Skip to content
← Back to job listings

Security Operations Engineer

Spotme · United Kingdom

RemoteImported listingfull-time14 days ago

About The Role

Join Onomi, a fast-growing company in the healthcare industry, as a Security Operations Engineer. In this role, you will be responsible for setting and running the security configuration of the company across various tools. You will work closely with the Chief Security and Trust Officer and have a significant impact on IT security in an environment where it truly matters. Your responsibilities will include identity and access management, endpoint management and protection, security controls and access models, and building internal tooling. You will have the opportunity to work remotely, enjoy a minimum of 25 days of paid time off, and benefit from a supportive and inclusive company culture.

  • Set and run the security configuration of the company across different tools, focusing on identity, access, and lifecycle management.
  • Implement and manage endpoint management and protection across the macOS fleet, ensuring compliance and security.
  • Design and configure security controls and access models inside various SaaS applications, ensuring they meet security requirements.
  • Understanding the usage of APIs, minimally knowledge around REST and HTTP methods status codes, authentication via API keys, OAuth 2.0
  • What you need to be great at:
  • Working across multiple areas of security rather than specialising in one, in combination with “standard IT activities”. Identity, endpoints, tool configuration and logging all sit in this role, and none of them get a dedicated person
  • Google Workspace as an identity platform, including SSO and SAML app integration, groups and org units, admin roles and delegation, context-aware access, the security and admin audit logs and the alerts built on them
  • Judging the balance between security that limits people and what the business actually needs to get done. Knowing which control is worth the friction and which one will simply be worked around
  • Because of our business, users often need immediate action. Some tickets can wait a week and some arrive as a Slack message because a customer event is happening now. Judging which is which, without treating everything as urgent or making people escalate to get attention, is a daily call
  • How you adapt your views and actions based on publicly known security incidents and breaches
  • What we are most curious about:
  • Where you think the effort really belongs when it comes to security settings and capabilities, and which attack vectors matter most for a company like ours
  • A detection or an alert you switched off, and what convinced you
  • Your process for choosing security tools, what you rule out early, and what you insist on testing before anything gets signed
  • How you handle the human pressure to override security requirements
  • How you decide between buying and building, what you base it on, and how the decision survives in real life

This is an external listing. JobSpring does not represent or verify the employer. Report this listing