Envista Security Operations & Engineering Lead (Brea, CA)

Envista Holdings Corporation

Brea (CA)

On-site

USD 156,000 - 191,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical/dental/vision benefits
401K match

Job summary

Envista Holdings Corporation is seeking a strategic Security Operations and Engineering Lead to drive enterprise cybersecurity operations, detection engineering, incident response, and security platform capabilities. This leader will own the SOC, incident response program, detection lifecycle, and security tooling ecosystem to build scalable, threat-informed, and measurable security operations.

The role emphasizes 24x7 monitoring, cross‑functional collaboration, and leadership of SOC/ENG teams

Qualifications

  • Bachelor's degree or equivalent industry experience and leadership experience are valued.
  • 7+ years of experience in cybersecurity, security operations, detection engineering, incident response, or security engineering.
  • 5+ years leading security operations, engineering, SOC, or incident response teams.
  • Experience operating security capabilities across cloud, SaaS, endpoint, identity, and enterprise environments.
  • Experience managing MSSP, MDR, SOC-as-a-Service, or strategic security service providers.
  • Hands-on experience with SIEM platforms (Microsoft Sentinel, Splunk, QRadar, Chronicle, etc.).
  • Experience in Azure, AWS, or GCP environments.
  • Understanding of Zero Trust security principles and modern detection strategies.
  • Ability to communicate technical risks to executive leadership and business stakeholders.
  • Experience coordinating investigations across security, IT, legal, privacy, HR, and executive stakeholders.

Responsibilities

  • Lead enterprise security operations including monitoring, triage, investigation, escalation, and response.
  • Oversee SOC and MSSP/MDR partnerships including SLAs, alert quality, escalation paths, and performance metrics.
  • Establish 24x7 monitoring aligned to enterprise risk.
  • Define KPIs/KRIs including MTTD, MTTR, alert fidelity, detection coverage, and response effectiveness.
  • Lead lifecycle management of SIEM, SOAR, EDR/XDR, CSPM, DLP, identity security, and cloud security platforms.
  • Drive automation across triage, enrichment, containment, and reporting workflows.
  • Define enterprise logging and telemetry strategy including onboarding, parsing, normalization, retention, and coverage standards.
  • Ensure tools are integrated, cost‑effective, and aligned to risk priorities.
  • Own incident response program including playbooks, exercises, breach workflows, and communications.
  • Lead major incidents through containment, eradication, recovery, and root cause analysis.
  • Ensure post‑incident reviews drive durable control improvements.
  • Coordinate with Legal, Privacy, HR, IT, and Communications.
  • Build detection engineering lifecycle: hypothesis to development to testing to tuning to deployment to validation to retirement.
  • Develop behavior‑based and threat‑informed detections aligned to MITRE ATT&CK.
  • Expand monitoring across endpoint, identity, cloud, SaaS, network, and critical applications.
  • Identify and close detection gaps via red team, pentest, and vulnerability insights.
  • Support exposure management, asset inventory visibility, and attack surface monitoring.
  • Drive continuous control monitoring and validation of key security controls.
  • Improve vulnerability remediation workflows and risk reduction outcomes.
  • Build and lead high‑performing security operations and engineering teams.
  • Establish clear roles, operating model, and accountability.
  • Provide executive reporting on threats, incidents, control gaps, and maturity.
  • Partner with GRC, Audit, IT, Architecture, and business leadership.

Skills

Security operations leadership
Incident response leadership
Detection engineering
Executive communication

Education

Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Systems, Business, Engineering, or related fields

Tools

Microsoft Sentinel
Splunk
QRadar
Chronicle

Job description

Job Summary

This position is based on‑site and requires four days per week in the Brea office to support collaboration and business needs.

We are seeking a strategic and hands‑on Security Operations and Engineering Lead to drive enterprise cybersecurity operations, detection engineering, incident response, and security platform capabilities.

This leader owns the SOC, incident response program, detection lifecycle, and security tooling ecosystem, and is responsible for building scalable, threat‑informed, and measurable security operations.

