
An Introduction to Primer
Primer is the unified infrastructure for global payments. We give finance and payments teams the visibility and control to reduce complexity, improve performance, and capture more revenue — all from a single platform.
Backed by Sofina, Peak XV Partners, ICONIQ, Tencent, Accel, and Balderton, we're building the payments layer the world's best companies rely on.
Primer is looking for a Security Engineer to help us detect, investigate, and respond to threats across our cloud infrastructure. You'll take ownership of a meaningful slice of our detection and response capability — tuning what our SIEM catches, building the automation that speeds up how we react, and being a first responder when something looks wrong.
What you'll be doing
- Plan and deliver detection and response work end-to-end — from a new detection rule to a fully automated response — within your area of ownership.
- Build, tune and maintain detections across our SIEM (Elastic) and AWS environment, closing gaps that existing coverage misses.
- Own an investigation queue: triage, investigate, escalate and resolve security incidents, and write up findings clearly enough to stand on their own.
- Build runbooks and automations (Python, and no-code tools like Zapier or Tines) to cut manual work out of triage and response.
- Make and document risk decisions in your area, and know when to pull in others.
- Support our compliance programme by keeping the controls you own audit-ready and contributing evidence for audits (e.g. SOC 2, PCI DSS).
- Use Terraform and Python to build and maintain the infrastructure behind your detections and tooling.
- Join our on-call rotation for incident response and monitoring.
What we're looking for
- Hands-on experience building and tuning detections in a SIEM (Elastic preferred; Splunk, Sentinel or similar also welcome)
- Experience with AWS and cloud-native detection and response
- Comfortable with Python for scripting and automation
- Experience with Terraform or other infrastructure-as-code
- Working knowledge of MITRE ATT&CK
- Real experience triaging, investigating and resolving security incidents
- Clear, structured written communication
Nice to have
- Experience with no-code security automation / SOAR-style tooling
- Exposure to compliance frameworks like PCI DSS, SOC 2 or ISO 27001
- Background in fintech, payments or another regulated industry
A typical interview process
- An initial intro call with a Talent Partner
- An interview with the Hiring Manager
- Challenge Stage - Contextualised to the role
- A final, values-alignment interview
Our benefits
- Fully remote and globally distributed team
- Competitive share options
- Uncapped holiday, with 25 days minimum to be taken
- Co-working space access across major cities
- Workations & Company Retreat
- The best equipment for your role
- £500 towards your home office setup
- Generous learning budget
- Private Medical Insurance
- Broad set of additional perks and benefits (depending on location)
Timezone overlap
UTC+0–+3
Benefits
Equity, Unlimited PTO, Coworking, Equipment, Home office, Learning, Health, Commission, Parental leave
Open to
Europe · Africa
Sign in to track applications and earn points.