Envista Security Operations & Engineering Lead (Brea, CA)

envista

Brea (CA)

On-site

USD 180,000 - 240,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Envista is seeking a strategic Security Operations and Engineering Lead to drive enterprise cybersecurity operations, detection engineering, incident response, and security platform capabilities. This on‑site role requires four days in the Brea office to support collaboration and business needs.

You will own the SOC, incident response program, detection lifecycle, and security tooling ecosystem, building scalable, threat‑informed, measurable security operations for the organization.

Qualifications

  • Bachelor's degree or equivalent experience in a related field and leadership experience.
  • 7+ years in cybersecurity, security operations, detection engineering, incident response, or security engineering.
  • 5+ years leading security operations, SOC, or incident response teams.
  • Experience across cloud, SaaS, endpoint, identity, and enterprise environments.

Responsibilities

  • Lead enterprise security operations including monitoring, triage, investigation, escalation, and response.
  • Oversee SOC and MSSP/MDR partnerships with SLAs, alert quality, escalation paths, and metrics.
  • Define KPIs/KRIs including MTTD, MTTR, alert fidelity, and detection coverage.
  • Own incident response program including playbooks, exercises, breach workflows, and communications.
  • Drive automation across triage, enrichment, containment, and reporting workflows.

Skills

Security operations
Incident response
Detection engineering
Leadership
Cloud security

Education

Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Systems, Business, Engineering, or related fields

Tools

Microsoft Sentinel
Splunk
QRadar
Chronicle

Job description

Job Description

JOB SUMMARY

This position is based on‑site and requires four days per week in the Brea office to support collaboration and business needs.

We are seeking a strategic and hands‑on Security Operations and Engineering Lead to drive enterprise cybersecurity operations, detection engineering, incident response, and security platform capabilities. This leader owns the SOC, incident response program, detection lifecycle, and security tooling ecosystem, and is responsible for building scalable, threat‑informed, and measurable security operations.

PRIMARY DUTIES AND RESPONSIBILITIES
Security Operations Leadership
  • Lead enterprise security operations including monitoring, triage, investigation, escalation, and response
  • Oversee SOC and MSSP/MDR partnerships including SLAs, alert quality, escalation paths, and performance metrics
  • Establish 24x7 monitoring aligned to enterprise risk
  • Define KPIs/KRIs including MTTD, MTTR, alert fidelity, detection coverage, and response effectiveness
Security Engineering & Platform Management
  • Lead lifecycle management of SIEM, SOAR, EDR/XDR, CSPM, DLP, identity security, and cloud security platforms
  • Drive automation across triage, enrichment, containment, and reporting workflows
  • Define enterprise logging and telemetry strategy including onboarding, parsing, normalization, retention, and coverage standards
  • Ensure tools are integrated, cost-effective, and aligned to risk priorities
Incident Response & Threat Management
  • Own incident response program including playbooks, exercises, breach workflows, and communications
  • Lead major incidents through containment, eradication, recovery, and root cause analysis
  • Ensure post-incident reviews drive durable control improvements
  • Coordinate with Legal, Privacy, HR, IT, and Communications
Detection Engineering & Monitoring
  • Build detection engineering lifecycle: hypothesis - development - testing - tuning - deployment - validation - retirement
  • Develop behavior-based and threat-informed detections aligned to MITRE ATT&CK
  • Expand monitoring across endpoint, identity, cloud, SaaS, network, and critical applications
  • Identify and close detection gaps via red team, pentest, and vulnerability insights
Exposure & Control Operations
  • Support exposure management, asset inventory visibility, and attack surface monitoring
  • Drive continuous control monitoring and validation of key security controls
  • Improve vulnerability remediation workflows and risk reduction outcomes
Leadership & Stakeholder Management
  • Build and lead high-performing security operations and engineering teams
  • Establish clear roles, operating model, and accountability
  • Provide executive reporting on threats, incidents, control gaps, and maturity
  • Partner with GRC, Audit, IT, Architecture, and business leadership
Job Requirements
  • Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Systems, Business, Engineering, or a related fields OR equivalent industry experience, military service, professional certifications, and demonstrated leadership experience are valued equally.
  • 7+ years of experience in cybersecurity, security operations, detection engineering, incident response, or security engineering.
  • 5+ years leading security operations, engineering, SOC, or incident response teams.
  • Experience operating security capabilities across cloud, SaaS, endpoint, identity, and enterprise environments.
  • Experience managing MSSP, MDR, SOC-as-a-Service, or strategic security service providers.
  • Hands‑on experience with SIEM platforms (Microsoft Sentinel, Splunk, QRadar, Chronicle, etc.)
  • Experience in Azure, AWS, or GCP environments.
  • Understanding of Zero Trust security principles and modern detection strategies.
  • Ability to communicate technical risks to executive leadership and business stakeholders.
  • Experience coordinating investigations across security, IT, legal, privacy, HR, and executive stakeholders.
PREFERRED SKILLS & EXPERIENCE
  • 10+ years of cybersecurity experience.
  • Experience building or transforming a SOC program.
  • Experience supporting a global or multi-business-unit environment.
  • Experience leading incident response for major cybersecurity events.
  • One or more of the following certifications: CISSP; CISM; CCSP; GIAC certifications (GCIH, GCIA, GCFA, GMON); Microsoft Security certifications; Splunk certifications; Microsoft Sentinel certifications; CrowdStrike certifications; AWS/Azure/GCP security certifications.

#LI-SC1

IND123

Target Market Salary Range

Actual compensation packages take into account a wide range of factors that are unique to each candidate, including but not limited to geographic location; skill sets; relevant education and certifications; depth of experience; performance; and other business and organizational needs. the disclosed reasonable estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Envista, it is not t

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations & Engineering Lead - Onsite in Brea
Security Operations & Engineering Lead - Onsite in Brea

envista • Brea (CA)

On-site
USD 180,000 - 240,000
Security Operations Leader – On-site in Brea
Security Operations Leader – On-site in Brea

Envista Holdings Corporation • Brea (CA)

On-site
USD 156,400 - 191,200
Director of IT Security Operations
Director of IT Security Operations

The Security Executive Council • United States

Remote
USD 170,000 - 210,000
Medical, dental, and vision coverage
401(k) company match
Generous Paid Time Off
+1
Cyber Security Engineer
Cyber Security Engineer

empirical Foods • North Sioux City (SD)

On-site
USD 100,000 - 140,000
Health benefits
Dental insurance
Vision insurance
+5
Senior Detection & Response Analyst
Senior Detection & Response Analyst

Remote Jobs • United States

On-site
USD 110,000 - 190,000
Global Cybersecurity Engineer
Global Cybersecurity Engineer

Ledgent Technology • Manassas (VA)

Hybrid
USD 140,000 - 145,000
Medical insurance
Dental insurance
Vision insurance
+5
Sr. SOC Analyst
Sr. SOC Analyst

HW3 • Village of Great Neck (NY)

On-site
USD 130,000 - 170,000
Senior Security Engineer
Senior Security Engineer

Ensono • United States

On-site
USD 112,000 - 130,000
Unlimited Paid Days Off
401k with company match
Education Reimbursement
+1
Sr. Security Engineer
Sr. Security Engineer

California Water Service • San Jose (CA)

On-site
USD 180,000 - 240,000
Senior Security Analyst, Detection & Response
Senior Security Analyst, Detection & Response

Jobgether • United States

On-site
USD 100,000 - 130,000
Competitive salary
Senior cybersecurity role
Diverse environments and platforms
+3