997,024open jobs
59,481companies
165,643added this week
Browse all
Salary
≈ $91k – $241k per year (Estimated)
Location
In office (Geneva)
Seniority
Senior · 4+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Sep 30, 2026. First seen by Alion on Sep 28, 2026. Vitol.com scores B on the Alion truth index.

Overview
Company
Impact
Profile match
Vitol is an energy and commodities company. We trade and distribute energy safely and responsibly around the world using our logistical expertise and infrastructure network.

Vitol is an energy and commodities company with revenues of $331 billion in 2024; its primary business is the trading and distribution of energy products globally - it trades over seven million barrels per day of crude oil and products and, at any time, has 250 ships transporting its cargoes.

Vitol’s clients include national oil companies, multinationals, leading industrial companies and utilities. Founded in Rotterdam in 1966, today Vitol serves clients from some 40 offices worldwide and is invested in energy assets globally including 24mM3 of storage, 850kbpd of refining capacity, and 10,000 service stations. To date, we have committed over $2.5 billion of capital to renewable projects and are identifying and developing low-carbon opportunities around the world.

We are seeking an experienced Security Operations Lead to build, manage, and continuously improve our internal Security Operations Centre (SOC). Based in Geneva or London, this role combines hands-on cyber defense with team leadership across three global offices (Singapore, London, and Houston). The ideal candidate is a technically proficient cybersecurity professional who can operate as both a senior incident handler (L2/L3) and a people leader shaping our detection and response capabilities.

KEY RESPONSIBILITIES

SOC Leadership & Governance

  • Lead a team of 4 SOC analysts/engineers distributed across Singapore, London, and Houston, ensuring 24/7 coverage alignment and consistent service quality.
  • Define and enforce SOC operating procedures, escalation paths, shift handover protocols, and performance metrics (MTTD, MTTR, false-positive rate).
  • Report on SOC performance, threat landscape trends, and risk posture to the CISO and senior stakeholders.
  • Manage the external SOC relationship - act as the primary interface with the outsourced SOC provider, govern service performance, drive continuous improvement, and ensure alignment with internal security objectives.

Detection Engineering & Threat Management

  • Own the detection engineering lifecycle: develop, tune, and maintain analytics rules, correlation logic, and custom detections in Microsoft Sentinel (KQL) and across the broader security stack.
  • Continuously improve detection coverage mapped to MITRE ATT&CK, reducing blind spots and noise.
  • Evaluate and integrate threat intelligence feeds to enrich alerts and drive proactive hunting.

Incident Response & Hands-on Operations

  • Act as a senior incident responder (L2/L3), leading triage, investigation, containment, eradication, and recovery for complex security incidents.
  • Coordinate cross-functional incident response with IT, Legal, Compliance, and business units.
  • Conduct post-incident reviews and root-cause analysis; translate findings into detection improvements and process updates.

Playbook & Process Development

  • Author, maintain, and test SOC playbooks and runbooks covering the full incident lifecycle (phishing, malware, insider threat, cloud compromise, ransomware, BEC, data exfiltration, etc.).
  • Improve existing playbooks and create new ones based on emerging threats, red team findings, and lessons learned.
  • Drive tabletop exercises and purple-team simulations to validate playbook effectiveness.

Red Team Collaboration & Purple Teaming

  • Partner with the internal Red Team to translate adversary emulation results into actionable detection rules and response procedures.
  • Participate in purple-team exercises, validating detection coverage and tuning alerts based on simulated attack paths.

Training & Capability Development

  • Mentor and develop SOC team members through structured training plans, knowledge-sharing sessions, and hands-on coaching.
  • Foster a culture of continuous improvement and professional growth across the distributed team.

Experience & Education

  • 4+ years of progressive experience in cybersecurity operations, incident response, or security engineering.
  • Demonstrated experience leading or managing a SOC team, including remote/distributed personnel.
  • Strong understanding of SOC operating models (tiered, hybrid, follow-the-sun).
  • Proven track record of building or significantly improving detection and response capabilities.

Technical Expertise

  • SIEM & Analytics: Microsoft Sentinel (KQL), log source onboarding, analytics rule development, workbook/dashboard creation.
  • Endpoint Security: Microsoft Defender for Endpoint (MDE), CrowdStrike Falcon (EDR/XDR).
  • Cloud Security: AWS (GuardDuty, CloudTrail, Security Hub) and Microsoft Azure (Defender for Cloud, Entra ID Protection); Wiz for cloud security posture management (CSPM).
  • Data Security & DLP: Microsoft Purview (DLP, Information Protection, Insider Risk), Varonis (data access governance, threat detection).
  • Network & Web Security: Zscaler (ZIA/ZPA), Palo Alto Networks (NGFW, Panorama, Cortex).
  • Incident Response: Digital forensics fundamentals, malware analysis, memory/disk acquisition, chain-of-custody practices.
  • Frameworks: MITRE ATT&CK, NIST CSF, NIST 800-61 (Incident Handling).

