- Experience
- 10+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 4 तासपूर्वी
- Work mode
- Work from home
- Resume
- Required to apply
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About Pantheon
Pantheon is a WebOps platform designed to empower developers, IT professionals, and marketers to build, test, and release websites that deliver exceptional results. We believe in making the power of the internet accessible to all, driven by values of Trust, Teamwork, Passion, and Customers First. We also embrace individuality, humor, and a healthy work-life balance, contributing actively to open-source communities.
Role Overview
As a Staff Security Engineer in Security Operations (SecOps), you will serve as both a strategic and hands-on leader, guiding and executing Pantheon's security operations vision. Your responsibilities will span defining long-term detection and response strategies, driving operational resilience, and mentoring the engineering organization on security practices. You will take ownership of the SecOps maturity roadmap and ensure alignment across Engineering, Infrastructure, Governance, Risk & Compliance (GRC), and executive leadership. Additionally, you will be the primary expert on EU regulatory requirements such as NIS2 and GDPR, ensuring Pantheon’s operational controls meet required standards for Ireland and Europe.
Key Responsibilities
- Develop and carry out a comprehensive, multi-year plan for Pantheon's security operations capabilities including detection engineering, incident response, threat intelligence, exposure management, and abuse prevention.
- Lead the design and maintenance of Pantheon's SecOps architecture—overseeing tools like SIEM, SOAR, EDR/XDR, cloud security posture, and identity monitoring platforms to ensure scalability and operational efficiency.
- Manage the threat detection program by creating precise, low-noise detection rules aligned with MITRE ATT&CK across cloud, endpoint, and identity surfaces.
- Oversee the entire incident response lifecycle, including playbooks, runbooks, severity frameworks, and post-incident reviews, while serving as the escalation point for complex cases.
- Develop and operate a structured threat intelligence program to consume and act upon intelligence from various sources to guide detection and response strategies.
- Architect automation for alert triage, enrichment, investigation, and response using SOAR, APIs, and scripting, raising the engineering standards of the SecOps tooling.
- Act as the SecOps authority on EU regulations (GDPR, NIS2) partnering with legal and GRC teams to meet audit and compliance requirements such as SOC 2, PCI DSS, and NIST CSF.
- Define and direct vulnerability and exposure management strategies, reducing remediation times through automation and clear ownership.
- Lead abuse and fraud prevention efforts with strategies addressing credential attacks, account takeovers, and platform misuse.
- Participate in business continuity and disaster recovery efforts, including designing and facilitating resilience exercises and red team collaborations.
- Communicate program metrics, risks, and strategic updates effectively to senior leadership and board members translating technical detail into business risk language.
- Mentor engineers, lead security training programs, and embed security mindset throughout the engineering teams via guidance and consultation.
Essential Qualifications and Experience
- Over 10 years of professional experience in information security, including at least 7 years in security operations, covering detection engineering, incident response, threat hunting, or SecOps leadership.
- Proven expertise in designing and managing enterprise-grade SIEM and SOAR solutions at scale (e.g., Chronicle, Splunk, Elastic SIEM, Palo Alto XSOAR, Tines).
- Hands-on experience with cloud-native security in GCP and/or AWS, including logging pipelines, cloud security posture management, and identity access management.
- Advanced knowledge of attack methodologies and threat actor behaviors such as MITRE ATT&CK and MITRE D3FEND and ability to develop corresponding detection and response mechanisms.
- Experienced incident response leader with skills in stakeholder management, war room coordination, and continuous improvement post incidents.
- Proficient in scripting and automation (Python, Bash, or similar) for solving security engineering challenges beyond simple tool configurations.
- Background in managing EU regulatory compliance from an operational security standpoint, particularly GDPR and NIS2.
- Ability to influence and collaborate across teams through design reviews, documentation, and program leadership.
- Strong verbal and written communication skills capable of articulating technical risks to a variety of audiences including executive management.
Preferred Skills and Background
- Certifications such as CISSP, CISM, GIAC (GCIA, GCED, GREM, GDAT), OSCP, or cloud security specialties like GCP Professional Cloud Security Engineer or AWS Security Specialty.
- Experience launching or scaling a detection engineering program with established metrics and continuous improvement methods.
- Familiarity with threat intelligence platforms (e.g., Recorded Future, Mandiant Advantage) and intelligence lifecycle management.
- Knowledge of abuse monitoring, phishing detection, and coordination with registrars, hosting providers, and law enforcement takedown processes.
- Experience with bug bounty programs and red team/purple team collaboration to validate detection coverage.
- Track record managing vendor relationships, conducting RFPs, and making build-versus-buy decisions for security tooling.
- Prior experience working within the Irish or EU regulatory landscape, including knowledge of the Data Protection Commission, NIS2 obligations, and ENISA guidance.
Work Arrangement and Additional Information
This position is based in Ireland and is fully remote within the country. Pantheon's distributed engineering culture primarily collaborates across North America and Europe, requiring flexibility for meetings and incident responses spanning multiple time zones. Employment fully complies with Irish labor laws including statutory leave and is compensated according to Irish market standards.
Level
Mid