Overview
In this role, you will safeguard Fuse’s IT and cloud environment, spanning AWS, identity providers, endpoints, and data centres. You’ll act as the security escalation point, owning end-to-end investigations and automation to streamline triage and response. Your work will span detection engineering, incident response, and audits, contributing to a secure, energy-focused tech platform. This position offers a chance to shape security practices across a fast-growing, mission-driven energy company.
Pay / Benefits
- competitive salary
- equity
- biannual bonus
- fully expensed tech
- private health insurance
- office meals allowance
Responsibilities
- Escalate IT security issues across IAM, security, and automation
- Champion security automation and tooling to ease team workloads
- Own end-to-end security monitoring by building and tuning log pipelines from AWS, endpoints, SaaS logs, and network logs
- Write, test, and maintain detection rules aligned with attacker behaviours
- Lead incident response from detection to containment and post-mortem with tested IR runbooks
- Perform forensic analysis on compromised endpoints, workloads, and accounts with proper evidence handling
- Collaborate with IT to enhance security policies and documentation
- Coordinate external audits and assessments as the security contact
- Track threat intelligence relevant to energy, trading, and GPU infrastructure and translate into detections
- Lead vulnerability management with prioritization by exploitability and drive remediation with IT/engineering teams
- Monitor data centre security (firewall logs, OOB access, east-west traffic) and enforce segmentation
- Feeback prevention by addressing root causes with IT and engineering
Key requirements
- Background in IT, SOC operations or similar hands-on technical work
- Solid grasp of cloud infrastructure, ideally AWS
- Strong networking knowledge (read PCAPs, detect beaconing in flow logs, reason about lateral movement)
- Knowledge of attacker tradecraft and ability to map investigations to it
- Proficiency in scripting (Python or similar) for automation
- Strong ownership mindset with end-to-end accountability
- Bonus: familiarity with EDR platforms (CrowdStrike, SentinelOne, Defender) and detection-as-code (Sigma, Git-based detections); SOAR or custom response automation; data centre/colocation security experience; ISO 27001 or SOC 2 audits; FortiGate logging and NetFlow/sFlow; DFIR certs (GCIH, GCFA, GCIA)
- Experience in energy, fintech, trading or other high-value targets is a plus
- problem-solving
- ownership
- end-to-end accountability
- AWS security
- log pipeline construction (CloudTrail, GuardDuty, VPC Flow Logs)
- detection engineering
…
