Security Operations & Engineering Lead

Jobtailor

Brea (CA)

On-site

USD 170,000 - 250,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Jobtailor is seeking an experienced security leader to guide enterprise security operations, incident response, and detection engineering across cloud, endpoint, identity, and SaaS environments. You will manage SIEM/SOAR tools, coordinate MSSP/MDR partnerships, and drive measurable risk reduction and executive reporting.

The role requires communicating risks to executives, leading security teams, and maturing a SOC program within a complex, multi-business context.

Qualifications

  • 7+ years in cybersecurity, security operations, detection engineering, incident response, or security engineering.
  • 5+ years leading security operations, engineering, SOC, or incident response teams.
  • Experience operating security capabilities across cloud, SaaS, endpoint, identity, and enterprise environments.

Responsibilities

  • Lead enterprise security operations including monitoring, triage, investigation, escalation, and response.
  • Oversee SOC and MSSP/MDR partnerships, including SLAs, alert quality, escalation paths, and performance metrics.
  • Define KPIs/KRIs including MTTD, MTTR, alert fidelity, detection coverage, and response effectiveness.
  • Own the incident response program, including playbooks, exercises, breach workflows, and communications.
  • Lead major incidents through containment, eradication, recovery, and root cause analysis.
  • Coordinate with Legal, Privacy, HR, IT, and Communications.

Skills

Incident Response
SIEM Management
Cloud Security
Detection Engineering
Automation
Risk Management
Zero Trust
Threat-Informed Detections
Leadership

Education

Bachelor's degree or equivalent

Tools

Microsoft Sentinel
Splunk
QRadar
Chronicle

Job description

  • Lead enterprise security operations including monitoring, triage, investigation, escalation, and response
  • Oversee SOC and MSSP/MDR partnerships, including SLAs, alert quality, escalation paths, and performance metrics
  • Establish 24x7 monitoring aligned to enterprise risk
  • Define KPIs/KRIs including MTTD, MTTR, alert fidelity, detection coverage, and response effectiveness
  • Lead lifecycle management of SIEM, SOAR, EDR/XDR, CSPM, DLP, identity security, and cloud security platforms
  • Drive automation across triage, enrichment, containment, and reporting workflows
  • Define enterprise logging and telemetry strategy, including onboarding, parsing, normalization, retention, and coverage standards
  • Ensure security tools are integrated, cost-effective, and aligned to risk priorities
  • Own the incident response program, including playbooks, exercises, breach workflows, and communications
  • Lead major incidents through containment, eradication, recovery, and root cause analysis
  • Ensure post-incident reviews drive durable control improvements
  • Coordinate with Legal, Privacy, HR, IT, and Communications
  • Build the detection engineering lifecycle from hypothesis through retirement
  • Develop behavior-based and threat-informed detections aligned to MITRE ATT&CK
  • Expand monitoring across endpoint, identity, cloud, SaaS, network, and critical applications
  • Identify and close detection gaps using red team, penetration test, and vulnerability insights
  • Support exposure management, asset inventory visibility, and attack surface monitoring
  • Drive continuous control monitoring and validation of key security controls
  • Improve vulnerability remediation workflows and risk reduction outcomes
  • Build and lead high-performing security operations and engineering teams
  • Establish clear roles, operating model, and accountability
  • Provide executive reporting on threats, incidents, control gaps, and maturity
  • Partner with GRC, Audit, IT, Architecture, and business leadership
Requirements
  • Candidates must reside within a commutable distance to both Brea, CA and Irvine, CA
  • Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Systems, Business, Engineering, or a related field OR equivalent industry experience, military service, professional certifications, and demonstrated leadership experience
  • 7+ years of experience in cybersecurity, security operations, detection engineering, incident response, or security engineering
  • 5+ years leading security operations, engineering, SOC, or incident response teams
  • Experience operating security capabilities across cloud, SaaS, endpoint, identity, and enterprise environments
  • Experience managing MSSP, MDR, SOC-as-a-Service, or strategic security service providers
  • Hands-on experience with SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, or Chronicle
  • Experience in Azure, AWS, or GCP environments
  • Understanding of Zero Trust security principles and modern detection strategies
  • Ability to communicate technical risks to executive leadership and business stakeholders
  • Experience coordinating investigations across security, IT, legal, privacy, HR, and executive stakeholders
  • Preferred: 10+ years of cybersecurity experience
  • Preferred: Experience building or transforming a SOC program
  • Preferred: Experience supporting a global or multi-business-unit environment
  • Preferred: Experience leading incident response for major cybersecurity events
  • Preferred: One or more certifications including CISSP, CISM, CCSP, GIAC, Microsoft Security, Splunk, Microsoft Sentinel, CrowdStrike, or AWS/Azure/GCP security certifications
Core Competencies

