique structured incident handling and a culture of curiosity.
- Governance Metrics & Reporting: Contribute to SOC KPI reporting and ISMS audit readiness and support the continuous improvement of SOC policies and standards translating technical findings into clear reporting for stakeholders.
- Tooling & Vendor Input: Maintain deep proficiency across SOC tooling (SIEM EDR SOAR cloud security) and contribute to tooling strategy renewals and annual security budget planning as the SOC scales.
Qualifications :
Essential:
- 5 years of experience within a Security Operations Center (SOC) or Cyber Defense function including demonstrable experience operating within a fast-growth or rapidly scaling organization.
- Proven track record of developing SOC capability and delivering SOC transformation or maturity programs (e.g. detection engineering automation process redesign tooling consolidation).
- Hands-on experience leading major or high-priority cyber incident response from initial triage through to executive-level post-incident reporting.
- Strong hands-on expertise with SIEM (preferably Microsoft Sentinel) EDR (e.g. Microsoft Defender for Endpoint) and SOAR platforms.
- Advanced analytical and investigative mindset with a genuine demonstrable curiosity for understanding root cause and emerging threat techniques.
- Strong forensics and security analysis skills with the ability to make sound well-informed decisions with minimal supervision under pressure.
- Excellent written and verbal communication skills including the ability to brief non-technical and executive stakeholders during live incidents.
- Degree in Cyber Security Information Technology Computer Science or a related field or equivalent demonstrable experience.
Desirable:
- Experience with SOC automation AI-enhanced detection and response KQL analysis scripting or Python.
- Exposure to threat intelligence platforms and structured frameworks such as MITRE ATT&CK.
- Familiarity with cloud security (Azure/AWS) and modern cyber defense methodologies.
- Experience mentoring or leading junior analysts within a SOC environment.
Relevant certifications such as CISSP CISM GCIH GCIA CEH Azure SC-200/AZ-500 or equivalent blue-team certifications.
Why Join Us
Opportunity to shape and lead the transformation of a growing global SOC function with a clear path toward Lead Security Engineer and SOC leadership roles.
Exposure to enterprise-grade security platforms and global cyber defense operations across a fast-growth SaaS business.
A collaborative high-performance culture where curiosity ownership and continuous improvement are genuinely valued.
Competitive salary certification sponsorship and career development.
For general information about IFS Applications visit
Additional Information :
We embrace flexibility and hybrid work opportunities to support diverse needs and lifestyles while also valuing inclusive workplace experiences. By fostering a sense of community we drive innovation strengthen connections and nurture belonging. Our commitment ensures you can work in a way that suits you best while also engaging with colleagues to share ideas and build meaningful relationships.
Remote Work :
No
Employment Type :
Full-time
About Company
We are growing! At IFS we are constantly growing to deliver award-winning solutions to hundreds of partners and thousands of customers worldwide! We help companies who want to be their best when it matters most at their #momentofservice. Visit https://ifs.link/IzM0px to find out mo ... View more