Soft Skills & Leadership

  • Excellent communication and stakeholder management skills; ability to translate technical findings for executive audiences.
  • Strong organisational and project-management abilities to coordinate across time zones.
  • Analytical mindset with attention to detail and a bias for action.
  • Preferred qualifications
  • Industry certifications: CISSP, CISM, GCIH, GCIA, GCED, SC-200, AZ-500, or equivalent.
  • Experience in the commodity trading, energy, or financial services sector.
  • Familiarity with automation and orchestration (SOAR) platforms, scripting (Python, PowerShell, KQL).
  • Experience with threat hunting methodologies and tools.
  • French language skills (advantageous for Geneva-based candidates).

Travel

  • Periodic travel between Geneva and London offices; occasional travel to Singapore and Houston for team engagement and alignment
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
997,024 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Geneva
≈ $114k – $268k per year (Estimated) • In office • 8+ years exp • Geneva
AI/ML
AI Agents
LLM
DevOps
CI/CD
Platform Engineering
Cybersecurity
SLSA
Quantum
IonQ
Apply
≈ $90k – $192k per year (Estimated) • In office • Full-Time • Schaffhausen
DevOps
Azure
AWS
Cloudflare
Incident Management
IAM
DNS
Cybersecurity
Microsoft Entra ID
Apply
≈ $67k – $166k per year (Estimated) • In office • Full-Time • 3+ years exp • Geneva
Cybersecurity
ISO 27001
NIST CSF
Apply
≈ $70k – $145k per year (Estimated) • In office • Full-Time • 3+ years exp • Associate's Degree • Greensboro
Management
Microsoft Office
Apply
≈ $11k – $31k per year (Estimated) • In office • Full-Time • Bengaluru
DevOps
Incident Management
Linux
Windows
Cybersecurity
SIEM
Management
Agile
Apply
Remote (Greece) • Athens
Python
Python
pySpark
AI/ML
Spark
SciPy
Pandas
NumPy
DevOps
Azure
AWS
Analytics
Seaborn
Matplotlib
Apply
Big Data Developer 2 hours ago
≈ $37k – $108k per year (Estimated) • Remote (Greece) • Full-Time • Bachelor's Degree • Athens
Python
Java
SQL
Bash
AI/ML
Hadoop
Spark
DevOps
GCP
Azure
Git
AWS
Linux
Apply
Hybrid • Full-Time • 1+ year exp • India
PowerShell
DevOps
VMWare
Azure
Windows Server
Hyper-V
Windows
TCP/IP
DNS
DHCP
Cybersecurity
Microsoft Defender
Microsoft Entra ID
Active Directory
LDAP
PKI
Management
ServiceNow
ITSM
Apply
≈ $52k – $135k per year (Estimated) • Remote (Greece) • Full-Time • Bachelor's Degree • Athens
JavaScript
TypeScript
C#
C#
ASP.NET Core
Frontend
Angular
React.js
DevOps
Azure DevOps
Azure
Management
Power Automate
Power Apps
SharePoint
Apply
≈ $58k – $144k per year (Estimated) • Remote (Greece) • Athens
DevOps
Azure DevOps
Azure
Management
Agile
Scrum
Apply
≈ $67k – $166k per year (Estimated) • In office • Full-Time • 3+ years exp • Geneva
Cybersecurity
ISO 27001
NIST CSF
Apply
Credit Analyst 7 days ago
≈ $66k – $139k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • Houston
Apply
GenAI Engineer 9 days ago
≈ $125k – $239k per year (Estimated) • In office • Full-Time • 3+ years exp • Houston
Python
AI/ML
Model Context Protocol
Prompt Engineering
Function Calling
AI Agents
LLM
RAG
Agentic Workflows
Multi-Agent Systems
Tool Use
DevOps
GCP
Azure
Git
AWS
Docker
Apply
≈ $37k – $73k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • Singapore
Python
Analytics
Microsoft Excel
Apply
Intern (Accounting) 14 days ago
≈ $5.5k – $16k per year (Estimated) • In office • Internship • Iskandar Puteri
Apply
$76k – $83k per year • In office • Full-Time • 2+ years exp • Bachelor's Degree • Geneva
Apply
≈ $38k – $72k per year (Estimated) • In office • Internship • Geneva
Apply
Hybrid • Full-Time • Geneva
Design
AutoCAD
Management
Smartsheet
SharePoint
Apply
≈ $38k – $93k per year (Estimated) • In office • Geneva
Apply
$32k per year • In office • Contractor • Geneva
Apply
See all jobs
This is one of many
997,024 more open roles from verified company boards, updated every day.