CF CloudFrame Job Scanner Open Dashboard →
Verified Active Opening

Security Operations Lead

Beam Up • London, United Kingdom

Job Description

At Beam, we’re building AI that serves society. We're a global team of ambitious, hardworking problem solvers, applying fast-moving startup energy to work that makes the world a better place. If you want to apply your talent to the biggest problems society faces, Beam is the place for you. You’ll be part of a high-performance culture where you'll make a huge impact, rapidly progress your career, and truly enjoy your work. Over 100,000 frontline workers already use Beam to take notes, provide live interpretation and handle phone calls, so they can focus on the people who need them most. This is just the beginning. The opportunity at Beam Beam builds AI tools for frontline public services in the UK, US, Australia and the EU: local authorities, health services, police forces, and state, federal and central government agencies. Our products handle some of the most sensitive data governments hold, and our customers' security teams hold us to the standards they hold themselves. The Security Operations Lead is Beam's first dedicated operational security role. You run security operations across six deployments in four regions: detection and response, vulnerability management, penetration testing, cloud security posture, external attack surface, third-party security assessment and adversarial testing of our AI products. You are also the assurance owner for the platform security controls Engineering operates: you check they work, hold the evidence, and answer for them to auditors and customers in every region. You report to the Chief Information Risk Officer and support them on security incidents. Day to day: tuning the SIEM and working with the MDR; triaging vulnerability findings and holding remediation to SLA with Engineering; scoping and running pen tests with our external partner; reviewing Engineering's platform controls and gathering evidence; running incident response exercises; answering the security half of customer and auditor questions. What you’ll be doing Running detection and response. Owning the SIEM and detection stack (a SIEM is in place but not deeply embedded; you decide whether it stays), owning detection rules, managing alert triage and noise, and selecting and managing the 24/7 MDR service so that out-of-hours compromise in any of our four regions is seen and acted on. Owning the vulnerability programme end to end. Detection, triage, remediation to SLA with Engineering and IT Ops, and reporting that matches what we tell customers. Includes cloud security posture (GCP, AWS), configuration drift across deployments, and the external attack surface (domains, DNS, TLS, security ratings). Scoping and coordinating penetration testing across all products and regions with our external partner, and owning the vulnerability disclosure programme. Assuring Engineering-owned platform controls: encryption and key management, network segmentation, workload hardening, privileged and non-human identity, secrets lifecycle, supply-chain integrity, audit-trail integrity, and data residency across regions. You check they operate, hold the evidence, and answer for them in ISO 27001, SOC 2, FedRAMP and IRAP assessments. Making Beam incident-ready. Incident response plans and runbooks, exercises with Engineering, forensics readiness, and hands-on support to the CIRO during security incidents. Leading AI threat modelling and adversarial testing (prompt injection, jailbreak, data extraction, caller-side attacks on telephony products) with our red-team partner, and providing security assurance for new product surfaces (desktop clients, browser extensions, integrations, public API). Running third-party security assessment of sub-processors and suppliers, delivering role-based security training to engineers and administrators, and reporting security metrics to the CIRO and leadership. Who we’re looking for A security operations lead who has built or run detection and response in a cloud-native environment. You have written and tuned detection

Job Reference ID: CF-179884 • Posted on CloudFrame Job Scanner