Security Operations Team Lead
You lead a Security Operations team that protects infrastructure and manages security operations across production and cloud environments. You guide incident triage, containment, eradication, investigations, and post-mortems; lead SecOps projects; develop incident reports; integrate AI and automated workflows; improve security controls; and mentor analysts while modernizing the SOC toward an autonomous model.
Responsibilities
- Manage and mentor SecOps analysts.
- Provide technical guidance, career development, and performance management.
- Lead triage, containment, eradication, investigations, and post-mortems for high-priority incidents.
- Lead SecOps projects from inception through maintenance.
- Coordinate investigation and response activities with stakeholders.
- Perform forensic investigations, log reviews, cloud investigations, and root-cause analysis.
- Develop incident analysis and findings reports.
- Identify security gaps and recommend improvements.
- Integrate AI models and automated workflows into SecOps operations.
- Modernize SOC operations through autonomous AI workflows.
Requirements
- 5+ years of incident response or cybersecurity operations experience.
- Experience managing security incidents and incident reporting in a global 24/7 production environment.
- Experience integrating AI models and automated workflows into SecOps operations.
- At least 1 year in a team lead, acting lead, or technical lead role.
- Expertise in attack and mitigation methods within AWS, GCP, or Azure.
- Experience with risk prioritization, host-based forensics, and OS artifact analysis.
- Understanding of system and security controls across at least two operating systems.
- Strong communication, collaboration, problem-solving, and analytical skills.
- Bachelor's degree in Computer Science, Information Technology, or a related field preferred.