Senior Information Security Engineer
Job Description
Purpose
The Senior Information Security Engineer is a senior technical and leadership role within IFS’s global Security Operations Center (SOC), responsible for driving advanced threat detection, deep-dive investigation and major cyber incident response across a fast-growing, global SaaS business. This role combines hands-on operational excellence with a mandate to mature the SOC itself – leading capability-building and transformation initiatives that scale detection engineering, automation and analyst tooling in step with IFS’s growth. The Senior Information Security Engineer acts as the senior escalation point for high-priority incidents, mentors and uplifts Tier 1/2 analysts, and brings a genuinely curious, investigative mindset to uncovering and closing gaps in the organization’s defensive posture.
Summary
IFS is seeking an experienced and highly curious Senior Information Security Engineer to strengthen its global Security Operations Center. Reporting to the SOC Manager, this role is central to detecting, investigating and responding to advanced threats across a fast-scaling, global SaaS estate, while also leading the ongoing transformation and maturity uplift of the SOC function itself.
We are looking for someone who has thrived in a fast-growth organization and is comfortable building process and capability from a lower level of maturity, and confident designing the detection engineering, automation and reporting foundations that a scaling security function needs. You will be very familiar with responding to cyber incidents and will experience leading major cyber incident responses, bringing the calm, structured leadership that high-pressure investigations demand.
This position suits a technically strong, and curious security professional who enjoys digging beneath the alert to understand root cause, who takes ownership of SOC transformation initiatives, and who can mentor and elevate the analysts around them.
Key Responsibilities:
• Major Incident Response & Leadership: Lead and coordinate the end-to-end response to high-priority and major cyber incidents – acting as senior technical authority and calm decision-maker under pressure, from triage through containment, eradication and post-incident review.
• Deep-Dive Investigation & Threat Validation: Perform advanced forensic analysis, malware and log investigation, and root-cause assessment, applying a naturally curious, hypothesis-driven approach to uncover threats others might miss.
• SOC Capability Development & Transformation: Design, lead and deliver SOC maturity and transformation initiatives – from detection engineering and use-case development to workflow automation, tooling consolidation and process redesign – drawing on proven experience building SOC capability within a fast-growth organization.
• Threat Detection Engineering: Build, tune and continuously improve SIEM detection logic, alerting and correlation rules (preferably Microsoft Sentinel) to reduce false positives and improve signal quality.
• Proactive Threat Hunting: Conduct intelligence-led threat hunts using MITRE ATT&CK; and emerging TTPs, identifying gaps in detection coverage before they can be exploited.
• Automation & AI Enablement: Champion the use of automation, SOAR playbooks and AI-assisted tooling to increase SOC efficiency and free analysts for higher-value investigative work.
• Vulnerability & Risk Management: Support vulnerability scanning, risk-based prioritization and remediation tracking across the environment.
• Runbooks, Documentation & Quality: Own the creation and continuous improvement of incident and detection runbooks, ensuring documentation quality and consistency across the SOC.
• Team Development & Mentorship: Act as an escalation point and mentor for Tier 1/2 analysts, coaching investigative technique, structured incident handling and a culture of curiosity.
• Governance, Metrics & Reporting: Contribute to SOC KPI reporting and ISMS audit readiness, and support the continuous improvement of SOC policies and standards, translating technical findings into clear reporting for stakeholders.
• Tooling & Vendor Input: Maintain deep proficiency across SOC tooling (SIEM, EDR, SOAR, cloud security) and contribute to tooling strategy, renewals and annual security budget planning as the SOC scales.
Requirements
Department: Information Services
Function: Information Technology
Experience Level: Executive