Collinson is a global loyalty and benefits company.
We use our expertise and products to craft customer experiences which enable some of the world's best-known brands to acquire, engage and retain the most demanding and choice-rich customers. In particular, our unique expertise and insight into high earning, frequent travellers allow us to create products and solutions for our clients that inspire greater customer engagement to drive more profitable relationships, enrich their travel experiences, protect what matters and assist in in times of need.
While specialising in Financial Services, Travel and Retail, we also support clients in multiple sectors. We have worked with over 90 airlines, 20 hotel groups and more than 600 financial institutions and banks, with clients including Accor Hotels, Air France KLM, American Express, British Airways, Cathay Pacific, Diners Club, Mandarin Oriental, Mastercard, Radisson Hotel Group, Sephora, Visa and VHI.
We take our 30 years' experience working with these kinds of household names in over 170 countries and help our clients to deliver the smarter experiences it takes to differentiate their propositions, and help them win deeper devotion with their customers.
Collinson is a privately-owned entrepreneurial business with 2,000 passionate people working in 20 locations worldwide. Our solutions include Priority Pass, the world's best known airport experiences programme, while we are also the trusted partner behind many of the leading financial services, airline and hotel brand's reward programmes and loyalty initiatives.
Purpose of the job
The Senior SecOps Engineer will have a strong background in security operations, incident response, and threat management. As a Senior SecOps Engineer, you will play a critical role in ensuring the security and integrity of our systems and data.
Key Responsibilities
• Lead and manage security operations, including monitoring, detection, and response to security incidents.
• Develop and implement security policies, procedures, and best practices.
• Design and manage security groups and access control lists to enforce least privilege principles.
• Implement and oversee IAM processes to ensure secure access to systems and data.
• Work with the DLP Analyst to develop and maintain DLP protection strategies to prevent data breaches and ensure compliance with regulatory requirements.
• Conduct vulnerability assessments and penetration testing to identify and mitigate security risks.
• Collaborate with cross-functional teams to design and implement security solutions. Write, review, and update security policies, procedures, and documentation.
• Conduct regular security assessments and audits to ensure adherence to industry standards and regulations as well as identify vulnerabilities and implement corrective actions.
• Investigate and analyze security breaches and incidents, providing detailed reports and recommendations.
• Coordinate incident response activities, including investigation, containment, eradication, and recovery.
• Provide regular updates and reports on the status of security incidents to stakeholders.
• Develop and maintain incident response plans and playbooks.
• Stay up to date with the latest security trends, threats, and technologies.
• Mentor and provide guidance to junior SecOps team members.
Knowledge, skills and experience required
• Bachelor's degree in Computer Science, Information Security, or a related field.
• Minimum of 5 years of experience in security operations, incident response, and threat management.
• Strong knowledge of security frameworks and standards (e.g., NIST, ISO 27001, CIS).
• Proficiency in security tools and technologies (e.g., SIEM, IDS/IPS, firewalls, antivirus).
• Experience with cloud security (e.g., AWS, Azure) and container security (e.g., Docker, Kubernetes).
• Relevant certifications (e.g., CISSP, CISM, CEH) are a plus.
Preferred Skills and Certifications:
• Advanced knowledge of scripting and automation (e.g., Python, PowerShell, Bash).
• Experience with DevSecOps practices and tools (e.g., Jenkins, GitLab, Ansible).
• Familiarity with regulatory compliance requirements (e.g., GDPR, HIPAA, PCI-DSS, DORA).
• Strong understanding of network security and protocols.
• Certifications such as OSCP, OSCE, or GIAC is highly desirable.
• Experience with security orchestration, automation, and response (SOAR) platforms.
Person Specification
• Excellent problem-solving and analytical skills.
• Strong communication and interpersonal skills.

Collinson is the global, privately-owned company dedicated to helping the world to travel with ease and confidence. We work with the world’s leading payment networks, over 1,400 banks, 90 airlines and 20 hotel groups worldwide. We deliver market-leading airport experiences, loyalty and customer engagement, and insurance solutions for over 400 million end consumers.
We are also the operator of Priority Pass, the world’s original and leading airport experiences programme. Travellers can access a network of 1,800+ airport lounges and travel experiences in 841 airports in 146 countries
Private ownership means we can focus on the values that are important to us. These drive everything we do and result in us acting with integrity and agility while making long-term investments and decisions.