HireFT
Browse JobsHow it worksPricingAboutSuccess Stories
    Back to jobs
    VI

    Vitol

    Energy and Commodities Trading

    Security Operations Lead

    Geneva, SwitzerlandOn-SiteFull-timePosted 18h ago
    View all jobs

    Job description

    We are seeking an experienced Security Operations Lead to build, manage, and continuously improve our internal Security Operations Centre (SOC). Based in Geneva or London, this role combines hands-on cyber defense with team leadership across three global offices (Singapore, London, and Houston). The ideal candidate is a technically proficient cybersecurity professional who can operate as both a senior incident handler (L2/L3) and a people leader shaping our detection and response capabilities.

    KEY RESPONSIBILITIES

    SOC Leadership & Governance

    • Lead a team of 4 SOC analysts/engineers distributed across Singapore, London, and Houston, ensuring 24/7 coverage alignment and consistent service quality.
    • Define and enforce SOC operating procedures, escalation paths, shift handover protocols, and performance metrics (MTTD, MTTR, false-positive rate).
    • Report on SOC performance, threat landscape trends, and risk posture to the CISO and senior stakeholders.
    • Manage the external SOC relationship — act as the primary interface with the outsourced SOC provider, govern service performance, drive continuous improvement, and ensure alignment with internal security objectives.

    Detection Engineering & Threat Management

    • Own the detection engineering lifecycle: develop, tune, and maintain analytics rules, correlation logic, and custom detections in Microsoft Sentinel (KQL) and across the broader security stack.
    • Continuously improve detection coverage mapped to MITRE ATT&CK, reducing blind spots and noise.
    • Evaluate and integrate threat intelligence feeds to enrich alerts and drive proactive hunting.

    Incident Response & Hands-on Operations

    • Act as a senior incident responder (L2/L3), leading triage, investigation, containment, eradication, and recovery for complex security incidents.
    • Coordinate cross-functional incident response with IT, Legal, Compliance, and business units.
    • Conduct post-incident reviews and root-cause analysis; translate findings into detection improvements and process updates.

    Playbook & Process Development

    • Author, maintain, and test SOC playbooks and runbooks covering the full incident lifecycle (phishing, malware, insider threat, cloud compromise, ransomware, BEC, data exfiltration, etc.).
    • Improve existing playbooks and create new ones based on emerging threats, red team findings, and lessons learned.
    • Drive tabletop exercises and purple-team simulations to validate playbook effectiveness.

    Red Team Collaboration & Purple Teaming

    • Partner with the internal Red Team to translate adversary emulation results into actionable detection rules and response procedures.
    • Participate in purple-team exercises, validating detection coverage and tuning alerts based on simulated attack paths.

    Training & Capability Development

    • Mentor and develop SOC team members through structured training plans, knowledge-sharing sessions, and hands-on coaching.
    • Foster a culture of continuous improvement and professional growth across the distributed team.

    Experience & Education

    • 4+ years of progressive experience in cybersecurity operations, incident response, or security engineering.
    • Demonstrated experience leading or managing a SOC team, including remote/distributed personnel.
    • Strong understanding of SOC operating models (tiered, hybrid, follow-the-sun).
    • Proven track record of building or significantly improving detection and response capabilities.

    Technical Expertise

    • SIEM & Analytics: Microsoft Sentinel (KQL), log source onboarding, analytics rule development, workbook/dashboard creation.
    • Endpoint Security: Microsoft Defender for Endpoint (MDE), CrowdStrike Falcon (EDR/XDR).
    • Cloud Security: AWS (GuardDuty, CloudTrail, Security Hub) and Microsoft Azure (Defender for Cloud, Entra ID Protection); Wiz for cloud security posture management (CSPM).
    • Data Security & DLP: Microsoft Purview (DLP, Information Protection, Insider Risk), Varonis (data access governance, threat detection).
    • Network & Web Security: Zscaler (ZIA/ZPA), Palo Alto Networks (NGFW, Panorama, Cortex).
    • Incident Response: Digital forensics fundamentals, malware analysis, memory/disk acquisition, chain-of-custody practices.
    • Frameworks: MITRE ATT&CK, NIST CSF, NIST 800-61 (Incident Handling).

    Soft Skills & Leadership

    • Excellent communication and stakeholder management skills; ability to translate technical findings for executive audiences.
    • Strong organisational and project-management abilities to coordinate across time zones.
    • Analytical mindset with attention to detail and a bias for action.
    • Preferred qualifications
    • Industry certifications: CISSP, CISM, GCIH, GCIA, GCED, SC-200, AZ-500, or equivalent.
    • Experience in the commodity trading, energy, or financial services sector.
    • Familiarity with automation and orchestration (SOAR) platforms, scripting (Python, PowerShell, KQL).
    • Experience with threat hunting methodologies and tools.
    • French language skills (advantageous for Geneva-based candidates).

    Travel

    • Periodic travel between Geneva and London offices; occasional travel to Singapore and Houston for team engagement and alignment

    Job details are sourced from the employer's original posting.

    Open job posting
    VI

    About the company

    Vitol

    We are the world’s largest independent energy and commodities trading company. Every day we use our expertise and logistical networks to distribute energy around the world, efficiently and responsibly. From 40 offices worldwide, we seek to add value across the energy supply chain, including deploying our scale and market understanding to help facilitate the energy transition. To date, we have committed over $1 billion of capital to renewable projects, and are identifying and developing low-carbon opportunities around the world. Our people are our business . Talent is precious to us and we create an environment in which individuals can reach their full potential, unhindered by hierarchy. Our team comprises more than 65 nationalities and we are committed to developing and sustaining a diverse work force.  Learn more about us here . ATB is owned by Vitol and it is the 7th crude refinery plant in Malaysia. Located at Pontian, Johor Darul Ta'zim, the 32kbpd refinery, is well-positioned to supply both the local bunkering and growing energy markets across the region. The refinery neighbours VTTI-owned ATB terminal which includes over 1m m3 storage as well as 6 onsite jetties and can accommodate any size or type of tanker. This unique positioning enables us to offer our customers a secure and fully integrated supply chain, from production and blending of quality marine fuels, to storage and delivery. Designed to be highly energy-efficient, the refinery deploys state-of-the-art technology including a distillation unit with a prefractionation column.

    View all Vitol jobs
    Industry
    Energy and Commodities Trading
    Open roles
    17

    Interested in this role?

    Apply with HireFT

    Free to start — no card required.

    Your fit

    How well do you match?

    Sign in to see how your résumé lines up with this role.