Primary Duties And Responsibilities
Security Operations Leadership
  • Lead enterprise security operations including monitoring, triage, investigation, escalation, and response
  • Oversee SOC and MSSP/MDR partnerships including SLAs, alert quality, escalation paths, and performance metrics
  • Establish 24x7 monitoring aligned to enterprise risk
  • Define KPIs/KRIs including MTTD, MTTR, alert fidelity, detection coverage, and response effectiveness
Security Engineering & Platform Management
  • Lead lifecycle management of SIEM, SOAR, EDR/XDR, CSPM, DLP, identity security, and cloud security platforms
  • Drive automation across triage, enrichment, containment, and reporting workflows
  • Define enterprise logging and telemetry strategy including onboarding, parsing, normalization, retention, and coverage standards
  • Ensure tools are integrated, cost‑effective, and aligned to risk priorities
Incident Response & Threat Management
  • Own incident response program including playbooks, exercises, breach workflows, and communications
  • Lead major incidents through containment, eradication, recovery, and root cause analysis
  • Ensure post‑incident reviews drive durable control improvements
  • Coordinate with Legal, Privacy, HR, IT, and Communications
Detection Engineering & Monitoring
  • Build detection engineering lifecycle: hypothesis to development to testing to tuning to deployment to validation to retirement
  • Develop behavior‑based and threat‑informed detections aligned to MITRE ATT&CK
  • Expand monitoring across endpoint, identity, cloud, SaaS, network, and critical applications
  • Identify and close detection gaps via red team, pentest, and vulnerability insights
Exposure & Control Operations
  • Support exposure management, asset inventory visibility, and attack surface monitoring
  • Drive continuous control monitoring and validation of key security controls
  • Improve vulnerability remediation workflows and risk reduction outcomes
Leadership & Stakeholder Management
  • Build and lead high‑performing security operations and engineering teams
  • Establish clear roles, operating model, and accountability
  • Provide executive reporting on threats, incidents, control gaps, and maturity
  • Partner with GRC, Audit, IT, Architecture, and business leadership
Job Requirements
  • Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Systems, Business, Engineering, or a related fields OR equivalent industry experience, military service, professional certifications, and demonstrated leadership experience are valued equally.
  • 7+ years of experience in cybersecurity, security operations, detection engineering, incident response, or security engineering.
  • 5+ years leading security operations, engineering, SOC, or incident response teams.
  • Experience operating security capabilities across cloud, SaaS, endpoint, identity, and enterprise environments.
  • Experience managing MSSP, MDR, SOC-as-a-Service, or strategic security service providers.
  • Hands‑on experience with SIEM platforms (Microsoft Sentinel, Splunk, QRadar, Chronicle, etc.)
  • Experience in Azure, AWS, or GCP environments.
  • Understanding of Zero Trust security principles and modern detection strategies.
  • Ability to communicate technical risks to executive leadership and business stakeholders.
  • Experience coordinating investigations across security, IT, legal, privacy, HR, and executive stakeholders.
Preferred Skills & Experience
  • 10+ years of cybersecurity experience.
  • Experience building or transforming a SOC program.
  • Experience supporting a global or multi‑business‑unit environment.
  • Experience leading incident response for major cybersecurity events.
  • One or more of the following certifications: CISSP; CISM; CCSP; GIAC certifications (GCIH, GCIA, GCFA, GMON); Microsoft Security certifications; Splunk certifications; Microsoft Sentinel certifications; CrowdStrike certifications; AWS/Azure/GCP security certifications.

IND123

Actual compensation packages take into account a wide range of factors that are unique to each candidate, including but not limited to geographic location; skill sets; relevant education and certifications; depth of experience; performance; and other business and organizational needs. The disclosed reasonable estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Envista, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. The total compensation package for this position may also include an annual performance bonus, medical/dental/vision benefits, 401K match, and/or other applicable compensation plans.

$156,400 - $191,200

Operating company:Corporate

Envista and its family of companies (Envista) will not accept unsolicited resumes from any source other than directly from a candidate. Envista will consider unsolicited referrals and/or resumes submitted by vendors such as search firms, staffing agencies, professional recruiters, fee‑based referral services and recruiting agencies (Agency) to have been referred by the Agency free of charge and Envista will not pay a fee for any placement resulting from the receipt such unsolicited resumes. An Agency must obtain advance written approval from Envista's internal Talent Acquisition or Human Resources team to submit resumes, and then only in conjunction with a valid fully‑executed contract approved by the Global Talent Acquisition leader and in response to a specific job opening. Envista will not pay a fee to any Agency that does not have such agreement and written approval in place.

Envista and all Envista Companies are equal opportunity employers that evaluate qualified applicants without regard to race, color, national origin, religion, sex, age, marital status, disability, veteran status, sexual orientation, gender identity, or other characteristics protected by law. The “EEO is the Law” poster is available at: https://www.dol.gov/sites/dolgov/files/ofccp/regs/compliance/posters/pdf/eeopost.pdf

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Microsoft Cloud Platform Engineer
Principal Microsoft Cloud Platform Engineer

Envista Holdings Corporation • Brea (CA)

On-site
USD 187,000 - 229,000
Lead End User Computing (EUC) Engineer
Lead End User Computing (EUC) Engineer

Envista Holdings Corporation • Brea (CA)

On-site
USD 145,000 - 193,000
Strategic HRBP, Corporate Functions
Strategic HRBP, Corporate Functions

Envista Holdings Corporation • Brea (CA)

On-site
USD 135,000 - 166,000
Envista Director, IT Integration (Brea, CA)
Envista Director, IT Integration (Brea, CA)

Envista Holdings Corporation • Brea (CA)

On-site
USD 203,000 - 248,000
Envista Sr. Manager, Salesforce Architect (Brea, CA)
Envista Sr. Manager, Salesforce Architect (Brea, CA)

Envista Holdings Corporation • Brea (CA)

On-site
USD 164,000 - 190,000
Sr. Security Operations Analyst
Sr. Security Operations Analyst

enVista • Carmel (IN)

Hybrid
USD 120,000 - 150,000
Competitive pay bonuses
Comprehensive health coverage
PTO and sabbatical programme
+3
Information Security Operations Lead/Manager
Information Security Operations Lead/Manager

enVista Corp. • Carmel (IN)

Hybrid
USD 140,000 - 190,000
Life Insurance
Short/Long Term Disability
401k with Company Matching
+2
Sr. FP&A Analyst
Sr. FP&A Analyst

Envista Holdings Corporation • Brea (CA)

On-site
USD 90,700 - 136,100
Sr. Director, Compensation
Sr. Director, Compensation

Envista Holdings Corporation • Brea (CA)

On-site
USD 197,000 - 240,000
401K match
Medical benefits
Vision benefits
Member of Technical Staff, SecOps & Threat Detection Engineer
Member of Technical Staff, SecOps & Threat Detection Engineer

Envoy Inc. • San Francisco (CA)

On-site
USD 180,000 - 240,000