Senior Security Engineer - Detection & Response - Eu/uk

Marqeta Marqeta · Fintech · United Kingdom · Remote · CyberSecurity

This role is for a Senior Security Engineer focused on detection and response within a fintech company. Responsibilities include investigating security incidents, proactive threat monitoring, incident command, developing response methodologies, and contributing to detection engineering using a detections-as-code approach. The role requires expertise in incident response, digital forensics, threat hunting, and security monitoring tools, with collaboration across teams and participation in on-call rotations. Experience in regulated environments like PCI DSS is a plus.

What you'd actually do

  1. Proactively monitor Marqeta’s environment for cyber threat activity and manage day-to-day security alerts through timely analysis, triage, and appropriate response actions
  2. Serve as incident commander during security events, directing investigation strategies and coordinating cross-functional response efforts
  3. Execute incident response activities aligned with the NIST Incident Response Lifecycle to detect, contain, eradicate, recover, and learn from cybersecurity incidents
  4. Contribute to the maintenance and improvement of the Cybersecurity Incident Response Plan (CIRP), playbooks, runbooks, and standard operating procedures to ensure consistent and effective response operations
  5. Participate in 24x7x365 on-call rotations, providing skilled guidance during security incidents and contributing to thorough post-incident reviews

Skills

Required

  • 5+ years of hands-on experience in security operations
  • strong expertise in incident response
  • digital forensics
  • threat hunting
  • Experience serving as an incident commander or leading incident response workstreams
  • Strong knowledge of the NIST Incident Response Lifecycle
  • Proficiency with security monitoring and forensic tools including EDR, SIEM, and SOAR systems
  • Experience developing detections-as-code
  • Working knowledge of MITRE ATT&CK
  • Experience tuning security solutions
  • Working knowledge of AWS cloud services
  • Ability to effectively communicate with technical and non-technical stakeholders

Nice to have

  • familiarity with version control, CI/CD pipelines, and detection testing frameworks
  • apply threat intelligence to enhance detection and response capabilities
  • developing automation workflows
  • securing cloud environments
  • payment processing, fintech, or other highly regulated environments
  • familiarity with PCI DSS incident handling requirements a plus
  • mentor and support the growth of junior security professionals

What the JD emphasized

  • strong expertise in incident response
  • digital forensics
  • threat hunting
  • security monitoring technologies
  • detection engineering
  • NIST Incident Response Lifecycle
  • MITRE ATT&CK framework
  • PCI DSS