FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Staff Security Engineer – Security Operations
Pantheon Platform. Lead end-to-end response for complex and critical incidents, including data breach scenarios, coordinated attacks, and platform-level events .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates extensive expertise in incident response methodology, including NIST 800-61 and SANS PICERL, with a proven track record in leading complex incident management and threat hunting initiatives. Proficient in utilizing AI tools and cloud-native environments to enhance detection and response capabilities.
Highest-signal resume keywords
Incident Response MethodologyMITRE ATT&CK ExpertisePython/Bash ScriptingGoogle SecOps/Chronicle GovernanceCISSP or Equivalent Certification
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Incident ManagementThreat HuntingDetection Logic DevelopmentIncident Response Programme ImprovementData Breach ResponseSeverity FrameworksAutomation Roadmap DevelopmentCloud-Native EnvironmentsAI Tool UtilizationPost-Incident Review
Soft Skills
Excellent CommunicationMentoringStakeholder CoordinationRisk Narrative TranslationTeam Collaboration
Tools & Technologies
Google SecOpsChronicleSIEMSplunkSentinelElasticAI AssistantsLLM ToolingAPIsCloud Platforms
Certifications & Qualifications
CISSPCISMGCIHGCIAGDAT
Industry Keywords
Information SecuritySecurity OperationsIncident ResponseThreat IntelligenceGRCSOC 2GDPRNIS2Red Team ExercisesPurple Team Exercises
Tech Stack
Tools & technologiesAWSCloudGoogle Cloud PlatformPythonSplunk
About the role
Key responsibilities & impact- Lead end-to-end response for complex and critical incidents, including data breach scenarios, coordinated attacks, and platform-level events
- Run incident war rooms and make severity and containment decisions
- Coordinate Engineering, Legal, and executive stakeholders
- Own blameless post-incident reviews
- Define and continuously improve incident response methodology, including severity frameworks, escalation paths, playbooks, runbooks, on-call standards, SLAs, and continuous improvement
- Lead MITRE ATT&CK-mapped threat hunting across cloud, endpoint, and identity surfaces
- Convert hunts and incidents into higher-fidelity, lower-noise detections and response procedures
- Set the automation roadmap for triage, enrichment, investigation, and response
- Use AI tools and LLM workflows to prototype, accelerate investigations, and help build ARES
- Govern Pantheon’s Google SecOps (Chronicle) platform, including detection coverage, log source strategy, data quality, and cost
- Mentor analysts and engineers through incidents, hunts, pairing, reviews, and tabletop exercises
- Translate operational reality into risk narratives and programme-level metrics for senior leadership
- Represent SecOps in architectural and product discussions
- Contribute to threat intelligence priorities, vendor and tooling evaluations, resilience testing, red/purple team exercises, and GRC evidence for SOC 2, GDPR/NIS2, and related obligations
Requirements
What you’ll need- 8+ years in information security with substantial time in security operations
- Demonstrated command of major incidents
- Deep incident response methodology knowledge, including NIST 800-61 / SANS PICERL or equivalent, applied in production
- Track record of building or materially improving an incident response programme
- Expert working knowledge of MITRE ATT&CK and attacker tradecraft
- Proven ability to convert threat hunts and incidents into detection logic and response procedures
- Daily use of AI assistants and LLM tooling; ability to use Claude effectively
- Comfortable with Python/Bash scripting, APIs, and cloud-native environments such as GCP and/or AWS
- CISSP or equivalent depth, such as CISM, GCIH/GCIA/GDAT-class GIAC
- Hands-on enterprise SIEM experience at governance level; Google SecOps/Chronicle strongly preferred, with Splunk, Sentinel, or Elastic acceptable
- Excellent written and verbal communication
- Visa sponsorship is not available at this time
Benefits
Comp & perks- Industry competitive compensation and equity plan
- Robust vacation package with 28 days of holiday
- Private medical and dental coverage
- Life and critical illness insurance
- Attractive workplace pension scheme
- Access to Employee Resource Platform
- Top-of-line equipment
- Monthly allowance for wellness and reading
- Access to LinkedIn Learning for continued development
- Team-based and company-wide events and activities