SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Fuse Energy is an AI-first energy company building a fully integrated energy system combining solar, batteries, grid infrastructure, power trading, and distributed energy solutions. The company has raised over $200M from top-tier investors including Balderton, Accel, Creandum, and others.
You will serve as a hands-on Information Security Analyst, acting as the security escalation point for IT operations. This is a technical, end-to-end ownership role spanning AWS infrastructure, identity management, endpoints, SaaS applications, and data centre environments.
Key responsibilities include:
- Act as escalation point for IT in IAM, security, and automation
- Own security monitoring end-to-end: build and tune log pipelines from AWS (CloudTrail, GuardDuty, VPC Flow Logs), endpoints, identity providers, SaaS audit logs, and network infrastructure
- Write, test, and maintain detection rules that reduce noise and measure coverage against real attacker behaviour
- Lead incident response from detection through containment, eradication, and post-mortem; own and test IR runbooks
- Perform forensic analysis on compromised endpoints, cloud workloads, and accounts
- Work with IT to develop and improve security policies and documentation
- Serve as point of contact for external audits and assessments
- Track threat intelligence relevant to energy, trading, and GPU infrastructure and turn it into detections and hunts
- Run vulnerability management from a threat-led angle: prioritise by exploitability and exposure
- Monitor data centre environments (firewall logs, OOB access, east-west traffic) and flag segmentation breaks
- Feed findings back into prevention by working with IT and engineering teams
- Act as security AI champion, building tools to automate repetitive triage and response tasks
Requirements:
- Background in IT, SOC operations, or other hands-on technical work
- Solid grasp of cloud infrastructure, ideally AWS
- Strong networking knowledge: can read a PCAP, spot beaconing in flow logs, reason about lateral movement across VLANs and firewalls
- Knows attacker tradecraft (initial access, persistence, privilege escalation, exfiltration) and can map investigations to it
- Comfortable scripting in Python or similar to automate enrichment, triage, and response
- Strong ownership mindset: sees things through end-to-end with little guidance
Bonus qualifications: deep familiarity with EDR platforms (CrowdStrike, SentinelOne, Defender); detection-as-code (Sigma, detections in Git, CI-tested); SOAR or custom response automation; defending data centre or colocation environments; ISO 27001 or SOC 2 audit experience; FortiGate logging and NetFlow/sFlow analysis; DFIR certifications (GCIH, GCFA, GCIA); experience in energy, fintech, trading, or other high-value-target sectors.