Salmon Group

SOC Manager at Salmon Group (Serbia)

Salmon Group· Serbia·

Role details

Work type
Remote
Employment
Full-Time

Salmon Group at a glance

A Philippine consumer fintech and licensed neobank offering AI-scored credit, cards, and deposits to underbanked Filipinos.

Salmon is a consumer financial technology company in the Philippines that provides credit lines, installment and cash loans, prepaid cards, and bank deposits to underbanked consumers, using AI credit scoring and a licensed rural bank it acquired.

~$310M ($160M equity + $150M bonds) raised · latest: $100M (April 2026): $60M equity + $40M debt · backed by International Finance Corporation (IFC, World Bank Group), ADQ (Abu Dhabi sovereign wealth fund), Lunate, Antler VC

Job description

Salmon is a technology-driven financial company building a banking and lending platform across Southeast Asia, starting in the Philippines.

We combine global fintech expertise with deep local market knowledge to make financial services simple, accessible, and useful for millions of people across the region.

7M+ app downloads. 2M+ monthly active users. 7,000+ partner stores. US$310M+ raised from leading global investors.

Manila-based, globally distributed, and hybrid-first — our team spans 45+ countries.

If you want to solve complex problems at scale and impact how millions of people access and manage money, come build with us.

Southeast Asia's fintech moment starts here.

ABOUT THE ROLE

You'll own Security Operations at group level across a regulated bank, consumer finance business, and shared technology platform, working directly with the Group CISO.

WHAT YOU'LL DO

  • Set the direction for monitoring, detection, and response across cloud, identity, endpoints, SaaS, and containerised environments
  • Lead the technical response during significant cyber incidents and coordinate the teams involved
  • Select, manage, and hold MSSP/MDR providers accountable, deciding when to build in-house versus buy

WHAT YOU'LL OWN

  • Own the monitoring architecture and telemetry strategy: SIEM design, data sources, retention, forensic readiness, and telemetry cost management
  • Define the threat scenarios that matter most to Salmon, maintain detection coverage against them, and drive threat hunting and detection validation using MITRE ATT&CK
  • Own incident readiness — playbooks, escalation, forensic readiness, post-incident reviews, and tabletop exercises — and take part in complex investigations hands-on, including KQL and telemetry analysis
  • Own Vulnerability and Exposure Management, setting remediation priorities and expectations and governing the risk acceptance process for exceptions
  • Own the operational side of DLP and selected access governance controls, including SSO coverage, privileged access monitoring, and access reviews
  • Set priorities for the Security Operations team and vendors, define metrics on coverage, detection quality, response performance, and provider performance, and own technical readiness for BSP and PCI DSS assurance activities

WHAT MAKES YOU A STRONG FIT

  • Practical experience managing MSSP/MDR or other security service providers, including selection, negotiation, escalation, or replacement
  • Hands-on depth with Microsoft Sentinel and KQL, and experience with Microsoft Defender XDR / Defender for Endpoint
  • Working knowledge of Microsoft 365 security and audit telemetry, identity and access telemetry, and cloud security monitoring in complex environments
  • Experience with containerised platforms and workloads, and with SIEM data flows, retention, tiering, and cost management
  • Track record of independently assessing a security function, prioritising against risk and cost, and leading through serious incidents with incomplete information
  • Comfortable communicating with engineers, providers, the CISO, senior management, Risk, and Internal Audit

OWNERSHIP AND FLEXIBILITY

  • Fully remote work with core collaboration hours from 12:00 to 6:00 PM Manila time (UTC+8)
  • Company-provided tools and equipment

HEALTH AND TIME OFF

  • Medical insurance support for you and your family through co-funding or reimbursement, depending on your location and subject to policy limits
  • Access to an internal mental health support specialist
  • 22 vacation days, Philippine public holidays, and 15 sick days

GROWTH AND TEAM EXPERIENCE

  • Opportunities to learn and share your expertise through internal expert meetups, external conferences, speaking opportunities, and industry publications
  • Company-sponsored trips to Manila to meet and work with your team in person
  • High-performing teams can earn a dedicated beach house week in Southeast Asia

We believe strong teams are built by people with different backgrounds, experiences, and points of view. Salmon is an equal opportunity employer, and we make hiring decisions based on skills, experience, and potential.

Why work at Salmon Group

  • Culture: Emphasizes “dependability,” innovation, and a human touch. Employees describe an agile, open environment where Day One employees shape the company.
  • Work model: Mostly office-based at the Taguig City headquarters (Four/NEO Building, Bonifacio Global City). Some field roles (collections, housekeeping) are site-specific.
  • Notable perks: Competitive salaries (e.g., PHP 30k-40k/month for junior roles; PHP 15k-25k for field roles). Popular roles include Credit Investigator (PHP 28k/month) and Collection Agent (PHP 16k/month).
  • Engineering culture: Strong focus on AI, data analytics, and technology innovation; the CTO and SVP of AI and Data are part of senior management.

Application questions