Security Operations Lead
Core
Lead detection, triage, and response operations for enterprise security incidents, blending hands-on incident handling with detection engineering and automation.
Role type
Senior IC Security Operations Lead (Detection & Response)
Builds
Resilient detection strategies, SOC playbooks, and automated response workflows
Domain
Cybersecurity / Security Operations Center (SOC)
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
SIEM rule authoring and tuning, threat hunting, incident response playbook development, automation scripting (Python/PowerShell/Bash), post-incident review and root cause analysis, alert triage and enrichment, EDR platform management, SOAR implementation
Preferred skills
Cross-functional technical influence, executive communication, mentorship of SOC analysts, advanced telemetry analysis
Technologies
Google Security Operations, Microsoft Sentinel, IBM QRadar, CrowdStrike, Microsoft Defender, SentinelOne
Responsibilities
Lead complex security incidents end-to-end, author and tune SIEM rules, conduct threat hunts, build and operationalize SOC playbooks, mentor SOC analysts, execute post-incident reviews and remediation plans
Seniority
Senior, hands-on IC