Security Operations Lead
Core
Strategic and operational ownership of internal SecOps capability and external MSSP relationship, acting as primary incident responder and driving maturity of the security function.
Role type
Senior individual contributor Security Operations Lead (player-coach)
Builds
Internal SecOps function, automated response playbooks, detection engineering roadmap, and threat intelligence capabilities
Domain
Fintech, Cloud Security, Managed Security Services
Deliverable
production ML models | infrastructure
Required skills
Incident Command, Advanced Tier 2/3 Analysis, Vendor Governance (MSSP), Detection & Logging Strategy, Automation-Driven Remediation, Threat Intelligence, Core Domain Ownership (EDR, Email Security, DLP, IAM), Capability Scaling
Preferred skills
Cloud-Native Literacy (AWS, Kubernetes, CI/CD), Python/Scripting, AI-augmented capabilities
Technologies
AWS, Kubernetes, CI/CD pipelines, Python, EDR, Email Security, DLP, IAM
Responsibilities
Serve as primary Incident Commander for high-severity escalations; Act as escalation point for technical investigations from MSSP; Maintain and evolve Security Crisis Management plan; Define KRIs/KPIs and run service reviews for MSSP; Own detection engineering roadmap and log ingestion pipelines; Oversee vulnerability management lifecycle and automated remediation workflows; Develop Threat Intel capability; Optimize posture across EDR, Email Security, DLP, and IAM; Drive technical roadmap for SecOps maturity and team expansion.
Seniority
Senior, hands-on IC with path to management
