Senior Security Operations Engineer
SunCore Digital · United Kingdom, United States · 2026-08-03
About this role
Senior Security Operations Engineer About the Role SunCore Digital is seeking a hands-on Senior Security Operations Engineer to assess and improve the security of our applications, cloud environments, development practices, identities, data, and operational tooling. This role will establish practical security standards, build and harden shared security controls, investigate risk, and review security-impacting implementations produced by reliability, recovery, DevOps, and application teams. System-owning teams remain responsible for remediating their applications and services and for operating routine system-specific controls after enablement. This is not a role that manually approves every normal software release. Security review will focus on defined risk areas, including changes involving privileged access, sensitive data, recovery systems, network exposure, secrets, infrastructure, authentication, authorization, and security controls. Responsibilities Security assessment
Assess the current security posture across web applications, Flutter mobile applications, APIs, backend services, cloud infrastructure, repositories, CI/CD, databases, and integrations.
Inventory externally accessible services and endpoints.
Identify vulnerabilities, insecure defaults, excessive permissions, unmanaged credentials, and control gaps.
Distinguish confirmed findings from suspected risks and unassessed areas.
Prioritize findings based on exploitability, potential impact, exposure, and launch relevance.
Define remediation requirements and work with system owners, who implement and maintain application- and service-specific fixes. Implement shared security controls where the control belongs to the security function.
Verify that critical findings are resolved effectively.
Identity and access management
Review access to cloud accounts, repositories, databases, CI/CD systems, production environments, and third-party services.
Identify former employee, contractor, shared, excessive, or undocumented access.
Establish least-privilege and access-review practices.
Review service accounts, machine identities, API credentials, and privileged roles.
Define and harden credential lifecycle requirements, and work with DevOps, platform staff, and system owners to implement appropriate issuance, storage, rotation, revocation, and emergency-access mechanisms.
Ensure critical access activity is logged where appropriate.
Support role-based access and authorization reviews.
Application and API security
Review authentication, authorization, session management, permissions, and data isolation.
Assess exposed APIs, input handling, file processing, sensitive-data handling, and administrative functions.
Independently assess high-risk negative-access paths and direct access to restricted endpoints.
Work with QA and developers to convert repeatable security scenarios into regression coverage owned by the applicable delivery team.
Review changes involving sensitive workflows or new public exposure.
Help establish secure coding and review expectations.
Support threat modeling for critical workflows and material architectural changes.
Mobile security
Assess mobile authentication, session handling, secure storage, API access, application permissions, logging, and sensitive-data exposure.
Review risks related to device storage, screenshots, notifications, local caches, and mobile configuration.
Work with the Mobile QA Engineer and mobile developers on security-related testing.
Review mobile release practices where they affect application security.
Security tooling and automation
Define, implement, and harden security-specific automation, including dependency scanning, secret scanning, static analysis, vulnerability scanning, and container or infrastructure scanning where appropriate; establish the long-term owner for each shared control before handoff.
Define security policies, rules, and acceptance thresholds; work with DevOps to integrate shared controls into CI/CD and with repository owners to maintain application-specific configuration.
Establish actionable security gates based on severity and context, while system owners remain responsible for remediation.
Avoid creating low-value controls that block delivery without reducing material risk.
Improve security finding visibility and reporting.
Define exception and escalation procedures.
Track critical remediation through verification.
Review of reliability and recovery implementations
Review security-impacting SRE and Disaster Recovery implementations before production adoption.
Evaluate changes involving:
Privileged automation
Service accounts
Secrets
Backup data
Recovery access
Network or firewall configuration
Infrastructure permissions
Failover paths
Sensitive logging or monitoring
Review DevOps, dashboard, and internal-tooling changes when they affect access, production data, infrastructure, or security controls.
Validate that operational improvements do not introduce avoidable security exposure.
Security operations and incident readiness
Establish security monitoring and escalation requirements.
Develop security incident-response procedures and runbooks.
Define initial security incident severity and notification paths.
Investigate security events and suspicious activity.
Support evidence preservation and technical incident analysis.
Conduct or coordinate security exercises.
Track post-incident corrective actions.
Ensure security runbooks are tested by qualified staff.
Data and vendor security
Identify where sensitive, personal, financial, or operational data is stored and transmitted.
Review encryption in transit and at rest.
Assess retention, deletion, export, logging, and access behavior.
Review third-party services that receive code, credentials, operational data, or sensitive information.
Support vendor security review based on business risk.
Help identify security and privacy obligations that require legal or…
Skills asked for
- devops
- flutter
- ci/cd
- sre
- rest
Similar jobs
- Senior IT Security Consultant (all genders)]init[ AG · Stuttgart
- Senior IT Security Consultant (all genders)]init[ AG · standortunabhängig
- Senior IT Security Consultant (all genders)]init[ AG · Bremen
- Senior IT Security Consultant (all genders)]init[ AG · Leipzig
- Senior IT Security Consultant (all genders)]init[ AG · Mainz
- Senior IT Security Consultant (all genders)]init[ AG · Köln
- Senior IT Security Consultant (all genders)]init[ AG · Hamburg
- Senior IT Security Consultant (all genders)]init[ AG · München
Your next role is already in here.
Search live openings from thousands of employers, save the ones worth a second look, and let JobBob keep watch for the rest.