At a Glance
- Tasks: Manage security operations, improve detection quality, and coordinate incident response.
- Company: Join Alpaca, a leading fintech company revolutionising financial services globally.
- Benefits: Enjoy competitive salary, stock options, health benefits, and a monthly stipend for home office setup.
- Other info: Work remotely with a diverse team and enjoy excellent career growth opportunities.
- Why this job: Make a real impact in security operations while working with cutting-edge technology.
- Qualifications: 3+ years in Security Operations, hands-on SIEM experience, and strong incident response skills.
The predicted salary is between 60000 - 80000 ÂŁ per year.
Alpaca is a US-headquartered self-clearing broker‑dealer and brokerage infrastructure for stocks, ETFs, options, crypto, fixed income, 24/5 trading, and more. Our recent Series D funding round brought our total investment to over $320 million, fueling our ambitious vision. Amongst our subsidiaries, Alpaca is a licensed financial services company, serving hundreds of financial institutions across 40 countries with our institutional‑grade APIs. This includes broker‑dealers, investment advisors, wealth managers, hedge funds, and crypto exchanges, totalling over 9 million brokerage accounts. Our global team is a diverse group of experienced engineers, traders, and brokerage professionals who are working to achieve our mission of opening financial services to everyone on the planet. We’re deeply committed to open‑source contributions and fostering a vibrant community, continuously enhancing our award‑winning, developer‑friendly API and the robust infrastructure behind it.
Your Role
We are seeking a Security Operations Engineer to mature Alpaca’s day‑to‑day security operations. This role will be responsible for managing our third‑party SOC relationship, operating and tuning our on‑prem SIEM, and acting as a critical bridge between IT Helpdesk and the Security team to ensure security issues are identified, triaged, and resolved quickly and consistently. You will be both hands‑on and operationally minded: improving detection quality, streamlining alert triage, coordinating incident response, and ensuring security operations scale with the business. You’ll play a key role in turning security signals into action and ensuring operational issues don’t become security incidents. This role reports to the Enterprise Security Architect and works closely with IT, DevOps, Engineering, and our external SOC partner. The Security Team is 100% distributed and remote.
Things You Get To Do
- Security Operations and Detection Engineering: Own the relationship with our managed SOC, including alert quality, escalation workflows, SLAs, runbooks, and continuous improvement of detection coverage and response effectiveness. Assist with triage, investigations, and respond to security alerts across endpoints, identity, cloud, network, and application logs. Operate and maintain our SIEM, including log onboarding, parsing, normalization, correlation rules, alert tuning, and lifecycle management to reduce noise and increase signal. Ensure critical systems generate the right security telemetry, filling gaps across endpoints, identity providers, network devices, SaaS tools, and cloud platforms. Continuously refine detection logic based on threat intelligence, SOC feedback, incident learnings, and emerging attack techniques.
- Incident Response & Metrics: Assist with security incidents, working with IT, Engineering, and external partners to contain, eradicate, and recover from incidents. Develop, maintain, and continuously improve incident response playbooks, escalation paths, and communication procedures. Track and report on key security operations metrics such as alert volumes, false positive rates, mean time to detect (MTTD), mean time to respond (MTTR), and SOC performance.
- IT & Security Collaboration: Act as the security liaison to the IT Helpdesk, ensuring security‑related tickets are properly triaged, prioritized, and resolved without slowing down business operations. Provide guidance and context to IT teams on security alerts, risks, and required actions, helping raise the overall security maturity of frontline support teams.
Who You Are (Must‑Haves)
- Excited about Alpaca’s mission and what we’re building.
- 3+ years of experience in Security Operations roles.
- Hands‑on experience operating and tuning a SIEM (on‑prem or cloud‑based).
- Hands‑on experience maintaining Kubernetes clusters.
- Working with Linux.
- Scripting or automation experience (Python, Bash) for security operations tasks.
- Experience working with a third‑party SOC or MSSP.
- Strong incident response and alert investigation skills across identity, endpoint, network, and cloud environments.
- Understanding of common attacker techniques and detection methodologies.
- Experience working closely with IT/helpdesk teams and translating security requirements into operational workflows.
- Familiarity with endpoint security, identity monitoring, and log‑based detections.
- Strong written and verbal communication skills, especially during incidents.
- Comfortable working cross‑functionally and handling escalations calmly and decisively.
Who You Might Be (Nice‑to‑Haves)
- Experience securing financial, trading, or other highly regulated platforms.
- Familiarity with compliance frameworks such as SOC 2, ISO 27001, or PCI.
- Experience with detection engineering frameworks (MITRE ATT&CK).
- Knowledge of cloud security logging (AWS/GCP/Azure) and SaaS security telemetry.
- Experience working with GitOps and CI/CD pipelines.
- Experience running tabletop exercises or incident response simulations.
- Security certifications (GCIA, GCIH, GCED, CISSP, or similar).
- Ability to balance security rigor with operational efficiency and business needs.
How We Take Care of You
- Competitive Salary & Stock Options.
- Health Benefits.
- New Hire Home‑Office Setup: One‑time USD $500.
- Monthly Stipend: USD $150 per month via a Brex Card.
Alpaca is proud to be an equal opportunity workplace dedicated to pursuing and hiring a diverse workforce.
Security Operations Engineer in London employer: Alpaca
Contact Detail:
Alpaca Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Security Operations Engineer in London
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, especially those already at Alpaca. A friendly chat can open doors and give you insider info that could make your application stand out.
✨Tip Number 2
Show off your skills! If you’ve got a portfolio or any projects related to security operations, share them. It’s a great way to demonstrate your hands-on experience and passion for the field.
✨Tip Number 3
Prepare for the interview by brushing up on common security scenarios. Think about how you’d handle incidents or improve detection processes. We want to see your problem-solving skills in action!
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining our team at Alpaca.
We think you need these skills to ace Security Operations Engineer in London
Some tips for your application 🫡
Show Your Passion: When you write your application, let your enthusiasm for Alpaca's mission shine through. We want to see that you're genuinely excited about what we're building and how you can contribute to our vision.
Tailor Your Experience: Make sure to highlight your relevant experience in Security Operations. We’re looking for specific examples of how you've operated and tuned a SIEM or worked with third-party SOCs. Tailoring your application to match the job description will help us see why you're a great fit!
Be Clear and Concise: Keep your application clear and to the point. Use straightforward language to describe your skills and experiences. We appreciate well-structured applications that make it easy for us to understand your qualifications.
Apply Through Our Website: Don’t forget to apply through our website! It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it gives you a chance to explore more about what we do at Alpaca.
How to prepare for a job interview at Alpaca
✨Know Your Stuff
Make sure you brush up on your knowledge of security operations, especially around SIEM tools and incident response. Be ready to discuss your hands-on experience with these technologies and how you've used them in past roles.
✨Show Your Problem-Solving Skills
Prepare to share specific examples of how you've tackled security incidents or improved detection processes. Think about metrics like MTTD and MTTR that you can reference to demonstrate your impact.
✨Understand the Company Culture
Familiarise yourself with Alpaca's mission and values. Show enthusiasm for their commitment to open-source contributions and how you can contribute to their diverse, remote team.
✨Ask Smart Questions
Prepare insightful questions about their security operations and how they collaborate with IT and external partners. This shows your genuine interest in the role and helps you gauge if it's the right fit for you.