Demonstrates expertise in leading enterprise security operations, incident response, and detection engineering while effectively managing security tools and partnerships. Proficient in developing and implementing security strategies aligned with risk management and compliance requirements.

Highest-signal resume keywords
  • Cybersecurity Experience
  • Incident Response Leadership
  • SIEM Platform Management
  • Cloud Security Expertise
  • Detection Engineering
Hard Skills
  • Security Operations
  • Detection Engineering
  • Incident Response
  • Vulnerability Management
  • Automation
  • Risk Management
  • Behavior-Based Detections
  • Threat-Informed Detections
  • Continuous Control MonitoringPost-Incident Review
Soft Skills
  • Communication
  • Leadership
  • Collaboration
  • Accountability
  • Executive Reporting
Certifications & Qualifications
  • CISSP
  • CISM
  • CCSP
  • GIAC
  • Microsoft Security
  • CrowdStrike
  • AWS Security Certification
  • Azure Security Certification
  • GCP Security Certification
Industry Keywords
  • SOC
  • MSSP
  • MDR
  • Zero Trust
  • MITRE ATT&CK
  • Endpoint Security
  • Identity Security
  • Cloud Security
  • SaaS Security
  • Enterprise Risk
Tools & Technologies
  • SIEM
  • SOAR
  • EDR
  • XDR
  • CSPM
  • DLP
  • Microsoft Sentinel
  • Splunk
  • QRadar
  • Cloud Security Platforms
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Operations Manager
Cybersecurity Operations Manager

Jobtailor • Dearborn (MO)

On-site
USD 140,000 - 190,000
Senior Advanced Cyber Security Architect
Senior Advanced Cyber Security Architect

Jobtailor • Duluth (GA)

On-site
USD 120,000 - 160,000
Senior Incident Responder, Global CSIRT
Senior Incident Responder, Global CSIRT

Jobtailor • United States

On-site
USD 120,000 - 180,000
Security Operations Lead
Security Operations Lead

Jobtailor • Pennsylvania

On-site
USD 120,000 - 160,000
Senior SOC Engineer
Senior SOC Engineer

Jobtailor • North Carolina

On-site
USD 120,000 - 180,000
Senior Information Security Engineer – SIEM, Detection
Senior Information Security Engineer – SIEM, Detection

Jobtailor • Washington

On-site
USD 170,000 - 250,000
Senior Manager, Cybersecurity – TVM, SIEM/SOAR
Senior Manager, Cybersecurity – TVM, SIEM/SOAR

Jobtailor • Chicago (IL)

On-site
USD 120,000 - 160,000
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder

OneMain Financial • Washington

On-site
USD 140,000 - 190,000
Senior Information Technology Security Analyst
Senior Information Technology Security Analyst

Jobtailor • Philadelphia

On-site
USD 110,000 - 160,000
Lead, Incident Response – Global CSIRT
Lead, Incident Response – Global CSIRT

Jobtailor • United States

On-site
USD 150,000 - 190,000
Health insurance