Lead, Cybersecurity Engineer Operations

Ritchie Bros.

Westchester (IL)

On-site

USD 140,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

RB Global is seeking a Lead, Cybersecurity Operations to guide the security operations team in detecting threats, responding to incidents, and maturing detection capabilities across the organization. You will own end‑to‑end incident response coordination, escalation support for analysts, and cross‑functional collaboration with leadership.

The role requires hands‑on leadership, deep technical expertise, and a track record of improving SOC performance in a fast‑paced threat landscape.

Qualifications

  • Bachelor’s degree in CS/IT/Cybersecurity or equivalent practical experience.
  • Security+, GCIH, GCIA, GCED, or equivalent certifications.
  • 5–8+ years of experience in cybersecurity operations or SOC environments.

Responsibilities

  • Lead Cybersecurity Operations Execution & Quality – Oversee day‑to‑day security monitoring, detection, and response activities, ensuring high‑quality investigations and timely remediation of security events and incidents.
  • Serve as Primary Technical Escalation Point – Act as the go‑to escalation resource for analysts, providing hands‑on guidance for complex investigations.
  • Own Incident Response Lifecycle & Stakeholder Coordination – Lead and coordinate complex security incidents end‑to‑end, while acting as a liaison between leadership and the SOC—translating strategic direction into actionable tasks.
  • Drive Detection & Response Maturity (SIEM & Tooling) – Lead SIEM‑driven operations and continuously improve detection capabilities through use‑case development, telemetry optimization, and enhanced coverage.
  • Coordinate SME Programs & Operational Initiatives – Break down strategic cybersecurity objectives into actionable workstreams, track progress and remove blockers.
  • Develop & Optimize Playbooks, Processes, and Automation – Create incident response playbooks, SOPs and automation opportunities to improve consistency and efficiency.
  • Leverage Metrics & Threat Insights to Drive Improvement – Track MTTD/MTTR and conduct advanced threat analysis to inform decisions.

Skills

Incident response leadership
Security operations
Threat detection

Education

Bachelor’s degree in CS/IT/Cybersecurity

Tools

SIEM platforms
EDR
NDR
Email security
WAF
Identity monitoring tools

Job description

About the Company

RB Global is a leading marketplace that provides value‑added insights, services, and transaction solutions for buyers and sellers of commercial assets and vehicles worldwide.

Benefits

Medical, dental, vision, and basic life insurance; 401(k) plan with 100% match for the first 4% contributed; 15 days of paid time off annually.

About the Role

We are seeking a Lead, Cybersecurity Operations to play a critical role in advancing our global Cybersecurity Operations (CSOC) capabilities. This individual will serve as a senior technical leader responsible for overseeing threat detection, incident response, and continuous improvement of security operations across the organization. As part of the Cybersecurity Operations Team, the Lead will drive operational excellence by enhancing detection strategies, improving incident response processes, and ensuring effective use of security technologies. This role acts as the primary technical escalation point for analysts and a key liaison between leadership and the SOC team—translating strategic direction into actionable work and ensuring meaningful outcomes.

This position requires a hands‑on leader with deep technical expertise, strong operational awareness, and a passion for elevating both team performance and cybersecurity capabilities in a fast‑paced, evolving threat landscape.

Responsibilities
  • Lead Cybersecurity Operations Execution & Quality – Oversee day‑to‑day security monitoring, detection, and response activities, ensuring high‑quality investigations and timely remediation of security events and incidents.
  • Serve as Primary Technical Escalation Point – Act as the go‑to escalation resource for analysts, providing hands‑on guidance for complex investigations and ensuring consistency and depth in investigative outcomes.
  • Own Incident Response Lifecycle & Stakeholder Coordination – Lead and coordinate complex security incidents end‑to‑end, while acting as a liaison between leadership and the SOC—translating strategic direction into actionable tasks and delivering clear, meaningful updates.
  • Drive Detection & Response Maturity (SIEM & Tooling) – Lead SIEM‑driven operations and continuously improve detection capabilities through use‑case development, tuning, telemetry optimization, and enhanced coverage across security domains.
  • Coordinate SME Programs & Operational Initiatives – Break down strategic cybersecurity objectives into actionable workstreams, track progress, remove blockers, and ensure successful execution of team initiatives.
  • Develop & Optimize Playbooks, Processes, and Automation – Create and refine incident response playbooks, SOPs, and automation opportunities to improve consistency, efficiency, and scalability of operations.
  • Leverage Metrics & Threat Insights to Drive Improvement – Track key operational metrics (MTTD, MTTR, alert fidelity) and conduct advanced threat analysis to inform decisions, strengthen defenses, and continuously improve security posture.
Requirements
  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field (or equivalent practical experience).
  • Security+, GCIH, GCIA, GCED, or equivalent certifications.
  • 5–8+ years of experience in cybersecurity operations or SOC environments.
  • Proven experience leading or coordinating incident response activities.
  • Hands‑on experience with SIEM platforms and building detection‑driven operations.
  • Strong familiarity with security technologies such as EDR, NDR, email security, WAF, and identity/security monitoring tools.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Cybersecurity Engineer
Lead Cybersecurity Engineer

RB Global Inc. • Westchester (IL)

On-site
USD 140,000 - 190,000
Senior Cybersecurity Operations Lead
Senior Cybersecurity Operations Lead

Ritchie Bros. • Westchester (IL)

On-site
USD 140,000 - 180,000
Senior SOC Lead: Threat Detection & Incident Response
Senior SOC Lead: Threat Detection & Incident Response

RB Global Inc. • Westchester (IL)

On-site
USD 140,000 - 190,000
Lead Cyber Security Engineer (HYBRID)
Lead Cyber Security Engineer (HYBRID)

Phantom Staffing • Boston (MA)

Hybrid
USD 120,000 - 160,000
W2 - Lead of Cybersecurity Operations
W2 - Lead of Cybersecurity Operations

Acumenz Consulting • Richardson (TX)

Hybrid
USD 120,000 - 150,000
Senior Manager, Global Security Operations
Senior Manager, Global Security Operations

Triwill Group • United States

On-site
USD 152,000 - 210,000
Remote work opportunity
Private workspace provided
Connectivity reimbursement
+1
SOC Manager
SOC Manager

HW3 • Jacksonville (FL)

On-site
USD 120,000 - 180,000
Sr. SOC Analyst
Sr. SOC Analyst

HW3 • Village of Great Neck (NY)

On-site
USD 130,000 - 170,000
Lead, Cybersecurity Architecture & Operations
Lead, Cybersecurity Architecture & Operations

Culligan International • Rosemont (IL)

Hybrid
USD 140,000 - 180,000
Cybersecurity Lead
Cybersecurity Lead

21 Air LLC. • Miami (FL)

Hybrid
USD 120,000 - 170,000