Lead Cybersecurity Engineer

RB Global Inc.

Westchester (IL)

On-site

USD 140,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

RB Global Inc. is seeking a Lead, Cybersecurity Operations to drive the growth of our global CSOC capabilities.

The role combines hands-on technical leadership with strategic vision, overseeing threat detection, incident response, and continuous improvement of security operations across the organization. The Lead will serve as the primary escalation point for analysts, translate leadership direction into actionable tasks, and partner with security teams to enhance detection maturity and

Qualifications

  • Bachelor’s degree in CS/IT/Cybersecurity or equivalent practical experience.
  • Security+ or GCIA/GCED equivalents.
  • 5–8+ years in cybersecurity operations or SOC environments.

Responsibilities

  • Oversee day-to-day security monitoring, detection, and response activities, ensuring high‑quality investigations and timely remediation of security events and incidents.
  • Act as the go‑to escalation resource for analysts, providing hands‑on guidance for complex investigations and ensuring depth in investigative outcomes.
  • Lead and coordinate complex security incidents end‑to‑end, acting as liaison between leadership and the SOC—translating strategic direction into actionable tasks and updates.
  • Lead SIEM‑driven operations and continuously improve detection capabilities through use‑case development, telemetry optimization, and enhanced coverage.
  • Break down strategic cybersecurity objectives into actionable workstreams, track progress, remove blockers, and ensure successful execution of team initiatives.
  • Create and refine incident response playbooks, SOPs, and automation opportunities to improve consistency, efficiency, and scalability of operations.
  • Track key operational metrics (MTTD, MTTR, alert fidelity) and conduct advanced threat analysis to inform decisions and strengthen defenses.

Skills

Threat detection
Incident response leadership
SIEM operations
Team leadership
Operational excellence

Education

Bachelor's degree in CS/IT/Cybersecurity
Security+ or GCIA/GCED equivalents

Tools

SIEM platforms
EDR
NDR
Email security
WAF

Job description

Description

About the Role: We are seeking a Lead, Cybersecurity Operations to play a critical role in advancing our global Cybersecurity Operations (CSOC) capabilities.

This individual will serve as a senior technical leader responsible for overseeing threat detection, incident response, and continuous improvement of security operations across the organization. As part of the Cybersecurity Operations Team, the Lead will drive operational excellence by enhancing detection strategies, improving incident response processes, and ensuring effective use of security technologies. This role acts as the primary technical escalation point for analysts and a key liaison between leadership and the SOC team—translating strategic direction into actionable work and ensuring meaningful outcomes.

This position requires a hands‑on leader with deep technical expertise, strong operational awareness, and a passion for elevating both team performance and cybersecurity capabilities in a fast‑paced, evolving threat landscape.

Responsibilities
  • Lead Cybersecurity Operations Execution & Quality: Oversee day‑to‑day security monitoring, detection, and response activities, ensuring high‑quality investigations and timely remediation of security events and incidents.
  • Serve as Primary Technical Escalation Point: Act as the go‑to escalation resource for analysts, providing hands‑on guidance for complex investigations and ensuring consistency and depth in investigative outcomes.
  • Own Incident Response Lifecycle & Stakeholder Coordination: Lead and coordinate complex security incidents end‑to‑end, while acting as a liaison between leadership and the SOC—translating strategic direction into actionable tasks and delivering clear, meaningful updates.
  • Drive Detection & Response Maturity (SIEM & Tooling): Lead SIEM‑driven operations and continuously improve detection capabilities through use‑case development, tuning, telemetry optimization, and enhanced coverage across security domains.
  • Coordinate SME Programs & Operational Initiatives: Break down strategic cybersecurity objectives into actionable workstreams, track progress, remove blockers, and ensure successful execution of team initiatives.
  • Develop & Optimize Playbooks, Processes, and Automation: Create and refine incident response playbooks, SOPs, and automation opportunities to improve consistency, efficiency, and scalability of operations.
  • Leverage Metrics & Threat Insights to Drive Improvement: Track key operational metrics (MTTD, MTTR, alert fidelity) and conduct advanced threat analysis to inform decisions, strengthen defenses, and continuously improve security posture.
Requirements
  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field (or equivalent practical experience).
  • Security+, GCIH, GCIA, GCED, or equivalent certifications.
  • 5–8+ years of experience in cybersecurity operations or SOC environments.
  • Proven experience leading or coordinating incident response activities.
  • Hands‑on experience with SIEM platforms and building detection‑driven operations.
  • Strong familiarity with security technologies such as EDR, NDR, email security, WAF, and identity/security monitoring tools.
EEO Information

Ritchie Bros. is an equal‑opportunity employer and ensures nondiscrimination in all activities in accordance with all applicable laws. This position is open to all qualified applicants who are legally entitled to work in the country in which this job is located. Candidate selection is made by Talent Acquisition. Only electronic applications can be accepted.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead, Cybersecurity Engineer Operations
Lead, Cybersecurity Engineer Operations

Ritchie Bros. • Westchester (IL)

On-site
USD 140,000 - 180,000
Lead Cyber Security Engineer (HYBRID)
Lead Cyber Security Engineer (HYBRID)

Phantom Staffing • Boston (MA)

Hybrid
USD 120,000 - 160,000
SOC Lead (Remote or Onsite)
SOC Lead (Remote or Onsite)

Crane Company • Stamford (CT)

On-site
USD 90,000 - 130,000
Sr. SOC Analyst
Sr. SOC Analyst

HW3 • Village of Great Neck (NY)

On-site
USD 130,000 - 170,000
Cyber Security Engineer—Technical Lead
Cyber Security Engineer—Technical Lead

Leidos • Bethesda (MD)

On-site
USD 150,000 - 180,000
Manager, Security Operations
Manager, Security Operations

Echo Global Logistics • Reno (NV)

On-site
USD 129,000 - 189,000
Bonus based on performance
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Ampcus Inc • Washington

On-site
USD 90,000 - 120,000
Sr. SOC Analyst
Sr. SOC Analyst

Insight Global • Santa Ana (CA)

On-site
USD 120,000 - 150,000
Cyber Security Engineer
Cyber Security Engineer

Empirical-Food • Dakota Dunes (SD)

On-site
USD 95,000 - 120,000
W2 - Lead of Cybersecurity Operations
W2 - Lead of Cybersecurity Operations

Acumenz Consulting • Richardson (TX)

Hybrid
USD 120,000 - 150,000