Security Operations Lead
Core
Lead a global 24/7 Security Operations Center (SOC) to monitor, detect, and respond to threats across cloud-native, AI-driven, and multi-cloud environments.
Role type
Senior Security Operations Lead (SOC Lead)
Builds
24/7 detection and response capabilities, SIEM ecosystems, and AI-integrated security operations for a global software platform.
Domain
Cloud Security / AI Security / Cybersecurity Operations
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
SOC leadership, SIEM ownership, detection engineering, cloud security monitoring (GCP), SaaS security monitoring, endpoint security telemetry, Kubernetes detection, threat hunting, log analysis, SOAR, scripting (Python/Go/Bash), identity security, MITRE ATT&CK
Preferred skills
UBA/UEBA, ML-driven anomaly detection, autonomous remediation systems, high-growth tech company experience, security certifications (GCIH, GCIA, etc.)
Technologies
GCP, AWS, Azure, Kubernetes, GKE, EKS, AKS, Chronicle, Splunk, Elastic, Sentinel, Panther, Okta, Google Workspace, GitHub, Slack, CrowdStrike, SentinelOne, Defender
Responsibilities
Lead and mentor a global SOC team for 24/7 monitoring and alert triage; Build operational rigor including processes, runbooks, SLAs, and metrics; Own the SIEM ecosystem from ingestion to dashboarding; Develop high-fidelity detections for cloud-native, identity, and endpoint threats; Evaluate and integrate AI-native SOC technologies for automation; Collaborate with Cloud Security, SRE, and Engineering to scale detection strategies.
Seniority
Senior, hands-on IC with leadership responsibilities