Senior SecOps Specialist

Há 2 dias

Porto, Portugal Teya Tempo integral 60 000 € - 90 000 € Contrato

Hello. We're Teya.

Teya was founded on a simple belief: local businesses deserve better.

They are the cafés, restaurants, salons, shops and entrepreneurs that bring character to our high streets, create jobs and keep communities moving. Yet for too long, financial services has made life harder for them - with clunky tools, poor support and complexity that gets in the way of running a business.

Teya exists to change that.

We're building a financial platform for local businesses across Europe - one built around simple tools, thoughtful design and real human support. Our Members rely on us to help them run their business with confidence, and that responsibility shapes the way we work.

We move fast. We care about quality. We stay close to the detail. And we believe great performance and genuine hospitality should go hand in hand.

If you want to build meaningful products, solve real problems and make a genuine difference for local businesses, we'd love to hear from you

Your Mission

As a SecOps Specialist, you protect Teya by detecting, investigating, and responding to security incidents while ensuring our security operations are reliable, scalable, and continuously improving.

You will lead complex SOC investigations, provide L3 support, maintain and improve core security tooling, and build automations and integrations that increase speed, consistency, and quality across security operations.

You will work closely with Security Engineering, IT, Infrastructure, Platform, Cloud, and Product teams to reduce risk and embed security effectively across the organisation.

You operate across incident response, detection engineering, security tooling, vulnerability management, threat intelligence, telemetry, and automation - turning operational insight into stronger controls and better engineering outcomes.

Responsibilities

Security Operations & Incident Response

Lead end-to-end investigation and response of complex security incidents.

Act as L3 escalation point for SOC analysts and MSSP.

Coordinate across Security, Engineering, IT, Cloud, Legal, and Compliance during incidents.

Make clear, risk-based decisions under pressure with strong documentation.

Maintain playbooks, runbooks, and incident workflows.

Drive post-incident reviews and ensure improvements are implemented and follow-ups completed.

Support incident metrics (MTTD, MTTR, recurrence, etc.)

SOC Tooling & Platform Operations

Operate and improve SIEM, EDR, email security, case management, and vulnerability tools.

Monitor health, coverage, data quality, and integrations.

Troubleshoot ingestion, parsing, API, and configuration issues.

Build and maintain integrations between security tools and internal systems.

Manage upgrades, changes, access reviews, and documentation.

Apply engineering practices (version control, testing, peer review, rollback).

Reduce operational toil through automation and simplification.

Vulnerability Management

Analyse and prioritise vulnerabilities based on risk and exploitability.

Work with Engineering and IT to drive remediation.

Track fixes, validate resolution, and elevate high-risk issues.

Improve vulnerability workflows and automation.

Identify recurring issues and recommend preventative controls.

Detection Engineering

Build, test, and maintain detection rules, queries, and correlation logic.

Manage full detection lifecycle (build -> test -> tune -> measure -> retire).

Use version control and detection-as-code where possible.

Reduce false positives and improve detection quality and coverage.

Map detections to threat behaviours (e.g. MITRE ATT&CK).

Validate detections through testing, incidents, and simulations.

Log & Telemetry Management

Onboard and maintain log sources across cloud, identity, endpoint, network, and SaaS.

Ensure logs are complete, reliable, and usable for detection and investigation.

Troubleshoot ingestion, parsing, schema, and data quality issues.

Build validation and monitoring for telemetry pipelines.

Offboard unused sources safely with documented impact.

Improve telemetry coverage by working with engineering teams.

Threat Intelligence

Monitor threats, vulnerabilities, and attacker techniques.

Translate intelligence into detections, investigations, and remediation actions.

Assess relevance to Teya's environment and risk profile.

Share actionable insights with relevant teams.

Improve security posture using trends and intelligence.

Gather and utilize intelligence for Shadow AI use-cases.

Cross-Functional Delivery

Partner with Engineering and Platform teams on security requirements.