Envista Security Operations & Engineering Lead (Brea, CA)
Core
Lead enterprise cybersecurity operations, detection engineering, incident response, and security platform capabilities to build scalable, threat-informed security operations.
Role type
Senior Security Operations and Engineering Lead
Builds
SOC operations, detection engineering lifecycle, security tooling ecosystem, and incident response programs
Domain
Enterprise cybersecurity, cloud security, and threat detection
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
Security operations leadership, SIEM/SOAR/EDR/XDR platform management, incident response program ownership, detection engineering lifecycle, MSSP/MDR partnership management, cloud security (Azure/AWS/GCP), Zero Trust principles, executive risk communication
Preferred skills
SOC program transformation, global/multi-business-unit environment experience, major incident response leadership, CISSP/CISM/CCSP/GIAC certifications
Technologies
Microsoft Sentinel, Splunk, QRadar, Chronicle, CrowdStrike, Azure, AWS, GCP
Responsibilities
Lead enterprise security operations including monitoring, triage, investigation, escalation, and response; Oversee SOC and MSSP/MDR partnerships including SLAs and performance metrics; Lead lifecycle management of SIEM, SOAR, EDR/XDR, CSPM, DLP, identity security, and cloud security platforms; Own incident response program including playbooks, exercises, breach workflows, and post-incident reviews; Build detection engineering lifecycle from hypothesis to retirement aligned to MITRE ATT&CK; Build and lead high-performing security operations and engineering teams
Seniority
Senior, hands-on IC with leadership responsibilities