Senior Security Engineer - Blue Team
OloOlo is a leading SaaS platform helping restaurant brands deliver more personalized and profitable guest experiences through digital ordering, payments, and guest engagement. The company is deliberately expanding its presence in Belfast and Northern Ireland as a core hub, with a local leadership team and community for the long term. This role is fully remote, offering you the flexibility to work from anywhere within the UK.
In the Senior Security Engineer - Blue Team role, you’ll focus on reducing identified risks, spotting and stopping adversarial activity, and keeping services available at all times. You’ll shape strategic risk mitigations to protect client data while supporting innovation, and you’ll deliver white-glove security support to both internal and external stakeholders. Mentoring other engineers and sharing security know-how will be a regular part of your days.
You’ll also help identify future projects based on risk, taking ownership of cross-functional initiatives and elevating the team’s capabilities through informal training and peer learning. It’s a hands-on, collaborative position that rewards practical security leadership and a steady, thoughtful approach to problem solving.
Day-to-day in the blue team
You’ll push to improve detection and response capabilities, continually refining how you monitor, alert, and respond to incidents. You’ll mentor junior and mid-level engineers, setting a high standard for security practices and offering guidance to support their professional growth. On a regular basis you’ll participate in on-call rotations, coordinating effective resolutions to escalated incidents and ensuring thorough, professional handling of security events.
Delivering white-glove service means you’ll manage incidents with care and completeness, while defining and implementing security practices that align with organisational goals and industry standards. You’ll own security projects from start to finish, prioritising tasks and coordinating with teams to ensure initiatives move forward in line with broader objectives. In parallel, you’ll use and optimise advanced tools, such as SIEM platforms and vulnerability scanners, to improve how the organisation detects, logs, and analyses security data.
Regular vulnerability assessments will be part of your routine, with you identifying gaps in controls and driving practical mitigations. You’ll support compliance work by maintaining documentation and contributing to audits and regulatory standards, helping to sustain certifications and best practices. Collaboration with development and IT teams will be ongoing to bake security into architectural decisions, and you’ll lead security awareness efforts to improve secure coding and defensive thinking across technical teams. Staying current on emerging threats and technologies, you’ll evaluate new tools and methods and guide risk management processes, including documenting security procedures for routine and high-stress incidents. Leadership reporting will be a part of your role, providing incident, vulnerability, and project metrics to inform security decisions, and you’ll push automation to reduce repetitive tasks and tighten detection and response through tooling integration.
The core prerequisites
- A degree in Computer Science, Information Security, or a related field, or equivalent security experience
- At least five years in security engineering and operations, with substantial blue-team work, security architecture, DevOps, and day-to-day operations
- Deep understanding of IT fundamentals, evolving threats, attack patterns, incident response, and security standards
- Proven track record leading incident response, including remediation, mitigation, and status reporting
- Skill in evaluating security events, distinguishing real incidents from false positives, investigation, countermeasures, and monitoring impact
- Strong grasp of OS, networking, and application hardening for Windows, macOS, and Linux, including virtualization security
- Experience deploying and maintaining security technologies such as IDS, DLP, FIM, firewalls, SIEM, MFA, vulnerability tools, web proxies, and WAFs
- Experience with cloud providers and Infrastructure as Code tools like Terraform, Ansible, or CloudFormation
- Proficiency in AWS security best practices
- Automation, development, or scripting skills to enhance security operations
- Advanced knowledge of Application Security, modern web protocols, and Web Application Firewalls
- Proficiency with email security protocols such as SPF, DKIM, and DMARC
- Experience leading security awareness initiatives and formal training for technical teams
- Familiarity with virtualization or container security as part of broader security programs
- Track record of delivering security metrics and insights to leadership
- Comfort with working across diverse, cross-functional teams and influencing security outcomes
Remote-first with on-call and leadership
This is a remote role within the United Kingdom, supported by Olo’s Belfast/Northern Ireland hub as part of the company’s long-term strategy. You’ll join an on-call rotation to respond to security incidents, coordinate effective resolutions, and maintain uptime across the platform. Collaboration with development and IT teams will be constant as you weave security into architectural thinking, governance, and everyday operations. You’ll help ensure documentation, audits, and regulatory standards stay up to date, contributing to ongoing compliance efforts and the organisation’s security maturity.
Tips to stand out in this security role
When you apply, lead with your five-plus years in security engineering and blue-team operations, and make sure to highlight any hands-on incident response leadership, cloud security work, and experience with IaC tools like Terraform or CloudFormation.
Back up your claims with concrete examples of how you evaluated security events, handled real incidents, and mentored others. If you’ve built or improved detection, logging, or automation, describe the impact in measurable terms, what you improved, how quickly you detected it, and what the result was for the business.
Prepare for interviews by walking through a real security incident you led: what the threat was, how you detected it, what steps you took, what the outcome was, and what you would do differently next time. Be ready to discuss how you collaborated with developers and IT to embed security into architecture and how you’d approach risk management in a scale-up environment.
Finally, consider a question that signals your practical focus on the role: ask how the team defines success for the blue team in the first 90 days, what top threats they’re watching, and how they measure security maturity and risk across the organisation.