{"id":1462865,"url":"https://alion.io/job/vitol-com-security-operations-lead","title":"Security Operations Lead","company":{"id":691744,"name":"Vitol.com","domain":"vitol.com","url":"https://alion.io/company/vitol-2","size_band":"51-200","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"SmartRecruiters","truth_index":{"grade":"B","score":79,"open_postings":6,"ghost_share":0,"stale_share":0.833,"repost_share":0,"time_to_fill_p50_days":48,"computed_at":"2026-10-01T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"lead","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Geneva, Switzerland"],"countries":["CH"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":91000,"max_usd":241000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":399},"experience_years_min":4,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"Cortex","optional":false},{"name":"Crowdstrike","optional":false},{"name":"DLP","optional":false},{"name":"Microsoft Defender","optional":false},{"name":"Microsoft Defender for Cloud","optional":false},{"name":"Microsoft Entra ID","optional":false},{"name":"Microsoft Sentinel","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"NIST CSF","optional":false},{"name":"Red Teaming","optional":false},{"name":"SIEM","optional":false},{"name":"Wiz","optional":false},{"name":"Zscaler","optional":false},{"name":"PowerShell","optional":true},{"name":"Prometheus","optional":true},{"name":"Python","optional":true}],"status":"live","first_seen_at":"2026-09-28T16:07:26Z","employer_posted_date":"2026-09-28","last_verified_at":"2026-09-30T22:44:06Z","board_verified":true,"closed_at":null,"days_open":3,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":3},"description":"Vitol is an energy and commodities company with revenues of $331 billion in 2024; its primary business is the trading and distribution of energy products globally - it trades over seven million barrels per day of crude oil and products and, at any time, has 250 ships transporting its cargoes.\nVitol’s clients include national oil companies, multinationals, leading industrial companies and utilities. Founded in Rotterdam in 1966, today Vitol serves clients from some 40 offices worldwide and is invested in energy assets globally including 24mM3 of storage, 850kbpd of refining capacity, and 10,000 service stations. To date, we have committed over $2.5 billion of capital to renewable projects and are identifying and developing low-carbon opportunities around the world.\n We are seeking an experienced Security Operations Lead to build, manage, and continuously improve our internal Security Operations Centre (SOC). Based in Geneva or London, this role combines hands-on cyber defense with team leadership across three global offices (Singapore, London, and Houston). The ideal candidate is a technically proficient cybersecurity professional who can operate as both a senior incident handler (L2/L3) and a people leader shaping our detection and response capabilities.\nKEY RESPONSIBILITIES\nSOC Leadership & Governance\nLead a team of 4 SOC analysts/engineers distributed across Singapore, London, and Houston, ensuring 24/7 coverage alignment and consistent service quality.\nDefine and enforce SOC operating procedures, escalation paths, shift handover protocols, and performance metrics (MTTD, MTTR, false-positive rate).\nReport on SOC performance, threat landscape trends, and risk posture to the CISO and senior stakeholders.\nManage the external SOC relationship - act as the primary interface with the outsourced SOC provider, govern service performance, drive continuous improvement, and ensure alignment with internal security objectives.\nDetection Engineering & Threat Management\nOwn the detection engineering lifecycle: develop, tune, and maintain analytics rules, correlation logic, and custom detections in Microsoft Sentinel (KQL) and across the broader security stack.\nContinuously improve detection coverage mapped to MITRE ATT&CK, reducing blind spots and noise.\nEvaluate and integrate threat intelligence feeds to enrich alerts and drive proactive hunting.\nIncident Response & Hands-on Operations\nAct as a senior incident responder (L2/L3), leading triage, investigation, containment, eradication, and recovery for complex security incidents.\nCoordinate cross-functional incident response with IT, Legal, Compliance, and business units.\nConduct post-incident reviews and root-cause analysis; translate findings into detection improvements and process updates.\nPlaybook & Process Development\nAuthor, maintain, and test SOC playbooks and runbooks covering the full incident lifecycle (phishing, malware, insider threat, cloud compromise, ransomware, BEC, data exfiltration, etc.).\nImprove existing playbooks and create new ones based on emerging threats, red team findings, and lessons learned.\nDrive tabletop exercises and purple-team simulations to validate playbook effectiveness.\nRed Team Collaboration & Purple Teaming\nPartner with the internal Red Team to translate adversary emulation results into actionable detection rules and response procedures.\nParticipate in purple-team exercises, validating detection coverage and tuning alerts based on simulated attack paths.\nTraining & Capability Development\nMentor and develop SOC team members through structured training plans, knowledge-sharing sessions, and hands-on coaching.\nFoster a culture of continuous improvement and professional growth across the distributed team.\n Experience & Education\n4+ years of progressive experience in cybersecurity operations, incident response, or security engineering.\nDemonstrated experience leading or managing a SOC team, including remote/distributed personnel.\nStrong understanding of SOC operating models (tiered, hybrid, follow-the-sun).\nProven track record of building or significantly improving detection and response capabilities.\nTechnical Expertise\nSIEM & Analytics: Microsoft Sentinel (KQL), log source onboarding, analytics rule development, workbook/dashboard creation.\nEndpoint Security: Microsoft Defender for Endpoint (MDE), CrowdStrike Falcon (EDR/XDR).\nCloud Security: AWS (GuardDuty, CloudTrail, Security Hub) and Microsoft Azure (Defender for Cloud, Entra ID Protection); Wiz for cloud security posture management (CSPM).\nData Security & DLP: Microsoft Purview (DLP, Information Protection, Insider Risk), Varonis (data access governance, threat detection).\nNetwork & Web Security: Zscaler (ZIA/ZPA), Palo Alto Networks (NGFW, Panorama, Cortex).\nIncident Response: Digital forensics fundamentals, malware analysis, memory/disk acquisition, chain-of-custody practices.\nFrameworks: MITRE ATT&CK, NIST CSF, NIST 800-61 (Incident Handling).\nSoft Skills & Leadership\nExcellent communication and stakeholder management skills; ability to translate technical findings for executive audiences.\nStrong organisational and project-management abilities to coordinate across time zones.\nAnalytical mindset with attention to detail and a bias for action.\nPreferred qualifications\nIndustry certifications: CISSP, CISM, GCIH, GCIA, GCED, SC-200, AZ-500, or equivalent.\nExperience in the commodity trading, energy, or financial services sector.\nFamiliarity with automation and orchestration (SOAR) platforms, scripting (Python, PowerShell, KQL).\nExperience with threat hunting methodologies and tools.\nFrench language skills (advantageous for Geneva-based candidates).\nTravel\nPeriodic travel between Geneva and London offices; occasional travel to Singapore and Houston for team engagement and alignment","description_format":"text","description_chars":5816,"description_truncated":false,"requirements":{"experience_years_min":4,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[{"language":"English","level":"All levels","optional":false},{"language":"French","level":"All levels","optional":true}]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Fossil Fuels","Incident Response","Oil & Gas"],"lifecycle":[{"event":"open","at":"2026-09-29T13:11:34Z"}],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":2,"expected_fill_days":48,"reasons":["conf:7","velocity","win:early"],"computed_at":"2026-10-01T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/vitol-com-security-operations-lead","json_url":"https://alion.io/job/vitol-com-security-operations-lead.json","meta":{"generated_at":"2026-10-01T19:20:05Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1878,"day_limit":5000,"remaining_today":3122,"minute_limit":60,"resets_at":"2026-10-02T00:00:00Z"}}}