- Direct, mentor, and manage the security operations team and oversee external MSSP partners
- Lead 24/7 security monitoring, incident triage, and response across Enterprise IT, cloud, Product/IoT, customer-facing applications, and Manufacturing/OT facilities
- Own monitoring, threat detection, and incident response for customer-facing applications, portals, APIs, authentication systems, and customer data pathways
- Lead threat monitoring and telemetry analysis for external-facing platforms and connected infrastructure
- Optimize SIEM/SOAR platforms, detection rules, threat-hunting playbooks, and automated response workflows
- Act as primary escalation lead and incident commander during complex cybersecurity incidents
- Lead containment, eradication, root-cause analysis, and customer communications
- Collaborate with plant operations and IC_S engineers on visibility, anomaly detection, and incident handling
- Support security logging, audit readiness, and incident response procedures aligned with applicable frameworks
- Develop, track, and present security metrics, threat landscapes, application security posture, and SOC KPIs to executives and stakeholders
- Serve as senior operational contact and manage on-call escalation rotations
Requirements
- Minimum of 5-7 years of experience in Security Operations (SOC), Threat Intelligence, or Incident Response
- At least 3+ years in a supervisory, management, or technical lead role
- Demonstrated success managing vendor/MSSP contracts, service delivery SLAs, and combined internal/external teams
- Hands-on leadership experience spanning enterprise IT, cloud infrastructure, customer-facing applications/platforms, and OT/ICS
- Working knowledge of application security monitoring, web/API threat detection, and securing customer-facing platforms and portals
- Understanding of ISO 27001, NIST SP 800-82, IEC 62443, or similar frameworks
- Strong experience acting as Incident Commander during major breach responses, cyber-attacks, or critical infrastructure outages
- Bachelor's or master's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical field, or equivalent related work experience
- Relevant certifications such as CISSP, CISM, GCIH, GCFA, GRID, or GICSP preferred
- Experience with SaaS platforms, IoT/connected product ecosystems, or remote monitoring applications preferred
- Familiarity with Microsoft Sentinel, Defender XDR, Palo Alto Networks, web application firewalls, API security tools, Dragos, Claroty, or Nozomi preferred
- Legally authorized to work in the United States
- Visa sponsorship is not available
Core Competencies
Demonstrates extensive experience in Security Operations, Incident Response, and Threat Intelligence with a strong focus on managing security teams and external partners. Proficient in application security monitoring, threat detection, and incident management across various platforms and infrastructures.
Highest-signal resume keywords
- Security Operations Management
- Incident Response Leadership
- Threat Detection and Monitoring
- Application Security Monitoring
- Vendor Management
ATS Optimization Keywords
Hard Skills
- Security Operations
- Incident Response
- Threat Intelligence
- Application Security Monitoring
- Web/API Threat Detection
- Root-cause Analysis
- Security Metrics Development
- Audit Readiness
- Cybersecurity Frameworks
- Incident Command
Soft Skills
- Leadership
- Mentoring
- Collaboration
- Communication
- Problem-Solving
Certifications & Qualifications
- CISSP
- CISM
- GCIH
- GCFA
- GRID
- GICSP
Industry Keywords
- ISO 27001
- NIST SP 800-82
- IEC 62443
- Enterprise IT
- Cloud Infrastructure
- OT/ICS
- Customer-Facing Applications
- MSSP
- SaaS Platforms
- IoT
Tools & Technologies
- SIEM
- SOAR
- Microsoft Sentinel
- Defender XDR
- Palo Alto Networks
- Web Application Firewalls
- API Security Tools
- Dragos
- Claroty
- Nozomi