Security Operations Team Lead
You lead a Security Operations team that protects infrastructure and manages security operations across production and cloud environments. You guide incident triage, containment, eradication, investigations, and post-mortems; lead SecOps projects; develop incident reports; integrate AI and automated workflows; improve security controls; and mentor analysts while modernizing the SOC toward an autonomous model.
Responsibilities
- Manage and mentor SecOps analysts
- Provide technical guidance and performance management
- Lead triage, containment, and post-mortems for high-priority incidents
- Lead SecOps projects from inception through maintenance
- Coordinate investigations and response activities with stakeholders
- Perform forensic investigations, log reviews, cloud investigations, and root-cause analysis
- Develop incident analysis and findings reports
- Identify security gaps and recommend improvements
- Integrate AI models and automated workflows into SecOps operations
- Modernize SOC operations through autonomous AI workflows
Requirements
- 5+ years of incident response or cybersecurity operations experience
- Security incident lifecycle management in a global 24/7 production environment
- Security incident reporting
- Security automation and AI workflow integration
- 1+ years in a team lead or acting lead role
- AWS, GCP, or Azure attack and mitigation expertise
- Risk prioritization
- System and security controls across at least two operating systems
- Host-based forensics
- OS artifact analysis
- Bachelor's degree in Computer Science, Information Technology, or a related field