Threat Response Technology and Capabilities Product Owner
Core
Lead the strategy and roadmap for incident response technology, automation, and AI augmentation across global Security Operations, defining the vision for tooling and workflows used by SOC, DFIR, and Threat Response teams.
Role type
Lead Security Engineer / Product Owner (Incident Response & AI)
Builds
Incident response tooling, SOAR playbooks, AI-augmented workflows, and analyst-facing automation pipelines.
Domain
Cybersecurity / Security Operations / AI in Security
Deliverable
production ML models | product features
Required skills
Incident response strategy, SOAR architecture, AI augmentation (agentic workflows, prompt engineering, LLM integration), DFIR (endpoint, network, cloud, identity), Python, PowerShell, SOC 3.0 concepts, vendor management, backlog governance.
Preferred skills
Digital forensics, threat hunting, building AI-augmented response programs from scratch, regulated financial services experience, mobile/cloud forensic acquisition, industry certifications (GCFA, GCIH, etc.).
Technologies
Splunk SOAR, Microsoft Sentinel, Logic Apps, Jupyter Notebooks, EDR, XDR, SIEM, AWS, Azure, GCP.
Responsibilities
Define multi-year strategy for incident response capabilities; maintain capability taxonomy mapped to NIST/MITRE frameworks; oversee SOAR playbook automation and AI augmentation; establish governance for AI-assisted response actions; drive integration strategy across detection and response platforms; manage vendor relationships and procurement; govern the product backlog and run agile delivery.
Seniority
Senior, hands-on IC